Guide · Standards compared

Cyber Essentials vs ISO 27001: what's the difference?

They're often named in the same breath, but they're different animals. Cyber Essentials is a pass/fail baseline of technical hygiene. ISO 27001 is a full information-security management system. One says "you have these basic protections in place"; the other says "you run a managed system that decides, implements and improves your security." Here's how they compare, where they overlap, and which one you need.

Cyber Essentials, in one line

Cyber Essentials is a UK government-backed scheme covering a defined set of basic technical controls — firewalls, secure configuration, user access control, malware protection and security update (patch) management. Certification is essentially pass/fail against those controls: the standard version is self-assessed and verified, and Cyber Essentials Plus adds a hands-on technical audit. It's quick, affordable, and a genuinely good baseline — and it's sometimes required for certain UK public-sector contracts.

ISO 27001, in one line

ISO/IEC 27001 is the international standard for an information security management system (ISMS). It isn't just a checklist of controls — it's the whole system around them: understanding your context and risks, deciding which controls apply (and recording that in a Statement of Applicability), setting objectives, running internal audits and management reviews, and improving continually. It's independently audited over a multi-year cycle. Far broader, and far deeper.

The key difference: controls vs a system

Cyber Essentials checks that you have certain technical controls at a point in time. ISO 27001 requires you to run a managed system that works out which controls you need on a risk basis, implements them, and keeps improving. Cyber Essentials is a snapshot of hygiene; ISO 27001 is an ongoing discipline. That's the distinction most comparisons miss — and it's why the two aren't interchangeable.

Overlap is real — but overlap isn't a pass. The technical controls Cyber Essentials checks do map to some of ISO 27001's technological controls, so work done for one helps toward the other. But that's a handful of controls — a small slice of ISO 27001, whose controls span organisational, people, physical and technological themes, on top of the entire management-system layer Cyber Essentials doesn't address. Holding Cyber Essentials does not make you "a third of the way" to ISO 27001; it means a few of the technological controls are in good shape. See how far your standards actually overlap →

Which do you need?

For many organisations it isn't either/or: they achieve Cyber Essentials first as a fast, affordable baseline, then build toward ISO 27001 — using the former as a stepping stone to the technical hygiene the latter also expects. If a tender is driving this, this guide covers where each standard shows up in bids →

What about SOC 2?

SOC 2 is the comparison US customers more often raise — a US-centric attestation covering similar ground to ISO 27001 but structured differently. SOC 2 vs ISO 27001 covers that properly. For UK buyers, Cyber Essentials is usually the one that comes first.

Where Kavorly fits

Kavorly runs the ISO 27001 management system — context, risk, Statement of Applicability, audits, management review and the controls beneath them — and maps the controls you implement toward other frameworks, so work done once counts where it applies. For the technical controls that Cyber Essentials and ISO 27001 share, it reads the real posture of your own Microsoft 365 tenant rather than relying on screenshots.

How ISO 27001 evidence works → · ISO 27001 vs ISO 42001 →


This guide is a general introduction, not certification advice. Cyber Essentials and ISO/IEC 27001 requirements are defined by their respective schemes and standards; refer to the official scheme documentation and a certification body for the authoritative detail.

Questions

Before you pick the wrong badge.

We have Cyber Essentials. Are we part-way to ISO 27001?

You're in good shape on a handful of technical controls — firewalls, patching, access, malware, secure configuration. That work isn't wasted. It is not a slice of the management system: risk assessment, internal audit, management review and the rest of ISO 27001 still have to be built and run.

A tender asked for Cyber Essentials. Should we skip ISO 27001?

Only if that's the only security ask you'll meet. Cyber Essentials is often the UK public-sector baseline and it's quicker. ISO 27001 is what shows up when a buyer wants a managed system, not a snapshot. Read the next few questionnaires you care about before you decide.

Is Cyber Essentials Plus basically ISO 27001?

No. Plus adds a hands-on technical test of the same Cyber Essentials controls. ISO 27001 is a different thing: an independently audited management system on a three-year cycle.

We already hold ISO 27001. Do we still need Cyber Essentials?

Often yes, if UK public contracts or a specific buyer still list it. It's a cheap extra once the technical hygiene is already there. It doesn't replace 27001, and 27001 doesn't always replace it on a pre-qualification form.

Next step

Working out which standard to chase?

See how far your standards already overlap — free, no sign-up — or check your ISO 27001 readiness in three minutes.