ISO 27001 is not something that startups need to think about for many years. An email from a business customer asks for your ISO 27001 certification as part our security review of vendors.
The certification issue isn’t one to look at the next time. It’s tied to a contract that the company is looking to end.
For a lot of growing businesses, that’s the practical starting point for ISO 27001 for small business. It’s difficult to figure out the steps to take without turning an easily manageable project into a compliance plan for larger companies.

This week, focus on Scope, not Shopping
The first instinct may be to begin comparing compliance systems and consultants. The best place to start is by defining what ISMS or Information Security Management System needs to include.
Scope matters because trying to include ineffective systems, locations or processes may result in additional documentation and evidence requirements.
Small SaaS businesses, for example could have an environment that’s centered around cloud infrastructures employees’ devices, customer information, and few key vendors. Understanding this environment will help establish the specific issues that the certification process must address.
Look over the Security You Already Possess
Companies that are researching ISO 27001 for startups sometimes believe that they require an entirely new security operation.
This might not be correct.
Modern startups might already be using cloud services, and require multi-factor authentication as well as restrict access for employees. They could also manage systems logs and handle backups. These practices should be compared against ISO 27001 requirements. However starting with things that are already working will prevent unnecessary duplication.
The documentation of policies, the risk assessment, determining the applicable Annex A Controls, completing the Statement for Applicability and gathering evidence are the other tasks.
You can now identify which invoices pay for what
The ISO 27001 cost becomes much easier to understand when expenses aren’t lumped into a single number.
When you consider the cost of an independent certification audit, compliance tools, and staff time A small business’s initial cost could be anything from $10,000 to $30,000. The cost of consulting can be added, but this is not an essential expense.
It is essential to distinguish between the ISO 27001 certification costs charged by a certified certification body and the software costs. A compliance platform is a great tool to organize the work, but it cannot award the certificate. The independent auditing process is what validates the certification.
Then comes the evidence
A policy that states the employee’s access to company resources is terminated upon their departure isn’t enough. An auditor requires evidence that the procedure actually works.
This distinction between demonstrating and saying is central to ISO 27001.
CertAssist is designed to help you organize this work without connecting directly to live systems in a company. It offers all the 93 ISO 27001 Annex A controls within one single board. It also offers customizable templates for policies and evidence as well as a Declaration of Applicability.
Templates can be used by small groups to avoid the tedious task of creating every policy from scratch.
Certification Day Isn’t the Finish Line
An organization that is just starting at the beginning may have to invest between three and six month getting ready for certification. This is contingent upon their existing security practices, as well as the resources they have available. The certification body then conducts the Stage 1 and Stage 2 audits.
Achieving these audits doesn’t mean you have the right to forget about the ISMS. The ISMS should continue to monitor controls and provide evidence. After the certification, surveillance audits are performed.
This is an important element to consider when creating the program. Smaller businesses do not only have to have an ISMS they can afford. It needs one its team can actually operate after the initial project has ended.
The most intelligent ISO 27001 program for a smaller company is not always the most comprehensive. It is one that meets the ISO 27001 requirements, is based on real security practices, withstands independent scrutiny and is able to be maintained once everyone is back to their regular jobs.