Cyber Readiness Pro
Readiness · ISO/IEC 27001:2022

Cyber Essentials proves you locked the door. ISO 27001 proves you have a system for keeping it locked.

Cyber Essentials checks a fixed list of technical controls once a year, self-assessed. ISO 27001 asks a bigger question: do you have an ongoing management system for information security at all? Documented risk assessment, policies that actually get followed, an internal audit programme, checked by an independent certification body rather than filled in yourself.

A self-serve ISO 27001 gap-check is coming soon. For now, a scoping call covers the same ground.

5 control domains

Documentation, organisational, people, physical, technological.

Independently certified

An external certification body audits and signs off, not a self-assessment.

Increasingly contract-required

Enterprise procurement, public-sector tenders, and insurers ask for it past SME scale.

Cyber Essentials and ISO 27001 answer different questions. Cyber Essentials checks a fixed list of technical controls, MFA, patching, firewalls, and you self-assess against it once a year. ISO/IEC 27001 asks whether you have an ongoing management system for information security: a documented risk assessment, policies that actually get followed, defined roles and responsibilities, an internal audit programme, and a formal management review, all checked by an independent certification body. Most businesses meet Cyber Essentials first. ISO 27001 usually shows up later, when a bigger customer's procurement team asks for it, a public-sector tender requires it, or an insurer wants to see it before extending cover.

Why this is worth a scoping call

Most businesses don't find out where their ISMS actually stands until an auditor tells them, or a deal stalls waiting on a certificate they don't have yet. A scoping call starts from a real picture of your gaps, not a guess. See the privacy policy for how your data is used.