Choosing between Cyber Essentials and ISO/IEC 27001 is one of the most common cybersecurity questions BroadVision hears from South African and UK-facing businesses in 2026. The two are not competing standards — Cyber Essentials is a focused UK government-backed technical scheme; ISO/IEC 27001:2022 is the international standard for running a full Information Security Management System. This guide breaks down scope, cost, timeframe, and which one fits your business right now.
Key takeaways
- Cyber Essentials covers five technical controls on internet-facing IT; ISO/IEC 27001:2022 covers a whole Information Security Management System (ISMS) with 93 Annex A controls grouped into four themes.
- Cyber Essentials Plus typically costs £1,500–£3,000+ for SMEs and takes 2–6 weeks. ISO 27001 first-time certification typically costs £10,000–£40,000+ in year one and takes 6–12 months.
- Cyber Essentials is UK-centric and often mandated for UK public sector contracts. ISO 27001 is recognised globally and routinely required in financial services, healthcare, and enterprise procurement, including South African POPIA-regulated environments.
- Most mature BroadVision clients hold both: Cyber Essentials Plus first for fast technical hygiene, ISO 27001 second to evidence ongoing governance.
- Pick the certification your next contract actually requires — and plan the second as your business grows into it.
The short version
Cyber Essentials is a UK NCSC-backed scheme, delivered through IASME, that proves you have the five technical controls every modern business needs. ISO/IEC 27001:2022 is the international standard, published by ISO and IEC and audited by UKAS-accredited bodies in the UK or SANAS-accredited bodies in South Africa, for running a full ISMS — governance, risk, people, suppliers, and continuous improvement.
Side-by-side comparison
| Dimension | Cyber Essentials | ISO/IEC 27001:2022 |
|---|---|---|
| Scope | Five technical controls on internet-facing IT | Whole Information Security Management System |
| Controls | 5 control themes | 93 Annex A controls in 4 themes |
| Audit style | Self-assessment, or Plus with hands-on technical audit | Two-stage external audit by an accredited body |
| Accreditation | IASME (sole UK accreditation body) | UKAS (UK), SANAS (South Africa), ANAB (US), etc. |
| Typical effort | 2–6 weeks | 6–12 months for first certification |
| Typical cost (SME) | £300–£500 basic; £1,500–£3,000+ Plus | £10,000–£40,000+ in year one |
| Recognition | UK-centric, often mandated for UK public sector | Recognised globally, expected in enterprise procurement |
| Renewal | Annually | Annual surveillance audits, full recertification every 3 years |
| Best for | Operational hygiene and quick procurement wins | Board-level information security, regulated industries |
What Cyber Essentials actually covers
Cyber Essentials focuses on five technical control areas: firewalls, secure configuration, user access control, malware protection, and security update management. The basic level is a self-assessment verified by a certification body. Cyber Essentials Plus adds a hands-on technical audit — external vulnerability scans, authenticated checks on a sample of devices, and email and web filtering tests.
The scheme is deliberately narrow. Done well, it eliminates the majority of opportunistic attacks that target unpatched software, weak passwords, and exposed admin interfaces. The UK National Cyber Security Centre (NCSC) reports it blocks roughly 99% of common internet-based attacks.
What ISO/IEC 27001:2022 actually covers
ISO/IEC 27001 is a management system standard. You are not just proving controls exist — you are proving you run a process that identifies risk, treats it, measures it, and improves it. The 2022 revision groups its 93 Annex A controls into four themes: organisational, people, physical, and technological. The 2013 version (114 controls in 14 sections) is no longer issued; transition to the 2022 version was required by October 2025.
Certification means an external auditor — UKAS-accredited in the UK, SANAS-accredited in South Africa, or equivalent — has reviewed:
- Your scope statement and risk methodology
- Your Statement of Applicability against Annex A controls
- Evidence the system is operating: incident logs, internal audits, management reviews, supplier assessments, awareness training records
- Evidence of continuous improvement over time
Which one fits your business
Start with Cyber Essentials if
- You are an SME with under 100 employees and standard cloud-first IT
- You need to satisfy a UK public sector or supply-chain requirement quickly
- You have not yet formalised your security baseline and want a defensible starting point
- Your security certification budget this year is under £10,000
- You are tendering for UK MoD, NHS, or central government contracts that mandate Cyber Essentials
Pursue ISO 27001 if
- You sell into financial services, healthcare, government, or large enterprise
- Customers ask for SOC 2, ISO 27001, or a detailed security questionnaire in every deal
- You handle regulated data — POPIA in South Africa, GDPR in the EU/UK, PCI DSS, or sensitive personal information
- You operate across multiple jurisdictions and need a globally recognised framework
- Your board wants assurance that information security is being actively managed, not just bought
Do both — in this order
Most mature BroadVision clients end up with both. Cyber Essentials Plus first, because it forces clean technical hygiene in weeks rather than months. ISO 27001 second, because the controls are easier to evidence once the technical baseline is already proven.
What the real cost looks like in 2026
The certification fee is the smallest line item. The real spend is internal time and remediation work.
- Cyber Essentials Plus. Plan for 4–6 weeks of focused effort, plus any remediation surfaced by the audit — typically patching, MFA rollout, and tightening admin access. Total programme cost for a 50-person SME: £4,000–£8,000 including certification fees and partner support.
- ISO/IEC 27001:2022. Plan for a dedicated lead (internal or fractional), 6–12 months of effort, tooling for risk and policy management, awareness training, and the external audit fees. SMEs commonly land between £15,000 and £40,000 in year one, dropping to £8,000–£15,000 annually for surveillance audits as the system stabilises.
A good managed partner compresses both timelines significantly by bringing pre-built policies, control mappings, and evidence collection from prior engagements.
What this means for South African businesses
For South African operators, ISO/IEC 27001 is the more commonly recognised standard, especially in financial services regulated by the FSCA and SARB, healthcare, and any business handling personal information under POPIA. Cyber Essentials only matters if you sell into the UK public sector or supply UK enterprises that mandate it. Many BroadVision clients headquartered in Johannesburg, Cape Town, or Durban pursue ISO 27001 as primary, and add Cyber Essentials Plus only when a specific UK contract requires it.
How BroadVision helps
We run both certifications as managed programmes. For Cyber Essentials Plus we handle the technical baseline — endpoint hardening, patch posture, MFA, conditional access, and the audit itself. For ISO 27001 we provide the ISMS framework, risk register, policy set, control implementation, internal audit, and ongoing surveillance support — backed by our wider managed IT services and strategic IT services practices.
If you are not sure which fits your business right now, that is the conversation worth having first. Book a 30-minute scoping call with our Strategic IT Services team, or reach out via our Contact page. For ongoing operational security under either certification, see our Managed IT Services.
FAQ
Is Cyber Essentials worth it for a small business?
Yes. For any UK-based or UK-facing SME, Cyber Essentials costs £300–£500, takes two to four weeks, and blocks the majority of opportunistic internet attacks. It is also frequently mandated in UK public sector tenders, so it usually pays for itself on the first contract. South African businesses with no UK exposure get less direct value and should normally prioritise ISO/IEC 27001 instead. BroadVision runs Cyber Essentials readiness checks against the five controls before you pay for assessment — see Strategic IT Services.
Does ISO 27001 include Cyber Essentials?
No. ISO/IEC 27001:2022 is broader in scope, and most of the five Cyber Essentials controls map to Annex A technological controls, but they are separate schemes with separate audits. Holding ISO 27001 does not produce a Cyber Essentials certificate, and UK contracts that mandate Cyber Essentials still require the IASME-issued certificate. BroadVision maps existing ISO 27001 evidence onto the Cyber Essentials question set so clients do not repeat work — talk to us.
How long does ISO 27001 certification take?
For an SME starting from a reasonable baseline, first-time ISO/IEC 27001:2022 certification typically takes 6–12 months: three to six months to build the Information Security Management System (scope, risk assessment, Statement of Applicability, policies, controls, internal audit), then a Stage 1 documentation audit and a Stage 2 implementation audit by a UKAS or SANAS accredited body, usually four to eight weeks apart. BroadVision has supported South African and UK organisations through that cycle since 2000, running the technical controls under Managed IT Services while the client owns governance.
What is the difference between ISO 27001:2013 and ISO 27001:2022?
ISO/IEC 27001:2022 reorganised Annex A from 114 controls in 14 sections into 93 controls across four themes — organisational, people, physical and technological — and added 11 new controls covering threat intelligence, cloud services, ICT readiness for business continuity and secure development. Clauses 4–10 are largely unchanged. The 2013 version was withdrawn for new certifications and the transition deadline passed in October 2025. BroadVision gap-assesses 2013-era ISMS documentation against the 2022 Annex A themes as a fixed-scope exercise — book a review.
Do we need both Cyber Essentials and ISO 27001?
Most organisations with serious UK exposure end up with both, in that order: Cyber Essentials Plus first for the technical baseline (achievable in four to six weeks), then ISO/IEC 27001 to evidence ongoing governance to enterprise and regulated customers. A South Africa-only business with no UK contracts is usually well served by ISO 27001 alone. BroadVision sequences the two so the Cyber Essentials evidence feeds directly into the ISMS — see Strategic IT Services.
What is POPIA's role in this decision for South African companies?
POPIA — South Africa's Protection of Personal Information Act, enforced by the Information Regulator — requires appropriate technical and organisational measures to secure personal information, but mandates no specific certification. ISO/IEC 27001 is the most widely recognised way to evidence POPIA compliance to customers, partners and the Regulator, which is why most regulated South African organisations prioritise it. BroadVision, based in Johannesburg, signs POPIA operator agreements and delivers the safeguards behind them under Managed IT Services.
