Cyber Essentials: are there any alternative standards?
Can an equivalent cyber security standard deliver the same outcomes as the NCSC’s Cyber Essentials scheme?

I’m often asked the question ‘If I have standard x why do I also need Cyber Essentials?’, where x, in a lot of cases, is the ISO/IEC 27001 certification standard, but there are others like PCI-DSS or a CBEST assessment.
As is often the case in cyber security, the answer is ‘it depends’.
To recap, Cyber Essentials was launched in 2014 to mitigate the most common cyber attacks we were seeing at the time. It focuses on the five controls that make the most significant difference stopping these attacks and are relatively straightforward to assess. Whilst is can be thought of as a control set, it was aligned to a very specific risk scenario: an attacker sitting on the Internet using “commodity capability” (that is, publicly available tools and techniques).
The controls are defined in a requirement document, which is used as the basis for independent assessment. There are two levels of assessment:
- a basic level which is a combination of self-assessment and independent audit
- a more rigorous level that involves physical testing of the controls
The assessment can only be carried out by recognised Certification Bodies that are approved by IASME, NCSC’s delivery partner.
Equivalence with other standards
So, when we talk about equivalence, we have to ask some questions:
-
Does the standard explicitly cover the 5 controls, or the overall outcome (i.e. resilience against a commodity attack)?
-
Does the assessment cover the system(s) that Cyber Essentials would have covered?
-
Is there independent assessment available?
-
Do the bodies carrying out the assessment have the necessary expertise and processes?
-
Does the assessment explicitly cover the control or the outcome?
-
In the case of Cyber Essentials Plus (CE+), does the assessment include physical testing of the controls or the outcome?
-
Is there a body overseeing the standard and the assessment regime?
-
Does that body have the appropriate expertise to fulfil the role, ie do they have the necessary expertise in cyber security?
Since ISO/IEC 27001 certification tends to be cited the most, let’s see how it addresses these questions.
The five sit within the list of controls from which an organisation selects. Also, as part of an organisation’s Information Security Management System, they could have explicitly identified managing the risk of internet attack as an outcome. Whilst the standard allows for it, ultimately it will depend on how an organisation has implemented it, as a result of their own risk assessment.
This is really a question about the application of the standard in a particular scenario. Neither Cyber Essentials nor ISO/IEC 27001 define the scope of application. This may be defined by the stakeholder requesting the assessment or (in the case of ISO/IEC 27001 certification) the organisation undergoing the assessment. As a result, the scope of the assessment activities may not cover the same things.
There are plenty of companies offering ISO/IEC 27001 certification, so there is certainly independent assessment available.
- For Cyber Essentials, only companies recognised by the NCSC can issue a Cyber Essentials certificate.
- For ISO/IEC 27001, although any organisation may legally carry out an assessment, only organisations accredited by UKAS can ensure that the assessment is truly independent.
Any company can offer certification against ISO/IEC 27001. However, UKAS accreditation confirms the certifying companies have met criteria for competence and impartiality. Therefore, if the company that carried out the assessment was accredited by UKAS, then the answer is ‘yes’, but that would need to be checked.
The assessment focuses on an organisation’s Information Security Management System. Assessing how well individual risks are being managed will largely depend on the assessor and the scope. Therefore we can’t say that that the controls or the outcome are explicitly covered in an ISO/IEC 27001 certification, because it will depend on how the organisation has implemented it, as a result of their own risk assessment. You’d have to find out exactly what that assessment has covered.
Physical testing is not part of the standard ISO/IEC 27001 assessment.
Yes. The standard is produced through the international standards-making process which UKAS directly supports (through the UK mirror committee BSI/IST33). With regards to the assessment regime, UKAS is subject to periodic peer-assessments through the European Accreditation Cooperation mechanism.
There is an international accreditation system of peer-review that reviews and confirms UKAS’s competence to accredit organisations that carry out ISO/IEC 27001 assessments in the UK. Whilst that process provides independent assessment of UKAS’s competence to offer a scheme that assesses an Information Security Management System, it's not clear how well it judges cyber security expertise. So the answer has to be ‘maybe’.
The devil is in the detail
So clearly, you can’t simply say that an ISO/IEC 27001 Certificate is ‘equivalent’ to a Cyber Essentials Certificate. That’s not to say there isn’t some equivalence in a particular case, but you’d need to dig into the detail to ensure:
- the company was accredited by UKAS
- the 5 controls or the overall outcome had been assessed
If you were looking for equivalence to a Cyber Essentials Plus certificate, then you’d also need to ask for evidence of physical testing against the controls or outcome.
I’ve used ISO/IEC 27001 in this example, but the same will apply to other standards.
So does that mean we can’t consider any form of general equivalency? It really depends on why someone wants to see the certificate in the first place. I’ve been working with Cabinet Office on the revision to the Cyber Essentials Procurement Policy Notice. That’s given me a few insights into how it’s being used by procurement folks, and perhaps where equivalence can be used. For example, in some cases it’s being used as an ‘indicator of good practice’, providing confidence that an organisation is at least considering its cyber risk and has taken active measures to manage it. Whilst a Cyber Essentials certificate provides appropriate evidence, an ISO/IEC 27001 certificate could provide the same.
Finally, it's worth noting that an ‘indicator of good practice’ isn’t evidence that a particular risk you care about is being managed. That’s a bit like going to a restaurant based on their food hygiene certificate; it tells you something about the restaurant, but little about the food you’re going to get. You would look for a sample menu and reviews before choosing a restaurant. In the same way, you will really have to investigate the details of the ISO/IEC 27001 certificate to see if it provides equivalence.
Chris Ensor
Deputy Director, Cyber Growth
Share and print this article
Written by
Deputy Director National Resilience Capabilities, NCSC


