Remote Support Start download

ISO 27001 for SMBs: A Realistic Start

ComplianceISO 27001ISMSConsulting
ISO 27001 for SMBs: A Realistic Start

“We need to do ISO 27001 — a large customer requires it.” This is how DATAZONE consultations regularly start. Sometimes the pressure comes from outside (NIS2 indirectly, large customers in supply chains, cyber-insurance audits), sometimes from inside (own maturity, planned internationalization, M&A preparation).

The reaction inside IT is usually mixed: relief that the topic is finally being addressed, paired with worry about the effort — and about invented statistics floating online (“8 out of 10 projects fail”, “average 500,000 EUR in year one”) that don’t hold up against practice.

This article is a sober on-ramp for mid-market companies that want to take ISO/IEC 27001 seriously. We give orders of magnitude, not point values. We sketch a pragmatic sequence. And we name tools — open source and commercial.

What is ISO/IEC 27001?

ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). It describes how an organization should manage information security systematically — not as a tool list, but as an ongoing management process.

The current version is ISO/IEC 27001:2022. It supersedes the 2013 version, modernized the structure and reduced the control catalogue (Annex A) from 114 to 93 controls in 4 themes (Organizational, People, Physical, Technological).

Important: ISO 27001 doesn’t say “you need a firewall from vendor X” — it says “you need documented risk management that treats risks appropriately, with evidence”. The actual implementation is the organization’s choice.

ISO 27001 vs. TISAX vs. NIS2 vs. C5

Frequently confused. Quick clarification:

  • ISO 27001: International, broad, ISMS standard. Certifiable.
  • TISAX: Industry-specific (automotive suppliers), based on VDA-ISA. Pseudo-certificate via the ENX platform.
  • NIS2: EU law, cybersecurity obligations for essential and important entities. Not a certificate — a legal obligation.
  • BSI C5: German cloud-compliance catalogue for cloud providers.

An ISO 27001 certification makes NIS2 significantly easier — the controls overlap heavily. With ISO 27001 in place you don’t start from zero for NIS2.

How Long Does it Realistically Take?

From DATAZONE experience with mid-market customers: 6–12 months of preparation is realistic — depending on:

  • Starting point: if you already have documented processes, an asset inventory and risk management, you don’t start from zero
  • Size: a 30-person company is faster than an 800-person one
  • Capacity: internal ISMS officer vs. external consultancy vs. dedicated project team
  • IT maturity: an IT with patch management, backup concept and monitoring delivers evidence faster than one that has to do homework first

The certification audit itself is two-stage (Stage 1: documentation audit, ~2–3 days; Stage 2: on-site audit, ~3–5 days depending on scope). Annual surveillance audits follow, with re-certification every three years.

How Much Does it Really Cost?

We are deliberately cautious here — the range is huge and blanket statements mislead.

External consulting: day rates for ISO 27001 consultants are in the usual consulting bracket — don’t assume one fixed-price quote, get 2–3 offers.

Certification audit: a four- to five-digit EUR amount depending on auditor and scope. Accredited certifiers (TÜV, DEKRA, DQS, BSI Group, etc.) publish day rates, and the number of audit days depends on headcount and scope.

Your own time: the largest and most underestimated item. Internal effort for documentation, training, drills, audits — typically 0.3–1.0 FTE in the hot phase, then 0.1–0.3 for ongoing operation.

Tooling: open source (verinice CE) is free to license but needs care. Commercial suites (HiScout, Datenschutzmanager, SecurityScorecard-style ISMS tools etc.) sit in the four- to five-digit range per year depending on modules.

We deliberately don’t quote a point value for the total investment — that would be pseudo-precision. To budget honestly, use the items above and apply realistic per-item assumptions for your size.

Annex A Controls 2022 — Overview

The 93 controls spread across four themes:

A.5 Organizational Controls (37 controls)

Information security policies, roles and responsibilities, asset management, classification of information, access control, supplier management, incident management, business continuity, compliance.

A.6 People Controls (8 controls)

Personnel selection, awareness, disciplinary process, remote-working rules.

A.7 Physical Controls (14 controls)

Security perimeters, access control, protection from environmental threats, equipment security, disposal, cabling security.

A.8 Technological Controls (34 controls)

Endpoint security, privileged access, identity management, authentication, capacity management, malware protection, information backup, logging monitoring, network security, web filtering, cryptography, secure development, cloud security, information security in project management.

Statement of Applicability (SoA)

The Statement of Applicability is the central document. It lists all 93 Annex A controls and for each:

  • Applicable / not applicable (with justification when not applicable)
  • Status of implementation
  • Reference to the concrete measure / document

The SoA is a key audit artefact — in Stage 1 (document review) and during the on-site audit where the auditor spot-checks whether what’s documented is actually lived.

Risk Assessment

ISO 27001 is risk-based. You identify information assets (data, systems, processes), assess protection needs (confidentiality, integrity, availability), identify threats and vulnerabilities — and treat the outcome (mitigate, accept, avoid, transfer).

Methodologically useful:

  • ISO/IEC 27005 as the risk-management standard
  • BSI Standard 200-3 (German variant, compatible with BSI IT-Grundschutz)
  • NIST SP 800-30 for US-shaped setups

In practice many mid-market companies work with a risk matrix (likelihood × impact) and a risk treatment table.

A Pragmatic Path for SMBs

The most common pitfall from DATAZONE’s view: tackling all 93 controls at once. That overloads the organization and produces poor half-finished documents.

Recommended sequence:

Phase 1 (months 1–2): foundation

  1. Get management commitment. ISO 27001 is a management decision, not an IT project.
  2. Define scope. Which sites, departments and data categories fall under the ISMS? The SoA follows.
  3. Appoint an ISMS officer. One person with a mandate — internally qualified or externally supported.
  4. Build an asset inventory. What data, systems and suppliers are relevant? This is the basis for everything that follows.

Phase 2 (months 3–5): risk management

  1. Conduct the risk assessment. Identify, document, derive measures.
  2. Write the risk-treatment plan.
  3. Create the Statement of Applicability (first version).

Phase 3 (months 4–7): policies and processes

  1. Information Security Policy as the top-level document.
  2. Sub-policies as needed (access control, mobile working, cryptography, suppliers, incident response, BCM, classification).
  3. Document processes — how is an asset onboarded? How is an incident reported? How are access rights revoked?

Phase 4 (months 5–9): implementation & evidence

  1. Implement technical controls (patch management, backup, logging, hardening, MFA, etc.) — see Linux Server Hardening, SSH Hardening, Backup Strategies.
  2. Training for all staff (phishing, password hygiene, data classification).
  3. Collect evidence — logs, minutes, tickets, training records. This is the main effort before the audit.

Phase 5 (months 8–10): internal audit and prep

  1. Internal audit (ideally with external consulting as a second pair of eyes).
  2. Management review by the board.
  3. Corrective measures from the internal audit.

Phase 6 (months 10–12): external certification

  1. Select certifier (accredited under ISO 17021).
  2. Stage 1 audit (document review).
  3. Stage 2 audit (on site).
  4. Receive certificate — and immediately set up the plan for the surveillance audits.

Tools for SMBs

Open source / free

  • verinice (Community Edition) — DACH classic, very strong on BSI IT-Grundschutz but also maps ISO 27001. Free; commercial support optional.
  • Excel + Word: for very small setups a well-structured Excel risk catalogue plus Word policies actually works. Doesn’t scale, but enough for a 10-person company.

Commercial

  • verinice.PRO — Pro version with extras
  • HiScout — established in DACH mid-market, modular ISMS suite
  • Datenschutzmanager — GDPR focus, ISO 27001 module optional
  • Drata, Vanta, Tugboat Logic — international SaaS players, popular with SaaS startups
  • TenableSC + audit modules — if you already run Tenable
  • ServiceNow GRC — enterprise player, makes sense from a certain size

Recommendation for DACH mid-market: verinice (Community or PRO) plus a GDPR tool. International setups: SaaS platform with connectors into your systems.

When is ISO 27001 Worth It for SMBs?

Clear drivers:

  • Large customers require it in supplier selection (automotive, banking, pharma, critical infrastructure)
  • NIS2 indirectly: ISO 27001 covers most NIS2 requirements
  • Cyber-insurance increasingly demands structured ISMS evidence — even without certificate
  • Market trust — especially in B2B software, customers increasingly expect the certificate
  • Own maturity — many companies realize the ISMS makes sense without the certificate and the certification “just” validates it

Not everyone needs it. A pure B2C business in a regulatory-quiet sector with no cyber-insurance pressure can run structured information security without ISO 27001. But: if you plan it, start early — an audit in six months can’t be passed ad hoc.

Common Pitfalls

  • Scope too large. ISO 27001 allows a clearly bounded scope (e.g. one product line, one site). Trying to certify the entire group on the first pass often fails.
  • Underestimating mandatory documentation. The ISMS lives on documentation. Collecting evidence only in audit month costs weeks.
  • Top management not engaged. No commitment, no ISMS. The “management review” clause is audit-critical.
  • Tool before process. An ISMS tool doesn’t replace a thought-through policy. Process first, tool second.
  • Consulting instead of ownership. External consulting accelerates — but the ISMS must be owned internally. Otherwise it dies after certification.

What’s DATAZONE’s Role?

We are not an ISO 27001 certifier. We are an IT service provider. But we deliver the technical evidence for many Annex A controls — through thoughtful infrastructure, backup strategies, hardening, monitoring, logging, disaster recovery plans.

Concretely: a customer running a Proxmox-TrueNAS environment with us, with documented backup plan, snapshot schedules, GDPR-compliant logging, compliance reports from DATAZONE Control, SSH hardening and Linux server hardening, has already lived a meaningful chunk of the A.8 controls — and that’s exactly what counts at audit: not a document nobody reads, but a reality the auditor sees.

For ISO 27001 advisory itself we partner with specialists. For the technical side, we are your point of contact.

Conclusion

ISO 27001 is achievable for SMBs — but not in four weeks. With 6–12 months of lead time, a clear scope, management commitment and realistic tooling you get to certification. The upside afterwards: a lived ISMS that also makes NIS2, cyber-insurance questions and customer audits significantly calmer.

Thinking about it but unsure where to start: begin with the asset inventory and the risk assessment. That’s the basis for everything else — and even without a certification goal it’s a useful exercise.

Sources and Further Reading

Need IT consulting?

Contact us for a no-obligation consultation on Proxmox, OPNsense, TrueNAS and more.

Get in touch