Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
ISO 27001 & Information SecurityUpdated: 11 July 2026

ISO 27001 Certification: Process, Timeline and Cost for SMEs

A clear guide: your contribution, our work and the route to the certification audit.

ISO 27001 certification becomes manageable when decisions and responsibilities are clear from the start. We structure the project, prepare the required documentation and get you ready for the audit. You provide one contact person, make information available and take the necessary decisions.

What you have at the end

  • A clearly scoped information security management system with defined responsibilities
  • Assessed risks, suitable controls and a defensible Statement of Applicability (SoA)
  • Operational evidence for the internal audit and certification audit
Watercolour illustration of a shield, padlock and servers representing an ISO 27001 management system

Your route to ISO 27001 certification

At every stage, you know what we handle and what we need from you.

  1. Define the scope

    We set sensible boundaries around sites, services, systems and interfaces.

    Your contribution: Confirm the objective and name a contact person.

  2. Review the starting point

    We review existing material and produce a prioritised gap list.

    Your contribution: Provide documents and enable short interviews.

  3. Assess risks

    We identify important information, systems and services – called information assets in ISO terminology – and derive the risks.

    Your contribution: Assess the impact on customers and the business.

  4. Set controls and the SoA

    We prioritise the necessary controls. The Statement of Applicability (SoA) records which ones apply and why.

    Your contribution: Approve priorities, budget and accepted residual risks.

  5. Support implementation

    We prepare lean requirements, coordinate open points and build the evidence set.

    Your contribution: Implement organisational and technical changes in daily operations.

  6. Check internally

    We prepare the internal audit and management review and close remaining gaps.

    Your contribution: Management takes the required decisions.

  7. Coordinate certification

    We align with the certification body and prepare you for the Stage 1 and Stage 2 audits.

    Your contribution: Join audit interviews and show the evidence.

What you need to contribute

Your own effort remains clearly bounded:

  • one responsible contact person,
  • access to relevant people and documents,
  • timely decisions and time for necessary operational changes.

Timeline and cost

Many SMEs need around six to twelve months. Actual cost depends mainly on scope, maturity, internal capacity and the certification body. We therefore provide a reliable total price only after these points are clear.

What we clarify before the project starts

At your request, we obtain comparison quotes from accredited certification bodies before you commission us. If cost is the priority, we look for an economical solution. If scheduling, support or sector experience matters more, we select accordingly.

See our ISO 27001 consulting page for more about the service.

Request a no-obligation initial call

Frequently asked questions

Do we have to implement all 93 Annex A controls?

No. They are considered, but only the controls required by your risks and obligations are implemented. The SoA records the rationale.

How much time does our team need?

You need one dedicated contact, decision-makers at a few milestones and time for operational or technical changes. We handle the method, documentation and audit preparation.

Is the certification body included in the consulting fee?

No. Consulting and independent certification are commissioned separately. At your request, we obtain suitable comparison quotes.

Sources

Next step

Let's talk.

Tell me where you stand and what you need.

Within 24 hours you receive a first assessment and a concrete meeting proposal — free and without commitment.

  • Reply within 24 hours
  • Personal assessment of your project
  • Funding eligibility checked on request

By submitting you agree to the processing of your details for answering your enquiry.