Buy The Certificate Your Pipeline Is Asking For.
A founder asked to produce a security certificate usually asks which one is best. It is the wrong question, and it leads to a year of work that opens no door. Cyber Essentials, ISO 27001 and a SOC 2 report are not three grades of the same qualification. They are three instruments of market access, each accepted by a different kind of buyer, and the right one is decided by where the next twelve months of revenue is coming from rather than by which is most rigorous. The government's own figures suggest the more expensive mistake is already common: 24% of UK businesses report having controls in all five areas that Cyber Essentials covers, while only 5% hold the certificate. A quarter of the market has done the work and cannot prove it.
Cyber Essentials areas
that proves it
up from 5% a year earlier
They are your buyers
Situation
Three instruments dominate the questions a smaller UK supplier now receives, and they come from different directions.
Cyber Essentials is the scheme the NCSC describes as the minimum standard of cyber security recommended by government, aligned to five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. The NCSC describes the standard certification as a combination of self-assessment and independent audit, and Cyber Essentials Plus as the same protections with more rigorous, independent technical testing. Procurement Policy Note 014, which took effect on 24 February 2025, requires it of suppliers to central government departments, executive agencies, non-departmental public bodies and NHS bodies where the contract involves citizen data, government employee data, OFFICIAL information or the systems that process it. The note is explicit that it should not be applied to every contract as a matter of course, but where those characteristics exist it is the condition of entry.
ISO 27001 is an international standard for an information security management system, and certification against it is issued by an independent certification body. In the UK the meaningful distinction is accreditation: the United Kingdom Accreditation Service describes itself as the National Accreditation Body for the United Kingdom, appointed by government to assess and accredit organisations providing certification and related services. Enterprise and regulated buyers in the UK and Europe tend to ask for ISO 27001, and the better informed ones ask whether the certificate came from an accredited body.
A SOC 2 report is a different species altogether. It is not a certificate. It is an attestation report prepared by a certified public accountant under the American Institute of Certified Public Accountants' framework, examining controls at a service organisation against the trust services categories of security, availability, processing integrity, confidentiality and privacy. North American software buyers ask for it as a matter of routine, and a UK company selling into that market will meet it in the first procurement conversation rather than the last.
Against that, adoption is thin. The Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found 5% of UK businesses holding Cyber Essentials, rising to 12% of small businesses, up from 5% the previous year, and 35% of large businesses, up from 21%. The same survey found that 24% of businesses reported having controls in all five areas the scheme covers, and that the overall certification rate had risen from 3% the previous year.
Insight
Those two numbers, 24% and 5%, are the whole argument. The gap between them is not a security gap. It is a proof gap, and it is expensive in a way that does not appear on any report, because the companies inside it are losing bids on paperwork while running controls that would have passed.
The useful reframing is this. A certificate is not a measure of how secure a company is. It is a statement a buyer's procurement function is willing to accept in place of investigating for itself. That is why the instruments are not interchangeable and why rigour is the wrong axis on which to compare them. ISO 27001 is a broader undertaking than Cyber Essentials, but a US buyer who wants a SOC 2 report will not accept it as a substitute, and a UK public body operating under PPN 014 will not accept a SOC 2 report in place of Cyber Essentials. The question is never which is strongest. It is which one the people with the budget have been told to look for.
The second point follows from the first. The underlying controls overlap heavily: access management, change control, logging, backup, incident response and supplier management appear in all three. That overlap is why the marginal cost of the second instrument is far lower than the first. The work that is expensive is the evidence discipline, and it is bought once.
Options
A company of between twenty and two hundred people has three realistic approaches.
The first is to certify nothing and answer questionnaires as they arrive. Each buyer is handled individually, with evidence assembled per deal.
The second is to certify comprehensively, taking ISO 27001 and a SOC 2 report together on the assumption that the broadest coverage removes the problem permanently.
The third is to certify to the pipeline. The company maps the next twelve months of expected revenue by buyer type, identifies the single instrument that unlocks the largest share of it, obtains that one first, and adds a second only when a named opportunity requires it.
Trade-offs
Certifying nothing preserves cash and is defensible for a company selling to buyers who do not ask, which in practice means small commercial customers and some consumer markets. Its weakness is that the cost is invisible. A procurement filter that excludes an uncertified supplier does not generate a rejection, so the loss never reaches a report, and the company concludes that certification was unnecessary because nothing appeared to go wrong.
Certifying comprehensively is the most defensible position in any single conversation and the least defensible use of money at this size. It commits a year of management attention and two sets of fees before the company knows which buyers it will actually serve. It is the right answer later, when both markets are live, and the wrong answer when one is hypothetical.
Certifying to the pipeline accepts that a gap will remain. A buyer will eventually appear asking for the instrument the company does not hold, and that deal will move slowly or not at all. In exchange, the first certificate is obtained in the cycle where it converts revenue rather than theory, the evidence discipline is established once, and the second instrument is a shorter exercise because the controls are already running and documented.
Recommendation
We recommend the third approach, decided on evidence rather than instinct. Take the pipeline and the named accounts for the next four quarters and sort them into three buckets: UK public sector and its supply chain; UK and European enterprise, particularly in financial services and other regulated sectors; and North American software buyers. Weight each bucket by expected revenue rather than by number of opportunities.
Where the first bucket dominates, start with Cyber Essentials and treat Cyber Essentials Plus as the follow-on when a buyer asks for independent technical testing of the controls. Where the second dominates, start with ISO 27001, use a certification body accredited by the United Kingdom Accreditation Service, and define the scope to cover the services the customer actually buys rather than a narrow corner of the business. Where the third dominates, start with a SOC 2 Type 2 report, accepting that it reports on a period of operation and therefore cannot be produced in the week a buyer asks for it.
In every case, build the evidence file first and the certificate second. The policies, the access reviews, the restore test record, the training log and the incident plan are common to all three instruments, and they are also what an enterprise security questionnaire and an insurer's proposal form ask for.
Why
The commercial case has three parts. First, revenue conversion. A certificate aligned to the buyers in the pipeline turns filtered opportunities into contestable ones, and the 24% figure suggests many companies are one administrative exercise away from that position. Second, sequencing cost. Taking the instrument the market is asking for first means the second is incremental rather than duplicative, because the control set and the evidence are shared. Third, credibility under scrutiny. Accredited certification and an attestation signed by a CPA firm carry weight precisely because the buyer did not have to take the supplier's word for it, which is the function being purchased.
Risks
Five risks are worth naming. Scope is the first and most common: an ISO 27001 certificate whose scope statement excludes the product the customer is buying is worth very little, and sophisticated buyers read the scope before the certificate. Second, the distinction between a SOC 2 Type 1 and a Type 2 report is material, since the first addresses the design of controls at a point in time and the second their operation across a period, and a buyer asking for a Type 2 will not be satisfied by a Type 1. Third, certification bodies differ, and a certificate from a body without accreditation may be challenged by a buyer who checks. Fourth, a certificate decays: it is a point in time statement maintained by surveillance activity and internal discipline, and a company that treats it as a one off purchase will meet the problem again at renewal. Fifth, a certificate does not remove the questionnaire. It shortens it, and buyers in regulated sectors will still ask their own questions.
Next Move
The first step costs nothing: take the pipeline, sort it into the three buckets above, and weight them by revenue. That single exercise usually settles the question that founders find hardest, which is not whether to certify but which instrument to buy first.
Garzon Cyber Solutions is built to carry that sequence through. The technical foundations are delivered with specialist technology partners, so the controls a certificate attests to are actually running. The compliance layer maps those controls to the instrument the pipeline requires, whether that is Cyber Essentials, ISO 27001 or readiness for a SOC 2 examination, and assembles the evidence once so that it also answers enterprise questionnaires and insurers. Where the company then needs a permanent owner for that file, we recruit on contingency, with nothing payable until the candidate accepts and starts. We are a young firm, and we built it on the view that these three capabilities are worth more delivered in sequence than bought separately.
Confidence note
Confirmed. That the Cyber Security Breaches Survey 2025/2026, published by DSIT and the Home Office on 30 April 2026, reports 5% of UK businesses holding Cyber Essentials certification, 12% of small businesses (up from 5% in the previous year), 35% of large businesses (up from 21%), and 24% of businesses reporting controls in all five areas the scheme covers, with the overall rate up from 3% in 2024/2025. That the NCSC describes Cyber Essentials as the minimum standard of cyber security recommended by government, aligned to the five technical controls named above, with the standard certification being a combination of self-assessment and independent audit and Cyber Essentials Plus adding more rigorous, independent technical testing. That Procurement Policy Note 014 took effect on 24 February 2025, applies to central government departments, executive agencies, non-departmental public bodies and NHS bodies, sets the Cyber Essentials requirement for contracts with the characteristics described, and states that Cyber Essentials should not be applied to all contracts as a matter of course. That the United Kingdom Accreditation Service describes itself as the National Accreditation Body for the United Kingdom, appointed by government to assess and accredit organisations providing certification, testing, inspection, calibration, validation and verification. That SOC reporting is described by the American Institute of Certified Public Accountants as a suite of service offerings that CPAs may provide in connection with system level controls at a service organisation, and that the trust services categories are security, availability, processing integrity, confidentiality and privacy.
Assessed. That UK public sector buyers ask for Cyber Essentials, UK and European enterprise buyers for ISO 27001, and North American software buyers for SOC 2 is our assessment from procurement practice and the policy position, not a published mapping; individual buyers vary and some ask for more than one. That the control sets overlap sufficiently for the second instrument to be materially cheaper than the first is our assessment from the standards themselves rather than a measured figure. The characterisation of a SOC 2 Type 1 as addressing design at a point in time and a Type 2 as addressing operating effectiveness over a period reflects standard practice in the market; the length of the observation period is agreed between the service organisation and its auditor. That buyers check the accreditation status of a certification body is our assessment from observed procurement behaviour.
Not known. What proportion of UK private sector buyers apply ISO 27001 as a hard gate rather than a preference. How many UK companies hold both ISO 27001 and a SOC 2 report. Whether the rise in Cyber Essentials certification among small businesses reflects procurement pressure, the policy note, or wider awareness, since the survey does not attribute the change.
Which of your next four quarters of revenue is sitting behind a certificate you do not hold?
Garzon Cyber Solutions puts the controls in place with specialist technology partners, maps them to the instrument your pipeline actually requires, and recruits the person who owns it on contingency. Cybersecurity, compliance and talent, delivered in that order, as one capability.
Start the Conversation →Sources: DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, 30 April 2026 · NCSC, Cyber Essentials Overview, accessed 2 October 2026 · Cabinet Office, Procurement Policy Note 014, Cyber Essentials Scheme, effective 24 February 2025 · United Kingdom Accreditation Service, What We Do, accessed 2 October 2026 · American Institute of Certified Public Accountants, System and Organization Controls (SOC) Suite of Services, accessed 2 October 2026