The Series B CTO gets the enterprise procurement questionnaire on a Thursday. Question 14: “Is your organization ISO/IEC 27001 certified? If yes, please attach the certificate. If no, please provide your target certification date.” She has never been through an ISO 27001 audit. She has been through a SOC 2 audit but the enterprise customer already asked for SOC 2 and now wants ISO 27001 on top. The Google search for “iso 27001 certification” returned twelve results that all read like consulting-firm marketing pages.
This article is the article she wishes had come up at the top of that search. ISO/IEC 27001 certification is achievable for an SMB in 12 to 18 months at a total cost of $60,000 to $200,000 across the initial certification plus three years of surveillance audits. The process has a specific shape, a specific set of documents, a specific two-stage audit sequence, and a specific choice of accredited certification body. Everything the CTO needs to know before signing her first contract sits below.
ISO 27001 is not a checklist. It is a management-system standard that requires the organization to identify its own information security risks, treat them with a risk-based selection of controls from Annex A, and continuously improve the ISMS over time. The certificate says you built the ISMS. The audit checks that you actually run it. A platform or consultant that treats the certification as a control-checklist exercise is preparing you for a failed audit.
What ISO 27001 actually is
ISO/IEC 27001:2022 is an international standard for Information Security Management Systems (ISMS). It is jointly published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Certification is issued by accredited certification bodies (in the US, bodies accredited by ANAB under ISO/IEC 17021-1 for information security management systems). The certificate is valid for three years, with mandatory annual surveillance audits and a full recertification audit at the three-year mark.
The standard has ten main clauses and an Annex A control set. Clauses 4 through 10 define the ISMS requirements: context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A defines 93 controls organized into four themes: organizational, people, physical, and technological. The buyer selects the applicable Annex A controls via a Statement of Applicability tied to the risk assessment.
The ten ISMS clauses (Clauses 4–10) — what the standard requires
Clauses 1 through 3 are scope, references, and terms. The certifiable requirements sit in Clauses 4 through 10. Every ISMS must satisfy all seven.
Annex A — the 93 controls in four themes
Annex A of ISO 27001:2022 organizes 93 controls into four themes. The Statement of Applicability documents which apply, which do not, and the justification for each choice. Every Annex A control must be considered; the SoA is the audit-facing artifact that shows the buyer did that consideration deliberately.
Three areas produce the most Stage 2 nonconformities for first-time SaaS certifications: A.5.29 (information security during disruption) because business-continuity planning is often skipped; A.8.15 (logging) and A.8.16 (monitoring activities) because logs exist but nobody actually reviews them; and A.5.19-A.5.22 (supplier relationships) because vendor risk management is usually treated as a checkbox rather than a documented process with reviews.
The two-stage audit that determines the certificate
ISO 27001 certification requires two formal audits performed by the accredited certification body.
Stage 1: documentation review. The auditor reviews the ISMS documentation, risk assessment, Statement of Applicability, policies, and procedures. Stage 1 identifies gaps that must be closed before Stage 2. Most Stage 1 audits are conducted remotely for SMBs and run 2 to 3 days depending on scope. The Stage 1 report includes findings and recommendations but does not itself confirm or deny certification.
Stage 2: implementation testing. The auditor tests the actual implementation of the ISMS. This includes interviewing staff, sampling controls, and validating that documented processes work in practice. Stage 2 is on-site (or detailed virtual with camera-verified access) and runs 3 to 5 days depending on scope. The Stage 2 report includes any major or minor nonconformities. Major nonconformities must be closed before the certificate is issued; minor nonconformities can be closed inside the surveillance cycle.
Stage 1 and Stage 2 are scheduled 4 to 6 weeks apart. Any certification body that suggests skipping Stage 1 is either non-accredited or is describing a marketing-labeled shortcut that will not withstand customer due diligence.
Any of the following signal a certification path that will not survive due diligence: promises of certification in under 12 months for a company over 50 employees; flat-fee quotes without a scope conversation; suggestions that Stage 1 can be skipped; no ANAB (or equivalent international) accreditation visible on the certification body's website; unwillingness to name a specific lead auditor before the contract is signed.
The four documents that make or break the certification
The ISMS documentation set is where most first-time certifications either succeed or fail. Four documents matter more than the others.
The Risk Assessment
The buyer's identified information security risks, scored by likelihood and impact, with owners and treatment decisions. The risk assessment drives the Statement of Applicability — you cannot select controls without first identifying the risks they treat. Poor risk assessments are the single most common Stage 1 finding.
The Statement of Applicability (SoA)
The buyer's declaration of which Annex A controls apply, which do not, and the justification for each. All 93 Annex A controls must be considered; those not applicable must have a documented reason. The SoA is the primary artifact the auditor reviews to understand the ISMS scope.
The Information Security Policy
The top-level policy signed by top management (CEO, board, or equivalent). This is the document that demonstrates the leadership commitment ISO 27001 Clause 5 requires. Template policies pulled off a website will not withstand the leadership interview.
The Internal Audit Program
The buyer's own internal audit plan, showing the frequency and scope of internal audits of the ISMS, plus the results of at least one completed internal audit before Stage 2. First-time buyers routinely forget the internal audit requirement and get a nonconformity at Stage 2.
Which certification body to pick
In the US, the choice of certification body matters more than most first-time buyers realize. The certification body determines the audit schedule, the auditor quality, and the recertification timeline. A good certification body assigns auditors who understand the buyer's industry. A less-good one rotates auditors every cycle and treats a SaaS company like a manufacturing plant.
BSI, SGS, and DNV are the three largest ANAB-accredited certification bodies operating in the US market. BSI tends to understand technology companies best. SGS has stronger manufacturing expertise. DNV started in energy and maritime and has expanded into general business services. For SaaS specifically, BSI is usually the closest cultural and technical fit. Non-accredited certification bodies produce certificates that fail customer due diligence and are functionally worthless for enterprise sales.
The choice happens before the ISMS work starts, not after. The certification body drives the audit timeline, and the buyer’s ability to schedule Stage 1 and Stage 2 at the right cadence depends on the certification body’s availability.
The 12–18 month timeline, phase by phase
Every ISO 27001 implementation timeline breaks into five phases. Speeding through any phase produces the same result: nonconformities at Stage 2 and a delayed certificate. Realistic numbers for a 20–200 employee SaaS company below.
Phase 1 · Scope + risk assessment (weeks 1–8)
Define the ISMS scope (what systems, what data, what business processes), identify the interested parties, document the risk assessment methodology, run the initial risk assessment. Output: scope statement, risk assessment methodology, first-pass risk register. First-timers often underestimate this phase — a rushed risk assessment produces a bad Statement of Applicability, which produces a bad Stage 1 audit.
Phase 2 · Documentation + Statement of Applicability (weeks 6–16)
Build the ISMS documentation set: Information Security Policy signed by leadership, procedures for each Annex A control the SoA includes, the SoA itself with justifications for each of the 93 controls (applicable or not, why). Phase 2 overlaps Phase 1 by 2-3 weeks — documentation drafting starts as soon as scope and risks are clear.
Phase 3 · Gap remediation + control implementation (weeks 12–36)
Close the gaps identified in the risk assessment and documentation phases. Implement the Annex A controls the SoA marks applicable. For a 50-person SaaS starting from moderate security maturity, expect 15-40 gaps; a company starting from zero can have 60+. This is the longest phase because it involves real engineering + operations work, not just documentation.
Phase 4 · Internal audit + management review (weeks 32–44)
Perform the first internal audit of the ISMS. Findings from the internal audit are expected — an internal audit with zero findings signals a formality that the Stage 2 auditor will scrutinize. Track findings to closure. Hold the management review meeting with documented minutes. Both are Clause 9 requirements without which Stage 2 will produce a nonconformity.
Phase 5 · Stage 1 + Stage 2 audits + certificate (weeks 44–52)
Stage 1 (documentation review, 2-3 days, remote for most SMBs). Address findings from Stage 1 in the 4-6 weeks between Stage 1 and Stage 2. Stage 2 (implementation testing, 3-5 days, on-site or detailed virtual). If no major nonconformities, certificate issued within 2-4 weeks of Stage 2. If major nonconformities, they must be closed and re-audited before certificate issuance.
Companies at the fast end (12 months) have an existing security lead, a moderate starting maturity, and a compliance automation platform. Companies at the slow end (18-24 months) are starting from zero, hiring for the ISMS lead role, or picking up ISO 27001 in parallel with running a SOC 2 audit. Companies who complete under 12 months typically had ISO 27001 planned as a fast-follow on a SOC 2 program and reused overlapping evidence — the controls overlap 60-80% depending on the SOC 2 TSC scope.
Do you actually need ISO 27001?
ISO 27001 is not required by any law. It’s a market signal, similar to SOC 2 but with different geography. Six signals that ISO 27001 is worth pursuing for your company right now:
- An EU, UK, or Middle East enterprise buyer has asked for it in the last 90 days. ISO 27001 is the de facto expectation for enterprise procurement outside North America. If a real prospect on your pipeline sent a security questionnaire that names ISO 27001 (not SOC 2), you need ISO 27001.
- You already have SOC 2 Type II and are pursuing international buyers. SOC 2 Type II is largely US-market. If your international enterprise pipeline is growing, ISO 27001 is the natural follow-on — the underlying controls overlap 60-80% with SOC 2 so the incremental work is less than starting from zero.
- Your buyer’s procurement questionnaire lists ISO 27001 as required. Not just “preferred” — “required.” UK financial services, German enterprises, and Australian federal-adjacent buyers routinely require ISO 27001 as a procurement floor.
- You’re selling to organizations with a formal ISMS (banks, insurance, government contractors). These buyers evaluate vendors against their own ISMS. An ISO 27001 certificate is the fastest way to establish the vendor’s ISMS is comparable to theirs.
- Your competitors have ISO 27001 and you don’t, and you’re losing deals in international markets. Match to compete. The certificate is a visible procurement checkbox that shows up on RFP responses immediately.
- You’re raising or acquiring internationally and investors, board members, or acquirers want to see the certificate. ISO 27001 is a Board-level signal that the security program is mature and internationally recognized.
If none of the six apply — your buyers are exclusively US, no international pipeline, no procurement requirement — SOC 2 Type II is almost certainly the better first framework. Revisit ISO 27001 as the international pipeline develops.
Pricing reality: what an SMB actually pays for ISO 27001 in year one and beyond
Initial certification: $25,000–$60,000 for the audit itself
Stage 1 audit ($4,000 to $8,000), Stage 2 audit ($8,000 to $20,000), certificate issuance ($1,000 to $3,000), plus travel if the certification body requires on-site presence. Actual audit fees scale with organization size and scope, not with the number of controls.
ISMS preparation: $10,000–$100,000 depending on path
Platform-augmented tools (vCISO Lite, mid-market compliance platforms) at $3,600–$18,000/year handle the documentation, risk assessment, and Statement of Applicability generation. Traditional consultancy engagements run $50,000–$150,000 for the same outcome. In-house drive with an experienced ISMS lead runs on internal labor (typically 200–400 person-hours).
Annual surveillance audits: $5,000–$15,000 each
Years 2 and 3 include a surveillance audit each. Surveillance audits are shorter than Stage 2 (typically 1 to 2 days) but must confirm the ISMS is still operating and any nonconformities from prior audits have been closed.
Recertification (year 3): $15,000–$40,000
The full recertification audit at the three-year mark is longer than a surveillance audit but shorter than the initial Stage 2. The buyer restarts the three-year cycle from that point.
Total three-year cost of ownership for ISO 27001 certification at an SMB: initial certification ($25K–$60K) + platform or consulting for ISMS prep ($10K–$100K) + two years of surveillance audits ($10K–$30K) + recertification ($15K–$40K) = $60,000 to $230,000 depending on the path. Platform-augmented buyers land at the low end; traditional consultancy buyers at the high end.
What separates a defensible certification from a marketing certificate
Three signals distinguish a real ISO 27001 program from a paper-thin one.
Whether the risk assessment names actual risks. The risk assessment should be specific to the buyer’s business, not a generic list of “unauthorized access” and “data loss.” A defensible risk assessment names the actual systems, the actual data, the actual threat actors, and the actual likelihood and impact scores. Auditors ask about specific risks by name and expect answers that show the risk was actually analyzed, not copy-pasted.
Whether the internal audit program has produced findings. The internal audit is required. Auditors expect to see that the buyer has performed at least one internal audit before Stage 2, and that the internal audit produced findings (not zero findings — that suggests the internal audit was a formality). Findings identified internally, tracked, and resolved before Stage 2 signal a mature ISMS.
Whether management review has occurred. Clause 9.3 requires management review of the ISMS at planned intervals. Auditors will ask for the minutes of the most recent management review meeting. Buyers who cannot produce the minutes are usually failing on Clause 9.3, which is a common minor nonconformity that shows up in Stage 2 reports.
How the platform choice affects the certification outcome
Platform-augmented compliance tools do not replace the ISMS. They generate the documentation, run the risk assessment against integrated systems, populate the Statement of Applicability, track control implementation, and produce the audit-ready evidence exports. What they do not do is stand in for the leadership decisions (Clause 5), the management review process (Clause 9.3), the internal audit program (Clause 9.2), and the continual improvement mindset (Clause 10) that the standard requires.
Buyers using a platform-augmented tool still need a person who owns the ISMS — often the CTO, the Head of Security, or the vCISO. The platform does the artifact generation; the person does the leadership and improvement work. Traditional consultancy engagements typically bundle both, at higher cost.
Common first-timer mistakes at ISO 27001
- Treating the SoA as a checkbox rather than a decision document. The Statement of Applicability is the audit-facing artifact for every one of the 93 Annex A controls. Buyers who mark controls as applicable without matching them to specific risks in the risk assessment get called out at Stage 1. The SoA should read as a series of documented decisions, not a spreadsheet of yes/no.
- Skipping the internal audit or performing it as a formality. Clause 9.2 requires an internal audit before Stage 2. An internal audit with zero findings signals the audit was performed as a formality. Real internal audits produce 5-15 findings that get tracked and closed. Auditors know this and probe for it at Stage 2.
- Under-documenting the management review. Clause 9.3 requires management review of the ISMS at planned intervals with specific inputs and outputs. Buyers who hold a management review meeting but don’t document minutes — or document minutes without covering the required Clause 9.3 inputs — get flagged for a common minor nonconformity.
- Picking the certification body last. The certification body drives the audit schedule. Buyers who complete the ISMS work and then start shopping certification bodies discover Stage 1 slots are 3-6 months out with the best auditors. Book the certification body early — often at Phase 2 — so the Stage 1 date is locked before Phase 4 finishes.
- Assuming the platform “is” the ISMS. Platform-augmented compliance tools generate documentation and track evidence. They do not make leadership decisions, run internal audits, or hold management reviews. Someone at the company still owns the ISMS. Buyers who confuse this get flagged at Clause 5 (leadership) or Clause 9 (performance evaluation) at Stage 2.
- Starting ISO 27001 in parallel with SOC 2 Type II without a plan for evidence overlap. The controls overlap 60-80% but the evidence formats differ. Buyers who run both in parallel without planning the evidence architecture end up doing similar work twice. Pick a lead framework (usually the one with an active enterprise ask), get it 80% built, then map the second framework onto the shared evidence.
- Certifying the wrong scope. A too-narrow ISMS scope produces a certificate that enterprise buyers reject as insufficient. A too-broad scope produces a Stage 2 that runs 2-3x longer and costs 2-3x more. The right scope covers “the systems, people, and data that produce the product enterprise customers pay for.” Anything narrower is a marketing certificate; anything broader is a paying-more-for-nothing certificate.
Get certified without hiring a full-time ISMS lead
vCISO Lite is the platform-augmented option for buyers who need ISO 27001 certification but do not have a full-time ISMS lead. The subscription covers ISMS documentation generation, risk assessment against the customer’s live stack, Statement of Applicability derivation, Annex A control implementation tracking, internal audit program setup, and audit-ready evidence export — plus a vCISO consultant who serves as the ISMS lead of record when needed. Published pricing from $299 to $1,499 per month across four tiers, with ISO 27001 covered at Growth ($699/mo) and above.
See vCISO Lite’s published pricing.
Sources
- ISO/IEC 27001:2022 — the current version of the international standard; 10 clauses + Annex A (93 controls in 4 themes: organizational, people, physical, technological): iso.org/standard/27001
- ISO/IEC 17021-1 — the accreditation standard certification bodies operate under: iso.org/standard/61651
- ANSI National Accreditation Board (ANAB) — the US accreditation body for ISO/IEC certification bodies: anab.ansi.org
- BSI Group ISO 27001 pricing and process overview: bsigroup.com
- SGS ISO 27001 certification services: sgs.com
- DNV ISO 27001 certification: dnv.com
- Schellman ISO 27001 + SOC 2 combined engagements: schellman.com/iso-27001
- vCISO Lite published pricing ($299-$1,499/mo across four tiers): vcisolite.com/pricing
Where this matters next
How to Choose the Right ISO 27001 Certification Company — the certification-body selection framework covered in detail: BSI vs SGS vs DNV vs Schellman, the accreditation check, and the red flags in the sales cycle.
SOC 2 Compliance Automation Tools: 2026 Buyer’s Guide — the SOC 2 side of the multi-certification question. Enterprise buyers often want both.
GDPR Compliance Software: 2026 Buyer’s Guide — the GDPR overlap for buyers selling into the EU. ISO 27001 controls overlap significantly with GDPR Article 32 safeguards.
vCISO Pricing in 2026: What Virtual CISO Services Actually Cost — the pricing tiers on which the platform-augmented ISO 27001 subscription sits.
Platform: Compliance — the ISO 27001:2022 Annex A control surface — policy library, statement of applicability, evidence chain, internal audit workflow inside the platform.
Use Case: Prove Compliance — how customers evidence ISO 27001 to their certification body without the marketing-page consultancy handshake.