Cyber Essentials vs ISO 27001: which first, and where the controls overlap
These two are not competing options. One is a technical baseline you can hold within weeks; the other is a management system that takes months and never really finishes. Most organisations end up doing both, in that order.
Written by Apexward Assure editorial team
Reviewed by Apexward Assure product team
Last reviewed: 30 August 2026
What each one actually is
Cyber Essentials is a UK government-backed scheme covering five technical control themes: firewalls, secure configuration, security update management, user access control and malware protection. You complete a self-assessment questionnaire, a certification body reviews and verifies your answers, and the certificate lasts twelve months. The question set is revised periodically, normally in April, so check which version is live before you start writing answers you will have to redo.
Cyber Essentials Plus is the same five themes with the self-assessment removed as the sole evidence. An assessor performs a hands-on technical audit: a sample of your devices is tested directly, with vulnerability scans of workstations and external addresses, tests of malware protection, and checks that account separation and multi-factor authentication behave as you said they do. It must follow within a defined window after your Cyber Essentials certification, so treat them as one exercise rather than two.
ISO 27001:2022 is a different kind of thing. It certifies an information security management system, not a list of settings. The standard’s clauses require you to define a scope, run a risk assessment and treatment process, set objectives, train people, conduct an internal audit and hold a management review. Annex A then offers 93 controls across four themes - organisational, people, physical and technological - which you select from, and justify excluding from, in a Statement of Applicability. Certification involves a two-stage audit by an accredited body, followed by surveillance audits across a three-year cycle.
The practical differences
| Cyber Essentials | ISO 27001:2022 | |
|---|---|---|
| What is certified | Five technical control themes | A management system plus selected controls |
| Typical elapsed time | Two to six weeks | Six to twelve months for a first certification |
| Who assesses | A certification body verifies your answers; Plus adds a technical audit | An accredited certification body, in two stages |
| Cycle | Annual, start again each year | Three-year cycle with annual surveillance audits |
| Ongoing burden | Low, provided your estate does not drift | Continuous: audits, reviews, corrective actions |
| Who asks for it | UK public sector, MOD supply chain, UK SME customers | Enterprise procurement, regulated sectors, international buyers |
Which one first
Cyber Essentials first, in almost every case. The reasoning is not that it is easier. It is that the five themes are the controls an ISO 27001 auditor will look at anyway, they are the controls that actually reduce your exposure to commodity attacks, and you can hold the certificate before an ISO 27001 project has finished defining its scope. A supplier who needs something to put in a tender next month has exactly one option here.
There are real exceptions. If the contract that triggered all of this specifies ISO 27001 with a deadline, go straight at it, because Cyber Essentials will not satisfy the clause. If your buyers are outside the UK, Cyber Essentials will not be recognised and ISO 27001 will. And if you already run a mature security function with documented risk management, the ISO 27001 gap may be smaller than it looks, in which case sequencing matters less.
Doing them at the same time is a common mistake in small teams. Both need the same two or three people, and the ISO project will absorb all available attention while the Cyber Essentials deadline is the one your customer is actually watching.
Where the controls overlap
The overlap is genuine but asymmetric. Everything Cyber Essentials asks for appears somewhere in Annex A. Very little of what ISO 27001 asks for appears in Cyber Essentials.
- Firewalls and network security. Boundary firewall configuration, administrative interfaces and default credentials map onto the Annex A network security and network services controls.
- Secure configuration. Removal of unnecessary software and accounts, disabled auto-run and device hardening map onto configuration management.
- Security update management. Patching within defined timeframes maps directly onto the technical vulnerability management control, and the evidence is the same evidence: a scan report and a patch policy.
- User access control. Account provisioning, least privilege, separated administrative accounts and multi-factor authentication map onto the identity, access rights and authentication controls, which are among the most heavily sampled in an ISO audit.
- Malware protection. Maps onto protection against malware, more or less verbatim.
The Cyber Essentials Plus audit is worth more than it looks in this context. Its output is independent technical verification that those controls are operating, which is precisely what an ISO 27001 auditor asks you to demonstrate for the technological controls. The device sample, the scan results and the remediation record are reusable evidence.
What does not transfer
The management system is the part you cannot shortcut, and it is most of the work. Nothing in Cyber Essentials asks you to define an information security scope, maintain a risk register with owners and treatment decisions, produce a Statement of Applicability, run an internal audit programme, or hold a documented management review with evidence that leadership acted on it. Nor does it touch supplier security, physical security, secure development, business continuity, personnel screening or incident management, all of which sit in Annex A.
Be realistic about that when you plan. Organisations that treat ISO 27001 as an extended Cyber Essentials arrive at their Stage 1 audit with excellent technical controls and no management system, and Stage 1 is specifically the audit that checks for the management system.
A sensible sequence
Get Cyber Essentials, and get it properly rather than optimistically: the certificate is only worth what your answers were. Add Cyber Essentials Plus if a customer asks for it or if you want the technical verification, which most organisations find catches something. Then, if ISO 27001 is genuinely required, start with scope and risk assessment rather than with controls, and use the Cyber Essentials evidence you already hold for the technological part of Annex A.
The one thing that makes both harder than they need to be is keeping evidence in one place for one scheme. Apexward Assure runs Cyber Essentials, Cyber Essentials Plus, ISO 27001 and the Defence Cyber Certification as a single compliance programme, with each piece of evidence mapped to every control it satisfies, and continuous monitoring to tell you when a control has drifted rather than finding out at the next assessment. It is free to use, so it costs nothing to see whether the mapping saves you the second collection. Certification itself is awarded by a certification body, not by the platform.