The CRA's 24-hour reporting duty has applied since 11 September 2026. Check whether it reaches you

Audit days per ISO/IEC 27006-1:2024, rates read 24 September 2026

ISO 27001 for a 10-person company

It is done at this size. The standard asks the same of 10 people as of a larger company; the audit is shorter.

Short answer
Yes

Up to 10 people is the smallest band of the audit-time chart: 5 auditor days for Stage 1 and Stage 2, €6,000 to €10,000 at the day rates read 24 September 2026.

Who it is for
A company of up to 10 people that a customer, a tender or an investor has asked for a certificate.
What to do
Write the scope, the risk register and the Statement of Applicability, hold an internal audit and a management review, then ask accredited bodies to quote.
  • 5

    Auditor days, Stage 1 and Stage 2

  • €6,000 to €10,000

    The initial audit, excl. VAT

  • 93

    Annex A controls, each applied or excluded with a reason

  • €249

    StandardOS a month, at any headcount

Year one at 10 people

Every line, who is paid, and where the figure comes from. The audit fee is arithmetic on the chart; the rest was read from the sources named.

LineEUR, excl. VAT
The certification audit An accredited certification bodyComputed here€6,000 to €10,000
Your own people's time 300 to 600 hoursYour companyheydata, Eurostat, read 24 September 2026€10,500 to €20,900
A copy of ISO/IEC 27001 A national standards bodyAustrian Standards, DIN Media, read 24 September 2026€138 to €166
StandardOS for a year StandardOSComputed here€2,988
A penetration test, if the auditor asks for one A testing firmSectricity, read 24 September 2026optional, not in the total€2,500 to €3,500
A trained implementer, if you want one A training providerCyber Academy, read 24 September 2026optional, not in the total€2,800 to €3,200
Year one, without the optional lines€19,600 to €34,100
Each later year of the cycle: the surveillance audit and StandardOS€5,000 to €6,300

StandardOS is software. It does not certify; an accredited certification body does, and you pay it directly.

What the standard asks of 10 people

The same records as at any size. Each one can be written free on this site:

Questions

Is there a minimum company size for ISO 27001?
No. The standard sets none, and the audit-time chart certification bodies work to starts with a band for up to 10 people.
Do we need a full-time security person?
No. Clause 5.3 asks top management to assign the responsibilities and authorities for information security; it does not ask for a full-time post.
What happens after the first audit?
A shorter surveillance audit in each later year of the cycle, €2,000 to €3,300 each at the same day rates, then recertification.

Start with the scope and the Statement of Applicability

No card to start · cancel in-app anytime

This page in:DeutschFrançaisNederlandsEspañolDansk