Audit days per ISO/IEC 27006-1:2024, rates read 24 September 2026
ISO 27001 for a 10-person company
It is done at this size. The standard asks the same of 10 people as of a larger company; the audit is shorter.
- Short answer
- Yes
Up to 10 people is the smallest band of the audit-time chart: 5 auditor days for Stage 1 and Stage 2, €6,000 to €10,000 at the day rates read 24 September 2026.
- Who it is for
- A company of up to 10 people that a customer, a tender or an investor has asked for a certificate.
- What to do
- Write the scope, the risk register and the Statement of Applicability, hold an internal audit and a management review, then ask accredited bodies to quote.
5
Auditor days, Stage 1 and Stage 2
€6,000 to €10,000
The initial audit, excl. VAT
93
Annex A controls, each applied or excluded with a reason
€249
StandardOS a month, at any headcount
Year one at 10 people
Every line, who is paid, and where the figure comes from. The audit fee is arithmetic on the chart; the rest was read from the sources named.
| Line | Paid to | EUR, excl. VAT | Where the figure comes from |
|---|---|---|---|
| The certification audit An accredited certification bodyComputed here | An accredited certification body | €6,000 to €10,000 | Computed here |
| Your own people's time 300 to 600 hoursYour companyheydata, Eurostat, read 24 September 2026 | Your company | €10,500 to €20,900 | heydata, Eurostat, read 24 September 2026 |
| A copy of ISO/IEC 27001 A national standards bodyAustrian Standards, DIN Media, read 24 September 2026 | A national standards body | €138 to €166 | Austrian Standards, DIN Media, read 24 September 2026 |
| StandardOS for a year StandardOSComputed here | StandardOS | €2,988 | Computed here |
| A penetration test, if the auditor asks for one A testing firmSectricity, read 24 September 2026optional, not in the total | A testing firm | €2,500 to €3,500 | Sectricity, read 24 September 2026 |
| A trained implementer, if you want one A training providerCyber Academy, read 24 September 2026optional, not in the total | A training provider | €2,800 to €3,200 | Cyber Academy, read 24 September 2026 |
| Year one, without the optional lines | €19,600 to €34,100 | ||
| Each later year of the cycle: the surveillance audit and StandardOS | €5,000 to €6,300 |
StandardOS is software. It does not certify; an accredited certification body does, and you pay it directly.
What the standard asks of 10 people
The same records as at any size. Each one can be written free on this site:
- 4.3The scope
- 5.2The information security policy
- 6.1.2The risk register and treatment plan
- 9.2The internal audit programme
- 9.3The management review minutes
Questions
- Is there a minimum company size for ISO 27001?
- No. The standard sets none, and the audit-time chart certification bodies work to starts with a band for up to 10 people.
- Do we need a full-time security person?
- No. Clause 5.3 asks top management to assign the responsibilities and authorities for information security; it does not ask for a full-time post.
- What happens after the first audit?
- A shorter surveillance audit in each later year of the cycle, €2,000 to €3,300 each at the same day rates, then recertification.
Start with the scope and the Statement of Applicability
No card to start · cancel in-app anytime