Skip to content

The Cyber Essentials scheme

What is the difference between Cyber Essentials and ISO 27001?

Cyber Essentials tests five technical control areas. ISO/IEC 27001 certifies an information security management system against its selected scope, risk treatment and applicable Annex A controls, documented in a Statement of Applicability. They answer different buyer requirements; use the written contract to choose the right assurance. See our Cyber Essentials versus ISO 27001 guide for a comparison.

Short answer

Cyber Essentials tests five technical control areas. ISO/IEC 27001 certifies an information security management system against its selected scope, risk treatment and applicable Annex A controls, documented in a Statement of Applicability. They answer different buyer requirements; use the written contract to choose the right assurance. See our Cyber Essentials versus ISO 27001 guide for a comparison.

Why this matters

This question affects how buyers compare Cyber Essentials with broader assurance schemes. Cyber Essentials is a baseline technical certification, so the useful answer is not only what the scheme is called, but what it proves, who administers it, and when a buyer should ask for Cyber Essentials Plus or a wider framework such as ISO 27001.

For procurement teams, the practical test is whether the certificate covers the organisation and scope named in the contract. For applicants, the practical test is whether the five technical controls are implemented across the devices, users, networks, and cloud services that access organisational data.

What to check next

  • Confirm the certificate holder and scope match the buyer requirement.
  • Check whether the contract asks for Cyber Essentials or Cyber Essentials Plus.
  • Use the IASME Certificate search tool to verify a certificate before relying on it.

Official sources and related Fig Group guidance

For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.