Cyber Essentials vs ISO 27001: Which Does Your Fleet Actually Need?
Businesses weighing up their security credentials almost always arrive at the same fork in the road. Should they pursue Cyber Essentials, ISO 27001, or both? The two get mentioned in the same breath so often that they can seem interchangeable. They are not. They solve different problems, demand very different levels of effort and suit businesses at different stages.
This guide sets out what each one is, how they genuinely differ and which your business actually needs. It also covers a part of the decision that most comparisons ignore entirely: what happens to your certification when your fleet is a mix of Windows and Apple, and why the Apple side is so often where the evidence falls apart.
What Cyber Essentials is
Cyber Essentials is a UK government-backed certification, run by IASME on behalf of the National Cyber Security Centre. It focuses on five technical controls that protect against the most common internet-based attacks: firewalls, secure configuration, security update management, user access control and malware protection.
The scheme comes in two levels. The base level is a self-assessment, where you answer a questionnaire about your setup and it is verified. Cyber Essentials Plus adds an independent technical audit, where an assessor checks a sample of your devices to confirm the controls are genuinely in place rather than simply declared.
Its great strengths are speed and accessibility. A well-prepared business can achieve certification in a matter of weeks, at a cost measured in hundreds rather than thousands of pounds. It renews annually. For many UK businesses it is the practical starting point for demonstrating security, and it is frequently required to win public-sector contracts.
What ISO 27001 is
ISO 27001 is an international standard for information security management. Rather than checking a fixed list of technical controls, it requires you to build and run an Information Security Management System, usually shortened to an ISMS. That is an ongoing, documented approach to identifying risks and managing them across the whole organisation.
The scope reaches far beyond IT. ISO 27001 covers people, processes, policies, physical security, supplier relationships and business continuity, not just the configuration of your devices. At its heart sits a risk assessment: you identify what could go wrong, decide how to treat each risk and document your reasoning in a Statement of Applicability.
Certification comes through an accredited body via a two-stage audit, followed by annual surveillance audits across a three-year cycle. Achieving it typically takes months of preparation and a meaningful investment of time and money. In return, it is recognised internationally and often demanded by enterprise clients and procurement teams before they will trust you with sensitive data.
The differences that actually matter
Set side by side, the two frameworks differ on four things that shape the decision.
Effort and cost
Cyber Essentials is deliberately achievable. Weeks of preparation, a modest fee, annual renewal. ISO 27001 is a project. Months of work, significant cost, ongoing internal audits and management reviews to maintain it. The gap in effort between the two is large, and businesses regularly underestimate it.
Depth of assurance
Cyber Essentials confirms that controls exist at the point of assessment. ISO 27001 requires evidence that you continuously identify risks, act on them and improve over time. A client who accepts Cyber Essentials wants to know you meet a baseline. A client who insists on ISO 27001 wants confidence that security is embedded in how you operate.
Recognition
Cyber Essentials carries real weight in the UK, particularly for government and public-sector work. ISO 27001 is the language of international and enterprise procurement. Which one opens doors depends entirely on who your customers are and where they are based.
So which does your business actually need?
The honest answer is that it depends on what is driving the decision. A few common situations make it clearer.
Choose Cyber Essentials first if you are a UK-focused small or medium business wanting a credible security baseline, if you need certification to bid for public-sector contracts, or if your cyber insurer is asking for it. It delivers a recognised, affordable result quickly, and it forces you to get the fundamentals right.
Prioritise ISO 27001 if enterprise or international clients are demanding it before they will sign, if you handle sensitive data at scale, or if procurement processes in your sector treat it as the price of entry. In regulated fields such as finance and legal, it is increasingly a competitive necessity rather than a nice-to-have.
For many maturing businesses the real answer is both, in sequence. Cyber Essentials establishes the technical foundation, and much of the evidence it produces feeds directly into the broader ISO 27001 effort. Starting with Cyber Essentials and building toward ISO 27001 is a well-trodden and sensible path. Our guide to Cyber Essentials and Cyber Essentials Plus is worth reading alongside this if you are still deciding on the right level.
The part most comparisons miss: your mixed fleet
Here is where the standard advice quietly breaks down. Almost every guide to Cyber Essentials and ISO 27001 is written with an unspoken assumption baked in: that your estate runs on Windows, managed through Active Directory and Group Policy. The controls, the evidence and the audit expectations are all framed around that world.
Most real businesses no longer live in that world. They run a mix. Windows laptops for some teams, Macs for others, iPhones and iPads across the board. And the moment an estate becomes mixed, the Apple side becomes the part where compliance evidence tends to fall apart.
The reason is straightforward. Many IT providers are Windows-first by background. They produce clean, comprehensive evidence for the Windows fleet, because that is the platform they know. When it comes to the Macs and iPhones, the same rigour often is not there. The devices are technically present but not genuinely managed to the same standard, and the evidence an assessor needs simply does not exist.
This matters for both frameworks, in different ways.
What each framework demands of your Apple estate
Cyber Essentials and your Macs
Every one of the five controls applies to your Apple fleet just as it does to Windows. FileVault encryption and the macOS firewall must be configured and enforced. Software updates, including third-party applications, must be applied within the required window. Administrator rights must be controlled. Malware protection must be appropriate to the platform.
For Cyber Essentials Plus in particular, an assessor will sample your Macs directly. If those devices are not managed through a proper MDM platform, demonstrating these controls across the fleet becomes guesswork. The patching control is the most common failure point, because Intune does not natively patch third-party Mac applications the way it handles Windows, and manual patching rarely holds up to scrutiny. Our Cyber Essentials checklist covers what each control requires in practice.
ISO 27001 and your Apple estate
ISO 27001 raises the bar further. Its risk-based approach means your Apple fleet must sit clearly within the scope of your ISMS. You need an accurate asset inventory that includes every Mac and iPhone, documented configuration management for those devices, and demonstrable, ongoing control over how they are patched, encrypted and accessed.
An auditor will expect to see that the Apple portion of your estate is managed with the same discipline as the rest. A business that can produce detailed, continuous evidence for its Windows fleet but only vague assurances for its Macs has a genuine gap in its management system, and a good assessor will find it.
Why proper Apple management changes the picture
When your Apple fleet is managed through a capable MDM platform, the evidence problem largely disappears. Jamf Pro or Microsoft Intune, configured correctly, enforce the controls both frameworks require and produce the reporting that proves it. Encryption status, patch compliance, configuration enforcement and access control become device-by-device evidence you can hand to an assessor, rather than claims you hope will be accepted.
This is the practical difference between passing an audit comfortably and scrambling to justify gaps. For a mixed fleet, it is usually the Apple side that decides which of those two experiences you have.
It is also where nDuo iQ earns its place. By bringing your Apple and Windows management into a single view, it lets you demonstrate compliance across the whole estate from one place, rather than stitching together evidence from separate systems and hoping the Apple portion holds up.
How nDuo helps
We help UK businesses achieve and maintain both Cyber Essentials and ISO 27001, with particular focus on the part most providers get wrong: the Apple estate inside a mixed fleet. That means configuring your Macs and iPhones to meet the controls each framework demands, producing the evidence an assessor needs, and keeping that evidence current as your fleet grows and the standards evolve.
If you are weighing up which certification your business needs, or you already hold one and suspect your Apple fleet is the weak link in your evidence, the starting point is an honest look at where your estate actually stands.
Read our Cyber Essentials guide for the full detail on the UK scheme, or our Cyber Essentials checklist to see exactly what each control requires across Mac and Windows.
Book a free consultation with our team to talk through which framework fits your business and where your Apple fleet stands against it.