ISO/IEC 27001:2022 · Information Security

The proof your customers demand before the contract

Information security is rarely certified on one's own initiative. It is demanded — by enterprise procurement, by insurers, increasingly by legislators. We get you there without a consulting mandate doubling the price. And if your ISMS is already running, in 48 hours.

  • Risk assessment and Statement of Applicability with guided templates
  • All 93 Annex A controls worked through in a structured way — with a reasoned decision for each control
  • Fixed price from €179/month, audit and monitoring included
  • Switching from another certification body: express possible if your ISMS is actively lived

Often bundled with ISO 9001 — half the system requirements are the same. We check beforehand whether express works for you — free of charge.

ISO-27001-Signet
48 hoursif your ISMS is already running
Required by enterprise procurement and regulatorsOwn management system according to ISO 9001Every certificate can be verified in the public register

A management system for information security — not a list of IT tools

The most common misconception: that ISO 27001 is an IT audit. It isn't. What's examined is whether you know your risks, make informed decisions about which measures to take, and whether those measures work. Technology is part of it — organisation, personnel and contracts are the rest.

Define scope

Which locations, systems and information fall under the system? A scope that is too broad is the most expensive mistake at the start.

Assess risks

Which threats affect which assets, with what impact? Traceable, repeatable, documented.

Select controls (Annex A)

93 controls in four themes: organizational, people, physical, technological. In the Statement of Applicability, you justify what you implement — and what you don't.

Operate and monitor

Access management, logging, supplier control, incident handling. Demonstrable, not just described.

Handle incidents

A security incident without a documented response is more costly in an audit than the incident itself.

Improve

Internal audits, management review, corrective actions. Just like ISO 9001 — and therefore easy to combine.

What companies want to know before certification

Annex A was restructured from 114 to 93 controls, organised into four themes instead of fourteen, and supplemented with eleven new controls — including threat intelligence, cloud security, data leakage prevention and secure coding. Those who built on the old version need a mapping, not a fresh start.

Where proof of evidence decides the contract

SaaS and software

Enterprise customers make 27001 a contractual condition. A SaaS provider with 25 employees loses a six-figure corporate contract during the security review — after certification, the same review is reduced to a document check.

IT service providers and MSPs

Access to customer systems requires demonstrable control. A managed service provider with admin rights at 60 customers must be able to prove access management and logging.

Finance and insurance

Regulatory oversight and the DORA environment demand structured risk management. A financial services provider uses the ISMS as the backbone for evidence towards regulators and outsourcing management.

Healthcare

Special categories of personal data. A hospital group demonstrates to regulators and patients that access to patient data is regulated and logged.

Public sector contracting authorities

Tenders require certified information security. Without ISO 27001, a service provider cannot participate in certain public procurement processes.

Industry and CRITIS-related environment

NIS2 significantly expands the scope of affected companies. A supplier in the energy sector is drawn into its customer's NIS2 obligations via the supply chain.

Consulting and law firms

Client confidentiality and liability. A law firm demonstrates structured confidentiality measures to its clients.

Retail and e-commerce

Payment and customer data. A retailer combines ISO 27001 with the requirements from payment processing and data protection.

Four steps — at the pace that suits you

After certification, a surveillance audit follows annually, and recertification after three years. Both are included in the price.

  1. Register and clarify scope

    You tell us how big your company is, where you work, and what you do. We explain how extensive the audit will be.

    1 to 2 days

    One registration meeting for all standards

  2. Prepare

    You use templates, task lists, and notes on missing documents. You don't start with a blank page.

    1 to 6 weeks, depending on pace

    One shared documentation

  3. Assessment in two stages

    First we review your documents and whether you are ready. Then we check whether the rules really work in your everyday work.

    1 to 4 days

    One combined audit plan, one appointment

  4. Decision and certificate

    An independent person decides. If successful, you receive your digital certificate, visible in the online register.

    1 to 3 days

    One certificate document with multiple standards

Step 2 is the only step whose duration depends on the chosen pace: with Express it is skipped, because the system is already running. With Standard it takes one to three weeks, with Guided up to six.

You determine the pace. We tell you which one is realistic.

We don't audit more superficially or briefly than others. Above all, we save waiting time. All three paces are audited according to the same rules.

48 hours

Express

Change of certification body or a very tight deadline

  • What happens: Assessment, decision and certificate
  • Your system is already running, your documents are complete
  • Internal audit and management review have been carried out
Start Express Check

2–4 weeks

Standard

Most small and medium-sized enterprises

  • What happens: Documents are organized and prepared with AI. This is followed by the audit.
  • Your processes already work
  • Documents are missing or not yet complete
Calculate price

2–8 weeks

Guided

Initial certification without preparation

  • What happens: You build your system with an independent partner. This is followed by the audit.
  • So far only a few rules, processes or documents
  • Independent consulting partners from our network
Schedule a call

For ISO/IEC 27001, Express is less often realistic. Risk assessment, statement of applicability, and implementation of the selected Annex A measures must be in place and lived. This is often the case when switching from another certification body, but almost never when building from scratch. Whether this applies to you, we clarify in advance with the free Express Check — or in five minutes on the phone.

How extensive the audit will be depends on your number of employees, your locations, and the type of your work. Not sure which column applies to you? Write to us — we'll tell you in a short conversation what's possible for you.

Scope of services

Included in the price — no asterisks

from €179 / month
  • Preparation platform with templates for all required documented information

  • Real-time gap analysis: you can see at any time what's missing for audit readiness

  • Certification audit Stage 1 and Stage 2 by qualified auditors

  • Certificate digital, multilingual, with entry in the public register

  • Annual surveillance audits over the entire certificate term

  • Recertification after three years

  • Personal contact person — no ticket system as the only door

One standard is rarely the end

Anyone who implements ISO standard 27001 builds half of what 9001, 14001, or 42001 additionally require. Combine now instead of starting over from scratch in two years.

Select ISO standards
1 standard

179 €/ month

  • First standard €179/month, each additional standard €149 instead of €179. From four standards, an individual offer.
  • From two standards, we manage your system as an integrated management system (IMS): shared document control, one internal audit program, one management review, one combined audit program. You maintain once what would otherwise be duplicated.
Calculate bundle price

Prices excl. VAT

Prices you should know before you start

Cancellable monthly. With annual payment, one month is free. For special requirements, we're happy to create an individual offer.

€179/month

1 standard

€1,969 per year

  • One certification
  • Preparation platform
  • Audit Stage 1 and Stage 2
  • Certificate and register entry
  • Surveillance audits
  • Support
Most popular choice

€328/month

2 standards

€3,608 per year — second standard €149 instead of €179

  • Everything from 1 standard
  • Second standard
  • Integrated management system
  • Dedicated point of contact

€477/month

3 standards

€5,247 per year — each additional standard €149

  • Everything from 2 standards
  • Third standard
  • Dedicated project support
  • Combined audit program
Enterprise

On request

Dedicated

  • Multiple locations
  • Corporate structures
  • API integration
  • Custom audit planning

Prices excl. VAT. The scope of the audit depends on the number of employees, locations and field of activity; for very large or multi-site organizations, we create an individual offer. What this means for your business is shown by the cost calculator.

Frequently asked questions about ISO 27001

From €179 per month, including preparation, audit, certificate and surveillance audits. Classically, the total costs for an SME in the first cycle are usually significantly higher, because consulting, certification body and internal effort are incurred separately. The cost calculator shows the difference for your size.

Find out in two minutes what ISO 27001 will cost you

No call, no mandatory form, with disclosed assumptions.