Viktar Patotski ·
· Security
· 12 min read
ISO 27001 Certification for SaaS: Steps, Timeline and Real Cost in 2026
How ISO 27001 certification works for a small SaaS company, how long it takes, and what it costs: audit days set by the standard, platform list prices, the mandatory internal audit, and the three-year cycle nobody budgets. With sources.
TL;DR: ISO 27001 certification for a 20-person SaaS costs $26k-$77k in year one, plus 200-400 hours of internal time. The audit is the one line you can calculate in advance: an international standard (ISO/IEC 27006) fixes the auditor days by headcount, 7 days for 16-25 people, and the certification body can cut that by 30% at most. At $1,500-$2,200 per auditor day that is $8k-$17k for the initial audit. The rest is a compliance platform ($9.5k list at the cheapest), a mandatory internal audit, a penetration test, and optional consulting. The trap is that the certificate is a three-year subscription: two surveillance audits, then a recertification at close to the initial price. Expect 3-6 months from start to certificate with a platform, 6-12 without one.
Why you’re Googling ISO 27001 certification
The trigger is the same as for SOC 2: a buyer’s security questionnaire. The difference is where the buyer sits. US procurement asks for a SOC 2 report. European, UK and Australian procurement asks for an ISO 27001 certificate, and since 2025 two EU laws push that question further down the supply chain.
NIS2 (the EU’s second Network and Information Security directive) has been in force in Germany since 6 December 2025 and grows the number of regulated companies there from about 4,500 to roughly 29,500. It does not require your company to be certified, but it requires your regulated customers to manage supply-chain security, and the cheapest way for them to do that is a contract clause asking you for ISO 27001. DORA (the EU Digital Operational Resilience Act, which applies to banks and insurers since 17 January 2025) does the same for anyone selling software to financial companies: their vendor register needs your security evidence, and a certificate is the evidence they know how to file.
So the question lands on a founder’s desk as “the customer’s legal team wants our ISO 27001 certificate before signing.” One deal of that size pays for the whole program, which is the only good reason to start.
ISO 27001 vs SOC 2 in one section
ISO 27001 is a certification. An accredited certification body (the audit firm that issues the certificate, accredited by a national body such as DAkkS (Deutsche Akkreditierungsstelle) in Germany, UKAS (United Kingdom Accreditation Service) or ANAB (ANSI National Accreditation Board, part of the American National Standards Institute) in the US) audits your ISMS (Information Security Management System: the scope, risk assessment, policies and reviews that run your security program) and issues a certificate valid for three years. Anyone can check it in the certification body’s own register, and for most countries in IAF CertSearch, the database of the International Accreditation Forum (IAF). German certificates are the gap: DAkkS does not share its data with CertSearch.
SOC 2 is an attestation. A CPA (certified public accountant) firm writes a confidential report with an opinion on your controls over an observation window. No certificate, no public register, a new report every year.
Most of the technical controls overlap. The AICPA (American Institute of CPAs, the body that owns SOC 2) publishes a mapping between the two, and most Annex A controls have a SOC 2 counterpart. Ignore the overlap percentages on vendor blogs (I found claims from 43% to 96%, and the AICPA mapping itself states no number). What SOC 2 gives you nothing for is the management-system part of ISO 27001: the documented scope, the risk assessment method and treatment plan, the Statement of Applicability, the internal audit and the management review. That is the extra work if you add ISO after SOC 2.
If your pipeline is US-only, skip ISO until a signed deal depends on it. If you sell into the EU, the UK or Australia, ISO 27001 is the credential your buyers recognize.
How ISO 27001 certification works, step by step
The current standard is ISO/IEC 27001:2022. Every 2013 certificate expired on 31 October 2025, so a supplier showing a “27001:2013” certificate today is showing an expired one. Annex A of the 2022 version lists 93 controls in four themes (37 organizational, 8 people, 14 physical, 34 technological). You do not have to implement all of them; you justify each inclusion or exclusion.
- Define the scope. Which product, which teams, which locations. A single SaaS product and the people who build and run it is the cheapest scope that still satisfies buyers.
- Run a risk assessment and write the Statement of Applicability. The SoA (Statement of Applicability, the document that lists every Annex A control and says whether you apply it and why) is the backbone of the audit. A threat model like the STRIDE example on a Spring Boot and AWS stack is solid input to the risk assessment.
- Operate the controls and collect records. The standard names no minimum period, but certification bodies expect around three months of evidence before the main audit: access reviews that happened, incidents that were logged, changes that went through review.
- Do the internal audit and the management review. Both are mandatory clauses (9.2 and 9.3). The internal auditor must be independent of what they audit, which in a 20-person company is easiest to outsource.
- Stage 1 audit. The certification body reviews your documentation and readiness. It finds gaps, you fix them.
- Stage 2 audit. The certification body tests whether the controls actually run. Pass, and the certificate is issued.
- Surveillance and recertification. A surveillance audit in each of the next two years, then a recertification audit at the end of year three, before the certificate expires. It opens the next three-year cycle.
For a cloud-native SaaS that already runs SSO (single sign-on), MFA (multi-factor authentication), infrastructure as code and centralized logging, most of the technological controls exist. The engineering work is making them provable: access reviews with a record, vulnerability management with a cadence, backups with a tested restore. Annex A control 8.8 (management of technical vulnerabilities) is where auditors expect to see a penetration test, the same logic as criterion CC4.1 (Common Criteria 4.1, monitoring activities) in SOC 2.
Timeline: 3-6 months from start to certificate with a compliance platform, 6-12 months from scratch. Vendor case studies of “certified in 4 weeks” come from companies that already ran the controls under another scheme.
What ISO 27001 certification costs, line by line
1. The certification audit: $8k-$17k, and the standard sets the days
No accredited certification body publishes a rate card. What is public is the audit-time chart in ISO/IEC 27006, the standard that tells certification bodies how many auditor days an ISMS audit needs for a given headcount. These are the rows that matter for a startup, for the initial audit (Stage 1 and Stage 2 combined):
| People in scope | Initial audit (auditor days) | Minimum after the 30% reduction |
|---|---|---|
| 1-10 | 5 | 3.5 |
| 11-15 | 6 | 4.2 |
| 16-25 | 7 | 4.9 |
| 26-45 | 8.5 | 6 |
| 46-65 | 10 | 7 |
| 66-85 | 11 | 7.7 |
| 86-125 | 12 | 8.4 |
Values are from the 2015 edition’s Table B.1. The 2024 edition (ISO/IEC 27006-1:2024, Annex C) is paywalled; secondary sources say it keeps the chart values and adds a rule that counts large groups doing identical simple work (a support team, for example) as fewer people. Reductions come from low-risk processes, a single service, or a mature, well-prepared ISMS. Surveillance audits take about a third of the initial time each year, recertification at least two thirds.
Vendor-reported day rates for accredited bodies run $1,500-$2,200 in the US, £1,250 and up in the UK, and €1,200-€2,500 in Germany, plus application, certificate and program-management fees of a few hundred to about $1,500 a year, plus travel if any part is on site. For a 20-person company that works out to:
- Initial audit: 4.9-7 days, so $8k-$17k with fees.
- Surveillance, each of the next two years: $3k-$7k.
- Recertification at the end of year three: $6k-$16k. Platform-partnered auditors quote it close to the initial fee.
The one itemized accredited quote I could find, reproduced by a UK consultant, is £6,804 for the initial certification of a consultancy under 10 people (three audit days plus application and program fees), then £3,103 a year.
2. The compliance platform: $9.5k-$20k a year
The same vendors sell SOC 2 and ISO 27001, and four of them publish list prices on AWS Marketplace (12-month contracts, checked October 2026):
| Vendor | List price with ISO 27001 |
|---|---|
| Sprinto | $7,500 platform + $2,000 first framework = $9,500 |
| Secureframe | $7,500 platform + $7,500 first framework = $15,000 |
| Vanta | Essentials $14,000 for 1-20 employees (frameworks by tier) |
| Drata | $25,000 platform + $7,500 for ISO 27001 = $32,500 |
Nobody should pay list. Vendr’s transaction data puts the median Vanta deal at $20k across 370 deals, with lows around $7.5k. If you already run SOC 2 on one of these, ISO 27001 is a second framework: +$2,000 at Sprinto’s floor, +$7,500 at Drata. EU-hosted platforms (Secfix, Kertos, TrustSpace) quote only; heyData lists €2,000-€6,000 a year for its ISMS platform, and TrustSpace publishes one example of €900 a month for a 20-person startup including weekly expert calls.
3. The internal audit: $3k-$10k
This is the line SOC 2 teams forget. Clause 9.2 requires an internal audit before the certification audit, done by someone independent of the work. EU firms quote €2,500-€5,000 for a small scope, US firms $5k-$10k. It recurs every year.
4. The penetration test: $5k-$15k
ISO 27001 does not mandate a pentest by name. Annex A 8.8 and 8.29 (security testing in development) make one the evidence auditors expect, and buyers ask for the summary anyway. A web app plus API at a credible boutique firm lands in this range. It also recurs every year.
5. Consulting: $0-$15k
With a platform and its templates, a team that can write clearly needs no consultant. A gap analysis or a fixed-fee implementation package costs $8k-$15k in the US, £3,500-£11,500 in the UK, from €12,000 in Germany. Pay for it when nobody on the team has time to own the ISMS documents, not as insurance.
6. Internal time: 200-400 hours
Nobody measures this well. Published estimates range from 150 hours (a vendor’s figure for a cloud-native team) to 800 hours (from scratch, no platform). For a 20-person team with SSO, MFA and infrastructure as code already in place, 200-400 hours is realistic: 5-10 weeks of one senior engineer, spread over the project, plus a few hours a month after certification to keep the records running.
The realistic budget: year one and the three-year cycle
For a 20-person, single-product SaaS:
| Line | Lean | Comfortable |
|---|---|---|
| Certification audit (initial) | $8k | $17k |
| Compliance platform | $9.5k | $20k |
| Internal audit | $3k | $10k |
| Penetration test | $5k | $15k |
| Consulting | $0 | $15k |
| Year one, cash | $26k | $77k |
| Internal time | 200 h | 400 h |
Years two and three each cost the platform, the pentest, the internal audit and a surveillance audit: $21k-$52k a year. Over the three years the certificate is valid that is about $67k-$181k. The recertification audit at the end of year three ($6k-$16k) then opens the next cycle. Budget it as a subscription, because that is what it is.
For a 60-person company every line grows: the audit to 7-10 days ($11k-$23k), platform deals to $12k-$25k, the internal audit to $3.5k-$10k, the pentest to $8k-$15k, and consulting, if you buy it, up to $25k. That is $35k-$98k in year one and 400-800 hours of internal time.
The traps that cost more than the audit
An unaccredited certificate. Certification bodies without accreditation sell certificates for a fraction of the price (one UK example: “£2,500 all-in”). They are legal and worthless in procurement. Check that the certificate carries an accreditation mark (DAkkS, UKAS, ANAB) and that the certification body is in IAF CertSearch or the accreditation body’s own database before you sign.
Budgeting one year instead of three. The certificate costs money every year, and the cycle ends in a recertification audit. Year one is only about 40% of the three-year cost.
Scope creep. Put the whole company in scope and you move up the audit-day chart and add evidence for teams that never touch customer data. Scope the product and the people who run it.
Confusing ISO 27001 with its German cousins. A vertical SaaS selling into automotive suppliers gets asked for TISAX (Trusted Information Security Assessment Exchange, an assessment label run for the German automotive industry, built on ISO 27001 Annex A), and an ISO certificate does not replace it. Some German public-sector buyers want ISO 27001 based on IT-Grundschutz, a separate certificate issued by the German federal security office, the BSI (Bundesamt für Sicherheit in der Informationstechnik). Ask which one the buyer means before you pick a certification body.
Starting Stage 2 too early. Without three months of records the Stage 2 audit finds nonconformities, and the follow-up visit is billed by the day.
Already have SOC 2? What adding ISO 27001 costs
The platform adds $2k-$7.5k a year. The audit is a second full engagement: a CPA firm’s SOC 2 fieldwork cannot stand in for Stage 1 and Stage 2. Firms that are both a CPA firm and an accredited certification body (Schellman, A-LIGN, Prescient and others) sell combined engagements and claim savings, but none publishes the arithmetic, so ask for itemized pricing of the shared fieldwork. The internal work is the ISMS layer listed above.
What I’d tell a founder budgeting this today
Start when a buyer outside the US makes it a condition, not before. Use a compliance platform and negotiate it, scope one product, get two or three accredited quotes and check the accreditation mark, outsource the internal audit, and keep the pentest at the low end of the range. Plan $26k-$35k cash for year one, about $21k-$30k a year after that, and a quarter of one senior engineer’s background time. The security work behind it, provable access control and vulnerability management, is what keeps you out of a breach anyway. The certificate is the receipt.
Sources
- Audit-time chart and surveillance/recertification rules: ISO/IEC 27006:2015 Annex B; 2024 changes via European Accreditation FAQ on ISO/IEC 27006-1:2024 and ANAB transition note
- 2022 transition, expired 2013 certificates, mandatory clauses: IAF MD 26:2023; three-year cycle: ISO/IEC 17021-1 section 9
- Annex A structure: ISO/IEC 27001:2022
- Day rates and fees: HighTable, Iseo Blue (itemized UKAS quote), Amtivo, ComplyCheck, heyData, StrongDM
- Platform list prices (AWS Marketplace): Sprinto, Secureframe, Vanta, Drata; transaction data: Vendr on Vanta; EU example: TrustSpace
- Internal audit, pentest and consulting ranges: Secfix, Drata, Konfirmity, soc2auditors.org consultants, Secureleap (internal hours)
- Run-in period before Stage 2: Bridewell
- SOC 2 overlap and the ISMS layer: AICPA mapping of the Trust Services Criteria to ISO 27001, Konfirmity
- NIS2 in Germany: Bundesregierung, Reed Smith (4,500 to 29,500 entities); DORA: regulation-dora.eu
- TISAX vs ISO 27001: DataGuard; IT-Grundschutz certification: BSI
A buyer just asked for your ISO 27001 certificate? I help SaaS teams build and evidence the technical controls behind it without derailing the roadmap: Security & Compliance consulting, or book a free 30-minute call and bring the questionnaire. Related: SOC 2 for SaaS startups: what it actually costs and a worked STRIDE threat model.