ISO 27001 for small businesses: scope, cost and timeline

A practical guide to ISO 27001 for small businesses in the UK: how to scope the ISMS small, what certification really costs, how long it takes, the four mistakes small firms make, and when Cyber Essentials is enough instead.

The short answer: Yes. A five-person company can hold the same certificate as a five-thousand-person bank, because ISO 27001 scales with the scope you define rather than your headcount. ISO 27001 for small businesses is mostly an exercise in drawing a tight boundary, running a real risk assessment inside it, and keeping the evidence somewhere an auditor can see. Most small UK firms reach audit-ready in two to three months, and certification body fees for a small scope sit in the low thousands of pounds a year.

You are probably reading this because a customer asked. A procurement pack landed, or a tender closed in six weeks, and buried in a security questionnaire was the line "supplier must hold ISO/IEC 27001 certification". That is how most small businesses meet the standard: because a bigger company made it a condition of the contract. The standard was written to be proportionate to the organisation applying it. Nobody tells small firms that, so they build an information security management system sized for a multinational and wonder why it swallowed a year.

{{snapshot}}

ISO 27001 for small businesses at a glance

  • There is no minimum company size. Auditors assess whether your ISMS fits your context, not whether you employ a security department.
  • Scope decides everything. Cost, timeline, audit days and workload all follow the boundary you draw around the ISMS.
  • Two to three months to audit-ready is realistic with a platform. Six to twelve months is the usual outcome when it lives in spreadsheets and shared drives.
  • Audit fees are the smaller number. For a tight scope they run to low thousands of pounds, spread across a three-year cycle with annual surveillance visits.
  • 93 Annex A controls in four themes. ISO 27001:2022 asks you to justify which apply in your Statement of Applicability. It does not ask a 20-person firm to implement all 93 regardless.

{{/snapshot}}

Can a small business really get ISO 27001 certified?

Yes, and the standard is unusually explicit about it. The clauses do not change by company size; only the evidence behind each one does. A 3,000-person insurer documents an access review across forty systems. A 25-person SaaS company documents one across six. Both satisfy the same control. Auditors check that a control is designed for your risks and operating, not that it fills pages.

Clause 4 asks you to define the issues that matter to your organisation, and everything downstream inherits that context. If you are a 30-person consultancy with no data centre and no physical archive, chunks of Annex A get marked not applicable with a written justification and you move on. Small firms consistently underuse that mechanism.

The practical constraint is attention, not capability. In a small company the person who owns ISO 27001 is the CTO, the head of ops or the office manager, and they already have a full-time job. Projects finish when there is a named owner, an hour or two a week protected, and a deadline attached to a real contract. If you are early stage and wondering whether it is too soon, the honest answer is usually that it is later than you think: this is far cheaper to build at 20 people than to retrofit at 120.

Scope it small, or pay for the difference

Scope is the single decision that determines what ISO 27001 costs you. It defines which products, teams, locations and systems the ISMS covers, and it is printed on the certificate for every customer to read. Too wide and you have doubled your workload and your audit days. Too narrow and your biggest customer asks why the service they buy is not named on it.

The rule that works for small businesses: scope to the thing you sell, plus the functions that support it. For a SaaS company that is the production platform, the engineering and support teams that touch it, the corporate IT those people use, and the cloud regions it runs in. Everything else comes along only if it shares an identity provider, not because you went looking for extra work.

Be specific about exclusions and write the justification down. Your cloud provider's physical data centre security is theirs, not yours, and belongs in supplier management. Payroll run by a bureau is a supplier control. Mapping this against the Annex A controls before you start work saves more time than any other hour you will spend on the project.

Usefully, most of the work does not scale with headcount at all.

Fixed regardless of your sizeScales with headcount, systems and scope
ISMS scope, policy set and Statement of ApplicabilityAssets and suppliers in the risk register
Risk assessment methodology, and running it onceAccess reviews and joiner/mover/leaver records
Internal audit programme and management review cycleCertification body audit days, which drive the fee
Incident, change and supplier management processesTraining and awareness records to collect each year
Stage 1 documentation review by the auditorNumber of sites and legal entities in scope

The left column is the bulk of a first certification, and a 15-person company does almost as much of it as a 500-person one. That is why per-employee cost looks brutal for small firms, and why templates already mapped to controls change the maths so sharply.

What ISO 27001 actually costs a small business

Four buckets, one of them genuinely negotiable.

  • Certification body fees. An accredited body quotes audit days based on your scope and headcount, then charges for stage 1, stage 2 and annual surveillance. Small scopes land in the low thousands of pounds a year. Get three quotes; the spread between UKAS-accredited bodies is wider than people expect.
  • Getting ready. A platform, a consultant, or your own evenings. Hicomply Essentials is £5,300 a year for small teams and startups and includes a dedicated Customer Success Manager, which is the number to hold against a consultancy day rate.
  • Tooling you were buying anyway. Password manager, MDM, logging, backup. If you already run these, the marginal cost is near zero.
  • Your time. The bucket nobody puts in the spreadsheet, and the one that decides whether this lands.

The consultant question deserves a straight answer. Consultants earn their fee when you need someone in the room who has argued with an auditor before. They are poor value as a permanent subscription. CloudPass, a UK and EU access-control cloud provider, paid roughly £5,000 a year for consultants who visited twice a year, with the ISMS living in OneDrive folders. After moving to Hicomply they went through audit with zero non-conformities.

For a number rather than a range, the ISO 27001 cost calculator takes your headcount, systems and scope and produces something you can put in front of a finance director.

How long it takes when you are 20 people

Two to three months to audit-ready is normal with a platform and an owner who has time booked. Six to twelve months is normal without one, and the difference is documentation and evidence chasing, not security work.

HealthBoxHR, an HR and payroll SaaS holding sensitive employee data, is the cleanest example we have. In their CTO's words: "Starting without anything in place, we were able to achieve ISO/IEC 27001:2022 certification in 12 weeks." They started from nothing, used policy and procedure templates already linked to controls, and watched ISMS status on a dashboard instead of reconstructing it from email threads.

Two things set the floor and no platform removes them. You must run at least one internal audit and one management review before stage 2, and your certification body wants to see controls that have operated for a period rather than controls switched on last week. Then add the auditor's own lead time, which in the UK can be four to eight weeks between booking and stage 1 during busy quarters. Book them early. It is the one dependency you do not control.

Four mistakes small firms make

Over-scoping because it feels safer

Someone decides the certificate should cover "the whole company", including three entities and a product still in beta. Audit days double, the risk register fills with assets nobody owns, and the project stalls. Certify what you sell today, then extend scope at the next surveillance audit. That is a routine, cheap change.

Downloading a policy pack and calling it an ISMS

Auditors read hundreds of these. A policy naming a Chief Information Security Officer you do not employ, or a change advisory board that has never met, is worse than no policy: it proves the document is fiction. Templates are a good starting point. Edit them until they describe what your team actually does, then delete the rest.

Treating it as an IT project

Roughly half of ISO 27001 is HR, legal, supplier management and governance: onboarding, contracts, confidentiality clauses, due diligence, management review. If the ISMS belongs entirely to whoever administers the laptops, you find these gaps at stage 2 with an auditor watching. Professional services firms feel it most, which is why ISO 27001 for consulting firms hinges on client data handling and subcontractors rather than infrastructure.

Keeping evidence in email and someone's laptop

The classic small-business failure. The controls work fine; the proof is scattered across Slack threads, an inbox and a folder structure one person understands. Then that person is on holiday during stage 2. Evidence needs one home with dates, owners and version history, which is the argument for putting the ISMS somewhere structured before you start collecting rather than after.

When Cyber Essentials is enough, and when it is not

Not every customer request needs ISO 27001, and pretending otherwise costs small companies money. Cyber Essentials is a UK government-backed scheme covering five technical control areas, achievable in weeks, and mandatory for many central government contracts. If the buyer's question is "are your laptops patched and your firewalls configured", it answers that well.

It does not answer what enterprise procurement actually asks. Cyber Essentials says nothing about how you assess risk, manage suppliers, handle incidents, or whether anyone reviews any of it next year. ISO 27001 is a management system with continual improvement built in, which is why it survives a buyer's security review and a self-attested checklist does not. The Cyber Essentials versus ISO 27001 comparison sets out where each one stops.

For most small UK firms: do Cyber Essentials first because it is quick and satisfies a real slice of public sector demand, then treat it as the technical foundation underneath ISO 27001. Sector matters too. Managed service providers get asked for ISO 27001 the moment they hold privileged access to client environments, and healthcare suppliers usually need it alongside NHS Data Security and Protection Toolkit obligations rather than instead of them.

{{snapshot}}

Hicomply's take

We have watched plenty of small companies talk themselves out of ISO 27001 on the assumption it was built for enterprises. It was not. What sinks small projects is scope creep dressed up as thoroughness: certifying entities you need not certify, writing policies for roles you have not hired, gathering evidence for controls you marked applicable out of nervousness. Draw the smallest honest boundary around what you sell, justify the exclusions, and keep evidence in one place from day one. What you build carries straight into SOC 2.

{{/snapshot}}

Get certified without hiring a compliance team

Small businesses rarely fail ISO 27001 on security. They fail on capacity: nobody has three months spare to assemble documents, chase screenshots and rebuild a risk register every time an auditor asks. That is the part worth automating. Policy templates mapped to controls, a risk register that populates from your assets, evidence collected on a schedule, and a dashboard that shows where you stand without a two-day audit of your own audit.

Start with the free ISO 27001 readiness assessment to see how far off you are, then book a demo and we will work through scope, timeline and cost for a company your size. Bring the customer questionnaire that started all this. It tells us more about your scope than a discovery call does.

Ready to Take Control of Your Privacy Compliance?

Hicomply’s platform provides an all-in-one solution to streamline, automate, and centralise your compliance activities, ensuring complete control and efficiency.

Book a demo
Last updated
August 17, 2026
Category
ISO 27001 by Industry
Topics
No items found.
Lucy Murphy
Head of Customer Success

Lucy works closely with customers to help them get the most out of the Hicomply platform, from onboarding to audit success. She brings a user-focused mindset to everything she does, making her well-placed to write about day-to-day challenges, shortcuts, and success strategies. Her content is grounded in what real InfoSec and compliance teams need to know — and how to get there faster.Expect helpful walkthroughs, product tips, and practical insights.

Popular ISO 27001 for Small Businesses queries, answered!

Can a small business get ISO 27001 certified?

Yes. ISO 27001 sets no minimum company size, and certification bodies certify teams of under ten every year. The clauses are identical whatever your headcount; only the volume of evidence behind each one changes. Auditors assess whether your management system suits your context, so a small firm with a tight scope can certify with proportionate documentation.

How much does ISO 27001 cost a small business in the UK?

Budget in four parts: certification body audit fees, which for a small scope run to low thousands of pounds a year across the three-year cycle; readiness support, whether a platform or a consultant; tooling you likely already buy; and internal time. Hicomply Essentials is £5,300 a year for small teams, which is the useful benchmark against consultancy day rates.

How long does ISO 27001 take for a small company?

Two to three months to audit-ready is realistic with a platform and an owner who has protected time. HealthBoxHR certified in 12 weeks starting from nothing. Doing it in spreadsheets typically takes six to twelve months. Add your certification body's lead time, which in the UK can run four to eight weeks between booking and stage 1.

Is Cyber Essentials enough instead of ISO 27001?

It depends on who is asking. Cyber Essentials covers five technical control areas and satisfies many UK public sector contracts, but it says nothing about risk assessment, supplier management, incident handling or governance. Enterprise procurement usually wants those. Most small firms do Cyber Essentials first, then use it as the technical base underneath ISO 27001.

Do small businesses have to implement all 93 Annex A controls?

No. ISO 27001:2022 lists 93 Annex A controls across four themes, and your Statement of Applicability records which apply to your scope and why the rest do not. A small consultancy with no data centre or physical archive will justifiably exclude several. What auditors want is a written, defensible reason, not blanket adoption.

Unlock Your Path to ISO 27001 Success

Download our Ultimate ISO 27001 Compliance Checklist for clear, step-by-step guidance to fast-track your certification.

End to end ISO 27001 compliance documentation

Your hub for the fundamentals of ISO 27001 compliance, curated best practices, and resources for GRC professionals.

ISO 27001 Overview

Achieve ISO 27001 Certification

ISO 27001 is the globally recognised standard for building a structured Information Security Management System (ISMS) that protects the confidentiality, integrity and availability of information. This article explains what ISO 27001 is, how it works, the core principles behind it, and what organisations must do to achieve certification. You’ll learn the standard’s structure, its key requirements, how the certification process unfolds, and the practical steps needed to implement an ISMS that is both compliant and effective.

Learn more about Achieve ISO 27001 Certification

Benefits Of ISO 27001 For Businesses

ISO 27001 certification is one of the most credible ways for businesses to prove they protect sensitive information with structure, consistency, and internationally recognised best practice. This guide explains what ISO 27001 certification is, why companies pursue it, the core business benefits, the costs involved, and how organisations of any size can achieve and maintain certification. Whether you're preparing for your first audit or strengthening your security posture, this article gives you the clarity, detail, and practical steps to move forward with confidence.

Learn more about Benefits Of ISO 27001 For Businesses

History And Evolution Of ISO 27001

ISO 27001 is now recognised as the world’s leading standard for managing information security, but its journey spans decades of technological change, emerging cyber threats, and global collaboration. This article traces the origins of ISO 27001, from its earliest foundations to the modern 2022 revision. You’ll learn how the framework developed, why it became globally adopted, how ISO 27002 fits into the picture, and how ISO standards evolved more broadly over time.

Learn more about History And Evolution Of ISO 27001
ISO 27001:2022 Requirements

Actions To Address Risks And Opportunities | Clause 6.1

Clause 6.1 of ISO 27001 defines how organisations must identify, assess, and treat information security risks — and how they must uncover opportunities to strengthen their Information Security Management System (ISMS). This clause acts as the engine of the ISO framework: it drives risk-based thinking, aligns controls to real-world threats, and ensures continual improvement. In this guide, we break down Clause 6.1 line by line, explain its relationship with Annex A, show you what documentation is required, and provide examples and best practices to help you implement it correctly and confidently.

Learn more about Actions To Address Risks And Opportunities | Clause 6.1

ISO 27001 Awareness | Clause 7.3

In this article, we explore everything you need to know about ISO 27001 Clause 7.3—its purpose, what the standard requires, how awareness strengthens your ISMS, and how to build a practical, auditor-ready awareness program that supports continuous security improvement.

Learn more about ISO 27001 Awareness | Clause 7.3

ISO 27001 Communication | Clause 7.4

In this guide, we break down exactly what ISO 27001 Clause 7.4 requires, why structured communication is essential to an effective ISMS, and how organisations can build a clear, compliant communication process supported by practical, real-world examples.

Learn more about ISO 27001 Communication | Clause 7.4

Internal Audit | Clause 9.2

Understanding the intricacies of ISO 27001:2022 is crucial for organisations aiming to enhance their information security management systems. Clause 9.2, which focuses on internal audits, plays a pivotal role in this context.

Learn more about Internal Audit | Clause 9.2
Information Security Management System (ISMS)

ISO 27001 ISMS Audit And Review Process

The audit and review process is one of the most important pillars of ISO 27001. It ensures your Information Security Management System (ISMS) is working as intended, risks are managed effectively, controls are operating correctly, and continual improvement is actively taking place. This guide explains every component of the ISO 27001 audit lifecycle — internal audits, external audits, certification audits, surveillance audits, and management reviews — and shows you how to prepare, what evidence auditors expect, and how to maintain long-term compliance.

Learn more about ISO 27001 ISMS Audit And Review Process

ISO 27001 ISMS Continuous Improvement Cycle

In this end-to-end guide, you’ll learn how continual improvement works in ISO 27001, why it’s essential for long-term security maturity, how the PDCA cycle operates inside an ISMS, and what processes, documentation, and actions are required to maintain compliance year after year.

Learn more about ISO 27001 ISMS Continuous Improvement Cycle
Annex A Controls — Organizational

Acceptable Use Of Assets | Annex A 5.10

Information security policies serve as the foundation of any robust cybersecurity program. Without clearly defined rules for acceptable use of information assets, organizations face increased vulnerability to data breaches, compliance violations, and operational disruptions. Control 5.10 of ISO 27001:2022 specifically addresses this critical aspect of information security management, requiring organizations to establish formal guidelines for how information and associated assets should be handled.

Learn more about Acceptable Use Of Assets | Annex A 5.10

Access Control Policies | Annex A 5.14

Information rarely stays still. Every organisation transfers data daily—between teams, systems, partners, customers, cloud platforms, and suppliers. Emails are sent, files are shared, storage media is moved, meetings are held, and conversations take place across calls and video conferences. Each transfer represents a moment of heightened risk.

Learn more about Access Control Policies | Annex A 5.14

Access Rights Management | Annex A 5.16

ISO 27001 Annex A 5.16 focuses on how organisations manage access rights by governing the full lifecycle of identities. This control ensures that only authorised users, systems, and services can access information assets, and that access is removed when no longer required.

Learn more about Access Rights Management | Annex A 5.16
Annex A Controls — People

Confidentiality And NDA Management | Annex A 6.6

Confidentiality obligations sit at the very core of information security. Without enforceable confidentiality controls, even the strongest technical safeguards can be rendered ineffective by human behaviour, contractual gaps, or unclear responsibilities. ISO 27001:2022 Annex A 6.6 formalises this reality by requiring organisations to define, implement, communicate, and enforce confidentiality and non-disclosure obligations across employees, contractors, suppliers, and other relevant parties.

Learn more about Confidentiality And NDA Management | Annex A 6.6

Disciplinary Process And Enforcement | Annex A 6.4

Establishing a fair disciplinary process is essential for organizations that want to effectively manage security violations while maintaining employee trust. When security breaches occur, organizations often struggle to respond consistently, which can lead to resentment, legal complications, or ineffective deterrence. Consequently, ISO 27001 includes specific requirements under Annex A 6.4 to ensure disciplinary processes are both fair and effective.

Learn more about Disciplinary Process And Enforcement | Annex A 6.4

Employee Screening And Background Checks | Annex A 6.1

In this guide, we explain everything organisations need to know about ISO 27001:2022 Annex A 6.1 — Employee Screening and Background Checks. You’ll learn what the control requires, why it exists, how auditors assess compliance, what evidence is expected, and how to design a screening process that is legally compliant, proportionate, and effective across different roles and risk levels.

Learn more about Employee Screening And Background Checks | Annex A 6.1
Annex A Controls — Physical

Access Control To Premises | Annex A 7.2

Physical security remains one of the most underestimated components of information security. While organisations invest heavily in cybersecurity tools, a single uncontrolled door, shared workspace, or unlogged visitor can undermine even the most mature digital controls. ISO 27001 Annex A 7.2 exists to address this exact risk by requiring organisations to establish and maintain effective access control to premises where information and information-processing facilities are located.

Learn more about Access Control To Premises | Annex A 7.2

Cabling And Electrical Security | Annex A 7.12

Modern technologies rely heavily on fiber, network, and power cables to function correctly. When we focus on ISO cyber security, we often overlook these critical components' physical vulnerabilities. Power and information cables face risks of damage and interception. Cyber criminals who gain access to fiber cables can disrupt all network traffic with simple techniques like 'bending the fiber.' This makes data and information unavailable.

Learn more about Cabling And Electrical Security | Annex A 7.12
ISO 27001 by Industry

ISO 27001 for Small Businesses

A practical guide to ISO 27001 for small businesses in the UK: how to scope the ISMS small, what certification really costs, how long it takes, the four mistakes small firms make, and when Cyber Essentials is enough instead.

Learn more about ISO 27001 for Small Businesses

ISO 27001 for Healthcare Companies

How UK health-tech firms, care providers and NHS suppliers use ISO 27001 to answer procurement security questions, and how it sits alongside the NHS DSPT, DTAC and Cyber Essentials Plus without duplicating the work.

Learn more about ISO 27001 for Healthcare Companies

ISO 27001 for Consulting Firms

How consultancies get ISO 27001 certified when their assets are people, laptops and client system access. Scoping by service line, the people and supplier controls auditors sample, and whether you need a consultant.

Learn more about ISO 27001 for Consulting Firms

ISO 27001 for Managed Service Providers

How UK MSPs certify to ISO 27001: what belongs in scope when you hold privileged access to client estates, the Annex A controls auditors focus on, and how CE+, ISO 27001 and SOC 2 fit together.

Learn more about ISO 27001 for Managed Service Providers

Your ISO 27001 Compliance Newsletter

Stay ahead with the latest expert insights, news, and updates on compliance.
Decorative