Most businesses shopping for security certification are answering the wrong question. Not “which standard is best”, because none of them is best. The real question is: who is going to ask you to prove your security, and what will satisfy them? Answer that, and the standard picks itself.
Here is the honest comparison. We are a licensed certification body for two of these three and consult on the third, so we make money whichever one you choose. That is precisely why you should trust what follows: we have no reason to steer you up the ladder.
Three numbers, one story. Each standard certifies more than the last, costs more than the last, and answers a harder question than the last. The mistake is thinking that makes the biggest one the right one.
The comparison
| Cyber Essentials | IASME Cyber Assurance | ISO 27001 | |
|---|---|---|---|
| What it certifies | Five technical controls are in place | Security is actually managed: governance, risk, people, data protection, resilience | A complete information security management system |
| How it’s assessed | Verified self-assessment; Plus adds independent testing | Level One verified assessment; Level Two independently audited | External audit by an accredited certification body, then surveillance every year |
| Who asks for it | Government contracts, insurers, supply chain questionnaires | Supply chains wanting governance evidence beyond the basics | Large enterprises, regulated sectors, international customers |
| Typical effort | Days to weeks of housekeeping | Weeks; scales with your size | Months, and a permanent ongoing commitment |
| Certification cost | £320 to £600 + VAT, set by IASME | Sized to your organisation | Thousands annually, before the implementation cost |
| We certify it | Yes, both levels | Yes, both levels | No; nobody you hire as a consultant can. We prepare you for it |
What each one is really for
Cyber Essentials answers: are the basics done? Firewalls, secure configuration, updates, access control, malware protection. It will not impress a Fortune 500 procurement team, and it is not trying to. What it does is take you out of the population that gets breached by accident, which is most of the breached population. Ask yourself honestly: could you evidence all five today? I bet at least one would take you a fortnight. That fortnight is the point.
IASME Cyber Assurance answers: is security actually run? Not just configured once and forgotten. Who owns risk? Who checks the backups restore? What happens when someone leaves, when a laptop vanishes, when the questionnaire asks about your data protection? Fourteen themes, audited at Level Two, sized so a five-person firm is not drowned in a fifty-person firm’s paperwork. It exists because there is a canyon between Cyber Essentials and ISO 27001, and most UK businesses live in it.
ISO 27001 answers: can you prove it to anyone, anywhere, indefinitely? It is the international heavyweight, and when a customer demands it, nothing else substitutes. But understand what you are signing up for: a management system that must be operated, audited and evidenced every year, forever. Bought for the right reasons, it is a serious asset. Bought because it sounded the most impressive, it becomes a shelf of documents that fails its first surveillance audit, and deserves to.
The decision, in four rules
- No certification yet? Cyber Essentials. Always. It is the prerequisite for Cyber Assurance, the foundation for ISO 27001, and the highest-value security work per pound a small business can do. There is no scenario where skipping it is clever.
- A specific customer demands a specific standard? That standard. This is not a philosophical choice. Read the contract. If it says ISO 27001, Cyber Assurance will not substitute, and arguing is a way to lose the work.
- Questionnaires asking about governance and data protection, not just technical controls? Cyber Assurance. It answers both categories of question with one certificate, at a weight your business can actually carry.
- Nobody is asking for anything? Then do Cyber Essentials for yourself and stop there for now. Certifications you collect for decoration are the most expensive kind.
The part nobody selling certification says out loud
A certificate never secured anything. The work behind it did. The certificate is how you prove the work to people who cannot inspect it themselves, which is why the right standard is always the one your customers recognise, never the one with the most controls in it.
And the ladder is real: the five controls become the technical foundation of Cyber Assurance’s fourteen themes, which become the operational core of an ISO 27001 management system. Businesses that climb it in order find each rung cheaper than the last one’s horror stories suggested. Businesses that leap to the top rung pay consultants to build what the lower rungs would have taught them.
Still unsure which one your situation points at? Get in touch. One conversation, and we will tell you which standard your obligations actually require, including when the answer is the cheapest one, or none at all yet.