Skip to main content
    NixInfinity-AI
    Pillar Comparison

    Cyber Essentials vs Cyber Assurance vs ISO 27001: Which Route?

    Published 16 July 2026

    What each one actually proves

    Cyber Essentials

    Five technical controls verified by self-assessment, reviewed by an IASME-licensed assessor. Proves you have the technical baseline that blocks the most common opportunistic attacks.

    IASME Cyber Assurance

    14 themes across 4 areas covering people, process, technology and risk. Includes CE as a mandatory prerequisite plus governance evidence – policies, risk register, business continuity. See the 14 themes deep dive.

    ISO 27001

    A full Information Security Management System (ISMS) audited by a UKAS-accredited certification body. Continual improvement cycle, internal audits, management reviews, documented controls against Annex A. International recognition.

    Side-by-side comparison

     Cyber EssentialsCyber AssuranceISO 27001
    Typical cost£320–£600 + VAT£1.8k–£5k + VAT£15k–£40k all-in
    Time to certify1–2 weeks4–8 weeks6–12 months
    Audit typeSelf-assessment + assessor reviewAssessor desk review (L1) or audit (L2)Stage 1 + Stage 2 + surveillance
    RenewalAnnualL1 annual, L2 every 3 yrs3-year cycle + annual surveillance
    Tender weightPublic sector baselineMid-market, regulated SMEsEnterprise, international
    Internal audit neededNoNo (L2 has external)Yes, recurring
    UK-onlyYesYesInternational

    Decision tree

    • Have you been asked by a UK buyer or grant funder? Start with CE.
    • Are buyers also asking about policies, risk register, BCP? Add CA.
    • Are you selling to enterprises, regulated sectors or internationally? Move to ISO 27001.
    • Are you only being asked once a year by one customer? CE alone may suffice.
    • Are you holding sensitive personal data at volume? Aim at CA minimum.

    The trap: skipping straight to ISO 27001

    We regularly see SMEs commit £30k to ISO 27001 before they have CE. The result is an ISMS built on a technical baseline that has never been independently checked. CE first, CA second, ISO third is the cheaper, faster, more defensible sequence.

    What about NIS2, DORA, CSR Bill?

    The forthcoming UK Cyber Security and Resilience Bill raises the floor for regulated sectors and their suppliers. Even where the new law applies, CE remains the practical baseline and CA the governance layer. ISO 27001 is a sufficient – often more than sufficient – way to evidence the duty for larger organisations.

    Specific comparisons

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions