ISO 27001
The standard your customers keep asking about.
No law makes a software company certify to ISO 27001; a customer's renewal, a tender or a bank under DORA does, and the first number to know is what the audit takes for a company of your size.
For 25 people the certification audit is 7 auditor days under ISO/IEC 27006 Annex B: €8,400 to €12,600 for the initial audit and €14,000 to €21,000 for the three-year cycle, at the day rates accredited bodies in Europe charge, audit fees only.
Open the cost calculator with this headcount93
controls in Annex A
26
clauses that carry requirements
3,404
tender notices name it in the EU and EEA observed 12 September 2026
What certification actually costs
Certification bodies do not publish prices, but the audit days are fixed by ISO/IEC 27006, so you can work out your own number.
Write the scope statement
Clause 4.3 from twelve answers: the sentence the certificate will carry, the boundaries, the interfaces and dependencies, the exclusions with their justification, and the issues considered.
Write the information security policy
Clause 5.2 from ten answers: the purpose, why security matters to this company, the commitments, the objectives, who is responsible, the topic policies under it, and how it is communicated and reviewed.
Write the risk register and treatment plan
Five answers pick the starter risks, each scored and treated with the Annex A controls; the register and the plan written as the auditor reads them, and the Statement of Applicability follows.
Write the internal audit programme
Clause 9.2 from five answers: the criteria, how many audits a year and what each covers, who audits and how they stay independent, the methods, the year's schedule over the clause sections and the Annex A themes, and how results are reported.
Write the management review minutes
Clause 9.3 as an agenda: the seven inputs in the clause's order with what was said about each, the four performance trends with their counts, the decisions, the actions with owner and date, and the minutes an auditor reads.
Write a corrective action record
Clause 10.2 for one finding: the nonconformity, the correction and its consequences, the cause, whether it exists elsewhere, the action with owner and date, the effectiveness check, and the change to the system, as the record an auditor reads.
Write the incident response plan
The Annex A incident controls from a few answers: who leads, how an event is reported, the three severity levels, the response steps, the GDPR, NIS2 and CRA clocks that apply, the evidence to keep, the review afterwards, the exercises.
Write the acceptable use policy
The rules every person signs, from a few answers: accounts and passwords, devices and personal devices, remote work, data handling, approved services and AI tools, communication, personal use, monitoring, reporting, leaving, breaches, acknowledgement.
Write the access control policy
Who gets access to what and how it is granted, protected, reviewed and removed, from a few answers: one identity per person, multi-factor authentication, roles, privileged accounts, third parties, the access review, leavers, logging, exceptions.
Write the supplier security policy
How the company chooses, contracts, watches and leaves its suppliers and cloud services, from a few answers: the critical suppliers, what is checked before signing, the six contract clauses, where data may live, the review, the exit.
Write the business continuity plan
What the company does when the product, the data, the office or a supplier is gone, from a few answers: the services covered, the hours to restore, the data loss tolerated, who declares a disruption, how security holds during it, the recovery, the exercise.
Write the Statement of Applicability
The 93 Annex A controls with a status each, a justification for every exclusion, and the Statement written as the auditor reads it, to copy or download.
All 93 Annex A controls
One plain-English line per control, grouped by the four themes of the 2022 edition.
What we cover, clause by clause
Every clause from 4 to 10, where its records live in the product, and where the limits of any software sit.
How many auditor days, by headcount
The ISO/IEC 27006 Annex B arithmetic that fixes the audit fee before anyone quotes you.
ISO 27001 or SOC 2 in Europe
3,405 EU tender notices name ISO 27001 against 104 for SOC 2. The query is public; run it yourself.
Where public buyers name ISO 27001, by country
Public buyers in the EU and EEA named ISO 27001 in 3,404 tender notices over the last year, 0.38% of everything they published. Seven in ten came from Germany and Poland; France, Spain and Italy name their national schemes instead.
The scope statement, the line a buyer reads first
Why a certificate that names the head office does not cover a SaaS product, what clause 4.3 requires, the eight conditions a financial customer applies under DORA, and three scope statements for a software company that pass.
The Statement of Applicability, read for a software company
The four columns of Clause 6.1.3(d), the exclusions an auditor accepts and the ones they never do, and how the Statement follows the risk treatment plan.
The risk assessment, read for a software company
What Clause 6.1.2 asks for, a five-point method with an acceptance threshold, the starter risks a software company carries, and why the treatment plan comes before the Statement.
The information security policy, read for a software company
What Clause 5.2 asks for and does not, the nine sections a two-page policy carries, objectives an auditor can measure, and the mistakes the first audit flags.
The management review, read as an agenda
The seven inputs of Clause 9.3 in order, the four trends with figures, the two outputs, what the minutes have to show, and the mistakes that turn a meeting into a finding.
The corrective action record, read as a sequence
What Clause 10.2 asks for after a nonconformity, the seven sections of a record an auditor accepts, why correction is not corrective action, and the mistakes that reopen a closed finding.
ISO/IEC 27701:2025, the privacy standard on top of 27001
The standalone edition read row by row: the 70 requirements a running ISO 27001 system half covers, the 33 privacy-only ones, and the GDPR articles each control evidences.
DORA for a software vendor: the contract clauses your bank customer will send
Nine clauses in every ICT service contract and six more for a critical or important function, read from Article 30; the register of information you appear in; and which clauses an ISO 27001 system already produces the evidence for.
Every free template on one page
What it costs, and how to get there
ISO 27001 certification cost for a company, by headcount
Auditor days come from the ISO/IEC 27006 Annex B chart, so certification cost tracks headcount more than industry. Here is the arithmetic, and the lines people forget.
ISO 27001 cost of implementation: the three-year number, not the first invoice
Certification runs on a three-year cycle with surveillance audits each year. Budgeting only for the first audit is the most common way the total surprises people.
Cheapest ISO 27001 certification: how to compare quotes without buying a worthless certificate
Certification body quotes vary, but the auditor days behind them are set by ISO/IEC 27006 Annex B. Here is how to read a quote, and the one check that matters more than price.
The cheapest way to get ISO 27001, and the part you cannot make cheaper
Most of an ISO 27001 budget is auditor days, and those are set by a published chart rather than by negotiation. Here is what actually moves the number, and what does not.
ISO 27001 compliance checklist, by clause
A checklist that follows the standard's own structure: clauses 4 to 10 and what each one asks you to be able to show, plus what Annex A adds.
Best ISO 27001 compliance software: what to ask before you compare features
Integration counts are easy to compare and rarely decide an audit. Here are the questions that do, including the one most vendors will not answer in writing.
Implementing ISO 27001 without consultants: what you take on, and what they were doing for the money
It is entirely possible to certify without a consultant. It is worth knowing what you are absorbing first, and which parts genuinely benefit from someone who has sat on the other side of an audit.
Related:ArticlesFree tools