Skip to content
Cyber Experts

What ISO 27001 really means for a 20-person company

Should your 20-person company certify ISO 27001? The honest answer, the actual cost, and three lighter alternatives that close most B2B deals.

Published on 4 min read

A growing number of small companies ask us about ISO 27001 certification. The trigger is almost always the same: a large enterprise prospect made it a condition of the contract. We've started writing this article instead of repeating the answer on every call.

The short version: ISO 27001 is a serious commitment, often more substantial than the prospect realises. There are lighter alternatives that close most deals, and the right path depends on three questions.

ISO 27001 in plain English

ISO/IEC 27001 is the international standard for information security management systems (ISMS). Certification means an accredited body has audited your organisation against 93 controls grouped in 4 themes (organisational, people, physical, technological) and confirmed compliance.

The certification covers a defined "scope", typically your whole company for an SMB, or a specific business line for larger ones. It is renewed every 3 years with surveillance audits in years 1 and 2.

The honest cost

For a 20-person company in France:

  • Preparation work: €25,000 to €60,000 (internal time + external consulting)
  • Initial certification (Stage 1 + Stage 2): €8,000 to €15,000
  • Annual surveillance audits: €4,000 to €8,000
  • Re-certification every 3 years: €8,000 to €15,000

→ Year 1 total: roughly €33,000 to €75,000. → 3-year total: roughly €50,000 to €110,000.

The biggest hidden cost is internal time. Expect 0.3 to 0.5 FTE of someone senior for 12 months during preparation, then ~0.1 FTE ongoing for maintenance.

Should you certify?

Three questions:

1. Is it a binary requirement to close a specific deal?

If a prospect explicitly conditions the contract on ISO 27001, and the deal value justifies it (typically €100k+ ARR), certify. The math is straightforward.

2. Will several future deals require it?

If your sales pipeline is full of regulated industries (banks, insurance, healthcare, public sector, large industrials), certification is part of the cost of doing business. Better do it once, properly, than chase it deal by deal.

3. Is it really required, or just preferred?

Most enterprise security questionnaires say "ISO 27001 OR equivalent demonstrable controls". The "or" is the door. Many deals close with documented controls, a recent pentest, and a defensible posture, without the formal certificate. This is the path most of our clients end up taking.

Three lighter alternatives that close most deals

1. A documented Ally

A 4-week engagement that produces a board-signable plan, an audit-grade posture document, a security kit, a trained team. Roughly €15,000. Closes most B2B deals where the buyer is reasonable.

2. A current pentest report + remediation

A pentest under 12 months old + evidence of remediation often satisfies enterprise security teams. €7,500 to €15,000 depending on scope. Particularly effective for SaaS / e-commerce.

3. A SOC 2 Type 1

Lighter than ISO 27001 (focused on 5 specific trust principles, not a full ISMS), and often accepted as ISO equivalent by enterprise buyers, especially US-headquartered ones. ~€20,000 to €40,000 for a 20-person company.

The 12–18 month journey if you do certify

For those who decide ISO 27001 is the right path:

  1. Months 1–3, gap analysis vs Annex A; scope definition; project setup
  2. Months 4–9, ISMS construction (policies, procedures, controls implementation, evidence gathering)
  3. Months 10–11, internal audit and management review
  4. Month 12, Stage 1 audit by certifier (documentation review)
  5. Months 13–14, remediate findings
  6. Month 15, Stage 2 audit (operational verification)
  7. Months 15–18, receive certificate; integrate maintenance into BAU

Cyber Experts' Advisory engagement frames the preparation through Stage 1, typically 6 months at 0.3–0.4 FTE.

What to do if a prospect just asked you for ISO 27001 next week

Five-step playbook for the next conversation:

  1. Ask for the security questionnaire, not the certificate. They typically have one.
  2. Confirm whether "ISO 27001 OR equivalent" applies. It usually does.
  3. Propose a timeline: "we can answer your questionnaire substantively in 2 weeks; ISO certification, if needed, would be a 12–18 month journey."
  4. Document your current posture honestly, the vendor questionnaire response process is exactly this.
  5. If after all that they still require formal certification, start the journey, with a clear ROI based on the deal value.

Related articles