Compliance
Cyber Essentials or ISO 27001: which one first
A UK-specific answer, including what each one actually costs in time rather than in certification fees, and when doing both is the wrong idea.
They are not competing options
Cyber Essentials is a UK government-backed scheme covering five technical control areas. It is a baseline, it is deliberately narrow, and it can be achieved in weeks. ISO 27001 is an international standard for an information security management system. It is broad, it is about process and governance as much as technology, and it takes months.
The question is almost never which one is better. It is which one the person asking you for it actually needs, and how soon.
| Cyber Essentials | ISO 27001 | |
|---|---|---|
| Scope | Five technical control areas | Whole management system |
| Typical time to achieve | 2 to 6 weeks | 6 to 12 months |
| External audit required | Plus only | |
| Recognised outside the UK | ||
| Required by UK public sector contracts | Often | Sometimes |
| Annual renewal | Surveillance audits |
Timescales are typical rather than guaranteed and depend heavily on estate size and starting maturity.
The five Cyber Essentials control areas
Firewalls, secure configuration, user access control, malware protection and security update management. In a Microsoft estate these map closely onto Intune configuration profiles, Defender policies, Entra ID access controls and update rings, which is why a well-managed Microsoft 365 tenant can often get most of the way there quickly.
The area that trips people up is update management, specifically the requirement to patch within a defined window. Organisations with unmanaged or long-lived devices fail here more than anywhere else.
When doing both at once is a mistake
If a contract requires ISO 27001 within a year, do not spend the first two months on Cyber Essentials to feel productive. The technical overlap is real but modest, and the scarce resource in an ISO project is the time of the people who must write the documentation. Cyber Essentials consumes exactly those people.
Doing both makes sense when you need Cyber Essentials for a specific near-term contract and ISO 27001 for a longer-term commercial reason. Then the sequence is deliberate rather than accidental.
If you want the evidence work automated
Optional, and genuinely not required. Plenty of organisations certify on spreadsheets.
Compliance automation with Microsoft 365 connectors
- Best for
- Teams heading for ISO 27001 or SOC 2 who would otherwise gather evidence by hand every quarter
- Watch out for
- It automates evidence, not the management system. You still write the scope, the risk assessment and the statement of applicability
Links above go to the vendor. Where a link is marked as an affiliate link, a purchase may earn this site a commission at no cost to you, and it played no part in the ranking.
The verdict
Cyber Essentials first, for most UK organisations
It is achievable in weeks, it is what UK public sector and many private contracts actually ask for, and the five control areas are genuine security improvements rather than paperwork.
ISO 27001 first
The right order when a named contract requires it, when you sell internationally, or when a customer security questionnaire has already asked for it.
Do neither yet if you have no contractual driver and no customer asking. Fix multi-factor authentication coverage and backup restore testing first. Both do more for your actual risk than either certificate.
Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.