ISO/IEC 27001:2022 · Information Security
The proof your customers demand before the contract
Information security is rarely certified on one's own initiative. It is demanded — by enterprise procurement, by insurers, increasingly by legislators. We get you there without a consulting mandate doubling the price. And if your ISMS is already running, in 48 hours.
- Risk assessment and Statement of Applicability with guided templates
- All 93 Annex A controls worked through in a structured way — with a reasoned decision for each control
- Fixed price from €179/month, audit and monitoring included
- Switching from another certification body: express possible if your ISMS is actively lived
Often bundled with ISO 9001 — half the system requirements are the same. We check beforehand whether express works for you — free of charge.
A management system for information security — not a list of IT tools
The most common misconception: that ISO 27001 is an IT audit. It isn't. What's examined is whether you know your risks, make informed decisions about which measures to take, and whether those measures work. Technology is part of it — organisation, personnel and contracts are the rest.
Define scope
Which locations, systems and information fall under the system? A scope that is too broad is the most expensive mistake at the start.
Assess risks
Which threats affect which assets, with what impact? Traceable, repeatable, documented.
Select controls (Annex A)
93 controls in four themes: organizational, people, physical, technological. In the Statement of Applicability, you justify what you implement — and what you don't.
Operate and monitor
Access management, logging, supplier control, incident handling. Demonstrable, not just described.
Handle incidents
A security incident without a documented response is more costly in an audit than the incident itself.
Improve
Internal audits, management review, corrective actions. Just like ISO 9001 — and therefore easy to combine.
What companies want to know before certification
Annex A was restructured from 114 to 93 controls, organised into four themes instead of fourteen, and supplemented with eleven new controls — including threat intelligence, cloud security, data leakage prevention and secure coding. Those who built on the old version need a mapping, not a fresh start.
The central document of the standard: a list of all Annex A controls together with your decision on whether it is applicable, how it is implemented, and why it may be excluded. Auditors almost always start here.
NIS2 is law, ISO 27001 is a standard. A certified ISMS does not automatically fulfil NIS2, but it covers a substantial part of the required risk management measures and provides the evidence structure that supervisory authorities expect.
Usually it shortens it drastically. Many procurement processes accept a certificate plus Statement of Applicability instead of a questionnaire with a three-digit number of questions.
Where proof of evidence decides the contract
SaaS and software
Enterprise customers make 27001 a contractual condition. A SaaS provider with 25 employees loses a six-figure corporate contract during the security review — after certification, the same review is reduced to a document check.
IT service providers and MSPs
Access to customer systems requires demonstrable control. A managed service provider with admin rights at 60 customers must be able to prove access management and logging.
Finance and insurance
Regulatory oversight and the DORA environment demand structured risk management. A financial services provider uses the ISMS as the backbone for evidence towards regulators and outsourcing management.
Healthcare
Special categories of personal data. A hospital group demonstrates to regulators and patients that access to patient data is regulated and logged.
Public sector contracting authorities
Tenders require certified information security. Without ISO 27001, a service provider cannot participate in certain public procurement processes.
Industry and CRITIS-related environment
NIS2 significantly expands the scope of affected companies. A supplier in the energy sector is drawn into its customer's NIS2 obligations via the supply chain.
Consulting and law firms
Client confidentiality and liability. A law firm demonstrates structured confidentiality measures to its clients.
Retail and e-commerce
Payment and customer data. A retailer combines ISO 27001 with the requirements from payment processing and data protection.
Four steps — at the pace that suits you
After certification, a surveillance audit follows annually, and recertification after three years. Both are included in the price.
Register and clarify scope
You tell us how big your company is, where you work, and what you do. We explain how extensive the audit will be.
1 to 2 daysOne registration meeting for all standards
Prepare
You use templates, task lists, and notes on missing documents. You don't start with a blank page.
1 to 6 weeks, depending on paceOne shared documentation
Assessment in two stages
First we review your documents and whether you are ready. Then we check whether the rules really work in your everyday work.
1 to 4 daysOne combined audit plan, one appointment
Decision and certificate
An independent person decides. If successful, you receive your digital certificate, visible in the online register.
1 to 3 daysOne certificate document with multiple standards
Step 2 is the only step whose duration depends on the chosen pace: with Express it is skipped, because the system is already running. With Standard it takes one to three weeks, with Guided up to six.
You determine the pace. We tell you which one is realistic.
We don't audit more superficially or briefly than others. Above all, we save waiting time. All three paces are audited according to the same rules.
48 hours
Express
Change of certification body or a very tight deadline
- What happens: Assessment, decision and certificate
- Your system is already running, your documents are complete
- Internal audit and management review have been carried out
2–4 weeks
Standard
Most small and medium-sized enterprises
- What happens: Documents are organized and prepared with AI. This is followed by the audit.
- Your processes already work
- Documents are missing or not yet complete
2–8 weeks
Guided
Initial certification without preparation
- What happens: You build your system with an independent partner. This is followed by the audit.
- So far only a few rules, processes or documents
- Independent consulting partners from our network
For ISO/IEC 27001, Express is less often realistic. Risk assessment, statement of applicability, and implementation of the selected Annex A measures must be in place and lived. This is often the case when switching from another certification body, but almost never when building from scratch. Whether this applies to you, we clarify in advance with the free Express Check — or in five minutes on the phone.
How extensive the audit will be depends on your number of employees, your locations, and the type of your work. Not sure which column applies to you? Write to us — we'll tell you in a short conversation what's possible for you.
Scope of services
Included in the price — no asterisks
Preparation platform with templates for all required documented information
Real-time gap analysis: you can see at any time what's missing for audit readiness
Certification audit Stage 1 and Stage 2 by qualified auditors
Certificate digital, multilingual, with entry in the public register
Annual surveillance audits over the entire certificate term
Recertification after three years
Personal contact person — no ticket system as the only door
One standard is rarely the end
Anyone who implements ISO standard 27001 builds half of what 9001, 14001, or 42001 additionally require. Combine now instead of starting over from scratch in two years.
179 €/ month
- First standard €179/month, each additional standard €149 instead of €179. From four standards, an individual offer.
- From two standards, we manage your system as an integrated management system (IMS): shared document control, one internal audit program, one management review, one combined audit program. You maintain once what would otherwise be duplicated.
Prices excl. VAT
Prices you should know before you start
Cancellable monthly. With annual payment, one month is free. For special requirements, we're happy to create an individual offer.
€179/month
1 standard
€1,969 per year
- One certification
- Preparation platform
- Audit Stage 1 and Stage 2
- Certificate and register entry
- Surveillance audits
- Support
€328/month
2 standards
€3,608 per year — second standard €149 instead of €179
- Everything from 1 standard
- Second standard
- Integrated management system
- Dedicated point of contact
€477/month
3 standards
€5,247 per year — each additional standard €149
- Everything from 2 standards
- Third standard
- Dedicated project support
- Combined audit program
On request
Dedicated
- Multiple locations
- Corporate structures
- API integration
- Custom audit planning
Prices excl. VAT. The scope of the audit depends on the number of employees, locations and field of activity; for very large or multi-site organizations, we create an individual offer. What this means for your business is shown by the cost calculator.
Frequently asked questions about ISO 27001
From €179 per month, including preparation, audit, certificate and surveillance audits. Classically, the total costs for an SME in the first cycle are usually significantly higher, because consulting, certification body and internal effort are incurred separately. The cost calculator shows the difference for your size.
For a new build, realistically six to eight weeks; with an existing ISMS significantly less, in a switch case down to as little as 48 hours, if risk assessment and measures are actively practiced. The bottleneck is almost always the risk assessment, not the audit.
No. You must decide for each control, with justification, whether it is applicable. The exclusion must be traceable — that is the purpose of the statement of applicability.
A mapping to the 2022 structure, assessment of the eleven new controls and adjustment of the statement of applicability. No new build required. Simply upload your existing documents to our platform and revise the AI suggestions.
No. NIS2 is law and in parts goes beyond it, among other things regarding reporting obligations and the personal responsibility of management. However, an ISMS covers a large part of the required measures and provides the documentation structure.
Yes. What matters is that you manage your providers and that the division of responsibility is documented.
We also certify organizations with fewer than ten employees. The effort scales with complexity, not just headcount.
This is not an exclusion criterion. What is checked is whether you recognized it, addressed it, and learned from it. That is exactly what the system is there for. The point here is to make continuous improvement visible.
Your certificate is issued by the country organization responsible for your market; you can see its status before signing the contract. For ISO/IEC 27001, accreditation is only mandatory in certain legally regulated sectors — if this applies to you, we'll let you know in the initial consultation. As a general rule: the same standard is assessed by the same benchmark, and public sector clients must accept equivalent evidence. Everything on this at .
Only if your ISMS is already running: risk assessment, statement of applicability, and the selected Annex A measures must be in place and actively practiced. This is often the case when switching from another certification body, but almost never when building from scratch. We'll tell you in the Express Checkbefore you book.
This is the actual point. Your ISMS lives in the platform: statement of applicability, risks, measures, and incidents are maintained there, our AI shows deviations and reminds you of review cycles. An ISMS that falls asleep between two audits won't survive a customer audit.
Platform and AI cover the standard case. Where you need more — such as for risk methodology or an independent internal audit — we refer independent consulting from our partner network. Whoever advised you does not audit you with us.
Find out in two minutes what ISO 27001 will cost you
No call, no mandatory form, with disclosed assumptions.
