Most businesses shopping for security certification are answering the wrong question. Not “which standard is best”, because none of them is best. The real question is: who is going to ask you to prove your security, and what will satisfy them? Answer that, and the standard picks itself.

Here is the honest comparison. We are a licensed certification body for two of these three and consult on the third, so we make money whichever one you choose. That is precisely why you should trust what follows: we have no reason to steer you up the ladder.

5Controls in Cyber Essentials
14Themes in IASME Cyber Assurance
93Annex A controls in ISO 27001

Three numbers, one story. Each standard certifies more than the last, costs more than the last, and answers a harder question than the last. The mistake is thinking that makes the biggest one the right one.

The comparison

Cyber EssentialsIASME Cyber AssuranceISO 27001
What it certifiesFive technical controls are in placeSecurity is actually managed: governance, risk, people, data protection, resilienceA complete information security management system
How it’s assessedVerified self-assessment; Plus adds independent testingLevel One verified assessment; Level Two independently auditedExternal audit by an accredited certification body, then surveillance every year
Who asks for itGovernment contracts, insurers, supply chain questionnairesSupply chains wanting governance evidence beyond the basicsLarge enterprises, regulated sectors, international customers
Typical effortDays to weeks of housekeepingWeeks; scales with your sizeMonths, and a permanent ongoing commitment
Certification cost£320 to £600 + VAT, set by IASMESized to your organisationThousands annually, before the implementation cost
We certify itYes, both levelsYes, both levelsNo; nobody you hire as a consultant can. We prepare you for it

What each one is really for

Cyber Essentials answers: are the basics done? Firewalls, secure configuration, updates, access control, malware protection. It will not impress a Fortune 500 procurement team, and it is not trying to. What it does is take you out of the population that gets breached by accident, which is most of the breached population. Ask yourself honestly: could you evidence all five today? I bet at least one would take you a fortnight. That fortnight is the point.

IASME Cyber Assurance answers: is security actually run? Not just configured once and forgotten. Who owns risk? Who checks the backups restore? What happens when someone leaves, when a laptop vanishes, when the questionnaire asks about your data protection? Fourteen themes, audited at Level Two, sized so a five-person firm is not drowned in a fifty-person firm’s paperwork. It exists because there is a canyon between Cyber Essentials and ISO 27001, and most UK businesses live in it.

ISO 27001 answers: can you prove it to anyone, anywhere, indefinitely? It is the international heavyweight, and when a customer demands it, nothing else substitutes. But understand what you are signing up for: a management system that must be operated, audited and evidenced every year, forever. Bought for the right reasons, it is a serious asset. Bought because it sounded the most impressive, it becomes a shelf of documents that fails its first surveillance audit, and deserves to.

The decision, in four rules

  1. No certification yet? Cyber Essentials. Always. It is the prerequisite for Cyber Assurance, the foundation for ISO 27001, and the highest-value security work per pound a small business can do. There is no scenario where skipping it is clever.
  2. A specific customer demands a specific standard? That standard. This is not a philosophical choice. Read the contract. If it says ISO 27001, Cyber Assurance will not substitute, and arguing is a way to lose the work.
  3. Questionnaires asking about governance and data protection, not just technical controls? Cyber Assurance. It answers both categories of question with one certificate, at a weight your business can actually carry.
  4. Nobody is asking for anything? Then do Cyber Essentials for yourself and stop there for now. Certifications you collect for decoration are the most expensive kind.

The part nobody selling certification says out loud

A certificate never secured anything. The work behind it did. The certificate is how you prove the work to people who cannot inspect it themselves, which is why the right standard is always the one your customers recognise, never the one with the most controls in it.

And the ladder is real: the five controls become the technical foundation of Cyber Assurance’s fourteen themes, which become the operational core of an ISO 27001 management system. Businesses that climb it in order find each rung cheaper than the last one’s horror stories suggested. Businesses that leap to the top rung pay consultants to build what the lower rungs would have taught them.

Still unsure which one your situation points at? Get in touch. One conversation, and we will tell you which standard your obligations actually require, including when the answer is the cheapest one, or none at all yet.