top of page
AAA's logo
  • Facebook
  • Twitter
  • Linkedin
Search

We Already Have Cyber Essentials Plus – Do We Still Need ISO 27001?

7 days ago
6 min read
Neon-lit laptop with futuristic interface showing DATABASE, CONFIG, LOGOUT and ENTER COMMAND: L over glowing keyboard

For many UK businesses, Cyber Essentials is the first formal cyber security certification they achieve.


Some then progress to Cyber Essentials Plus, complete the technical assessment and quite reasonably think:


“If we've already got Cyber Essentials Plus, why would we need ISO 27001 as well?”


It's a good question.


After all, both are associated with information security, both can provide assurance to customers, and both regularly appear in supplier questionnaires and tender requirements.


But they are not interchangeable.


For some businesses, Cyber Essentials Plus may provide exactly the level of assurance their customers need.


For others, particularly those moving into larger contracts or handling more sensitive information, ISO 27001 can become the next requirement.


The key is understanding what each certification is actually demonstrating.


The short answer

Cyber Essentials Plus and ISO 27001 address information security from different angles.


Cyber Essentials Plus provides strong assurance around a defined set of technical cyber security controls.


ISO 27001 looks much more broadly at how the organisation manages information security risk as a whole.


That includes technology, but also people, suppliers, processes, responsibilities, incidents, business continuity and management oversight.


So having Cyber Essentials Plus does not automatically mean you already meet ISO 27001.


Equally, having ISO 27001 does not mean a customer asking specifically for Cyber Essentials Plus will necessarily waive that requirement.


If a tender names one of them specifically, you need to pay attention to what it actually asks for.


What Cyber Essentials Plus is really demonstrating

Cyber Essentials focuses on practical protections against common internet-based cyber threats.


Cyber Essentials Plus goes further by introducing independent technical testing to verify that the required controls are working.


For many smaller and medium-sized businesses, this is extremely useful.


It provides customers with independent assurance that fundamental protections are in place rather than relying entirely on the organisation saying:


“Yes, we're secure.”


That can be particularly valuable where customers are concerned about the technical basics.


But information security does not stop at the technical perimeter.


And that is where ISO 27001 becomes different.


ISO 27001 asks a broader question

ISO 27001 is less about passing a defined technical security test and more about demonstrating that the organisation has a structured system for managing information security risk.


Consider a business that has excellent technical controls.


Its devices are secured. Updates are applied. Access is restricted. Malware protection is in place.


But what happens when:


  • an employee leaves?

  • a supplier starts processing sensitive customer information?

  • a new SaaS application is introduced?

  • an information-security incident occurs?

  • senior management accepts a significant security risk?

  • critical information becomes unavailable?


Those issues cannot be managed through technical configuration alone.


They require processes, responsibilities and management decisions.


ISO 27001 is designed around that wider management system.


Why larger customers often ask for more

This distinction becomes particularly noticeable as businesses move into larger supply chains.


A smaller customer might mainly want reassurance that your IT environment has sensible cyber security protections.


A larger organisation may want to understand how security is governed across your entire business.


Its security questionnaire might ask:


Who is responsible for information security?

How do you assess risk?

How are suppliers reviewed?

How do you manage incidents?

How do you control employee access?

How are security objectives monitored?

How does senior management review security performance?


At this point, the conversation has moved beyond purely technical cyber controls.


The customer is asking whether information security is being managed.


That is where ISO 27001 can provide additional assurance.


Does Cyber Essentials Plus help if you want ISO 27001?

Absolutely.


A business that has already achieved Cyber Essentials Plus is likely to have addressed several important technical areas.


That provides a useful foundation.


It may mean that some of the technical controls required within your wider information-security arrangements are already established and independently tested.


But ISO 27001 will require you to look beyond those controls.


You will need to consider areas such as:


  • your information-security risk assessment

  • roles and responsibilities

  • information assets

  • supplier security

  • employee security

  • incident management

  • continuity arrangements

  • internal auditing

  • management review

  • continual improvement


The work therefore shifts from:


“Do we have these technical controls?”


towards:


“How do we systematically manage information-security risk across the organisation?”


The supplier question becomes much bigger

Supplier management is a good example of the difference.


A company can have very strong internal technical security but still rely on external providers for:


  • cloud hosting

  • payroll

  • CRM

  • file storage

  • IT support

  • software development


Those organisations may hold or access significant amounts of your information.


ISO 27001 therefore expects you to think about the risks created by those relationships.


Who has access to what?

What security requirements have you placed on the supplier?

What happens if the supplier suffers an incident?

How do you review whether it remains suitable?


Cyber security increasingly depends on the wider ecosystem around the business, not simply the devices inside it.


People matter just as much as technology

The same applies internally.


Technical controls can reduce risk, but employees still make decisions every day.


They share information.

Approve access.

Use cloud applications.

Respond to suspicious emails.

Work remotely.

Handle customer information.


Information security therefore also depends on:


  • competence

  • awareness

  • responsibilities

  • access management

  • onboarding

  • role changes

  • leavers


ISO 27001 brings those areas into the management system.


The aim is to make security part of how the organisation operates rather than treating it solely as an IT responsibility.


What if a tender asks for ISO 27001?

This is the important commercial point.


If a tender states that ISO 27001 certification is mandatory, having Cyber Essentials Plus does not automatically mean the requirement has been met.


They are different certifications.


Likewise, telling the buyer:


“We have Cyber Essentials Plus, which is basically the same thing”

is unlikely to help, because it isn't the same thing.


The buyer may allow equivalent evidence, but only if the procurement rules say it will.


Where the requirement is unclear, ask.


Do not spend time guessing what procurement meant.


What if the tender asks for Cyber Essentials Plus and you already have ISO 27001?

The same principle applies in reverse.


An organisation with ISO 27001 may have a mature information security management system.


But if a contract specifically requires Cyber Essentials Plus, you should not simply assume ISO 27001 replaces it.


Some buyers want the specific technical assurance that Cyber Essentials Plus provides.


Others may accept alternatives.


Again, the buyer's requirement determines the answer.


So do you need both?

Possibly.


There are plenty of organisations for which holding both makes commercial sense.


Cyber Essentials Plus can demonstrate independently tested technical cyber security controls.


ISO 27001 can demonstrate the wider system used to manage information-security risks across the organisation.


Together they answer slightly different customer questions.


But that does not mean every business should immediately pursue both.


The commercial case depends on who you sell to.


Look at what your customers are actually asking for

Before deciding on your next certification, look at the evidence already coming from your market.


Review:


  • supplier questionnaires

  • tender requirements

  • framework applications

  • enterprise customer security reviews

  • recent sales opportunities

  • customer contracts


If Cyber Essentials Plus satisfies those requirements, you may have no immediate reason to add ISO 27001.


If ISO 27001 is starting to appear repeatedly, that is a different signal.


At that point, the absence of certification may start becoming a barrier to the type of work you want to win.


The wrong reason to get ISO 27001

The weakest reason is simply:


“Everyone seems to be getting it.”


ISO 27001 requires ongoing management.


There are internal audits, management reviews, risk assessments, controls and surveillance audits to maintain.


It should therefore solve a genuine business requirement.


Good reasons might include:


  • customers are requesting it

  • tenders require it

  • enterprise sales are being delayed by security assurance

  • sensitive information is central to your service

  • the business needs a more structured approach to security risk


If none of those apply, certification may not yet be the priority.


The wrong assumption if you already have Cyber Essentials Plus

The other mistake is assuming there will be nothing left to do.


Cyber Essentials Plus can give you a head start.


But ISO 27001 is not simply a bigger technical cyber security assessment.


You may already be technically well controlled while still needing to develop areas around governance, risk, suppliers, people, auditing and management oversight.


That is why understanding your starting point matters before setting a certification deadline.


Which should you do first?

For some businesses, Cyber Essentials or Cyber Essentials Plus is a logical first step.

It creates a practical baseline and can satisfy many customer requirements.


For others, particularly where enterprise customers are already demanding ISO 27001, it may make sense to start building the wider management system earlier.


There is no universal sequence.


The best route is the one aligned with:

the customers you want to win and the risks your organisation actually needs to manage.


Not sure whether Cyber Essentials Plus is enough?

If your customers are beginning to ask about ISO 27001, it is worth understanding the gap before deciding whether another certification is necessary.


Our free ISO readiness check can help you understand:


  • whether ISO 27001 is relevant to your business

  • how much of the required framework may already be in place

  • where likely gaps exist

  • what your practical next step should be


👉 Take the free ISO readiness check here: https://www.aaa-cert.co.uk/get-certified-the-quick-and-easy-way


Final thought

Cyber Essentials Plus and ISO 27001 should not really be viewed as competitors.


They answer different questions.


Cyber Essentials Plus provides valuable assurance around core technical cyber protections.


ISO 27001 asks whether the organisation has a systematic way of identifying, managing and continually reviewing information-security risk.


For many businesses, Cyber Essentials Plus will be enough for the customers they serve today.


The question is whether it will still be enough for the customers they want to serve tomorrow.

 
 
 

Comments


bottom of page