The right certification depends on what your commercial environment is actually asking for.
Cyber Essentials, IASME Cyber Assurance and ISO 27001 are not interchangeable. Each addresses a different level of scrutiny and serves a different commercial purpose. The right route is the one that satisfies your buyer, contract or regulator — not the most impressive-sounding option.
The main certification routes and what each one does.
| Certification | What it assesses | Audit type | Best fit |
|---|---|---|---|
| Cyber Essentials | Five technical controls against common cyber attacks | Verified self-assessment | Supply chain baseline, government contracts, insurance |
| Cyber Essentials Plus | Same five controls with independent technical testing | Technical audit by assessor | Where buyers require independently verified technical assurance |
| IASME Cyber Assurance L1 | Broader governance including policies, risk and suppliers | Verified self-assessment | Where CE alone is not enough but full audit not yet required |
| IASME Cyber Assurance L2 | Same as L1 with independent audit of operating controls | Independent audit | Higher-trust procurement, public sector, supply chain scrutiny |
| ISO 27001 | Full information security management system | Stage 1 + Stage 2 certification audit | Enterprise contracts, regulated sectors, investor diligence |
How to choose the right route for your situation.
What is driving the requirement? A contract, a buyer, a regulator, an insurer or an internal governance decision all point to different routes.
Some buyers specify a standard by name. Others describe an outcome — independently audited assurance, for example — which gives more flexibility on route.
Where you start affects the effort required and the most efficient route to the right outcome. Existing controls may already satisfy more than you expect.
The best certification is the one that satisfies the commercial requirement without unnecessary overhead. Over-certification creates maintenance burden with no additional commercial benefit.
A short conversation usually clarifies the right route.
Most organisations spend less than 20 minutes with YDC before having a clear view of which certification fits their situation, what the effort looks like and what a realistic timeline is.