Guide · July 2026

How much does ISO 27001 really cost a small company?

Every consultant answers “it depends” — true, but useless on its own. Here is the honest version: the three components the budget is made of, what moves each one, and indicative ranges so you can sanity-check any quote you receive. (These are orders of magnitude for the Greek market, not an offer; the written quote after a free assessment is.)

1 · Consulting

Gap analysis, risk assessment, policies and procedures, control implementation support, internal audit, mock audit. For a team of roughly 10–50 people, Greek-market projects typically land in the low-to-mid four figures up to around €10,000, depending on maturity and scope. Beware of both extremes: suspiciously cheap usually means template folders; suspiciously expensive usually means corporate methodology sold to a 15-person company.

2 · Certification body

The audit itself (stage 1 + stage 2) is priced per audit day, and audit days are determined by headcount and scope based on international rules — so quotes between accredited bodies are comparable. For small organisations, think roughly €2,500–6,000 for year one, with annual surveillance audits at a fraction of that, and a recertification audit in year three. Always request 2–3 quotes; we help you compare them.

3 · Your own time

The cost nobody puts in the spreadsheet: a project owner on your side (a few hours weekly), the team adopting new habits (MFA, access reviews, incident drills), management attending reviews. A well-run project respects this time — it is the scarcest resource of a small company.

What drives the price

Four things, in order of impact: headcount within scope, number of sites, complexity of your infrastructure (fully cloud is cheaper to certify than hybrid on-prem), and how much structure already exists. A 12-person SaaS team on one cloud stack is a fundamentally different project from a 45-person company with three offices and a server room.

4 ways to keep the budget down (legitimately)

Realistic scope

Certify the service your clients care about — not every corner of the company. A tight scope cuts consulting and audit days without weakening the certificate’s commercial value.

Use what you already run

Google Workspace/Microsoft 365 controls, cloud provider compliance, a password manager, existing MDM — mapped correctly, they cover a surprising share of Annex A.

ΕΣΠΑ funding

Consulting and certification are eligible expenses in several SME programmes. Timed right, a meaningful part of the budget comes back.

Avoid the rebuild

The most expensive ISO 27001 is the one done twice: a paper system that collapses at the first client audit and gets rebuilt properly a year later.

Related reading: ISO 27001 · NIS2 guide · ΕΣΠΑ funding · ISO certification cost (general)

Want a number instead of a range? Tell us your headcount, sites and stack — the assessment is free and the quote written, specific and locked.

Free Assessment

Start your journey to certification

Book a free initial assessment. We will analyse your needs and recommend the optimal standard and timeline.