Cyber Essentials vs Cyber Assurance vs ISO 27001: Which Route?
Published 16 July 2026
What each one actually proves
Cyber Essentials
Five technical controls verified by self-assessment, reviewed by an IASME-licensed assessor. Proves you have the technical baseline that blocks the most common opportunistic attacks.
IASME Cyber Assurance
14 themes across 4 areas covering people, process, technology and risk. Includes CE as a mandatory prerequisite plus governance evidence – policies, risk register, business continuity. See the 14 themes deep dive.
ISO 27001
A full Information Security Management System (ISMS) audited by a UKAS-accredited certification body. Continual improvement cycle, internal audits, management reviews, documented controls against Annex A. International recognition.
Side-by-side comparison
| Cyber Essentials | Cyber Assurance | ISO 27001 | |
|---|---|---|---|
| Typical cost | £320–£600 + VAT | £1.8k–£5k + VAT | £15k–£40k all-in |
| Time to certify | 1–2 weeks | 4–8 weeks | 6–12 months |
| Audit type | Self-assessment + assessor review | Assessor desk review (L1) or audit (L2) | Stage 1 + Stage 2 + surveillance |
| Renewal | Annual | L1 annual, L2 every 3 yrs | 3-year cycle + annual surveillance |
| Tender weight | Public sector baseline | Mid-market, regulated SMEs | Enterprise, international |
| Internal audit needed | No | No (L2 has external) | Yes, recurring |
| UK-only | Yes | Yes | International |
Decision tree
- Have you been asked by a UK buyer or grant funder? Start with CE.
- Are buyers also asking about policies, risk register, BCP? Add CA.
- Are you selling to enterprises, regulated sectors or internationally? Move to ISO 27001.
- Are you only being asked once a year by one customer? CE alone may suffice.
- Are you holding sensitive personal data at volume? Aim at CA minimum.
The trap: skipping straight to ISO 27001
We regularly see SMEs commit £30k to ISO 27001 before they have CE. The result is an ISMS built on a technical baseline that has never been independently checked. CE first, CA second, ISO third is the cheaper, faster, more defensible sequence.
What about NIS2, DORA, CSR Bill?
The forthcoming UK Cyber Security and Resilience Bill raises the floor for regulated sectors and their suppliers. Even where the new law applies, CE remains the practical baseline and CA the governance layer. ISO 27001 is a sufficient – often more than sufficient – way to evidence the duty for larger organisations.
