The short answer: Yes. A five-person company can hold the same certificate as a five-thousand-person bank, because ISO 27001 scales with the scope you define rather than your headcount. ISO 27001 for small businesses is mostly an exercise in drawing a tight boundary, running a real risk assessment inside it, and keeping the evidence somewhere an auditor can see. Most small UK firms reach audit-ready in two to three months, and certification body fees for a small scope sit in the low thousands of pounds a year.
You are probably reading this because a customer asked. A procurement pack landed, or a tender closed in six weeks, and buried in a security questionnaire was the line "supplier must hold ISO/IEC 27001 certification". That is how most small businesses meet the standard: because a bigger company made it a condition of the contract. The standard was written to be proportionate to the organisation applying it. Nobody tells small firms that, so they build an information security management system sized for a multinational and wonder why it swallowed a year.
{{snapshot}}
ISO 27001 for small businesses at a glance
- There is no minimum company size. Auditors assess whether your ISMS fits your context, not whether you employ a security department.
- Scope decides everything. Cost, timeline, audit days and workload all follow the boundary you draw around the ISMS.
- Two to three months to audit-ready is realistic with a platform. Six to twelve months is the usual outcome when it lives in spreadsheets and shared drives.
- Audit fees are the smaller number. For a tight scope they run to low thousands of pounds, spread across a three-year cycle with annual surveillance visits.
- 93 Annex A controls in four themes. ISO 27001:2022 asks you to justify which apply in your Statement of Applicability. It does not ask a 20-person firm to implement all 93 regardless.
{{/snapshot}}
Can a small business really get ISO 27001 certified?
Yes, and the standard is unusually explicit about it. The clauses do not change by company size; only the evidence behind each one does. A 3,000-person insurer documents an access review across forty systems. A 25-person SaaS company documents one across six. Both satisfy the same control. Auditors check that a control is designed for your risks and operating, not that it fills pages.
Clause 4 asks you to define the issues that matter to your organisation, and everything downstream inherits that context. If you are a 30-person consultancy with no data centre and no physical archive, chunks of Annex A get marked not applicable with a written justification and you move on. Small firms consistently underuse that mechanism.
The practical constraint is attention, not capability. In a small company the person who owns ISO 27001 is the CTO, the head of ops or the office manager, and they already have a full-time job. Projects finish when there is a named owner, an hour or two a week protected, and a deadline attached to a real contract. If you are early stage and wondering whether it is too soon, the honest answer is usually that it is later than you think: this is far cheaper to build at 20 people than to retrofit at 120.
Scope it small, or pay for the difference
Scope is the single decision that determines what ISO 27001 costs you. It defines which products, teams, locations and systems the ISMS covers, and it is printed on the certificate for every customer to read. Too wide and you have doubled your workload and your audit days. Too narrow and your biggest customer asks why the service they buy is not named on it.
The rule that works for small businesses: scope to the thing you sell, plus the functions that support it. For a SaaS company that is the production platform, the engineering and support teams that touch it, the corporate IT those people use, and the cloud regions it runs in. Everything else comes along only if it shares an identity provider, not because you went looking for extra work.
Be specific about exclusions and write the justification down. Your cloud provider's physical data centre security is theirs, not yours, and belongs in supplier management. Payroll run by a bureau is a supplier control. Mapping this against the Annex A controls before you start work saves more time than any other hour you will spend on the project.
Usefully, most of the work does not scale with headcount at all.
| Fixed regardless of your size | Scales with headcount, systems and scope |
|---|---|
| ISMS scope, policy set and Statement of Applicability | Assets and suppliers in the risk register |
| Risk assessment methodology, and running it once | Access reviews and joiner/mover/leaver records |
| Internal audit programme and management review cycle | Certification body audit days, which drive the fee |
| Incident, change and supplier management processes | Training and awareness records to collect each year |
| Stage 1 documentation review by the auditor | Number of sites and legal entities in scope |
The left column is the bulk of a first certification, and a 15-person company does almost as much of it as a 500-person one. That is why per-employee cost looks brutal for small firms, and why templates already mapped to controls change the maths so sharply.
What ISO 27001 actually costs a small business
Four buckets, one of them genuinely negotiable.
- Certification body fees. An accredited body quotes audit days based on your scope and headcount, then charges for stage 1, stage 2 and annual surveillance. Small scopes land in the low thousands of pounds a year. Get three quotes; the spread between UKAS-accredited bodies is wider than people expect.
- Getting ready. A platform, a consultant, or your own evenings. Hicomply Essentials is £5,300 a year for small teams and startups and includes a dedicated Customer Success Manager, which is the number to hold against a consultancy day rate.
- Tooling you were buying anyway. Password manager, MDM, logging, backup. If you already run these, the marginal cost is near zero.
- Your time. The bucket nobody puts in the spreadsheet, and the one that decides whether this lands.
The consultant question deserves a straight answer. Consultants earn their fee when you need someone in the room who has argued with an auditor before. They are poor value as a permanent subscription. CloudPass, a UK and EU access-control cloud provider, paid roughly £5,000 a year for consultants who visited twice a year, with the ISMS living in OneDrive folders. After moving to Hicomply they went through audit with zero non-conformities.
For a number rather than a range, the ISO 27001 cost calculator takes your headcount, systems and scope and produces something you can put in front of a finance director.
How long it takes when you are 20 people
Two to three months to audit-ready is normal with a platform and an owner who has time booked. Six to twelve months is normal without one, and the difference is documentation and evidence chasing, not security work.
HealthBoxHR, an HR and payroll SaaS holding sensitive employee data, is the cleanest example we have. In their CTO's words: "Starting without anything in place, we were able to achieve ISO/IEC 27001:2022 certification in 12 weeks." They started from nothing, used policy and procedure templates already linked to controls, and watched ISMS status on a dashboard instead of reconstructing it from email threads.
Two things set the floor and no platform removes them. You must run at least one internal audit and one management review before stage 2, and your certification body wants to see controls that have operated for a period rather than controls switched on last week. Then add the auditor's own lead time, which in the UK can be four to eight weeks between booking and stage 1 during busy quarters. Book them early. It is the one dependency you do not control.
Four mistakes small firms make
Over-scoping because it feels safer
Someone decides the certificate should cover "the whole company", including three entities and a product still in beta. Audit days double, the risk register fills with assets nobody owns, and the project stalls. Certify what you sell today, then extend scope at the next surveillance audit. That is a routine, cheap change.
Downloading a policy pack and calling it an ISMS
Auditors read hundreds of these. A policy naming a Chief Information Security Officer you do not employ, or a change advisory board that has never met, is worse than no policy: it proves the document is fiction. Templates are a good starting point. Edit them until they describe what your team actually does, then delete the rest.
Treating it as an IT project
Roughly half of ISO 27001 is HR, legal, supplier management and governance: onboarding, contracts, confidentiality clauses, due diligence, management review. If the ISMS belongs entirely to whoever administers the laptops, you find these gaps at stage 2 with an auditor watching. Professional services firms feel it most, which is why ISO 27001 for consulting firms hinges on client data handling and subcontractors rather than infrastructure.
Keeping evidence in email and someone's laptop
The classic small-business failure. The controls work fine; the proof is scattered across Slack threads, an inbox and a folder structure one person understands. Then that person is on holiday during stage 2. Evidence needs one home with dates, owners and version history, which is the argument for putting the ISMS somewhere structured before you start collecting rather than after.
When Cyber Essentials is enough, and when it is not
Not every customer request needs ISO 27001, and pretending otherwise costs small companies money. Cyber Essentials is a UK government-backed scheme covering five technical control areas, achievable in weeks, and mandatory for many central government contracts. If the buyer's question is "are your laptops patched and your firewalls configured", it answers that well.
It does not answer what enterprise procurement actually asks. Cyber Essentials says nothing about how you assess risk, manage suppliers, handle incidents, or whether anyone reviews any of it next year. ISO 27001 is a management system with continual improvement built in, which is why it survives a buyer's security review and a self-attested checklist does not. The Cyber Essentials versus ISO 27001 comparison sets out where each one stops.
For most small UK firms: do Cyber Essentials first because it is quick and satisfies a real slice of public sector demand, then treat it as the technical foundation underneath ISO 27001. Sector matters too. Managed service providers get asked for ISO 27001 the moment they hold privileged access to client environments, and healthcare suppliers usually need it alongside NHS Data Security and Protection Toolkit obligations rather than instead of them.
{{snapshot}}
Hicomply's take
We have watched plenty of small companies talk themselves out of ISO 27001 on the assumption it was built for enterprises. It was not. What sinks small projects is scope creep dressed up as thoroughness: certifying entities you need not certify, writing policies for roles you have not hired, gathering evidence for controls you marked applicable out of nervousness. Draw the smallest honest boundary around what you sell, justify the exclusions, and keep evidence in one place from day one. What you build carries straight into SOC 2.
{{/snapshot}}
Get certified without hiring a compliance team
Small businesses rarely fail ISO 27001 on security. They fail on capacity: nobody has three months spare to assemble documents, chase screenshots and rebuild a risk register every time an auditor asks. That is the part worth automating. Policy templates mapped to controls, a risk register that populates from your assets, evidence collected on a schedule, and a dashboard that shows where you stand without a two-day audit of your own audit.
Start with the free ISO 27001 readiness assessment to see how far off you are, then book a demo and we will work through scope, timeline and cost for a company your size. Bring the customer questionnaire that started all this. It tells us more about your scope than a discovery call does.


.avif)























