Why organisations still need Cyber Essentials certification, even if they have ISO27001

Book a free no obligation informal chat

Online meeting

Discuss what you need to protect, improve or understand with Oxford Systems.

Book your meeting

Does a business still benefit from Cyber Essentials if it already holds ISO/IEC 27001 certification? The two approaches can work together, but they have different purposes. Understanding that distinction helps leaders make informed decisions about security, customer expectations and preparation for assessment.

Different certifications, complementary assurance

Business leaders discussing security governance and technical assurance

ISO/IEC 27001 establishes requirements for an information security management system. It helps an organisation manage information security risks through people, processes and technology, with continuing review and improvement. Cyber Essentials has a different focus: a defined baseline of technical controls designed to address common internet-based threats. An ISO/IEC 27001 certificate should therefore not be treated as a Cyber Essentials certificate.

For managers, the useful question is what assurance the business and its customers need. Review the scope of your existing certification, the services you deliver and any requirements in customer agreements. Cyber Essentials can complement the management system by providing evidence against its own technical requirements. Plan both activities together so that responsibilities, evidence and improvements support a coherent security programme.

ISO: ISO/IEC 27001 · NCSC: Cyber Essentials

Check the technical controls in practice

Security assessment workstation with network equipment and monitoring dashboards

The five Cyber Essentials control areas are firewalls, secure configuration, security update management, user access control and malware protection. They address practical safeguards on the technology your organisation uses. Policies and risk assessments are valuable, but the team still needs to establish whether the relevant systems meet the current Cyber Essentials requirements.

Ask the responsible technical team to compare the assessment questions with actual settings and working practices. Check that device and software records are accurate, access is reviewed and updates have clear owners. Where a gap is found, agree an action, a realistic completion date and evidence that the improvement works. Raising an issue early gives management time to address dependencies and operational constraints before submitting an assessment.

NCSC: the five technical controls

Give customers and suppliers clear evidence

Digital approval records and a signing key representing supplier assurance evidence

Customers may require Cyber Essentials certification from suppliers even when those suppliers already hold ISO/IEC 27001 certification. The two certificates answer different assurance questions. Check each procurement or contract requirement directly, including the required certification level and scope, rather than assuming that one qualification will automatically satisfy a request for the other.

Procurement and security teams should agree what evidence they need and how it relates to the service being supplied. Review the certificate, its scope and its validity, alongside other relevant due diligence. Certification supports a conversation about security; it does not replace understanding the supplier’s access, dependencies or responsibilities. Making these expectations clear at the outset can reduce uncertainty during onboarding and contract renewal.

IASME: supply-chain assurance

Turn the assessment into a manageable plan

Start by reviewing the current Cyber Essentials assessment questions and infrastructure requirements, then identify the work needed before applying. Cyber Essentials uses a verified self-assessment. Cyber Essentials Plus adds independent technical testing of the same control areas. Choose the level that meets your customer requirements and assurance needs, with guidance from a Certification Body where necessary.

Use your existing management processes to assign an accountable lead, coordinate technical changes and keep evidence organised. Include the IT provider, service owners and commercial team where their input is needed. Cyber Essentials certification is renewed annually, so build the review into a continuing improvement cycle. Oxford Systems can help you discuss the requirements and practical next steps without losing sight of the wider security objectives of your business.

IASME: assessment and preparation · IASME: certification and renewal

Contact us