How does Cyber Essentials differ from ISO 27001?

ISO 27001 adopts a more holistic approach and is focused on the development, implementation and continual improvement of an information security management system (ISMS).

Adopting a risk-based approach, ISO 27001 considers threats to all of its information assets in whatever form, i.e. paper, information systems or digital media.

When certifying to ISO 27001, you need to provide the assessor with evidence that you are meeting all the mandatory elements of the management system e.g. understanding the organisation, demonstrating leadership commitment, conducting risk assessments and treatment, evaluating performance and continually improving.

The controls you implement are dictated by your risk assessment. Cyber Essentials on the other hand is a ‘snapshot in time’ assessment, where the focus is on protecting data and programs on networks, computers, servers and other elements of IT infrastructure, from cyber threats.

There is no risk assessment involved and all the security measures set out by the NCSC must be in place at the time of the certification assessment. The same applies to Cyber Essentials Plus.

We have been a partner with URM Consulting for many years. They offer a great service and are a team of real experts in all things cyber security.
IT support company
Apply for Cyber Essentials certificationApply for Cyber Essentials Plus

NHS Cyber Security Open Letter: What Does it Mean for Suppliers?

Published on
16 Feb
2026

URM’s blog explains the recent open letter to suppliers issued by the NHS, what it means, why it matters, and the practical steps you can take to prepare.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
19/1/2026
Minimising the Impact When a Breach Occurs

URM’s blog explores the importance of cyber resilience & the steps organisations can take to prepare for and mitigate the impact of a cyber incident.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
9/1/2026
Strengthening Your Cyber Defences: Practical Steps for Every Business

URM’s blog explores common weaknesses in organisations’ security programmes, & outlines practical, cost-effective measures to reduce the likelihood of a breach

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
18/12/2025
Deconstructing the EU Cyber Resilience Act

URM’s blog breaks down the new EU Cyber Resilience Act, what products/entities are in scope, the security requirements it imposes on organisations, and more.

Read more
"
URM has guided us through the Cyber Essentials and Cyber Essentials Plus certifications for the past couple of years. The process has always been straightforward and well-structured, providing us with a clear roadmap to enhance our cybersecurity posture. Achieving these certifications has focused our efforts and significantly boosted our confidence in our security measures, reassuring our clients and stakeholders of our commitment to protecting their data. The rigorous assessment for Cyber Essentials Plus gave us an in-depth understanding of our vulnerabilities and how to address them effectively.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.