Skip to content
Frameworks

Cyber Essentials vs ISO 27001: which does your customer actually want?

Check the exact customer or tender requirement before choosing Cyber Essentials, Plus or ISO 27001. Compare their different assurance purposes and permitted evidence.

silhouette of road signage during golden hour

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

11 min read

Share

Section 01

Cyber Essentials vs ISO 27001: which does your customer actually want?

When a customer asks for "security certification", first ask which certificate or controls the contract actually requires. Cyber Essentials, Cyber Essentials Plus and ISO 27001 address different assurance tasks. Choosing by questionnaire length or a general sector label can lead you to buy the wrong evidence.

This guide is for UK suppliers comparing those tasks. The buyer's tender, contract and accepted equivalents decide whether a particular certificate satisfies its requirement.

Section 02

The short decision tree

If the request names Cyber Essentials or Plus: check the required level, legal entity, scope and deadline. Do not substitute ISO 27001 without the buyer's agreement. Fig Group's published Basic prices start at £299.99 + VAT; Plus is a separate technical assessment with its own pricing and schedule. Compare the current tiers.

If the request includes a long supplier-risk questionnaire: inspect the actual questions and evidence instructions. Its question count alone does not establish a requirement for ISO 27001, SOC 2 or Cyber Essentials; ask whether the buyer accepts another form of evidence.

If the request asks for baseline technical controls: Cyber Essentials may be a good fit, subject to the buyer's stated scope and acceptance criteria. A certificate does not answer every governance or product-specific assurance question.

If the buyer is in a regulated or public sector: read its actual tender and applicable assurance rules. Current PPN 014 applies to specified procurements by central-government bodies and NHS bodies; it calls for relevant, proportionate controls and permits equivalent evidence. Procurements begun before 24 February 2025 can fall under the preceding note.

Section 03

When Cyber Essentials is sufficient

Cyber Essentials covers five technical control categories: firewalls, secure configuration, user access control, malware protection, and security update management. It is a verified self-assessment, not an ISO 27001 management-system certificate. PPN 014 says in-scope buyers should require Cyber Essentials, Plus or equivalent controls where relevant and proportionate, rather than applying the scheme to every contract.

Cyber Essentials is the right answer when:

  • The customer asks for "Cyber Essentials" by name.
  • You are bidding on a public-sector tender where CE is the stated minimum.
  • You are a supplier in a private-sector supply chain and the ask is for "baseline cyber hygiene evidence".
  • Your insurer explicitly accepts Cyber Essentials for the relevant condition.
  • Your deadline allows for preparation and a complete, compliant Basic submission before midday UK time on a UK Business Day. Fig Group's six-working-hour Basic assessment guarantee is subject to its certification terms; it is not a promise to remedy an unprepared estate before tomorrow's tender.

Section 04

When ISO 27001 is the real requirement

ISO/IEC 27001 is a management-system standard covering an information security management system (ISMS), including risk assessment, control selection, internal audit and management review. Its scope and certification process differ from the five Cyber Essentials technical control categories.

ISO 27001 is the right answer when:

  • The contract explicitly requires ISO 27001 certification for the relevant scope, or the buyer confirms it accepts that route.
  • You are asked for an ISMS and its risk-management evidence, not only a baseline technical certificate.
  • A sector-specific obligation or customer requirement calls for broader assurance; confirm its actual scope and permitted evidence rather than inferring ISO 27001 from the sector alone.

Section 05

The overlap: using CE as a foundation for ISO 27001

Cyber Essentials evidence can inform an ISO 27001 risk assessment and some selected technological controls. It does not establish that every Annex A control is implemented or that an ISMS has passed an ISO audit. Map the actual CE scope and evidence to the controls selected in your ISO statement of applicability.

What ISO 27001 requires on top:

  • An ISMS scope statement (sections 4.3 of the standard).
  • A risk assessment methodology and risk register (section 6).
  • Policies and evidence for relevant people, physical, supplier, continuity and incident-response controls.
  • Internal audits and management reviews.
  • A Statement of Applicability (SoA) documenting which Annex A controls are in and out of scope, and why.

Practical sequence: confirm the buyer's required evidence and timing, then select Basic, Plus, ISO 27001 or an accepted equivalent. If you later pursue ISO 27001, retain relevant CE evidence as input to the ISMS; the project schedule depends on your scope and current controls.

Section 06

What to say to the customer

If you are not sure what the customer wants, ask: "Which certificate, scope and accepted equivalents does this contract require, and when must we hold them?" If the buyer has not decided, agree the assurance objective before choosing a scheme. Plus provides third-party technical testing, but it is not an automatic substitute for an ISMS or every procurement requirement.

Section 07

Bottom line

The right evidence follows the buyer's actual requirement. Cyber Essentials addresses a verified technical baseline; Plus tests it; ISO 27001 certifies a management system. A long DDQ or regulated-sector label does not choose for you.

Use existing CE evidence where it fits, and pursue ISO 27001 when the buyer or your own risk programme calls for it.

Compare Cyber Essentials and Plus | See current pricing | Read about the Fig Group platform

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

See how Fig Group simplifies certification and framework alignment for your organisation.

Request a demo