Guide · Standards compared
Cyber Essentials vs ISO 27001: what's the difference?
They're often named in the same breath, but they're different animals. Cyber Essentials is a pass/fail baseline of technical hygiene. ISO 27001 is a full information-security management system. One says "you have these basic protections in place"; the other says "you run a managed system that decides, implements and improves your security." Here's how they compare, where they overlap, and which one you need.
Cyber Essentials, in one line
Cyber Essentials is a UK government-backed scheme covering a defined set of basic technical controls — firewalls, secure configuration, user access control, malware protection and security update (patch) management. Certification is essentially pass/fail against those controls: the standard version is self-assessed and verified, and Cyber Essentials Plus adds a hands-on technical audit. It's quick, affordable, and a genuinely good baseline — and it's sometimes required for certain UK public-sector contracts.
ISO 27001, in one line
ISO/IEC 27001 is the international standard for an information security management system (ISMS). It isn't just a checklist of controls — it's the whole system around them: understanding your context and risks, deciding which controls apply (and recording that in a Statement of Applicability), setting objectives, running internal audits and management reviews, and improving continually. It's independently audited over a multi-year cycle. Far broader, and far deeper.
The key difference: controls vs a system
Cyber Essentials checks that you have certain technical controls at a point in time. ISO 27001 requires you to run a managed system that works out which controls you need on a risk basis, implements them, and keeps improving. Cyber Essentials is a snapshot of hygiene; ISO 27001 is an ongoing discipline. That's the distinction most comparisons miss — and it's why the two aren't interchangeable.
Overlap is real — but overlap isn't a pass. The technical controls Cyber Essentials checks do map to some of ISO 27001's technological controls, so work done for one helps toward the other. But that's a handful of controls — a small slice of ISO 27001, whose controls span organisational, people, physical and technological themes, on top of the entire management-system layer Cyber Essentials doesn't address. Holding Cyber Essentials does not make you "a third of the way" to ISO 27001; it means a few of the technological controls are in good shape. See how far your standards actually overlap →
Which do you need?
- Cyber Essentials — if you want a quick, affordable security baseline, or a specific contract (often UK public sector) asks for it.
- ISO 27001 — if customers or tenders require a recognised information-security management system, you handle significant data, or you sit in a supply chain with security obligations.
For many organisations it isn't either/or: they achieve Cyber Essentials first as a fast, affordable baseline, then build toward ISO 27001 — using the former as a stepping stone to the technical hygiene the latter also expects. If a tender is driving this, this guide covers where each standard shows up in bids →
What about SOC 2?
SOC 2 is the comparison US customers more often raise — a US-centric attestation covering similar ground to ISO 27001 but structured differently. SOC 2 vs ISO 27001 covers that properly. For UK buyers, Cyber Essentials is usually the one that comes first.
Where Kavorly fits
Kavorly runs the ISO 27001 management system — context, risk, Statement of Applicability, audits, management review and the controls beneath them — and maps the controls you implement toward other frameworks, so work done once counts where it applies. For the technical controls that Cyber Essentials and ISO 27001 share, it reads the real posture of your own Microsoft 365 tenant rather than relying on screenshots.
How ISO 27001 evidence works → · ISO 27001 vs ISO 42001 →
This guide is a general introduction, not certification advice. Cyber Essentials and ISO/IEC 27001 requirements are defined by their respective schemes and standards; refer to the official scheme documentation and a certification body for the authoritative detail.