ISO 27001 Certification: Process, Timeline and Cost for SMEs
A clear guide: your contribution, our work and the route to the certification audit.
ISO 27001 certification becomes manageable when decisions and responsibilities are clear from the start. We structure the project, prepare the required documentation and get you ready for the audit. You provide one contact person, make information available and take the necessary decisions.
What you have at the end
- A clearly scoped information security management system with defined responsibilities
- Assessed risks, suitable controls and a defensible Statement of Applicability (SoA)
- Operational evidence for the internal audit and certification audit

Your route to ISO 27001 certification
At every stage, you know what we handle and what we need from you.
- Define the scope
We set sensible boundaries around sites, services, systems and interfaces.
Your contribution: Confirm the objective and name a contact person.
- Review the starting point
We review existing material and produce a prioritised gap list.
Your contribution: Provide documents and enable short interviews.
- Assess risks
We identify important information, systems and services – called information assets in ISO terminology – and derive the risks.
Your contribution: Assess the impact on customers and the business.
- Set controls and the SoA
We prioritise the necessary controls. The Statement of Applicability (SoA) records which ones apply and why.
Your contribution: Approve priorities, budget and accepted residual risks.
- Support implementation
We prepare lean requirements, coordinate open points and build the evidence set.
Your contribution: Implement organisational and technical changes in daily operations.
- Check internally
We prepare the internal audit and management review and close remaining gaps.
Your contribution: Management takes the required decisions.
- Coordinate certification
We align with the certification body and prepare you for the Stage 1 and Stage 2 audits.
Your contribution: Join audit interviews and show the evidence.
What you need to contribute
Your own effort remains clearly bounded:
- one responsible contact person,
- access to relevant people and documents,
- timely decisions and time for necessary operational changes.
Timeline and cost
Many SMEs need around six to twelve months. Actual cost depends mainly on scope, maturity, internal capacity and the certification body. We therefore provide a reliable total price only after these points are clear.
What we clarify before the project starts
At your request, we obtain comparison quotes from accredited certification bodies before you commission us. If cost is the priority, we look for an economical solution. If scheduling, support or sector experience matters more, we select accordingly.
See our ISO 27001 consulting page for more about the service.
Frequently asked questions
Do we have to implement all 93 Annex A controls?
No. They are considered, but only the controls required by your risks and obligations are implemented. The SoA records the rationale.
How much time does our team need?
You need one dedicated contact, decision-makers at a few milestones and time for operational or technical changes. We handle the method, documentation and audit preparation.
Is the certification body included in the consulting fee?
No. Consulting and independent certification are commissioned separately. At your request, we obtain suitable comparison quotes.