
ISO 27001 certification has become one of the most sought-after credentials in information security. Whether you are an IT manager preparing a board presentation, a startup CTO responding to a client security questionnaire, or a compliance officer mapping your organisation’s risk posture, this guide walks you through exactly what ISO 27001 requires, how the certification process works, what it costs, and how long it takes.
What Is ISO 27001?
The standard explained: ISMS and its purpose
ISO 27001 is the international standard for Information Security Management Systems (ISMS). Published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), it provides a systematic framework for establishing, implementing, maintaining, and continually improving information security within an organisation.
The core idea behind ISO 27001 is risk-based governance. Rather than prescribing a fixed set of technical controls, the standard requires organisations to identify their specific information security risks and then select, implement, and monitor controls proportionate to those risks. This makes ISO 27001 applicable across sectors and company sizes, from a ten-person fintech startup to a multinational logistics provider. Certification itself is issued by an accredited third-party certification body. When your organisation achieves ISO 27001 certification, it signals to clients, partners, regulators, and supply-chain stakeholders that your information security posture has been independently verified against a globally recognised benchmark.
ISO 27001:2022 vs. the 2013 version: what changed
The current version is ISO/IEC 27001:2022, published in October 2022. Organisations certified under the 2013 edition had until October 2025 to transition. Any organisation starting a new certification journey today must certify against the 2022 version. The most visible change in 2022 is the restructured Annex A. The previous edition contained 114 controls across 14 domains. The 2022 revision reorganised these into 93 controls across 4 themes: Organizational, People, Physical, and Technological. Eleven entirely new controls were added to address modern threat landscapes, including threat intelligence, cloud security, data masking, web filtering, secure coding practices, and data leakage prevention.
Beyond Annex A, the 2022 update introduced the concept of “attributes” for controls (allowing organisations to tag controls by security concept, operational capability, and information security property), and added a requirement for organisations to identify and document the “information security properties” relevant to each control. The main clauses (4 to 10) remain structurally similar but include refined language around planning, interested parties, and risk treatment.
Who Needs ISO 27001 Certification?
Industries and business types that benefit most
ISO 27001 certification is relevant to any organisation that stores, processes, or transmits sensitive information. That said, certain sectors see the strongest commercial and regulatory pull:
Financial services and fintech: Banks, payment processors, and insurance companies face regulatory expectations around data protection that ISO 27001 helps satisfy. Many procurement frameworks in this sector require suppliers to hold the certification.
Healthcare and life sciences: Organisations processing health data under GDPR or national healthcare regulations use ISO 27001 as a structural framework for demonstrating appropriate safeguards.
SaaS and cloud providers: B2B software vendors increasingly encounter ISO 27001 requirements in enterprise sales cycles, especially in European, UK, and APAC markets.
Government and public sector contractors: Many public procurement frameworks, particularly in Germany, the UK, and across the EU, require or favour ISO 27001 certification for IT suppliers.
Professional services: Law firms, consulting companies, and accounting practices handling confidential client data face growing client-driven demands for certification.
ISO 27001 for startups and SMBs
ISO 27001 is not just for large enterprises. Startups and small-to-medium businesses increasingly pursue certification for two reasons: closing enterprise deals faster and satisfying due diligence requests from investors or partners. For a startup selling into regulated industries or large enterprises, ISO 27001 removes a common procurement blocker. The upfront investment is meaningful, but many organisations recoup it through shortened sales cycles and higher-value contract wins. For SMBs, the certification process also has an internal benefit: it forces the organisation to document processes, assign ownership for security responsibilities, and build hygiene practices that reduce the risk of costly incidents.
ISO 27001 Requirements and Controls
Annex A controls: the 93 controls across 4 themes
Annex A of ISO 27001:2022 lists 93 controls grouped into four themes. These are not all mandatory: organisations must evaluate each control and either implement it or document a justified exclusion in their Statement of Applicability (SoA).
Organizational controls (37 controls): These cover policies, roles, responsibilities, supplier relationships, incident management, and business continuity. Examples include information security policies, classification of information, asset management, and supplier security.
People controls (8 controls): These address the human element: screening, terms of employment, security awareness, training, disciplinary processes, and remote working. The relatively small count reflects how much human-risk content was consolidated compared to the 2013 edition.
Physical controls (14 controls): These govern physical and environmental security, including perimeter controls, clear desk and screen policies, physical media disposal, equipment maintenance, and monitoring of physical premises.
Technological controls (34 controls): This is the largest new grouping and covers the technical side of security, including access control, cryptography, network security, vulnerability management, logging and monitoring, and the eleven newly introduced controls. The new controls address threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.
Mandatory clauses (4-10) and what they require
Beyond Annex A, ISO 27001:2022 contains ten numbered clauses. Clauses 4 through 10 are mandatory for certification: no exclusions are permitted. Clause 4 (Context): Define the internal and external issues relevant to information security, identify interested parties and their requirements, and determine the scope of the ISMS. Clause 5 (Leadership): Top management must demonstrate commitment to the ISMS, establish an information security policy, and assign roles and responsibilities.
Clause 6 (Planning): Conduct a risk assessment, define risk acceptance criteria, produce a risk treatment plan, and create the Statement of Applicability. Clause 7 (Support): Ensure adequate resources, competence, awareness, communication, and documented information. Clause 8 (Operation): Implement and control the processes defined in planning, run the risk assessment on a scheduled basis, and manage the risk treatment plan. Clause 9 (Performance evaluation): Monitor, measure, analyse, and evaluate ISMS performance. Conduct internal audits and management reviews. Clause 10 (Improvement): Address nonconformities through corrective action and drive continual improvement of the ISMS.
The Certification Process Step by Step
Scoping and gap analysis
The first step is defining what falls within your ISMS scope: which systems, locations, processes, and business units will be covered by the certification. Scope decisions have significant downstream effects on cost, complexity, and the value the certificate provides to clients. A narrow scope certifies faster but may satisfy fewer client requirements; a broad scope takes longer but delivers stronger commercial positioning. Following scope definition, a gap analysis compares your current state against the requirements of clauses 4 to 10 and the controls you plan to implement. The gap analysis produces a prioritised remediation roadmap and is typically the first deliverable when working with an external consultant.
Building your ISMS documentation
ISO 27001 is documentation-heavy by design. The standard requires a range of mandatory documented information, including: the ISMS scope document, the information security policy, the risk assessment methodology, the risk register, the risk treatment plan, the Statement of Applicability, internal audit results, management review records, and evidence of corrective actions. Beyond the mandatory documents, most organisations produce supporting policies and procedures covering areas such as access control, cryptography, incident response, asset management, supplier onboarding, and business continuity. Building and reviewing these documents typically represents the most time-intensive phase of the project, especially for organisations formalising practices that previously existed only informally.
Stage 1 audit: documentation review
Once your documentation is in place, the certification body conducts a Stage 1 audit, sometimes called a documentation review or readiness review. The auditor reviews your ISMS documentation to confirm it meets the formal requirements of the standard and that you are ready to proceed to Stage 2. The Stage 1 audit is typically conducted remotely and lasts one to two days depending on the size and complexity of your scope. Auditors will flag any major gaps or areas of concern that must be resolved before Stage 2. Common Stage 1 findings include incomplete Statements of Applicability, missing links between the risk register and the risk treatment plan, and internal audit programmes that have not yet been completed.
Stage 2 audit: operational effectiveness
The Stage 2 audit is the main certification assessment. The auditor visits your organisation (on-site or a combination of on-site and remote) and evaluates whether the controls and processes described in your documentation are actually being implemented and operating effectively. Auditors will interview staff across functions, review evidence of control operation (logs, access control records, training records, supplier contracts, incident reports), and test whether the procedures in your documentation reflect what actually happens in practice.
The Stage 2 audit typically takes two to five days for small and medium organisations, longer for larger or multi-site scopes. If the auditor identifies nonconformities during Stage 2, these are classified as major or minor. Major nonconformities prevent certification until resolved; minor nonconformities must be addressed before the next surveillance audit.
Certification, surveillance, and recertification
Once all nonconformities are resolved and the audit report is reviewed and approved, the certification body issues your ISO 27001 certificate. Certificates are valid for three years. During the three-year cycle, the certification body conducts annual surveillance audits (typically lighter in scope than the initial certification audit) to verify that the ISMS continues to operate effectively and that any previously identified nonconformities have been addressed. At the end of the three-year cycle, a recertification audit is conducted, which is broadly similar in scope to the original Stage 2.
How Much Does ISO 27001 Certification Cost?
Breakdown: consultant fees, tooling, and audit costs
ISO 27001 certification costs fall into three main categories:
Consultant fees: Most organisations engage an external consultant or managed service provider to lead the implementation. Consultant fees typically cover gap analysis, documentation development, internal audit support, and pre-audit preparation. For a typical SMB engagement, expect to budget between EUR 15,000 and EUR 50,000 for professional services, depending on scope complexity and your team’s internal availability.
Tooling: Dedicated ISMS platforms (such as Vanta, Drata, or Sprinto) can accelerate documentation, evidence collection, and ongoing compliance management. Costs range from a few thousand euros per year for smaller organisations to tens of thousands for enterprise deployments. Some organisations manage their ISMS using standard tools such as SharePoint, Confluence, or spreadsheets, which reduces software costs but increases manual effort.
Audit fees: Certification body fees vary by accreditation body, geography, and audit duration. For small organisations, Stage 1 and Stage 2 audit fees typically range from EUR 3,000 to EUR 8,000 combined. For medium organisations, EUR 8,000 to EUR 20,000 is a typical range. Annual surveillance audits are generally priced at around 30 to 50 percent of the initial audit fee.
Cost by company size
The following ranges provide a practical planning benchmark for total all-in costs (consultant, tooling, and audit fees combined) for an initial certification: Small organisations (fewer than 50 staff): EUR 10,000 to EUR 30,000 Medium organisations (50 to 250 staff): EUR 30,000 to EUR 80,000 Large organisations (more than 250 staff): EUR 80,000 to EUR 200,000 and above These figures assume a reasonable internal time commitment from your team. Organisations with very limited internal bandwidth, or those pursuing broad multi-site scopes, should budget toward the upper end. Organisations with a strong existing security baseline and good internal documentation capability can often achieve certification toward the lower end of the range.
How Long Does ISO 27001 Take?
Typical timelines from kickoff to certificate
Timeline depends on the size and complexity of the organisation, the scope of the ISMS, the internal resources available, and the starting security maturity. The following ranges are based on typical project experience:
Small organisations (fewer than 50 staff): 3 to 6 months from project kickoff to certificate
Medium organisations (50 to 250 staff): 6 to 12 months
Large organisations (more than 250 staff): 12 to 18 months or more
The most common causes of timeline delay are documentation development (particularly when processes need to be formalised before they can be documented), internal audit scheduling, and management review sign-off. Engaging an experienced implementation partner and dedicating at least one internal resource as ISMS owner significantly reduces these delays. Certification bodies typically need two to four weeks of lead time between Stage 1 and Stage 2 audits, and the report review and certificate issuance process usually adds another two to four weeks after Stage 2 completion.
ISO 27001 vs. SOC 2: choosing the right framework
ISO 27001 and SOC 2 are both widely recognised information security frameworks, but they serve different markets and have different structures. ISO 27001 is an international standard with certification issued by accredited bodies. It is the dominant framework for European, UK, government, and APAC procurement.
If your primary customer base is in the EU or UK, if you are pursuing public sector contracts, or if your prospects include regulated industries with international procurement requirements, ISO 27001 is almost always the right starting point. SOC 2 is a US-focused attestation framework administered by the American Institute of CPAs (AICPA). It is the standard reference point for US enterprise SaaS buyers, particularly in the technology sector. SOC 2 reports are point-in-time attestations rather than ongoing certifications: a Type I report attests to control design at a point in time, while a Type II report attests to operating effectiveness over a defined period (typically six to twelve months).
For organisations selling primarily into the US market, SOC 2 Type II is often the more commercially relevant credential. For organisations with a global or European-first go-to-market, ISO 27001 is typically preferable. Increasingly, scale-ups pursuing both markets pursue both frameworks, with ISO 27001 first due to its structured certification pathway and then layering in SOC 2 once the ISMS foundation is in place. If you are unsure which framework to prioritise, consider where your next ten enterprise deals will come from and what your security questionnaire responses currently require. For organisations building a cybersecurity compliance foundation from scratch, ISO 27001 provides the more systematic and globally transferable starting point.
How much does ISO 27001 certification cost?
For most small organisations (fewer than 50 staff), total all-in costs for ISO 27001 certification, including consultant fees, tooling, and audit fees, typically range from EUR 10,000 to EUR 30,000. Medium organisations (50 to 250 staff) should budget EUR 30,000 to EUR 80,000. Large organisations can expect EUR 80,000 to EUR 200,000 or more. Annual surveillance audits and recertification costs should be factored into multi-year budgets as well.
Is the ISO 27001 exam difficult?
ISO 27001 certification for organisations is not an exam: it is an audit process conducted by an accredited certification body. However, there are individual certifications such as the ISO 27001 Lead Implementer and Lead Auditor credentials, which do involve written examinations. These exams are considered moderately to highly challenging, requiring solid knowledge of the standard’s clauses, risk assessment methodology, and control implementation. Most candidates spend 20 to 40 hours in structured preparation before attempting them.
Conclusion
ISO 27001 certification is a meaningful investment in both security posture and commercial positioning. For organisations selling into European markets, handling regulated data, or responding to enterprise procurement requirements, it is increasingly a prerequisite rather than a differentiator. The 2022 revision brought the standard up to date with modern threats, and the structured certification process, from gap analysis through Stage 1 and Stage 2 audit to ongoing surveillance, gives organisations a clear pathway to a globally recognised credential.
The key variables that determine success are scope definition, internal resource commitment, and the quality of your implementation partner. With the right approach, small organisations can achieve certification in three to six months, and the commercial returns in shortened sales cycles and increased client trust typically justify the investment well within the first year. If you are evaluating your options or looking to build the internal skills needed to sustain your ISMS over the long term, explore Cybersteps’ cybersecurity compliance manager training programmes.
Ready to Build a Career in Cybersecurity?





