Where Does $10,000 to $30,000 Actually Go During ISO 27001 Certification?

A startup can go years without thinking seriously about ISO 27001. An email comes in from a potential enterprise client: “Please provide your ISO 27001 certificate to us as part of our vendor security audit.”

Suddenly, certification isn’t something to consider next year. It’s because of an agreement that the company is attempting to end.

For many growing companies, that’s the practical starting point for ISO 27001 for small business. The trick is figuring out what exactly needs to happen without turning a manageable security project into an enterprise-sized compliance program.

Week One should be about Scope, Not Shopping

The first instinct may be to start comparing compliance platforms and consultants. It is best to establish the requirements that ISMS (Information Security Management System) should cover.

It is important to look at the scope, because the addition of systems, locations and procedures that aren’t required can lead to additional documentation or evidence requirements.

Small SaaS companies, for instance they may have an environment that’s focused around cloud infrastructures and employee devices, as well as client information, and a few critical vendors. Understanding the environment will aid in determining what certification is needed.

Take a list of the security features you already have

A few companies who are studying ISO 27001 as a startup assume that they must build a new security operation.

It could be that it isn’t.

Modern startups may already have established cloud providers and need multi-factor authentication, a restricted set of access to employees and system logs that can be used to manage the process of onboarding and offboarding. Current practices need to be assessed against ISO 27001 requirements, but starting with what is already effective can avoid unnecessary duplicates.

Writing policies, conducting a risk assessment, determining the appropriate Annex A Controls, completing the Statement for Applicability and collecting evidence are the remaining tasks.

You now know which invoices you pay for and what.

The ISO 27001 cost becomes much more understandable when expenses aren’t bundled into one number.

The initial cost for a small-sized business can be as low as $10,000-$30,000 depending on the amount of time spent by employees, using software to guarantee compliance, and independent audits of certification. A consulting fee can be included, but it isn’t considered a necessary expense.

The ISO 27001 certification cost charged by an accredited certification agency is particularly important to differentiate from the fees for software. While a compliance platform may assist in organizing the process, it is not able to issue the certificate. Certification is awarded by an independent audit.

Then comes the proof

A policy that says employees’ access to company resources is suspended after their departure isn’t enough. Auditors will have to examine evidence to prove that the system is in place.

This distinction between saying and demonstrating is the defining factor of ISO 27001.

CertAssist is designed to manage this process without connecting directly to live systems in a company. It includes all the 93 ISO 27001 Annex A controls on one screen. It also includes customizable templates for policies and proof, as well as a Statement of Applicability.

In a small team template will eliminate the inefficient writing of every policy on the blank page.

Certification Day Isn’t a Finish Line

A new company can spend anywhere from three to six months working towards certification based on its current security practices and available resources. The certification body will then conduct Stage 1 and Stage 2 audits.

It isn’t enough to ignore the ISMS. After certification, the controls and proofs must be maintained. Audits for surveillance will follow.

This is an important aspect to take into consideration when designing the program. A small company doesn’t merely require an ISMS it can afford to create. It should have an ISMS that its team can utilize after the project is completed.

It is rare that the largest organization has the best ISO 27001 program. It’s one that complies with ISO 27001 standards, shows true security practices, endures independent audits, and is manageable once everyone returns to normal duties.

Recent Post

Table of Contents