CRYPTOITDATACRYPTOITDATA

Cybersecurity

ISO 27001 for small businesses: where to start and what it costs

A practical guide to ISO 27001 certification for SMBs: what the standard involves, the implementation stages, how long it takes, what it costs and when it is truly worth it.

8 min read

The question usually comes up suddenly: an important client or a tender asks for ISO 27001 certification before you can sign the contract. Or you realise that, without a recognised security framework, you lose credibility with partners. The good news is that ISO 27001 is perfectly accessible to small businesses too — provided you approach it correctly.

What ISO 27001 actually is

ISO/IEC 27001 is the international standard for information security management systems (ISMS). Importantly, it does not certify a product or a server, but a way of managing security risks. It demonstrates that your company systematically identifies threats to information and applies controls proportionate to the risk.

In other words, ISO 27001 does not say "you have antivirus", but "you have a process by which you rationally decide what you protect, how and why". This is also why it overlaps heavily with NIS2 requirements and with good cybersecurity practice.

The myth "it is only for corporations"

The standard is scalable by design. A 15-person company does not have to implement the same controls as a bank — it only has to implement the controls justified by its own risk profile. You define the scope: you can certify just one department, one product or one process, not necessarily the whole organisation. That keeps effort and cost under control.

The implementation stages

  1. 1Defining the scope: which information, processes and locations are in the system.
  2. 2Risk analysis: identify information assets, threats and vulnerabilities, then assess impact and likelihood.
  3. 3Selecting controls: choose from Annex A (the reference controls) those justified by the risks, documented in a Statement of Applicability (SoA).
  4. 4Documenting policies and procedures: not bureaucracy for its own sake, but rules the team actually follows.
  5. 5Implementation and operation: put the controls into practice and gather evidence (logs, records, training).
  6. 6Internal audit and management review: you check yourself before the external auditor does.
  7. 7Certification audit: an accredited certification body assesses the system in two stages and issues the certificate.

How long it takes

For a small or mid-sized company, a well-run implementation typically takes 3-6 months to the certification audit. The factors that matter: how mature your security environment already is, how broad the chosen scope is, and how quickly the internal team responds. The certificate is then valid for 3 years, with annual surveillance audits.

What it costs

The cost has two distinct components: (1) implementation — consulting, internal time and any technical tools; and (2) the certification itself, paid to the accredited certification body, calculated based on headcount and complexity. For a small company, certification is surprisingly affordable; the variable part is the implementation effort, which drops dramatically if you start from an already orderly environment or work with an experienced partner.

The expensive mistake is not the certification — it is the chaotic implementation, where you buy tools you do not need and write policies no one follows.

When it is truly worth it

  • Clients or tenders explicitly require it — the most common trigger.
  • You process sensitive data and want to demonstrate seriousness (complementary with data protection / GDPR).
  • You are preparing for NIS2 — ISO 27001 covers most of the requirements.
  • You want a real competitive edge over uncertified competitors.

How we can help

We are ISO 27001 certified and an authorised DNSC auditor — we have walked this path both for ourselves and for clients. We help you define a realistic scope, do the risk analysis without turning it into an endless project, and reach certification with the minimum necessary effort. If you are considering ISO 27001, let us talk for 30 minutes about your specific situation.

Frequently asked questions

Can a company with 10 employees obtain ISO 27001?+

Yes. The standard is scalable: you implement the controls justified by your own risk profile, not a fixed set. Many small companies are certified, often for a well-defined scope (a product or a department).

What is the difference between ISO 27001 and GDPR?+

ISO 27001 is a framework for managing information security (how you protect any important information). GDPR is a specific legal regulation for personal data. They complement each other: a well-built ISO 27001 ISMS directly supports GDPR compliance.

Does ISO 27001 automatically make me NIS2 compliant?+

Not automatically, but it gets you very close. The two frameworks overlap significantly on risk management and technical and organisational controls. With ISO 27001 implemented, you are typically at 70-80% of the NIS2 requirements.

How often must the certification be renewed?+

The ISO 27001 certificate is valid for 3 years, with annual surveillance audits to confirm the system remains functional. At the end of the cycle a recertification audit follows.

Have a concrete question?

30 minutes, free. We discuss exactly your situation.

Book a consultation