ISO 27001 for startups and SMEs: when it is worth it
Tanmoy HossainLast updated
On this page
The short answer
ISO/IEC 27001 is the international standard for an information security management system: a managed, written down way of deciding what information matters to your business, what could go wrong with it, and what you do about that. Certification means an independent certification body has audited you against it.
For most startups and small businesses it is worth it when a customer you want will not buy without it, and rarely before. The certificate lasts three years with yearly surveillance audits. Most of the cost is your own team's time, plus the certification body's fee, which depends on your size, complexity and number of sites. A certification body such as NQA says well-managed projects can be certified in 2 to 3 months, and 6 months or more is not uncommon.
Source: NQA, ISO 27001 certification (opens in a new tab), correct as of 5 October 2026.Signs a customer will require it
Buyers rarely open with "you need ISO 27001". It creeps in. The signs are worth spotting early, because the question usually lands during procurement, after everyone has agreed they want to work with you. That is the worst moment to start a project that takes months.
Watch for these:
- The security questionnaire asks about your management system. Questions about an information security policy, a risk assessment, supplier reviews or internal audits are ISO 27001 questions in disguise. My guide to answering supplier security questionnaires covers how to handle them honestly.
- Tender documents list certificates. Public sector and enterprise tenders commonly ask which certificates you hold, sometimes before anyone reads your proposal.
- The contract has a clause. Look for wording such as "ISO 27001 or equivalent" in the security schedule. "Or equivalent" gives you room to show your own evidence. Without it, you need the certificate.
- They ask for your certificate number and scope. That means they intend to check it, and they will notice if the scope does not cover the product they are buying.
There is a real difference between "do you have it?" and "do you work to it?". Some buyers will accept a company that runs its security in line with the standard and can show the evidence. Others need the certificate itself, because their own auditors ask them to prove their suppliers are certified. Read the wording, and ask. A direct question to the buyer's security team costs nothing and often saves months.
What certification involves, in plain English
An information security management system sounds like software. It is not. It is a set of decisions, written down and kept up to date: what information you hold, what could go wrong with it, what you do about each risk, and how you check those things keep happening.
The work runs in this order:
- Scope. Decide which parts of the business and which systems are covered. For most startups, that is the product your customers use and the people and suppliers who run it.
- Risk assessment. List what could go wrong, how likely it is and how much it would hurt.
- Controls and policies. Choose how you deal with each risk. The 2022 edition groups its controls into four themes: organisational, people, physical and technological.
- Run it. Do what the policies say for long enough to have records that prove it.
- Internal audit and management review. Check yourselves, then have leadership review the results and make decisions. A certification body expects both before its main audit; NQA says the system must be operational, with evidence of internal audits and a management review, before stage 2.
- Stage 1 audit. The auditor reviews your documents, confirms the scope and checks you are ready.
- Stage 2 audit. The auditor tests whether it works in practice, sampling real records and processes, and reports any nonconformities.
- Certificate, then surveillance. The certificate lasts three years, with surveillance audits in between, usually once a year, and a recertification audit at the end.
Choose an accredited certification body
Anyone can print a certificate. What a buyer trusts is accreditation. UKAS, the UK's government-appointed national accreditation body, describes its role as checking the checkers: it assesses whether certification bodies are competent and impartial. For information security, certification bodies are accredited against ISO/IEC 27006, the standard for bodies that audit and certify information security management systems. Only UKAS accredited certificates carry the UKAS accreditation symbol, and buyers can confirm them on the free UKAS CertCheck database.
Source: UKAS, accreditation vs certification (opens in a new tab), correct as of 5 October 2026.What it costs, and how long it takes
There is no list price. Certification bodies quote individually, and the audit time behind the quote depends on the size and structure of your organisation, the complexity and risk of what you do, and the number of sites in scope. The fee is the part you can see. The bigger cost is your own team's time: writing a small set of policies, running the controls and keeping the records.
Timing depends mostly on how much is already in place. NQA puts well-managed projects with experienced people at 2 to 3 months, and says 6 months or more is not uncommon. The step that cannot be rushed is running the system long enough to produce evidence.
Where small companies overspend
The money usually goes on the wrong things, in this order.
Scoping too widely. Putting the whole company in scope feels thorough. It multiplies the controls, the records and the audit time. Scope what your customers are buying and the people and suppliers who touch it. You can widen it later.
Buying tools before knowing what you need. Compliance platforms can help, but buying one first means paying for a system before you know what your system is. Most small companies can run a sensible management system with the tools they already use: the ticketing system, the code repository, the cloud console and a shared drive.
Policy packs nobody follows. A downloaded set of thirty policies looks impressive and creates thirty promises. The auditor's job is to test those promises against what actually happens. Every policy you cannot evidence is a nonconformity waiting to be found. Fewer, shorter policies that describe how you really work are cheaper and safer.
Controls bigger than the risk. The standard asks you to manage your risks, not to copy a bank. A ten person software company does not need the controls of a hundred person one.
Outsourcing the thinking. Consultants can speed things up. But if they write a system your team does not recognise, you will pay for it again at every surveillance audit, when the gap between the paperwork and the reality shows.
Lessons from three audits with zero nonconformances
As CTO of a cybersecurity awareness SaaS company, I held ISO 27001:2022 with zero nonconformances across three audit cycles, and helped the business grow to more than 200 enterprise and public sector clients. These are the principles I work to, and the ones I bring to every company I help.
Write down what you do, then do what you wrote. The management system should describe how your team already works, tightened where it needs to be. An auditor tests your words against your records. If they match, there is nothing to find.
Make evidence a by-product of normal work. Review changes in the code repository. Grant and remove access through tickets. Log incidents where the team already works. Then, when the auditor asks for proof, it already exists, and nobody has to assemble a folder the week before.
Keep the scope and the controls proportionate. Every control has to be run, evidenced and audited every year. Fewer controls, run well, beat many controls run half-heartedly. That is what makes zero nonconformances realistic.
Treat the internal audit as a rehearsal, and be harder on yourselves than the auditor will be. Find the gaps, fix them and record the fix. A gap you found and closed is evidence that the system works.
Lead it from the top. The management review should be a real meeting where leadership makes decisions about risk, budget and priorities. When it is a box ticked by the most junior person in the room, the auditor notices.
You do not need a compliance hire to start. A small team can run this with clear owners and a regular slot in the calendar for the recurring work: access reviews, supplier reviews, risk register updates and staff training. What matters is that the routine happens, every time.
Is it worth it before your first enterprise deal?
My rule of thumb: start ISO 27001 when a deal you want depends on it, or when the same questions keep coming back in every questionnaire. Before that, the money is usually better spent on the product.
That does not mean doing nothing. In my view the right first step for most small companies is Cyber Essentials, which the NCSC describes (opens in a new tab) as the minimum standard of cyber security the Government recommends for organisations of all sizes (correct as of 5 October 2026). It covers five technical controls, and my guide explains what Cyber Essentials costs and covers. Alongside it, put the foundations in place that ISO 27001 will need anyway: a short security policy you follow, an owner for each system, multi-factor authentication, access that is removed when people leave, and a list of your suppliers. Those make a later certification faster and cheaper.
If a buyer asks for ISO 27001 before you have it, do not bluff. Say where you are, show the controls you already run and give a dated plan for certification. That honesty wins more deals than a vague "in progress". My guide to answering supplier security questionnaires covers how to word it.
When you are ready, this is the work I do as part of getting small companies enterprise-ready: scoping it tightly, building only what you need, and getting the evidence right first time.
Questions
How long does an ISO 27001 certificate last?
Three years. It is kept current by surveillance audits, usually once a year, and renewed with a recertification audit at the end of the three years. That is how certification bodies such as NQA describe the cycle (opens in a new tab) (correct as of 5 October 2026).
Does it matter which certification body I use?
Yes. Choose one accredited by UKAS for ISO 27001. UKAS is the UK's government-appointed national accreditation body, and it checks the certification bodies themselves. Buyers can confirm an accredited certificate on UKAS CertCheck (opens in a new tab) (correct as of 5 October 2026).
Is an ISO 27001:2013 certificate still valid?
No. Certified organisations had to move to the 2022 edition by 31 October 2025, and certificates based on the 2013 edition are no longer valid after that date, as NQA explains (opens in a new tab) (correct as of 5 October 2026).
Can DreamSolve certify us?
No. DreamSolve prepares companies for certification; it is not a certification body. Your certificate comes from an independent, accredited certification body, which is exactly what makes it worth having.
How DreamSolve helps
Enterprise Readiness is how I get a small company ready for ISO 27001: a gap analysis, the minimum credible set of policies and controls, and the evidence an auditor will ask for. I held ISO 27001:2022 with zero nonconformances across three audit cycles. DreamSolve prepares you for certification; it is not a certification body.

Written by
Tanmoy Hossain
Fractional CTO. About seven years building and leading technology at a cybersecurity SaaS company, from systems developer to CTO.