ISO 27001 certification: requirements, costs and process

ISO 27001 certification: requirements, costs and process

A practical guide to ISO 27001 certification and building an information security management system.

Last updated: 7 September 2026 | 14 min. read

ISO 27001 is the international standard for information security. The standard helps you to systematically manage risks to your information. From data leaks to ransomware, from human errors to system failures.

In this guide you will read everything you need to know: from the basic principles to the costs, from preparation to choosing a certifier. No sales pitches, just clear information.


1. What is ISO 27001?

ISO 27001 is an international standard for information security. The standard describes requirements for an Information Security Management System (ISMS): a structured approach to protect the confidentiality, integrity and availability of information.

In short: ISO 27001 helps you to systematically identify, manage and reduce information security risks.

With an ISO 27001 certificate you demonstrate that your company has a working ISMS, actively manages risks and continuously improves in the field of information security.

1.1 The three pillars of information security

ISO 27001 is built on three core principles, often referred to as the CIA Triad:

PrincipleWhat it means
ConfidentialityOnly authorized persons have access to information
IntegrityInformation is correct and complete and has not been changed without authorisation
Availability (Availability)Information is accessible when needed

The gist: it’s about protecting information against all types of threats, whether technical, human or physical.

1.2 Annex A: the 93 controls

An important part of ISO 27001 is Annex A. This is a catalogue of 93 management measures (controls) divided into four categories:

CategoryNumber of controlsExamples
Organizational37Policies, roles, risk management, supplier management
Human8Screening, awareness, working from home, confidentiality
Physical14Access control, security monitoring, equipment
Technological34Authentication, encryption, network security, logging

You don’t have to apply all 93 controls. In your Statement of Applicability you record which controls are relevant to your organisation and why.

1.3 Current version: ISO 27001:2022

info

The current version is ISO 27001:2022. This replaces the 2013 version. Most important changes: a completely revised Annex A with 93 controls (was 114) and eleven new measures for, among other things, cloud security and threat intelligence.

Transition deadline: October 31, 2025. After that date, all certificates based on the 2013 version are invalid.


2. Why certify ISO 27001?

A certificate is not a goal in itself. It is a means. The question is: does it help your business?

2.1 Five concrete benefits

tip
The most important reason for most companies: customers and clients demand it. ISO 27001 is increasingly a strict requirement in tenders, especially in IT, finance and healthcare.

In addition to access to assignments, there are more benefits:

  • Better risk management - You systematically identify and manage information security risks. The number of incidents is decreasing.
  • Demonstrated compliance - Demonstrate compliance with the GDPR and prepare for NIS2. Auditors and supervisors appreciate a certificate.
  • Protection of reputation - A data breach can haunt your company for years. Prevention is cheaper than recovery.
  • Customer trust - You show that you take information security seriously. This makes a difference, especially with sensitive data.
  • Foundation for extension - ISO 27001 shares the same structure with ISO 9001 (Quality) and ISO 22301 (Business Continuity).

2.2 For whom is it relevant?

ISO 27001 is relevant for any organisation that processes information. But some sectors benefit more from it:

SectorWhy relevant
IT servicesCustomers demand it, processing customer data
FinanceLegal requirements, sensitive financial data
CarePatient data, NEN 7510 as a supplement
GovernmentBIO standards framework, tender requirements
EcommerceCustomer data, payment data
Suppliers to large companiesChain responsibility

2.3 When it may not be necessary

Honest advice: certification is not the best choice for everyone.

Ask yourself this question: Are my customers asking for it? Do I process sensitive information? If not, carefully consider whether the investment is worth it.

Other situations in which you have to be critical:

  • Sole proprietorships without sensitive customer data are unlikely to have the ROI
  • If you just want a certificate for the sake of having it, without actually improving the processes, it is of little use to you
  • In very small organisations, the overhead may outweigh the benefits
note
Alternative for small organisations: You can also work according to ISO 27001 without certification. You implement the approach internally, but skip the external audit. No certificate, but better security.

3. The ISO 27001 certification process

You go through six steps from decision to certificate. Count on six to eighteen months, depending on your starting position and IT complexity.

3.1 The six steps to certification

  1. Determine scope - Which parts of your organisation, systems and locations are covered by the ISMS? Start small if necessary and expand later.

  2. Perform risk analysis - Identify information security risks and determine what measures are needed. This is the heart of ISO 27001.

  3. Set up ISMS - Implement controls, establish policies, train employees, and document processes.

  4. Complete proof period - Work under your ISMS for a minimum of three months. Auditors want proof that the system works in practice.

  5. Internal audit and management review - Check yourself whether everything is working and have management formally assess the ISMS.

  6. External audit - The certifier carries out the audit in two phases. If successful you will receive the certificate.

3.2 The external audit: phases one and two

info

Phase 1 (Stage 1) is a documentation and readiness check. The auditor assesses your ISMS documentation, Statement of Applicability and risk analysis. Usually lasts one to two days.

Phase 2 (Stage 2) is the on-site practical audit. The auditor speaks with employees, checks processes and verifies whether paper and practice correspond. Lasts two to five days.

3.3 Timeline

Your situationLead timeAudit duration
Already have a management system (e.g. ISO 9001)5-9 months2-3 days
Good IT basis, but no ISMS yet6-12 months3-4 days
Complex IT environment or multiple locations12-18 months4-5 days

3.4 Who does what?

PartyRole
YouRisk analysis, setting up ISMS, internal audits, training employees
IT departmentImplementing technical measures, logging, monitoring
Consultant (optional)Guidance, gap analysis, templates, training
CertifierPerform audit, issue certificate
Accreditation bodyChecks the certifier (RvA, UKAS, etc.)

Good to know: A consultant is not mandatory. Many organisations with experienced IT and compliance people do it themselves.


4. What does ISO 27001 cost?

The costs vary greatly. They depend on your company size, IT complexity and whether you engage a consultant. ISO 27001 is generally more expensive than ISO 9001 due to the more intensive audit.

Rule of thumb for SMEs: Count on €5,000 - €15,000 in the first year, then €2,000 - €5,000 per year.

4.1 Cost items overview

Cost itemIndication
Certification audit (year 1)€4,000 - €10,000
Surveillance audit (per year)€2,000 - €5,000
Recertification (every three years)€3,500 - €8,000
Consultant (optional)€10,000 - €25,000
Tooling/software (optional)€1,000 - €5,000 per year
Internal hours150 - 300+ hours

4.2 Price indication per company size

Company sizeFirst yearAnnually thereafter
Small (up to 10 FTE)€4,000 - €8,000€2,000 - €3,500
Medium (10-50 FTE)€6,000 - €15,000€3,000 - €6,000
Large (50-250 FTE)€10,000 - €25,000€5,000 - €10,000
Enterprise (250+ FTE)€20,000 - €50,000+€8,000 - €15,000+

Prices indicative, excl. VAT, excl. consultant and internal hours.

4.3 What influences the price?

Five factors determine your costs:

  1. Number of employees (more = more audit time)
  2. IT complexity (in-house development, cloud, data centers)
  3. Number of locations (each location is assessed)
  4. Current maturity (starting from scratch is more expensive than optimizing)
  5. Certifier’s choice (prices vary 20-40%)
tip
Save by comparing. Always request quotes from at least three certification bodies. Pay attention not only to price, but also to sector experience and your working relationship with the auditor. All accredited certification bodies provide a valid certificate.

5. Preparation for ISO 27001

Good preparation is half the battle. Most of the time is spent on the risk analysis and setting up your ISMS, not on the audit itself.

5.1 What do you need to arrange internally?

note
First step: Ensure commitment from management. Information security is a management responsibility. Without support from above, certification becomes a difficult process.

Then follow these steps:

  • Appoint project leader - Someone with a mandate, IT knowledge and time commitment
  • Determine scope - Which systems, processes and locations are covered by the ISMS?
  • Perform Risk Analysis - Identify threats, vulnerabilities and risks
  • Implement measures - Technical and organizational, based on the risk analysis
  • Create awareness - Train employees, phishing testing, communicate policies
  • Start proof period - Work for at least three months according to the ISMS
  • Perform internal audit - Test whether everything works before the certifier arrives

5.2 What documentation is needed?

The standard requires at least:

DocumentWhat it is
Information Security PolicyYour vision and objectives in the field of information security
Scope of the ISMSWhich parts of your organisation will be certified
Risk analysis and treatment planIdentified risks and chosen measures
Statement of Applicability (SoA)Which controls you apply and which you do not, with substantiation
Process descriptionsHow you work (incident management, access management, change management)
RegistrationsProof that you do what you say (audits, incidents, training)

No need for a thick manual. Many organisations work with a digital system or compact documents. The form is free, as long as it is current and accessible.

5.3 Three common mistakes

warning
Mistake 1: Focusing too technically. ISO 27001 is not just about IT. Organizational and human measures are at least as important. Consider policy, awareness and supplier management.

Mistake 2: Paper tiger

Your documents must correspond with practice. If you write down that you will check logs every week, you should actually do so. Auditors ask for evidence.

Mistake 3: Starting the proof period too late

You must have worked under your ISMS for at least three months before the external audit can take place. Plan this, otherwise your certification date will be postponed.


6. The ISO 27001 audit

The external audit is the moment of truth. Exciting, but if you are well prepared there is little to worry about.

6.1 Phases one and two

The audit consists of two parts:

Phase 1: Documentation and readiness check (often partly remote)

The auditor assesses your ISMS documentation: policy, risk analysis, Statement of Applicability. Is everything present and consistent? Are you ready for the on-site audit? After phase one you will receive feedback and time to make adjustments.

Phase 2: On-site audit (on location)

Now the auditor comes along. He or she speaks to employees at all levels, reviews systems and processes, checks logs and registrations, and verifies whether paper and practice match.

The gist: The auditor is looking for evidence that your ISMS is effective. Not only that procedures exist, but that they work and actually manage risks.

6.2 Possible outcomes

OutcomeWhat’s happening?
CertificateYou meet the requirements
Minor deviationsCertificate, but resolve points for next audit
Major deviationsFix first, then reaudit within 90 days
Requirements not metRestart the process
info
Most well-prepared organisations obtain the certificate in one go. Small deviations are common and are not a disaster - they indicate areas for improvement.

6.3 Tips for a smooth audit

  1. Know your own system - Know where your documents are and how your processes work
  2. Prepare employees - Tell them what to expect. They do not need to know the standard, but they do need to know their own tasks
  3. Be honest - Don’t try to hide anything. Auditors value openness more than perfection
  4. Have proof ready - Logs, registrations, training records. Make sure you can quickly show what the auditor is asking
  5. View it as an opportunity - A good auditor provides valuable feedback. Use it to really improve

7. Choosing an ISO 27001 Certifier

There are more than 25 certifiers active in the Netherlands for ISO 27001. They differ in price, approach and specialisation. How do you choose the right one?

7.1 Five criteria to pay attention to

CriterionWhy important
AccreditationNon-accredited certificates are often not recognised
Industry experienceAn auditor who understands IT and security adds more value
PriceDifferences of 20-40% are normal
ServicePermanent contact person? Quick responses? Flexibility?
Working relationship with the auditorYou will work together for at least three years
warning
Pay attention to accreditation. Always choose an accredited certifier. Non-accredited certificates are often not recognised by clients. Accreditation can be with the RvA (Netherlands), UKAS (UK), DAkkS (Germany) or other IAF members - these are mutually recognised.

7.2 What is accreditation?

Accreditation bodies audit certifiers. They check whether auditors are qualified for ISO 27001, whether the certifier works independently, and whether the audit is carried out correctly.

Each country has its own authority: the RvA in the Netherlands, UKAS in the United Kingdom, DAkkS in Germany. They recognise each other’s certificates through the IAF (International Accreditation Forum). A certificate from a UKAS-accredited certifier is therefore just as valid as one from an RvA-accredited one.

7.3 Questions to ask

Before you choose, ask potential certifiers these questions:

  • Are you accredited for ISO 27001? At which agency?
  • What is your experience in my sector (IT, finance, healthcare)?
  • Does the auditor have experience with our technology (cloud, development, specific systems)?
  • Who will be my auditor? Can I speak to that person in advance?
  • What is the lead time from quotation to certificate?
  • What are the total costs for three years (including surveillance)?
  • How do you deal with deviations during the audit?

The right choice is not necessarily the cheapest. An auditor who understands your IT environment and provides constructive feedback is worth more than a few hundred euros in savings.

note

Ready to compare? View our overview of certification bodies in the Netherlands and find one that fits your company.

Compare certification bodies →


8. Frequently asked questions about ISO 27001

How much does ISO 27001 certification cost?

For an SME (10-50 employees): €5,000 - €15,000 in the first year, then €2,000 - €5,000 per year. ISO 27001 is more expensive than ISO 9001 due to the more intensive audit and technical component. The exact price depends on company size, IT complexity and number of locations.

How long does certification take?

With an existing management system (e.g. ISO 9001): five to nine months. From scratch: six to twelve months. Complex IT environments: twelve to eighteen months. The audit itself takes two to five days.

Is ISO 27001 mandatory?

No, it’s voluntary. But many clients and sectors do demand it - especially in IT services, finance, healthcare and government. It also helps with GDPR and NIS2 compliance.

What changes in ISO 27001:2022?

The Annex A has been completely revised. Where the old version had 114 controls in fourteen categories, there are now 93 controls in four categories (organizational, human, physical, technological). Eleven new controls have been added, including for threat intelligence, cloud security and data leakage prevention. Transition deadline: October 31, 2025.

Can I do it without a consultant?

Yes. Especially if you already have experience with management systems or have a strong IT department. A consultant can speed things up and prevent pitfalls, but is not mandatory.

What is accreditation?

Accreditation bodies (such as RvA, UKAS, DAkkS) inspect certifiers. Their certificates are internationally recognised through the IAF. Always choose an accredited certifier.

How often is an audit after certification?

A surveillance audit (control) every year. Full recertification every three years. Your certificate is valid for three years, provided you successfully complete the annual audits.

Can I switch certifiers?

Yes, anytime. Your new certifier will take over your file and plan a transfer audit. Your certificate remains valid during the transfer. Many organisations switch because of price, service or a better connection with the auditor.

What is the difference between ISO 27001 and NEN 7510?

NEN 7510 is the Dutch standard for information security in healthcare. It is based on ISO 27001 but contains additional requirements specific to the healthcare sector. Often both standards are combined in an audit.

Want to know more? Read our complete guide to NEN 7510 certification.

Does ISO 27001 help with GDPR?

Yes. ISO 27001 demonstrably helps to meet the requirement of “appropriate technical and organizational measures” from the GDPR. It does not guarantee full GDPR compliance, but covers a large part of the security requirements.


This guide is updated regularly. Last checked: December 2025.

Compare ISO 27001 certification bodies

Receive suitable quotations without obligation.

Request free quotations