Home · Blog
ISMS

ISO 27001 in an SME: effort, duration and cost

July 20, 2026 · 9 min read · ODCUS

A major customer presses the point during a tender: no new framework agreement without an ISO 27001 certificate. Or the company newly falls under the Swiss Information Security Act and needs a working ISMS by the end of 2026. In both cases the same question lands on the management team's table: what does ISO 27001 mean for us in effort, duration and cost, and who does the work in the end?

For a Swiss SME with 50 to 500 employees that worry is justified. ISO 27001 sounds like a large corporation, like ring binders, like a project a small IT team can never carry alongside daily operations. The honest answer is more uncomfortable and at the same time more reassuring than expected: the path is doable, but it runs differently than most people think. It does not start with buying new software, it starts with tidying up what is already there.

TLDR

ISO 27001 in an SME is not a software purchase, it is organisational work. The biggest effort sits in processes, responsibilities and evidence, not in new tools. In our experience a good year passes from start to certificate, while the actual build of the ISMS can be bundled into a 90-day programme. Costs spread across internal time, external support and the audit by an accredited body. Companies that tidy up before they buy get there cheaper and more credibly.

Most SMEs believe ISO 27001 means buying a lot of new tools. The opposite is true. A certificate confirms lived order, not the length of the licence list. More protection. Fewer tools. Lower cost. The most expensive route to the standard is the one where a company tries to replace missing structure with additional software.

What does ISO 27001 require from an SME?

ISO 27001 requires no particular product and no particular technology. The standard asks for an information security management system, ISMS for short, meaning a traceable cycle of objectives, responsibilities, risk assessment, controls and regular review. What gets certified is not your firewall, it is the way you steer security.

Concretely it asks for a cleanly defined scope, an understanding of the assets worth protecting, a risk assessment and matching controls from its catalogue, each with a justification for why a control applies or deliberately does not. After that you check regularly whether the whole thing works, and improve it. The current version ISO/IEC 27001:2022 modernised that catalogue and added topics such as cloud security. The certificate itself is issued at the end by an independent, accredited certification body, not by you and not by the consultant who supported you.

The decisive point for an SME: an ISMS is lived practice, not a binder on a shelf. An auditor notices within a few conversations whether a policy steers daily work or was written for the review. Which is exactly why treating the topic as a pure documentation project achieves little.

What does ISO 27001 really cost in an SME?

The cost spreads across three pots, and the largest is rarely software. First, internal time, because your people describe processes, assess risks and implement controls. Second, external support for the build, if the method or the capacity is missing in house. Third, the certification audit itself by an accredited body, which is charged separately and scales with size and scope.

The most expensive and most underestimated item is almost always internal time. A new tool is ordered quickly, but a risk register that is accurate and processes that are lived come only from work by people who know the company. Anyone who ignores that effort and buys software instead pays twice: once for licences that do not replace an ISMS, and afterwards anyway for the order that is still missing.

With us the path rarely starts with a large programme, it starts with a stocktake at a fixed price. Our Cyber Assessment checks the current state against ISO 27001 in two weeks and delivers a clear list of what is still missing for a certificate. Only then does the actual ISMS build follow as a 90-day programme, whose fixed price is set after that scoping. That way nobody pays for scope they do not need, and the number is fixed before the work starts.

How long does the path to the certificate take?

In our experience a good year passes from start to certificate in an SME, rarely less. The actual build of the ISMS can be bundled into around 90 days. After that it takes time until the processes are lived in daily work and enough evidence has accumulated, because an auditor wants to see effectiveness over a period, not freshly written policies.

The usual sequence looks like this: the build is followed by an internal audit and a management review. Only then comes the accredited body, first with a document review and afterwards with a second audit that examines lived effectiveness in operations. If you pass, the certificate is normally valid for three years, with annual surveillance audits in between. So ISO 27001 is not a one-off project with an end date, it is an operating mode that keeps running.

The duration shortens less through speed in the project than through a clean starting point. A company that has already tidied its landscape and knows which tool serves which purpose gets through noticeably faster. Which is exactly why it pays to consolidate the security tools before building the ISMS. A chaotic tool collection does not make the standard easier, it makes it more expensive.

Where the effort really sits

The effort of ISO 27001 sits in the order, not in the technology. The building blocks that cost time are almost everywhere the same: drawing the scope cleanly, building a solid asset and risk register, writing few policies that actually get applied, clarifying responsibilities and bringing staff along. None of it is bought as a licence.

This work is unspectacular, but it is the core. A risk register that reflects the real situation is worth more than any dashboard. A handful of clear policies that bite in daily work is worth more than a hundred-page manual nobody reads. And a team that understands why it does things carries an ISMS through the years. Anyone who takes that seriously notices quickly: the standard forces exactly the tidying up that was overdue anyway.

What ISO 27001 looks like in a Swiss SME

A machinery supplier from central Switzerland with around 180 employees came to us with a clear trigger. A major customer in the automotive supply chain had set an ISO 27001 certificate as a condition in the framework agreement, with a deadline of a little over a year. IT consisted of three people, no ISMS existed, but a collection of security tools grown over years did.

We did not start with the text of the standard, we started with a stocktake. It showed two things. First, the existing technology already covered most of the required controls, it was just not documented and in part not switched on. Second, the structure was missing entirely, meaning scope, risk register, responsibilities and evidence. The existing security was usable at its core, what was missing was the order on top of it.

During the ISMS build we set the scope to the customer processes the certificate was needed for, instead of covering the whole company. That reduced the effort considerably. Part of the expensively purchased tooling fell away because existing features did the same job. After the build, an internal audit and the two certification audits, the company held its certificate in time before the customer deadline expired. The side effect counted almost as much for the management team: for the first time there was a clear picture of what is protected and who decides in an emergency.

ISG obligation or ISO 27001: what is mandatory, what is optional?

In short: the ISG can require an ISMS by law, while ISO 27001 is almost always voluntary and driven by the market. Both aim at the same thing though, a working management system for information security. Building one well usually serves the other too.

Organisations subject to the Swiss Information Security Act, primarily operators of critical infrastructure and, through contracts, their suppliers, need a working ISMS by the end of 2026. On top of that, since 1 April 2025 there is an obligation to report cyber attacks to the Federal Office for Cybersecurity within 24 hours, as the official BACS information on the reporting duty sets out. ISO 27001 by contrast is not a legal obligation, it is evidence that customers, tenders and supply chains increasingly demand. The practical advice stays the same in both cases: whether the ISG, ISO 27001 or a customer audit is the trigger, the first sensible step is always an honest stocktake before anything is bought or built.

Frequently asked questions

Do we really need a certificate or is a lived ISMS enough?

That depends on the trigger. If a customer, a tender or a legal requirement explicitly asks for the certificate, there is no way past the audit by an accredited body. If it is only about better security and about being able to show something to your own board, a properly lived ISMS often already covers the actual need. The certificate is the external proof, not the protection itself.

Can we carry out the certification ourselves?

The certificate must come from an independent, accredited body, because nobody audits themselves. The build of the ISMS you can in principle handle internally, if method and time are available. Many SMEs lack exactly that, which is why they have the build supported and then give the certification to a separate body. Whoever builds must never be the one who certifies.

What happens after we have the certificate?

It stays in motion. The certificate is normally valid for three years, with annual surveillance audits and a recertification at the end of the cycle. A certificate on paper with no lived processes behind it shows up at the first surveillance audit at the latest. Which is exactly why the effort only pays off if the ISMS becomes part of operations and does not stay a project that falls asleep after the review.

Not sure whether a fractional CISO fits your company?

In a free intro call we work out whether senior security leadership on a mandate makes sense for your company, and in what form. Honest answer included, even when it is "not yet".

Book a free intro call