Cyber Essentials vs ISO 27001 for G-Cloud Suppliers
Published 29 July 2026
Why ISO 27001 does not replace Cyber Essentials
ISO 27001 is an information security management system standard – it covers governance, risk and controls at a policy and process level. Cyber Essentials is a technical-control certification against a specific NCSC-defined baseline. G-Cloud 15 and GCA declarations name Cyber Essentials specifically. Your ISO certificate does not tick the CE box, however comprehensive it is.
Where each one wins
- Cyber Essentials – required, fast (days to weeks), affordable (£320 + VAT), technical-control focused.
- ISO 27001 – optional at G-Cloud level, slow (6 to 12 months), expensive (typically £15k+), governance and risk focused.
- IASME Cyber Assurance – the affordable middle ground for governance maturity. See Cyber Assurance vs ISO 27001.
What G-Cloud 15 evaluators actually score
The framework question set uses Cyber Essentials as a mandatory gate. Additional standards (ISO 27001, ISO 27017, ISO 27018, SOC 2) may be scored favourably at the call-off stage depending on the buyer, but they do not substitute at framework qualification.
Practical sequence for G-Cloud suppliers
- Get Cyber Essentials first – it unlocks framework eligibility.
- If a specific lot names it, add Cyber Essentials Plus.
- If you sell governance maturity to enterprise or public sector buyers, add IASME Cyber Assurance or ISO 27001.
Cost and time comparison
- CE: days, £320 + VAT.
- CE Plus: 1 to 3 weeks, £1,400 + VAT.
- Cyber Assurance Level 1: verified self-assessment, weeks, £320 + VAT.
- Cyber Assurance Level 2: audit, months, quote-based.
- ISO 27001: 6 to 12 months, £15,000+.
For the evergreen comparison (not framework-specific), see Cyber Essentials vs ISO 27001. To move fast on the framework requirement, open the G-Cloud 15 hub.
