It is possible for a start-up to go for years without seriously considering ISO 27001. A potential enterprise client will send an email saying “Please supply ISO 27001 as part of our review of our vendor.”
The issue of certification is no longer something that is going to be discussed in the coming year. It’s connected to a contract that the company is looking to end.
For many growing companies it’s the most practical starting point for ISO 27001 for small business. The problem is to figure out what’s actually needed without turning a manageable compliance program into a massive security initiative.

This week, focus on Scope and not on Shopping
The first thought is to begin comparing compliance systems and consultants. The better place to begin is determining what Information Security Management System, or ISMS is required to cover.
It is important to know the scope because trying include unnecessary systems, locations or processes may result in additional documentation and requirements for evidence.
A small SaaS company, like could have a specific environment that is built around cloud infrastructure employees’ devices, customer details, and even a handful of critical vendors. Knowing the specifics of the environment will help you determine what your certification project should address.
Review the Security You Already Have
Many companies who are looking into ISO 27001 to start ups assume they will need to establish a new security company.
It could be that it isn’t.
Modern startups might already have established cloud providers, and may require multi-factor identification, restricted employee permissions, system logs to manage documents for onboarding and offboarding. It is still necessary to evaluate current practices against ISO 27001, but if you start with what is working now, it can save unnecessary duplicates.
The documentation of policies, the risk assessment, determining the applicable Annex A Controls, completing the Statement for Applicability and gathering evidence are the remaining tasks.
You will now be able to determine which invoices are paid for by what
The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.
Initial expenses for a small organization may total roughly $10,000 to $30,000 once the independent certification audit, compliance software, and internal staff time are taken into account. A consulting fee can be added, however it is not an essential expense.
It is crucial to distinguish between ISO 27001 certification costs charged by a certified body for certification and software fees. The compliance platform is a tool that allows for the organization of work but is unable to issue a certification. The independent auditing process is the one that certifies the certificate.
Then comes the evidence
A policy that states that access to employees is restricted after leaving isn’t enough. The auditor needs evidence that the procedure is operating.
ISO 27001 is based on the distinction between saying and showing.
CertAssist was designed to help to manage this process without having to connect to the live systems of the business. It contains all 93 ISO 27001 Annex A controls on one screen. It also offers customizable templates for policies and evidence along with a Statement of Applicability.
For a small team, templates could also help to reduce the time-consuming process of writing each policy from the beginning of a blank document.
The End Line isn’t Certification Day.
A business that is beginning from scratch may spend approximately three to six months preparing for certification according to its current security practices and resources. The certification body conducts audits in Stage 1 and 2.
After you have passed the audits, it isn’t enough to put aside your ISMS. The ISMS has to continue to monitor controls and provide evidence. Following certification, surveillance audits must be conducted.
This is an important aspect to think about when designing the program. It’s not enough for small businesses to simply use an ISMS that it can afford. It’s in need of one that can realistically operate after the initial phase is over.
The most intelligent ISO 27001 program for a smaller organization is rarely the biggest. The most effective ISO 27001 program is the one that meets the standards, is based on actual security practices, and is able to stand up to scrutiny from an outsider and be able to be managed after everyone has returned to work.
