Skip to main content

Cyber Essentials: are there any alternative standards?

Can an equivalent cyber security standard deliver the same outcomes as the NCSC’s Cyber Essentials scheme?

iStock.com/Sakibul Hasan

I’m often asked the question ‘If I have standard x why do I also need Cyber Essentials?’, where x, in a lot of cases, is the ISO/IEC 27001 certification standard, but there are others like PCI-DSS or a CBEST assessment.

As is often the case in cyber security, the answer is ‘it depends’.

To recap, Cyber Essentials was launched in 2014 to mitigate the most common cyber attacks we were seeing at the time. It focuses on the five controls that make the most significant difference stopping these attacks and are relatively straightforward to assess. Whilst is can be thought of as a control set, it was aligned to a very specific risk scenario: an attacker sitting on the Internet using “commodity capability” (that is, publicly available tools and techniques).

The controls are defined in a requirement document, which is used as the basis for independent assessment. There are two levels of assessment:

  • a basic level which is a combination of self-assessment and independent audit
  • a more rigorous level that involves physical testing of the controls

The assessment can only be carried out by recognised Certification Bodies that are approved by IASME, NCSC’s delivery partner.


Since ISO/IEC 27001 certification tends to be cited the most, let’s see how it addresses these questions.


Written by

Chris Ensor

Deputy Director National Resilience Capabilities, NCSC