News and updates from Maple

What is Cyber Essentials Plus, and how is it different from ISO 27001? image

What is Cyber Essentials Plus, and how is it different from ISO 27001?

Alongside ISO 27001, Maple Technology has also achieved Cyber Essentials Plus. The two accreditations often get mentioned in the same breath, but they test different things in different ways. Here's what Cyber Essentials Plus actually covers, and why we think both matter.

What Cyber Essentials Plus actually is

Cyber Essentials is a UK government-backed scheme, developed with the National Cyber Security Centre, designed to protect organisations against the most common cyber attacks. There are two tiers: Cyber Essentials, which is based on self-assessment, and Cyber Essentials Plus, which adds independent, hands-on technical verification.

That's the key distinction. With Cyber Essentials Plus, an external assessor doesn't just review a questionnaire - they actively test the technical controls across an organisation's devices, network, and systems to confirm they work as claimed.

The scheme focuses on five core technical controls:

  • Firewalls and internet gateways
  • Secure configuration of devices and software
  • User access control
  • Malware protection
  • Security update (patch) management

How it differs from ISO 27001

ISO 27001 certifies the management system: the governance, the processes, the ongoing discipline around information security across an entire organisation. Cyber Essentials Plus is narrower and more technical: it verifies that specific, fundamental defences are correctly configured and actually hold up against testing, on the devices and systems in use right now.

Think of it as strategy versus verification. ISO 27001 shows a mature system is in place to manage risk over time. Cyber Essentials Plus shows the technical basics are demonstrably solid today. Together, they cover both the governance and the ground-level reality, which is exactly why we pursued both rather than treating either as sufficient alone.

Why it matters for your business

The vast majority of successful cyber attacks exploit basic, preventable weaknesses: unpatched software, weak access controls, poor configuration. Cyber Essentials Plus specifically targets these fundamentals, independently verified rather than taken on trust.

For clients working with Maple, that means:

  • Independently tested confirmation that our own devices, network, and systems meet a recognised technical security baseline
  • Assurance that isn't based on a form we filled in ourselves
  • A provider that holds itself to the same standard it recommends to clients

It's also increasingly a requirement, not just a nice-to-have. Many contracts, particularly in the public sector and supply chains for regulated industries, now specify Cyber Essentials or Cyber Essentials Plus as a minimum requirement for suppliers.

Considering it for your own organisation?

Cyber Essentials Plus is a strong starting point for businesses that haven't pursued formal security accreditation before, precisely because it focuses on fundamentals rather than a sprawling management system. The technical assessment can surface gaps you didn't know existed, even in an environment you'd consider well managed, so it's worth treating the run-up to assessment as a genuine review rather than a formality.

Together, ISO 27001 and Cyber Essentials Plus give a much fuller picture than either alone, and that's exactly why we pursued both.