The question usually comes up suddenly: an important client or a tender asks for ISO 27001 certification before you can sign the contract. Or you realise that, without a recognised security framework, you lose credibility with partners. The good news is that ISO 27001 is perfectly accessible to small businesses too — provided you approach it correctly.
What ISO 27001 actually is
ISO/IEC 27001 is the international standard for information security management systems (ISMS). Importantly, it does not certify a product or a server, but a way of managing security risks. It demonstrates that your company systematically identifies threats to information and applies controls proportionate to the risk.
In other words, ISO 27001 does not say "you have antivirus", but "you have a process by which you rationally decide what you protect, how and why". This is also why it overlaps heavily with NIS2 requirements and with good cybersecurity practice.
The myth "it is only for corporations"
The standard is scalable by design. A 15-person company does not have to implement the same controls as a bank — it only has to implement the controls justified by its own risk profile. You define the scope: you can certify just one department, one product or one process, not necessarily the whole organisation. That keeps effort and cost under control.
The implementation stages
- 1Defining the scope: which information, processes and locations are in the system.
- 2Risk analysis: identify information assets, threats and vulnerabilities, then assess impact and likelihood.
- 3Selecting controls: choose from Annex A (the reference controls) those justified by the risks, documented in a Statement of Applicability (SoA).
- 4Documenting policies and procedures: not bureaucracy for its own sake, but rules the team actually follows.
- 5Implementation and operation: put the controls into practice and gather evidence (logs, records, training).
- 6Internal audit and management review: you check yourself before the external auditor does.
- 7Certification audit: an accredited certification body assesses the system in two stages and issues the certificate.
How long it takes
For a small or mid-sized company, a well-run implementation typically takes 3-6 months to the certification audit. The factors that matter: how mature your security environment already is, how broad the chosen scope is, and how quickly the internal team responds. The certificate is then valid for 3 years, with annual surveillance audits.
What it costs
The cost has two distinct components: (1) implementation — consulting, internal time and any technical tools; and (2) the certification itself, paid to the accredited certification body, calculated based on headcount and complexity. For a small company, certification is surprisingly affordable; the variable part is the implementation effort, which drops dramatically if you start from an already orderly environment or work with an experienced partner.
The expensive mistake is not the certification — it is the chaotic implementation, where you buy tools you do not need and write policies no one follows.
When it is truly worth it
- Clients or tenders explicitly require it — the most common trigger.
- You process sensitive data and want to demonstrate seriousness (complementary with data protection / GDPR).
- You are preparing for NIS2 — ISO 27001 covers most of the requirements.
- You want a real competitive edge over uncertified competitors.
How we can help
We are ISO 27001 certified and an authorised DNSC auditor — we have walked this path both for ourselves and for clients. We help you define a realistic scope, do the risk analysis without turning it into an endless project, and reach certification with the minimum necessary effort. If you are considering ISO 27001, let us talk for 30 minutes about your specific situation.