Insights · 16 February 2026

Cyber Essentials or Cyber Trust?
How to choose.

CSA's two marks are not two rungs of one ladder, and neither one is chosen by headcount. How the choice actually works, and the two mistakes we correct most often.

The question arrives in almost the same words every time. A director has been told by a customer, a bank or a tender document that the company needs "the CSA mark," and wants to know which one. The honest answer is that Cyber Essentials and Cyber Trust are not two rungs of one ladder. They are built for organisations at different stages, and choosing wrongly tends to cost months of preparation, and sometimes a second round of assessment fees.

Side by side

Two marks,two different jobs.

The baseline

Cyber Essentials

Nine clause groups covering assets, protective controls, updates, backup and incident response. A self-assessment, verified by an independent assessor. The scope is deliberately finite: it asks whether you are doing the things that prevent the majority of ordinary incidents.

9 clause groups · verified self-assessment · 2 years
The risk-based framework

Cyber Trust

Five tiers, Supporter through to Advocate, drawing on twenty-two cybersecurity domains. A risk assessment indicates your tier, then a two-stage audit checks first your design and then whether the controls are actually running.

5 tiers · 22 domains · two-stage audit · 3 years + annual surveillance

The sizing mistake we correct most often

People pick a Cyber Trust tier by counting endpoints or headcount. It is an easy mistake to make, because endpoint bands do appear in the paperwork. They appear in funding package descriptors, where they help size the support you can claim. They are not what determines your tier.

Your tier comes out of the risk assessment: what you hold, who would want it, what would happen if you lost it. A thirty-person firm running a regulated data set can sit above a two-hundred-person firm that holds very little. If someone names your tier on the basis of your staff count, ask which risk assessment produced that answer.

The second mistake, which is more expensive

Cyber Essentials does not get you most of the way to Cyber Trust. The two schemes are related, and the relationship is routinely read as more generous than it is. Two things are worth knowing before you plan around it.

First, Cyber Essentials separates requirements ("shall") from recommendations ("should"), and the recommendations do not block your Cyber Essentials certification. Under Cyber Trust those same recommendations become mandatory from the Practitioner tier upward. Treating them as optional is the most reliable way to walk into a Cyber Trust assessment believing you are ready.

Second, we mapped the two schemes clause by clause against CSA's self-assessment workbook (version 2025-04, mapped February 2026). On that count, sixteen of the thirty-eight assessable Supporter and Practitioner clauses in Cyber Trust have a Cyber Essentials equivalent. The remaining twenty-two exist only in Cyber Trust:

  • Formal risk identification, analysis and response, reviewed regularly
  • Identifying the laws that apply to you, and evidencing how you meet them
  • Tracking who has completed security awareness training
  • Breach reporting to management, authorities and affected individuals
  • Approved encryption protocols, algorithms and minimum key lengths
  • Network access control, stateful firewalling and web filtering

Because the tiers are cumulative, all thirty-eight are assessed at Promoter and above. That is our mapping rather than a CSA publication, and it moves when the workbook is revised, so check the version you are working from. We are happy to share the mapping if it would help.

Cyber Essentials is a genuine head start.
It is not two thirds of the job.

Sixteen of the thirty-eight baseline Cyber Trust clauses have a Cyber Essentials equivalent. The other twenty-two are Cyber Trust only.

9
Cyber Essentials clause groups
5
Cyber Trust tiers, set by risk
22
Baseline clauses with no CE equivalent
2/3
Years of validity, CE / CT

When the answer is "neither, yet"

Certification assesses what you already do. It is not a programme that installs good practice on your behalf, and entering early tends to produce a long list of findings and a second round of work.

Three questions are a fair self-test:

  • Can you produce a current list of your devices, software and user accounts?
  • Can you show that someone has restored from a backup recently, rather than that backups are running?
  • Is there a named person who would run an incident, and does anyone else know their name?

If any of those is uncomfortable, that work comes first. It also tends to be the least expensive phase, because it needs decisions and record-keeping rather than new technology.

How much runway each one needs

Cyber Essentials can move quickly, because the assessment is a verified self-assessment rather than a staged audit.

Cyber Trust needs planning room, and the arithmetic is worth doing before you commit to a date. The gap between Stage 1 and Stage 2 cannot exceed six months, or Stage 1 has to be redone. Assessors also expect to see roughly three months of operating records by the time Stage 2 runs, so a control implemented the week before the audit has nothing to show. Add whatever remediation your own gap analysis turns up, which for most first-time organisations is the longest item on the list. On those three assumptions, a first Cyber Trust certification is a project you start about a year out. If your controls are already running and evidenced, it is shorter.

Funding

Support is available for both, and the mechanics differ by scheme and by your eligibility. Greenwich is a CSA-funded CISOaaS provider, so this is a conversation we have with clients before the engagement is scoped rather than after. It is worth having early, because the funding route can change how the work is staged.

The short answer

If you are an SME with a straightforward IT estate and a customer asking for assurance, start with Cyber Essentials. It is proportionate, it is finite, and it will surface the gaps that matter.

If you hold significant volumes of personal or commercially sensitive data, operate in a regulated supply chain, or have been told specifically that Cyber Trust is expected, size the tier from a risk assessment and give yourself a year.

If neither is true yet, do the inventory, prove a restore, and name an incident owner. Then call us.

One disclosure

Greenwich holds the Cyber Trust mark itself, certified at Promoter tier in November 2025, with the optional Cloud Security and AI Security pillars in scope alongside the classical one. We went through the two-stage audit as the client rather than the consultant.

Not sure which applies?

Tell us what you hold and who is asking for assurance. That is usually enough for us to say which mark fits, or to say that neither does yet.

There is more of this in our
regulatory watch.