A conversation I have almost weekly: a company wants “the ISO 27001” because a customer asked about their cybersecurity. Halfway through scoping, it turns out what the customer actually asked for was evidence of good cyber hygiene — and there was a faster, cheaper way to give it. Here is how to think about the pathway.
Two different questions
Cyber Essentials (CSA’s national mark) answers the question: “has this company done the cybersecurity basics?” Asset inventory, anti-malware, access control, secure configuration, software updates, backups, incident response. It is designed for SMEs and is assessed on declared evidence — practical, fast, affordable.
ISO 27001 answers a bigger question: “does this company run a management system that continuously governs its information security?” It is an international certification with a risk-based ISMS, internal audits, management reviews, and a certification body audit cycle. It is what MNCs, regulated industries and overseas customers recognise.
The mistake in both directions
Overshooting: a 15-person local firm signs up for ISO 27001 because “it sounds more powerful”, spends months and five figures, and discovers their customers would have accepted Cyber Essentials. The ISMS then becomes shelf-ware they dread maintaining.
Undershooting: a growing tech firm gets Cyber Essentials, then six months later a large client’s vendor assessment demands ISO 27001 anyway — and they start again from scratch, paying twice for overlapping work.
The honest decision test
- Who is asking? Local SME customers, government SME programmes → Cyber Essentials usually satisfies. MNCs, financial institutions, overseas clients, formal vendor-assessment questionnaires → ISO 27001 is usually the named requirement. Read the actual contract clause before deciding.
- What do you hold? If you process sensitive personal data, run client systems, or sit in a critical supply chain, the risk-based depth of 27001 (or Cyber Trust Mark) fits. If your exposure is ordinary office IT, Essentials-level hygiene is genuinely proportionate.
- Where are you going? If enterprise clients are 12–18 months away in your plan, sequencing matters more than choosing.
The sequencing secret: the work overlaps heavily
This is the part most companies never get told: the two are not separate projects. The asset inventories, access-control policies, patching discipline, backup regime and incident-response plan you build for Cyber Essentials map directly onto ISO 27001’s Annex A controls. Done deliberately, Cyber Essentials becomes phase one of a future ISMS — the certificate you can show customers this quarter, while the 27001 foundation quietly accumulates underneath.
The same logic applies to the Cyber Trust Mark, CSA’s risk-based mark for more digitally mature organisations: its domains overlap substantially with 27001 controls, so a company holding one should never pay full price to build the other from zero.
Bottom line
Start from the contract in front of you, not the certificate with the bigger name. If nobody has named a standard yet, Cyber Essentials first is the right default for most Singapore SMEs — provided whoever builds it does so with the 27001 mapping in mind, so nothing is thrown away when you level up.
Thong Kian Leong is the founder and principal consultant of Sage Shield Safety Consultants, a bizSAFE STAR and CSA Cyber Security Essentials-certified firm that has served 1,300+ organisations, delivering ISO 27001, Cyber Essentials and Cyber Trust Mark end to end. Talk to us about the right pathway.