ISO 27001 vs Cyber Essentials vs Cyber Essentials Plus: A Quick Guide

TL;DR

Certification means managed risk, not zero risk

The most common misreading of ISO 27001 is treating it as a guarantee of flawless security. It isn’t:

  • The standard requires organisations to identify, assess and treat information risk within a defined risk appetite, not eliminate it.
  • Every certified organisation carries documented residual risk, that’s expected, and it should be visible in their risk treatment plan.
  • A supplier can be validly certified while still having known gaps, what matters is whether those gaps are tracked and being closed.

Bottom line: the certificate tells you a risk management process exists. It doesn’t tell you what’s still open.

Scope is where certificates quietly stop covering what you’re buying

A supplier can hold a genuine, current ISO 27001 certificate with a scope statement that excludes the exact thing you’re procuring, offshore support, a specific data centre, a recently acquired business unit:

  • Check the scope statement itself, not just the certificate, for which sites, services and business units are actually covered.
  • Check the date of the last surveillance audit. Certification is maintained through annual audits and a full recertification every three years, a stale audit trail is worth chasing.
  • Ask for the Statement of Applicability (SoA), the document mapping which of the 93 Annex A controls apply and why, it’s the real evidence behind the badge.

Worth noting: the logo on a website tells you almost nothing. The scope statement and SoA tell you what’s actually been tested.

The 2022 revision changed what’s actually being audited

ISO/IEC 27001:2022 replaced the 2013 version’s 114 controls across 14 domains with 93 controls across 4 themes, Organisational, People, Physical and Technological. Every existing certificate had to transition by 31 October 2025 or lapse:

  • 11 entirely new controls were added, including threat intelligence, cloud security, data masking, data leakage prevention and secure coding, areas the 2013 version didn’t explicitly cover.
  • A certificate still structured around the old 2013 domains should have transitioned or been reissued by now.

In practice: this is a quick, useful sense check the next time you’re handed a supplier’s certificate.

What ISO 27001 does, and doesn’t, do for your regulatory obligations

ISO 27001 certification is frequently accepted as evidence toward other obligations, but it’s a head start, not a substitute:

  • UK GDPR: supports the accountability principle (Article 5(2)), demonstrating appropriate technical and organisational measures.
  • NIS2 / UK Cyber Security and Resilience Bill: maps closely to the risk-management measures both require, though neither is satisfied by ISO 27001 alone.
  • DORA (EU financial entities): shares the same risk-based structure, but DORA adds requirements ISO 27001 doesn’t cover, specific incident-reporting timelines and threat-led penetration testing, so a gap assessment is still needed.

The takeaway: treat ISO 27001 as the foundation for these obligations, not the finish line.

Matching the framework to what’s actually driving the requirement

These frameworks aren’t interchangeable, and the one your organisation needs, whether you’re reading this in the UK or New Zealand, often depends on who’s asking:

FrameworkWho it suitsIndustry / sectorRegulatory or contractual driver
Cyber EssentialsSMEs and first-time biddersAny sector bidding for UK central government workMandatory baseline for UK government contracts handling personal data; commonly required for cyber insurance underwriting
Cyber Essentials PlusOrganisations needing independently-verified technical controlsDefence supply chain, at every tier, not just the primePrerequisite for MOD Defence Cyber Certification Level 2+ under Def Stan 05-138 / DEFCON 658
ISO 27001Mid-market to enterprise, regulated or outsourced-service organisationsFinancial services, critical infrastructure, managed services, any org handling sensitive third-party data at scaleSupports UK GDPR accountability; maps closely to NIS2 / UK Cyber Security and Resilience Bill; a head start, not a substitute, for EU DORA

In practice: most organisations we work with hold Cyber Essentials as a baseline and build toward ISO 27001 as their risk profile and customer requirements grow, with sector-specific frameworks layered on top where a particular contract or regulator demands it.

Official reference: ISO/IEC 27001 overview (iso.org)

Official reference: Cyber Essentials overview (NCSC UK)

New Zealand context

ISO 27001 is a global standard, so a New Zealand-issued certificate carries exactly the same weight as a UK one. What sits around it differs a little:

  • Accreditation: look for a certification body accredited by JAS-ANZ (the Joint Accreditation System of Australia and New Zealand), the NZ/Australia equivalent of the UK’s UKAS, against the same ISO/IEC 17021-1 standard.
  • Government and critical infrastructure: NZISM (the New Zealand Information Security Manual) sets baseline controls for government agencies and their suppliers, sitting alongside ISO 27001 rather than replacing it. Many NZ procurement processes now accept ISO 27001 as evidence of security maturity.
  • SME baseline: New Zealand’s NCSC published Minimum Cyber Security Standards (MCSS) in October 2025, the closest NZ equivalent to Cyber Essentials in spirit, though structured as a maturity model for GCISO-mandated public sector agencies rather than a pass/fail badge.
  • Data protection: ISO 27001 supports Privacy Act 2020 obligations in New Zealand in much the same way it supports UK GDPR accountability.

Official reference: Minimum Cyber Security Standards (NCSC NZ)

Our view: whichever side of the world you’re reading this from, the certificate means the same thing. It’s the accreditation body, the sector-specific layer on top, and the regulator asking the question, that differs.

What we’re seeing in practice

Where clients most often get caught out isn’t the accreditation itself, it’s assuming one certification covers a requirement it doesn’t:

  • Assuming Cyber Essentials satisfies a defence contract that actually requires Cyber Essentials Plus under Def Stan 05-138 / DEFCON 658, a requirement that flows down through every tier of the supply chain, not just the prime contractor.
  • Assuming a supplier’s ISO 27001 certificate covers a service that its scope statement actually excludes.
  • We help clients work through gap analysis and achieve Cyber Essentials, Cyber Essentials Plus and ISO 27001, and we hold ISO 27001 ourselves.

ITogether’s Independent Verdict

Certifications aren’t the goal, the risk management behind them is. The real value for a CISO isn’t the badge, it’s what the scope statement, Statement of Applicability and audit history reveal about how a supplier actually manages risk, and whether that maps to the regulation or contract actually driving the requirement.

👉 Working toward Cyber Essentials, Cyber Essentials Plus or ISO 27001, or want to know more about ours, get in touch.

📞 UK +44 (0) 113 341 0123

📞 NZ +64 (0)9 802 2444

📧 hello@itogether.com

FAQs

Does ISO 27001 certification mean an organisation has no security risks?

No. It means risk is identified, assessed and treated within a defined risk appetite, and reviewed on an ongoing audit cycle. Ask for the risk treatment plan and Statement of Applicability for the real picture.

What changed in the ISO 27001:2022 revision?

Annex A moved from 114 controls across 14 domains to 93 controls across 4 themes, adding 11 new controls including threat intelligence, cloud security and data leakage prevention. Every certificate had to transition by 31 October 2025 or lapse.

Is Cyber Essentials Plus the same as ISO 27001?

No. Cyber Essentials Plus independently tests five technical controls and is often the specific prerequisite for defence supply chain contracts under Def Stan 05-138. ISO 27001 is a broader, risk-based management system covering the whole organisation.

Does ITogether hold ISO 27001?

Yes. ITogether is ISO 27001 accredited, and we help clients achieve Cyber Essentials, Cyber Essentials Plus and ISO 27001 too.

What’s the New Zealand equivalent of Cyber Essentials?

New Zealand’s NCSC published Minimum Cyber Security Standards (MCSS) in October 2025. It’s the closest local equivalent in spirit, though it’s structured as a maturity model for GCISO-mandated public sector agencies rather than a self-assessed pass/fail badge like Cyber Essentials.

0 Comments

Submit a Comment