How much does ISO 27001 really cost a small company?
Every consultant answers “it depends” — true, but useless on its own. Here is the honest version: the three components the budget is made of, what moves each one, and indicative ranges so you can sanity-check any quote you receive. (These are orders of magnitude for the Greek market, not an offer; the written quote after a free assessment is.)
1 · Consulting
Gap analysis, risk assessment, policies and procedures, control implementation support, internal audit, mock audit. For a team of roughly 10–50 people, Greek-market projects typically land in the low-to-mid four figures up to around €10,000, depending on maturity and scope. Beware of both extremes: suspiciously cheap usually means template folders; suspiciously expensive usually means corporate methodology sold to a 15-person company.
2 · Certification body
The audit itself (stage 1 + stage 2) is priced per audit day, and audit days are determined by headcount and scope based on international rules — so quotes between accredited bodies are comparable. For small organisations, think roughly €2,500–6,000 for year one, with annual surveillance audits at a fraction of that, and a recertification audit in year three. Always request 2–3 quotes; we help you compare them.
3 · Your own time
The cost nobody puts in the spreadsheet: a project owner on your side (a few hours weekly), the team adopting new habits (MFA, access reviews, incident drills), management attending reviews. A well-run project respects this time — it is the scarcest resource of a small company.
What drives the price
Four things, in order of impact: headcount within scope, number of sites, complexity of your infrastructure (fully cloud is cheaper to certify than hybrid on-prem), and how much structure already exists. A 12-person SaaS team on one cloud stack is a fundamentally different project from a 45-person company with three offices and a server room.
4 ways to keep the budget down (legitimately)
Realistic scope
Certify the service your clients care about — not every corner of the company. A tight scope cuts consulting and audit days without weakening the certificate’s commercial value.
Use what you already run
Google Workspace/Microsoft 365 controls, cloud provider compliance, a password manager, existing MDM — mapped correctly, they cover a surprising share of Annex A.
ΕΣΠΑ funding
Consulting and certification are eligible expenses in several SME programmes. Timed right, a meaningful part of the budget comes back.
Avoid the rebuild
The most expensive ISO 27001 is the one done twice: a paper system that collapses at the first client audit and gets rebuilt properly a year later.
Related reading: ISO 27001 · NIS2 guide · ΕΣΠΑ funding · ISO certification cost (general)
Want a number instead of a range? Tell us your headcount, sites and stack — the assessment is free and the quote written, specific and locked.
Free Assessment