Skip to main content
ISO 27001

ISO 27001 vs Cyber Essentials Plus: What Really Differs

By Goldline Consultancy

10 min read

Contents

    The question comes up on nearly every scoping call. An organisation holds Cyber Essentials Plus. Their board, customer, or prime contractor is asking about ISO 27001. They want to know what the difference is, whether CE Plus is a meaningful credit against ISO 27001, and what the realistic timeline and effort looks like to bridge from one to the other.

    This piece answers those questions in practical terms. It covers what each standard is actually certifying, where the real overlap lies, where the real gap lies, and what a realistic ISO 27001 implementation timeline looks like for an organisation starting from a mature CE Plus posture.

    What Cyber Essentials Plus actually certifies

    Cyber Essentials Plus is a UK government-backed cyber hygiene certification operated by IASME on behalf of the NCSC. It verifies that five technical control areas are implemented and demonstrably effective.

    The five control areas are boundary firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. CE Plus adds an external technical assessment on top of the self-assessed Cyber Essentials baseline. An assessor runs authenticated and unauthenticated vulnerability scans against a sample of devices and verifies that the controls claimed in the self-assessment are actually in place.

    CE Plus is excellent at what it does. It is a high-value, low-cost, annually renewed validation that the organisation's technical hygiene meets a defined minimum. It is the right starting point for most UK SMEs asking "where should we begin on cyber."

    What CE Plus is not is a management system certification. It certifies that specific technical controls exist. It does not certify how the organisation decides which controls are needed, how it manages supplier risk, how it responds to incidents, how it ensures the controls remain effective between certifications, or how senior leadership is engaged with information security as an ongoing discipline.

    What ISO 27001 actually certifies

    ISO 27001 is an international standard for information security management systems. It certifies that the organisation has a functioning ISMS, a structured, documented, continually improving approach to information security, that meets the requirements of the standard.

    Those requirements span clauses four through ten of the standard, and are broadly the same management system requirements as ISO 9001 or ISO 14001: context, leadership, planning, support, operation, performance evaluation, and improvement. An organisation with ISO 27001 certification is evidencing that it does all of these things specifically in relation to information security.

    Annex A of ISO 27001:2022 contains ninety-three information security controls organised into four themes: organisational, people, physical, and technological. The organisation does not have to implement all ninety-three. It has to assess each one's applicability to its specific context, document the decision in a Statement of Applicability, and implement the controls it deems applicable. This is the reason two ISO 27001-certified organisations can have meaningfully different control sets. Both are compliant, because both have made reasoned decisions documented in their SoA.

    The certificate is issued for three years, with annual surveillance audits in between. This is a more significant ongoing commitment than CE Plus.

    Where the real overlap lies

    The overlap between CE Plus and ISO 27001 Annex A is substantial in the technical control areas but minimal in the management system layer.

    In technical controls, CE Plus's five areas map directly onto specific Annex A controls. Boundary firewalls and internet gateways map to A.8.20 and A.8.21. Secure configuration maps to A.8.9. User access control maps to A.5.15, A.5.16, A.5.17, and A.5.18. Malware protection maps to A.8.7. Security update management maps to A.8.8 and A.8.32. An organisation passing CE Plus will have twenty to twenty-five Annex A controls already substantially implemented, around a quarter of the full control set.

    This is a meaningful credit. It means the technical implementation effort for ISO 27001 is materially lower for a CE Plus holder than for an organisation starting cold.

    What does not overlap is everything outside those technical controls. ISO 27001 requires documented policies across organisational and people controls (A.5 and A.6, around thirty-seven controls between them), physical controls (A.7, fourteen controls), and management system clauses (clauses four through ten). None of these are in CE Plus scope.

    In practical terms: roughly a quarter of the Annex A controls carry over with meaningful implementation credit. Three quarters of the Annex A controls, and the entire management system layer, are new work.

    Roughly a quarter of the Annex A controls carry over from Cyber Essentials Plus with meaningful implementation credit. Three quarters of Annex A, and the entire management system layer, are new work.

    Where the real gap lies

    The gap is not technical. It is structural.

    The structural layer ISO 27001 requires includes a documented context of the organisation, including identification of interested parties and their requirements. A documented information security policy approved by senior leadership. A documented risk assessment methodology and operational risk register. A Statement of Applicability. A risk treatment plan. Documented supplier security management. A documented incident management process. A documented business continuity plan covering information availability. Internal audit programme. Management review cycle. Continual improvement process.

    For an organisation coming from CE Plus, the shock is typically not in the technical work. It is in the volume of documentation, the cadence of governance activity, and the time commitment from senior leadership. ISO 27001's management system requirements are not optional. A management review held once, rushed, documented briefly, will not pass audit. A risk register updated once and never revisited will not pass audit. An internal audit programme that audits only the technical controls and ignores the management system will not pass audit.

    This is the most common source of failed or delayed ISO 27001 implementations. Organisations focus on the technical controls, which they mostly already have via CE Plus, and underestimate the governance layer.

    Realistic timelines from a CE Plus baseline

    For an organisation holding Cyber Essentials Plus, with twenty to two hundred and fifty employees, and a scope calibrated to their actual buyer requirement, a realistic timeline from decision to certification is twelve to twenty weeks.

    This assumes a structured implementation approach. It assumes executive sponsorship. It assumes reasonable availability of existing documentation to build from. It assumes the organisation is willing to run the governance cadence (management reviews, internal audits) inside the implementation window rather than deferring them until after certification.

    Compare this to the six-to-twelve-month timelines typical of organisations starting from scratch (without CE Plus, without existing security documentation, without established IT policies) and the CE Plus credit becomes clear. CE Plus shortens the technical implementation roughly in half. It does not shorten the governance implementation, which is where most of the remaining work lives.

    Organisations that rush this, that try to compress twelve to twenty weeks into six, typically discover the problem at Stage 2 audit. Non-conformities around internal audit coverage, management review evidence, and risk treatment progress are the most common findings at first audit for organisations that compressed the governance work. Correcting these findings after audit is slower and more expensive than doing them properly inside the implementation window.

    Our ISO 27001 Implementation service page covers the three-phase delivery structure we use for organisations in this position: Gap Assessment, ISMS Implementation, Ongoing Support.

    Ongoing commitment: CE Plus vs ISO 27001

    Both standards require annual recertification effort, but the ongoing profile is meaningfully different.

    CE Plus is renewed annually. The renewal effort is typically one to two weeks of internal preparation plus a day or two of assessor time. The effort is concentrated at renewal and minimal in between. Organisations that maintain reasonable technical hygiene year-round find renewal straightforward.

    ISO 27001 requires continuous operation of the ISMS. Surveillance audits are annual, but the underlying rhythm is ongoing. Risk assessment updates when the business changes. Supplier reviews on new suppliers. Incident response plans tested at least annually through exercise. Internal audits run on a rolling schedule covering the full scope over the three-year cycle. Management reviews at documented cadence. Staff awareness refreshed annually. This is a meaningful organisational commitment, typically two to five days per month of distributed effort depending on organisation size, that persists between audits.

    Organisations that treat ISO 27001 as a CE Plus-style annual exercise fail surveillance audits. The standard is explicit that the management system must be continually operational. This is a positive: it is what makes the certificate a meaningful credibility signal to primes and customers. But it is not the same commitment profile as CE Plus.

    Is CE Plus still enough?

    For some organisations, CE Plus is still the right endpoint. For a services business that does not handle sensitive customer data at scale, does not sit in a regulated sector, and is not under prime contractor or customer pressure to demonstrate a management system, CE Plus provides meaningful assurance at manageable cost.

    For other organisations, CE Plus is no longer enough. Defence suppliers under JOSCAR scrutiny, regulated enterprise organisations, organisations bidding into public sector procurement frameworks that specify ISO 27001, organisations handling enterprise customer data at material volume: these organisations are increasingly being told CE Plus is a floor, not a ceiling.

    The question is not whether one standard is better than the other. Both serve their purpose. The question is whether the assurance CE Plus provides matches what your buyers, regulators, or commercial obligations require. For an increasing share of UK organisations in defence supply chain, regulated enterprise, or public sector procurement, the answer is that CE Plus alone is not enough. For organisations in this position, ISO 27001 for Defence Suppliers covers the specific prime contractor and JOSCAR dynamics in more detail.

    Closing

    Cyber Essentials Plus and ISO 27001 are related standards that certify different things. CE Plus certifies technical cyber hygiene. ISO 27001 certifies that the organisation has a functioning information security management system. Roughly a quarter of ISO 27001's Annex A control set overlaps with CE Plus technical control areas; three quarters, plus the entire management system layer, does not.

    The realistic timeline from CE Plus to ISO 27001 for an SME with appropriate scope is twelve to twenty weeks with structured implementation, assuming executive engagement and willingness to run the governance cadence inside the implementation window rather than after it.

    If you are assessing whether ISO 27001 is the right next step for your organisation and want a practitioner-led gap assessment from your existing CE Plus baseline, we run scoped Phase 1 Gap Assessments designed exactly for this transition.

    Goldline Consultancy is led by an ISO 27001 Lead Implementer (PECB) and delivers ISO 27001 implementation as a fixed-scope engagement for UK defence supply chain and regulated organisations. Take our free ISMS maturity self-assessment or book a free 45 minute diagnostic.

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.