ISO 27001 Certification

The honest guide to cost, timeline, and the decisions that determine whether certification actually protects your business - or just checks a box.

Key Numbers

Total cost (SMB)
$15,000 - $40,000
Total cost (Enterprise)
$40,000 - $150,000
Certification timeline
6 - 18 months
Annual surveillance audit
$3,000 - $8,000
Recertification (every 3 years)
$8,000 - $20,000
Controls required
93 (ISO 27001:2022)

Cost Breakdown

Internal Costs (often underestimated)

Staff time for gap assessment and remediation 200-600 hours
Policy writing and documentation 80-150 hours
Employee security awareness training All staff, 2-4 hours each
Risk assessment workshops 40-80 hours

External Costs

Gap assessment / readiness consultant $5,000 - $20,000
Certification body (Stage 1 + Stage 2 audit) $8,000 - $25,000
Penetration testing (often required) $5,000 - $15,000
ISMS tooling / GRC platform $2,000 - $10,000/year

Certification Timeline

Month 1-2
Gap assessment, scope definition, project team
Month 3-5
Policy development, risk assessment, control implementation
Month 6-9
Internal audit, management review, remediation
Month 9-12
Stage 1 audit (documentation review), Stage 2 audit (on-site)
Month 12+
Certification issued, surveillance audit scheduled

Timeline depends heavily on scope. A 50-person SaaS company can certify in 6 months. A 500-person manufacturer may take 18.

What Companies Get Wrong

The five failure modes I see repeatedly - and they almost always trace back to early project decisions.

1.
Scope is everything

Certifying "the whole company" adds 12 months and $30K unnecessarily. Define the minimal scope that satisfies your customer requirements.

2.
Risk assessment before controls

Companies buy tools before doing the risk assessment. You end up with controls that don't match your actual risk profile.

3.
Documentation theater

200-page policies nobody reads. ISO 27001:2022 expects evidence of operation, not documentation weight.

4.
Treating it as an IT project

ISO 27001 requires management commitment. If the CEO isn't involved in the risk acceptance process, the certification won't survive the surveillance audit.

5.
Choosing the wrong certification body

UKAS-accredited bodies are recognized globally. Non-accredited certification has no value with enterprise customers or in regulated industries.

When ISO 27001 Makes Sense

  • Enterprise customers in finance, healthcare, or government require it for vendor onboarding
  • You're bidding on EU public sector contracts (NIS2 increasingly references it)
  • You want a structured framework for your security program, not just the certificate
  • Your company is pre-IPO and wants demonstrable security governance

When It Doesn't (Yet)

  • You're pre-Product Market Fit and security is mostly AWS defaults + MFA
  • Your only customer segment doesn't ask about it
  • You don't have 6 months of focused internal bandwidth

Frequently Asked Questions

How long does ISO 27001 certification take?

6 to 18 months depending on company size and scope. A focused 50-person SaaS company with a defined scope can certify in 6-9 months. A manufacturing company with complex infrastructure and multiple sites typically takes 12-18 months.

What does ISO 27001 certification cost?

Total cost for an SMB is typically $15,000 to $40,000, including consultant fees, certification body audit, and internal staff time. Enterprises with complex environments spend $40,000 to $150,000.

Do I need a consultant for ISO 27001?

Not required, but most companies benefit from an experienced consultant for scope definition and the initial gap assessment. The scope decision in week one affects cost and timeline more than any other factor.

Is ISO 27001 required by law?

Not directly in most jurisdictions, but NIS2 in the EU (effective 2024) references it for essential and important entities. Enterprise customers in finance, healthcare, and government increasingly require it as a vendor qualification.

Sources & Further Reading

Last reviewed: October 2026

Preparing for ISO 27001? Let's Talk About Scope First.

The scope decision in week one shapes everything that follows - cost, timeline, and whether the certification holds up in your first surveillance audit. 30 minutes is enough to map your situation.

Book a Free 30-Min Session