Cyber Essentials vs ISO 27001: which does your customer actually want?
Check the exact customer or tender requirement before choosing Cyber Essentials, Plus or ISO 27001. Compare their different assurance purposes and permitted evidence.

Section 01
Cyber Essentials vs ISO 27001: which does your customer actually want?
When a customer asks for "security certification", first ask which certificate or controls the contract actually requires. Cyber Essentials, Cyber Essentials Plus and ISO 27001 address different assurance tasks. Choosing by questionnaire length or a general sector label can lead you to buy the wrong evidence.
This guide is for UK suppliers comparing those tasks. The buyer's tender, contract and accepted equivalents decide whether a particular certificate satisfies its requirement.
Section 02
The short decision tree
If the request names Cyber Essentials or Plus: check the required level, legal entity, scope and deadline. Do not substitute ISO 27001 without the buyer's agreement. Fig Group's published Basic prices start at £299.99 + VAT; Plus is a separate technical assessment with its own pricing and schedule. Compare the current tiers.
If the request includes a long supplier-risk questionnaire: inspect the actual questions and evidence instructions. Its question count alone does not establish a requirement for ISO 27001, SOC 2 or Cyber Essentials; ask whether the buyer accepts another form of evidence.
If the request asks for baseline technical controls: Cyber Essentials may be a good fit, subject to the buyer's stated scope and acceptance criteria. A certificate does not answer every governance or product-specific assurance question.
If the buyer is in a regulated or public sector: read its actual tender and applicable assurance rules. Current PPN 014 applies to specified procurements by central-government bodies and NHS bodies; it calls for relevant, proportionate controls and permits equivalent evidence. Procurements begun before 24 February 2025 can fall under the preceding note.
Section 03
When Cyber Essentials is sufficient
Cyber Essentials covers five technical control categories: firewalls, secure configuration, user access control, malware protection, and security update management. It is a verified self-assessment, not an ISO 27001 management-system certificate. PPN 014 says in-scope buyers should require Cyber Essentials, Plus or equivalent controls where relevant and proportionate, rather than applying the scheme to every contract.
Cyber Essentials is the right answer when:
- The customer asks for "Cyber Essentials" by name.
- You are bidding on a public-sector tender where CE is the stated minimum.
- You are a supplier in a private-sector supply chain and the ask is for "baseline cyber hygiene evidence".
- Your insurer explicitly accepts Cyber Essentials for the relevant condition.
- Your deadline allows for preparation and a complete, compliant Basic submission before midday UK time on a UK Business Day. Fig Group's six-working-hour Basic assessment guarantee is subject to its certification terms; it is not a promise to remedy an unprepared estate before tomorrow's tender.
Section 04
When ISO 27001 is the real requirement
ISO/IEC 27001 is a management-system standard covering an information security management system (ISMS), including risk assessment, control selection, internal audit and management review. Its scope and certification process differ from the five Cyber Essentials technical control categories.
ISO 27001 is the right answer when:
- The contract explicitly requires ISO 27001 certification for the relevant scope, or the buyer confirms it accepts that route.
- You are asked for an ISMS and its risk-management evidence, not only a baseline technical certificate.
- A sector-specific obligation or customer requirement calls for broader assurance; confirm its actual scope and permitted evidence rather than inferring ISO 27001 from the sector alone.
Section 05
The overlap: using CE as a foundation for ISO 27001
Cyber Essentials evidence can inform an ISO 27001 risk assessment and some selected technological controls. It does not establish that every Annex A control is implemented or that an ISMS has passed an ISO audit. Map the actual CE scope and evidence to the controls selected in your ISO statement of applicability.
What ISO 27001 requires on top:
- An ISMS scope statement (sections 4.3 of the standard).
- A risk assessment methodology and risk register (section 6).
- Policies and evidence for relevant people, physical, supplier, continuity and incident-response controls.
- Internal audits and management reviews.
- A Statement of Applicability (SoA) documenting which Annex A controls are in and out of scope, and why.
Practical sequence: confirm the buyer's required evidence and timing, then select Basic, Plus, ISO 27001 or an accepted equivalent. If you later pursue ISO 27001, retain relevant CE evidence as input to the ISMS; the project schedule depends on your scope and current controls.
Section 06
What to say to the customer
If you are not sure what the customer wants, ask: "Which certificate, scope and accepted equivalents does this contract require, and when must we hold them?" If the buyer has not decided, agree the assurance objective before choosing a scheme. Plus provides third-party technical testing, but it is not an automatic substitute for an ISMS or every procurement requirement.
Section 07
Bottom line
The right evidence follows the buyer's actual requirement. Cyber Essentials addresses a verified technical baseline; Plus tests it; ISO 27001 certifies a management system. A long DDQ or regulated-sector label does not choose for you.
Use existing CE evidence where it fits, and pursue ISO 27001 when the buyer or your own risk programme calls for it.
Compare Cyber Essentials and Plus | See current pricing | Read about the Fig Group platform
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
See how Fig Group simplifies certification and framework alignment for your organisation.
Request a demoRelated solutions
Continue exploring Fig Group
Related guides
Continue reading
Guides
Who needs Cyber Essentials Plus?
Cyber Essentials Plus is needed when a tender, contract, framework, customer, or risk decision explicitly requires independently tested assurance. Contract value alone does not determine the level.
Read articleFrameworks
Does Your G-Cloud Contract Require Cyber Essentials?
A G-Cloud listing does not automatically require a Cyber Essentials certificate, but many call-off contracts can require Cyber Essentials, Cyber Essentials Plus, or equivalent controls. Here is how to identify the requirement and act before contract award.
Read articleCompliance
How Long Does Defence Cyber Certification Take? Realistic Timelines for L0 and L1
DCC Level 0 is typically 2-3 weeks; Level 1 is typically 6-10 weeks for a prepared organisation. The slowest end of the L1 band stretches to 16+ weeks. This guide breaks down where the time actually goes, what you can compress, and what you cannot. Caveat: timelines reflect Fig Group published delivery model. Other IASME-licensed Certification Bodies may publish different timelines - verify before committing to a tender deadline.
Read article

