Cyber Essentials vs ISO 27001 vs SOC 2: which one the customer asked for
The email says "please confirm your security certifications". Somebody senior reads that as ISO 27001 and commits to a nine-month project. Two weeks in, somebody finally asks the customer what they actually need, and the answer is Cyber Essentials, because they are a UK public sector body and that is what their procurement rules specify.
Cyber Essentials vs ISO 27001 is not really a comparison of security standards. It is a question about which buyer you are talking to, and getting it wrong in either direction is expensive.
Cyber Essentials vs ISO 27001: what each one is
Cyber Essentials is a UK government-backed scheme covering five technical control themes: firewalls, secure configuration, security update management, user access control and malware protection. It is a self-assessment, verified by a certifying body, and it is about whether specific technical basics are in place.
It is deliberately narrow. There is no management system, no risk assessment, no policy set and no audit of how you operate. The NCSC's Cyber Essentials overview sets out the controls and the current requirements, and it is worth reading the actual requirements document because the controls are specific about things like supported software and account separation.
Cyber Essentials Plus is the same five controls with technical verification: an assessor tests a sample of your devices rather than taking your word for it. Same scope, higher confidence, more work.
ISO 27001 is an international standard for an information security management system. Scope, risk assessment, policies, controls selected from Annex A, internal audit, management review, continual improvement. It certifies that you run a system for managing security, not that any particular technical control exists.
SOC 2 is a US attestation report produced by a CPA firm against the AICPA trust services criteria. Type I covers design at a point in time. Type II covers operating effectiveness over a period, typically three to twelve months, and Type II is what buyers mean when they ask for SOC 2. It produces a report rather than a certificate, and the report is long, confidential, and shared under NDA.
Which buyers ask for which
This is the practically useful part.
UK public sector asks for Cyber Essentials, and for some contracts requires it. It may also ask for ISO 27001 on larger engagements.
UK SME and mid-market asks for Cyber Essentials, or asks a questionnaire and accepts either. Many will accept Cyber Essentials plus a well-answered questionnaire.
UK and European enterprise asks for ISO 27001. It is the recognised answer in this market and a certificate ends the conversation.
US buyers, especially technology companies, ask for SOC 2 Type II. Some will accept ISO 27001, increasingly so, but the default expectation in US procurement is SOC 2 and you may be asked to explain why you have the other thing.
Regulated sectors ask for whatever their regulator or their own framework specifies, which may be none of the above.
So the first action is not choosing a standard. It is asking the customer who triggered this what their procurement actually requires, in writing. That conversation takes a day and can save nine months of the wrong project.
Effort, honestly
Without inventing numbers, because certification fees vary by body and by headcount and any figure here would be stale.
Cyber Essentials is days to a few weeks of work for a company with reasonable IT hygiene, and the fee is published by the scheme's delivery partner and tiered by organisation size. The work is mostly confirming and fixing specific technical settings.
Cyber Essentials Plus adds an assessor testing devices, so add the cost of that assessment and the effort of getting a device sample genuinely compliant rather than mostly compliant.
ISO 27001 is six to nine months for one person part time, as covered in the implementation note, plus certification body fees quoted per engagement and an ongoing annual surveillance cost.
SOC 2 Type II requires an audit period during which controls operate, plus a CPA firm's fee, which is generally the most expensive of the four. It also recurs annually, and the report has a useful life buyers will ask about.
The ratio that matters: Cyber Essentials is roughly an order of magnitude less effort than ISO 27001, and it satisfies a meaningful share of UK buyers.
Sequencing, which is the actual decision
Cyber Essentials first is usually right, and for reasons beyond cost.
The five Cyber Essentials controls are things ISO 27001 will require anyway. Patching, access control, malware protection and secure configuration all appear in Annex A. So doing Cyber Essentials is not a detour, it is the first slice of the same work with a certificate at the end of it.
It also gives you something to say now. A deal waiting on assurance can proceed on Cyber Essentials while ISO 27001 runs in the background, which converts a blocked sales conversation into a delayed one.
And it surfaces the technical gaps cheaply. If you cannot pass Cyber Essentials, you are not close to ISO 27001, and finding that out in three weeks is better than finding it out in month five.
The exception: if the customer who triggered this is a European enterprise or explicitly requires ISO 27001, Cyber Essentials will not satisfy them and doing it first delays the thing they asked for. Ask first.
Doing more than one
ISO 27001 and SOC 2 overlap substantially in controls and not at all in structure. If you genuinely need both, do ISO 27001 first and map to SOC 2 second: the management system, risk assessment and evidence discipline transfer, whereas SOC 2 first leaves you without the clause 4 to 10 apparatus that ISO requires and SOC 2 never asked for.
Holding Cyber Essentials alongside ISO 27001 is common and cheap to maintain, and it answers the UK public sector question without a conversation.
What is not worth doing is holding a certification your customers never ask for because it seemed thorough. Each one carries an annual cost and a recurring evidence burden, and the surveillance audit note covers what that costs in year two when the enthusiasm has gone.
The question to ask this week
Send one email to the customer who started this: "For our records, could you confirm which specific certification or attestation your procurement process requires, and whether alternatives are accepted."
The answer determines a nine-month commitment, it takes them two minutes, and almost nobody asks. The book covers the ISO 27001 route in detail if that turns out to be the answer, and the security and compliance work covers either.