When a procurement team sees Cyber Essentials, they learn your organisation has the technical basics, boundary protection, secure configuration, patching discipline, access control and malware defence, verified against a government-backed standard within the last 12 months. It says nothing about your governance, your suppliers, your incident process or how you'll behave as the relationship grows.
When they see ISO 27001, they learn an accredited auditor has examined how you manage information security as a system: leadership accountability, risk assessment, supplier management, incident response, continual improvement, plus the technical controls. That is why enterprise and international buyers weight it so heavily, and why it costs one to two orders of magnitude more to achieve. Neither certificate is ‘better’; they are evidence at different altitudes.
Read the contract language literally. ‘Cyber Essentials’ and ‘ISO 27001’ are not interchangeable to the buyer who wrote the clause, and satisfying the wrong one satisfies nothing.
For UK organisations without either certificate, the economics usually point one way: do Cyber Essentials first. It closes live technical risk in weeks, satisfies UK public-sector baselines immediately, and costs less than a day of ISO consultancy. Then, if and when buyer demand justifies it, begin ISO 27001, reusing CE's asset registers, access controls and patching discipline as ready-made Annex A evidence.
The reverse order, starting a six-month ISO programme while tenders requiring CE pass by, burns opportunity for no benefit, since CE certification typically falls out of a competent ISO implementation almost for free anyway. The only common exception: contracts that explicitly demand ISO 27001 on a deadline, in which case run CE in parallel during month one of the ISO programme.
Certification strategy is procurement strategy. Start from what your next twelve months of buyers will ask for, and sequence backwards from that.
The practical differences that drive the decision, current as of July 2026.
| Dimension | Cyber Essentials | ISO 27001 |
|---|---|---|
| What it certifies | Five technical controls (firewalls, secure configuration, updates, access control, malware protection) | A full Information Security Management System: governance, risk, people, suppliers, technology (93 Annex A controls) |
| Assessment | Verified self-assessment (Danzell v3.3); Plus adds an independent technical audit | Stage 1 + Stage 2 audits by a UKAS-accredited certification body, then annual surveillance |
| Typical cost | £320–£600 + VAT fee; CE Plus £1,400–£4,000+ VAT for SMEs | £25k–£150k+ implementation plus £8k–£25k audit fees over the first 3-year cycle |
| Time to certify | Days–weeks | Typically 4–9 months |
| Recognition | UK-specific; mandated across government and MOD supply chains | International; the default enterprise and cross-border credential |
| Validity cycle | 12 months, full annual reassessment | 3-year certificate with annual surveillance audits |
| Ongoing effort | Low: maintain the five controls | Significant: a living management system with audits, reviews and improvement cycles |
| Best first step for | UK SMEs, public-sector suppliers, fast credibility | Enterprise sellers, international expansion, regulated sectors |
Figures are typical UK market ranges as of July 2026; ISO 27001 costs vary widely with scope and organisation size.
Book a call and we’ll read your actual contract requirements with you, then recommend CE, ISO 27001, or both, in the order that wastes nothing.