Cyber Essentials, Cyber Essentials Plus or ISO 27001: which does my business need?
The short answer: Cyber Essentials is the UK government-backed basic: it proves you have the core security controls in place, and it's usually the first thing customers, insurers and public-sector contracts ask for. Cyber Essentials Plus is the same standard, but an assessor tests your systems to check it's true. ISO 27001 is the international standard for running information security properly across your whole business, and it's what larger customers and regulated sectors expect. Most small businesses start with Cyber Essentials, add Plus when a customer asks for it, and go for ISO 27001 only when contracts or growth demand it.
The three side by side
| Cyber Essentials | Cyber Essentials Plus | ISO 27001 | |
|---|---|---|---|
| What it proves | You've put five core security controls in place | The same, independently tested | You run information security as an ongoing, risk-based system |
| How it's checked | Online self-assessment questionnaire, verified by a certification body | The questionnaire plus a hands-on technical audit of a sample of your devices and accounts | Two-stage audit by an accredited certification body, then yearly checks |
| Lasts | 12 months | 12 months | 3 years, with yearly surveillance audits |
| Typical effort for a small business | Days to a few weeks | A few weeks, including fixing what the test finds | Several months |
| Recognised | UK | UK | Worldwide |
| Typical trigger | Government contracts, insurers, supply chain questionnaires | Customers or contracts that want proof, not a self-assessment | Enterprise customers, regulated sectors, international work |
Cyber Essentials: the essential first step
Cyber Essentials is a UK scheme backed by the National Cyber Security Centre (NCSC) and delivered by IASME. It covers five areas that stop the most common attacks:
- Firewalls: controlling what can get into your network and devices.
- Secure configuration: removing default passwords and unnecessary software.
- User access control: only giving people the access they need, and protecting accounts properly.
- Malware protection: antivirus and blocking untrusted software.
- Security update management: keeping operating systems, apps and firmware patched.
You answer an online questionnaire about how your business works, and a certification body reviews it. The current version (v3.3, for assessments started from late April 2026) is stricter than before: multi-factor authentication (MFA) must be switched on for every cloud service that offers it, and missing it on an in-scope service is an automatic fail. High-risk and critical updates must be applied within 14 days. Cloud services like Microsoft 365 are firmly in scope.
Cost: IASME's certification fee depends on the size of your business. At the time of writing it starts from about £320 plus VAT for businesses with fewer than 10 staff. Getting help to prepare costs extra.
A useful bonus: UK businesses with a turnover under £20 million that certify their whole business with Cyber Essentials are entitled to free cyber liability insurance, subject to the scheme's terms. Check the current details with IASME when you apply.
Cyber Essentials Plus: the same standard, proven
Plus covers exactly the same five controls. The difference is that an assessor checks them for real. They typically:
- scan your internet-facing systems for weaknesses;
- test a sample of your computers and phones to check they're patched and protected;
- check that malicious emails and downloads would be blocked;
- confirm that accounts really do need MFA.
You need a current Cyber Essentials certificate first, and the Plus audit has to be completed within three months of it. Plus costs more than the basic certificate because of the testing time, and it's common to find a few things to fix along the way. That's the point: it catches the gaps a questionnaire can miss.
ISO 27001: the full management system
ISO/IEC 27001 is different in kind. Rather than a fixed checklist, it requires you to run an information security management system (ISMS): a way of working that identifies your risks, decides how to handle them, and keeps improving.
In practice that means:
- agreeing the scope (which parts of the business, which locations, which services);
- carrying out a risk assessment and deciding how to treat each risk;
- choosing controls from Annex A, which in the current 2022 version has 93 controls in four themes: organisational, people, physical and technological;
- writing a Statement of Applicability that explains which controls you use and why;
- policies, staff training, supplier checks, incident handling and business continuity;
- internal audits and management reviews, so the system keeps working after the certificate arrives.
Certification is by an accredited certification body (look for UKAS accreditation in the UK). There's a Stage 1 audit that reviews your documents and readiness, then a Stage 2 audit that checks you actually work that way. Certificates last three years, with surveillance audits each year in between.
Effort: for a small business, getting ready typically takes several months, depending on how much is already in place and how much time you can give it. Costs include the certification body's audits plus any consultancy and tools.
Which should you go for?
- You're asked for "Cyber Essentials" on a tender or by your insurer: get Cyber Essentials. It's quick, affordable and often required for UK government contracts that handle personal data.
- A customer wants evidence, not a self-assessment: go for Cyber Essentials Plus.
- Enterprise customers send you long security questionnaires, or you work in finance, health, legal, tech or with international clients: plan for ISO 27001. Many businesses get Cyber Essentials first and then build towards ISO 27001, because the controls overlap.
- Nobody's asking yet: Cyber Essentials is still worth doing. It closes the holes most attacks rely on, and it's a strong selling point.
How Microsoft 365 helps
A well set up Microsoft 365, especially Business Premium, covers a lot of the technical ground for all three:
- MFA and Conditional Access for account protection;
- Intune to enforce device settings, encryption and updates;
- Defender for malware protection on computers and email;
- audit logs, data protection and secure sharing settings that support ISO 27001 controls.
But owning the licences isn't enough. What assessors care about is how it's configured and whether every account and device is covered. See Which Microsoft 365 plan do I need?
Common questions
Can a small business get ISO 27001?
Yes. The standard is the same for everyone, but the scope, documents and controls can be sized to a small business. Plenty of businesses with fewer than 20 staff hold it.
Does ISO 27001 replace Cyber Essentials?
Not formally. They're separate schemes, and UK public-sector contracts often ask for Cyber Essentials specifically, even if you hold ISO 27001. Because the technical controls overlap, having one makes the other much easier.
How long does Cyber Essentials take?
If your setup is in good shape, the questionnaire itself can be done in a day or two. Most of the time goes on fixing gaps first, typically MFA, old devices or missing updates.
What happens if we fail?
For Cyber Essentials, the certification body tells you what didn't meet the standard, and you fix it and resubmit within the scheme's rules. For ISO 27001, auditors raise "nonconformities" that you need to correct, and minor ones don't stop certification.
Where do we start?
Find out where you stand. Our free Microsoft 365 audit shows the gaps that matter most for Cyber Essentials, such as MFA, admin accounts and updates. If you need certification, see our Cyber Essentials and ISO 27001 support.
Want us to check yours?
Our free Microsoft 365 audit looks at your licences, security, email and backups, and tells you in plain English what to fix first. No card, no obligation.