Cyber Essentials vs ISO 27001, the Honest UK Cost and Time Comparison
Net Sec Group is an IASME and NCSC certification body. We sit on one side of this comparison and have nothing to sell on the other, which lets us put a real price on Cyber Essentials next to a credible UK SME estimate for ISO 27001 without hand-waving the ISO numbers. This article is the comparison on the two metrics buyers actually use to decide: total UK cost and total weeks-to-certificate. The four-row decision table sits below; the buyer-profile mapping that follows tells you which row is yours.
The article sits on the comparisons hub. For the related self-cert-versus-assisted decision (which is its own choice once a buyer picks the certification path), see Cyber Essentials self-certification vs assisted. For the broader Net Sec Group treatment with ISO 27001 control mapping detail, see Cyber Essentials vs ISO 27001 on netsecgroup.io.
What Cyber Essentials and ISO 27001 actually are
Cyber Essentials is a UK government-backed certification scheme administered by IASME on behalf of the NCSC. It tests five technical controls against a Self-Assessment Questionnaire (CE Basic) plus an optional technical assessment day (CE Plus). The certificate is recognised across UK central and local government procurement; current procurement policy (PPN 03/23, May 2023) requires Cyber Essentials for relevant contracts handling personal data and certain ICT services.
ISO/IEC 27001 is an international standard for an Information Security Management System (ISMS). The certification process tests the firm's ISMS against the standard's clauses and against a control set published as Annex A. Certification is granted by a UKAS-accredited certification body (separate from the consultancy that helps prepare the ISMS) following a stage 1 (documentation review) and stage 2 (audit) cycle, with annual surveillance audits and a re-certification audit at year three.
The two are not the same kind of artefact. Cyber Essentials is a technical-controls certification with a UK procurement-recognised stamp. ISO 27001 is a management-system certification with international procurement recognition and a heavier evidence load.
The four-row decision table
| Path | Total UK cost band | Weeks-to-certificate | Typical buyer profile | Recommendation | |---|---|---|---|---| | CE Basic | from £320 (Net Sec Group fast-track tier price; see pricing page) | 1 to 7 days | Contract-driven SME, tender requires CE | Start here | | CE Plus | £1,200 to £2,450 typical SME engagement (£1,500 to £3,000 when CE Basic and pre-assessment readiness are combined into one engagement; see CE Plus options) | 4 to 12 weeks total runway (3 to 5 days assessor engagement on top of preparation) | Procurement-led SME, contract requires CE Plus or stronger assurance | Direct path | | ISO 27001 | £8,000 to £30,000 typical UK SME (consultancy plus UKAS-accredited certification body fees, year 1) | 6 to 12 months | Enterprise pursuing multi-year procurement, international customer base, regulated sector | Plan for the long cycle | | CE Plus plus ISO 27001 | CE Plus engagement plus ISO 27001 cycle (sequenced, controls map onto Annex A subset) | 7 to 14 months total | Buyers committing to both for procurement and international standing | Sequence CE Plus first, then layer ISO |
The cost bands for CE come from the Net Sec Group pricing page; the .io site lists the published fast-track and standard tiers transparently. The ISO 27001 bands are typical UK SME cost ranges referenced to UKAS-accredited certification bodies; we do not publish a CB-specific ISO price because Net Sec Group does not certify ISO 27001 and we are not naming a commercial CB.
Buyer profile 1, contract-driven SME
Profile: a 5 to 50 person UK firm with a procurement requirement on the desk. The buyer's question is "what gets us through the procurement gate fastest and cheapest?". The answer is CE Basic if the contract requires CE, CE Plus if the contract requires CE Plus or stronger assurance, ISO 27001 only if the contract names ISO 27001 specifically.
Recommendation: start at CE Basic. The 12-hour fast-track engagement covers the case where the contract closes next week. The 7-day prep plan and 30-day prep plan cover the cases with more runway. CE Plus is the next layer if the contract escalates the requirement.
What ISO 27001 buys you that CE does not: a management-system certificate that documents the firm's whole ISMS, internationally recognised. For a contract-driven SME with no international customer base, the ISMS-documentation overhead is rarely justified by the procurement value of the contract.
Buyer profile 2, procurement-led SME pursuing CE Plus directly
Profile: a UK SME where procurement-grade assurance is part of the firm's competitive positioning, not just a tender-driven response. The buyer wants the higher-assurance certificate from the start.
Recommendation: CE Plus, with CE Basic as the prerequisite. Total runway 4 to 12 weeks depending on the firm's starting state on the five controls. Net Sec Group runs both CE Basic and CE Plus engagements; see CE Basic options and CE Plus options for the engagement structures.
What ISO 27001 buys you that CE Plus does not: international recognition. For a UK-only customer base, CE Plus is the higher-recognised certificate in UK procurement contexts; ISO 27001 becomes meaningful at the point the firm starts pursuing customers outside the UK with an information-security expectation that names ISO.
Buyer profile 3, enterprise pursuing multi-year procurement or international customers
Profile: a UK firm with a multi-year procurement strategy, an international customer base, or operating in a regulated sector where the regulator expects ISMS-style evidence (financial services, healthcare, defence-adjacent).
Recommendation: ISO 27001, with CE Plus as a complementary layer. The two are not redundant: ISO 27001 documents the management system; CE Plus documents the technical controls assessed against UK government scheme requirements. UK government procurement processes routinely accept both.
Cost-and-time reality: ISO 27001 stage 1 and stage 2 audits run 6 to 12 months from project start, including ISMS-build consultancy time. The UKAS-accredited certification body fees are 30 to 50 per cent of the total cost; consultancy is the larger share. Year 2 and 3 surveillance audits are smaller, year 3 re-certification rebuilds toward the original cost. CE Plus alongside is a 4 to 12 week parallel project.
Buyer profile 4, regulated sector or compliance-mandated buyer
Profile: a firm in a sector where the regulator (FCA, MHRA, MoD, NHS Digital) expects evidence the firm operates an ISMS or equivalent.
Recommendation: ISO 27001 to satisfy the regulator. CE Plus alongside if the firm is also bidding into UK government procurement that names CE.
The pragmatic note: regulators rarely accept CE alone as ISMS evidence. CE tests technical controls; the regulator wants ISMS-level documentation that ISO 27001 produces. The decision is not about cost; the decision is about regulatory acceptance.
How CE Plus controls map onto ISO 27001 Annex A
This section is the practitioner observation that buyers committing to both should know. The five Cyber Essentials controls map onto a subset of ISO 27001 Annex A controls; the work done for CE Plus is not wasted on the ISO project, it is foundational.
| CE control | ISO 27001 Annex A controls (current 2022 version) | |---|---| | Boundary firewalls and internet gateways | A.8.20 (Network security), A.8.21 (Security of network services), A.8.22 (Segregation of networks) | | Secure configuration | A.8.9 (Configuration management), A.8.27 (Secure system architecture) | | User access control | A.5.15 (Access control), A.5.16 (Identity management), A.5.18 (Access rights), A.8.5 (Secure authentication) | | Malware protection | A.8.7 (Protection against malware) | | Security update management | A.8.8 (Management of technical vulnerabilities) |
The mapping does not run the other way: ISO 27001 contains many controls that CE does not test (risk assessment, supplier relationships, incident management, business continuity, training and awareness, internal audit, management review). Doing CE Plus does not give you ISO 27001; doing ISO 27001 covers the CE Plus technical scope but does not produce the IASME-issued CE certificate that UK procurement specifically asks for.
For the deeper technical mapping detail, see Cyber Essentials vs ISO 27001 on netsecgroup.io and the Cyber Essentials Basic vs Plus reference for the within-CE comparison. For the SOC 2 question (a different US-recognised standard buyers sometimes ask about), see Cyber Essentials vs SOC 2.
Common questions
My contract requires "Cyber Essentials or equivalent". Does ISO 27001 count?
UK procurement routinely accepts ISO 27001 as equivalent to CE for contract-acceptance purposes when the contract uses "or equivalent" language. The cleanest route, where the choice is open, is the lower-cost CE certificate; ISO 27001 carries broader value but the certification cost and runway are the trade-off.
My customer asked specifically for ISO 27001. Will CE Plus do?
No, not when ISO is named specifically. The customer is asking for ISMS evidence; CE does not produce ISMS evidence. The decision is between buying ISO 27001 and turning down the customer.
Can I do CE Plus while the ISO 27001 project is in flight?
Yes, and this is the cleanest sequencing for buyers committing to both. CE Plus runs 4 to 12 weeks; ISO 27001 runs 6 to 12 months. Run CE Plus in the first quarter of the ISO project; the technical-controls evidence captured for CE Plus feeds directly into the ISO Annex A evidence pack.
Is the £8,000 to £30,000 ISO 27001 estimate realistic for a 10-person firm?
The lower end is realistic for a 10-person firm with a clean cloud-only architecture, an experienced IS lead in-house, and a tight scope statement. The higher end is realistic for a 10-person firm with multi-environment infrastructure, no in-house IS leadership, and a broad scope. Mid-band (£15,000 to £20,000) is the typical landing point.
My business is multi-tenant SaaS with US customers. CE or ISO?
ISO 27001 is the answer for US-customer recognition. CE is the answer for UK procurement. Multi-tenant SaaS firms in this position typically pursue both (and SOC 2 for the US enterprise market on top); the Cyber Essentials vs SOC 2 reference covers the SOC 2 question.
My company is in a regulated sector (FCA, NHS Digital, MoD). What does the regulator actually expect?
ISO 27001 in regulated UK sectors generally. The regulator's published expectations are the authoritative source; consult the latest sector-specific guidance, not generic certification-comparison articles. CE alongside ISO is helpful but not a substitute.
Where do we book CE?
Book a Cyber Essentials assessment with Net Sec Group. The booking form lets you describe whether you are pursuing CE alone or CE alongside an ISO 27001 project; the assessor responds with a confirmed engagement timeline.
Reference material
- Cyber Essentials vs ISO 27001 (the deeper Net Sec Group comparison)
- Cyber Essentials vs SOC 2
- Cyber Essentials Basic vs Plus
- CE Basic options
- CE Plus options
- Cost calculator
Where this fits on this site
This article is the cost-and-time comparison spoke under the comparisons hub. The other comparisons spoke is Cyber Essentials self-certification vs assisted, which is the next decision once the buyer chooses CE. For the engagement-speed paths once CE is the chosen certification, see the timelines hub.