ISO 27001 is the world's most recognised international standard for information security management. It is also one of the most misunderstood in the context of mid-sized companies. There are organisations that pursue it without really needing it and organisations that should have it and do not consider it because they assume it is only for large corporations.
This article does not try to sell you the certification process. It tries to give you the real data to decide whether it makes sense for your company now, in 12 months or never.
What ISO 27001 really is (and what it isn't)
ISO 27001 is a management framework, not a list of technical controls. It certifies that your organisation has an Information Security Management System (ISMS) implemented, documented and under continuous improvement. It does not certify that your systems are secure — it certifies that you have a structured process to identify risks, implement controls and continuously improve.
What it really costs to get certified
| Component | Estimated range |
|---|---|
| Implementation consulting (if outsourced) | €15,000 – €45,000 |
| Certification audit (accredited body) | €4,000 – €12,000 |
| ISMS management tools | €2,000 – €8,000 / year |
| Team training | €1,500 – €5,000 |
| Annual maintenance audit | €3,000 – €8,000 |
| Total year 1 cost (typical range) | €25,000 – €70,000 |
How long does it really take
The most common timeline for a mid-sized company is 12 to 18 months from start to certification. Projects completed in less than 9 months often have problems in maintenance audits because they have not had enough time to demonstrate that the ISMS works continuously, not just at the time of the certification audit.
Companies that try to certify in less than 6 months are almost always building a paper ISMS — documents that do not reflect operational reality. ISO 27001 requires the system to work, not just to exist in a PDF.
When it makes sense to certify
- Your target clients are enterprise or public administration and require it as a contractual condition
- You handle sensitive data (health, finance, personal data at scale) and need to demonstrate due diligence
- You compete in tenders where certification provides differentiating points
- You have investors or partners who require formal evidence of risk management
- Your sector is being actively regulated (NIS2, DORA, etc.) and certification simplifies compliance
When it does not yet make sense
- If you do not have a security officer (or equivalent) with real time to dedicate to the project
- If none of your clients or prospects have asked for it or will ask for it in the next 18 months
- If you have basic unresolved security issues (no MFA, no patch management, no verified backups)
What you can do before certifying
- Attack surface audit: know exactly what assets you have exposed
- MFA on all critical systems
- Password policy with corporate password manager
- Documented access management process (onboarding and offboarding)
- Basic incident response plan — what to do when something goes wrong
- Verified backups with tested restoration procedure
