ISO 27001 Certification: You're Probably Closer Than You Think
Most businesses that approach ISO 27001 for the first time assume it will take years and cost a fortune. In reality, many SMEs already have a lot of the groundwork in place — they just haven't documented it.
What ISO 27001 actually requires
ISO 27001 is an international standard for information security management. At its core, it requires you to:
1. Identify the information assets your business relies on 2. Assess the risks to those assets 3. Implement controls to manage those risks 4. Document your approach and demonstrate it's working
That's it. The standard doesn't tell you which specific tools to use or how to configure your firewall. It asks you to think systematically about risk and show that you're managing it.
What you probably already have
If you're a functioning business with any kind of IT setup, you likely already have:
- Access controls — people log in with passwords, not everyone has admin rights - Backups — you're backing up your data somewhere, even if it's just to a cloud drive - Some form of incident awareness — you know what to do if a laptop gets stolen or an account gets compromised - Supplier relationships — you have contracts with your cloud providers, SaaS tools, and IT support
These aren't just good practices — they're ISO 27001 controls. The gap is usually documentation and formality, not the controls themselves.
Where most SMEs actually fall short
The areas that typically need the most work:
Risk assessment — ISO 27001 requires a formal, documented risk assessment. Most SMEs do this informally in their heads. Writing it down is the main task.
Policies — You need an information security policy, an acceptable use policy, and a handful of others. These don't need to be long, but they need to exist.
Management commitment — The standard requires visible buy-in from leadership. This is usually easy to get once leadership understands what's at stake commercially.
Internal audit and review — You need to periodically check that your controls are working. This can be done internally or with outside help.
How long does it actually take?
For a focused SME with good existing practices, 6–9 months from kickoff to certification is realistic. Larger or more complex organisations take longer, but size alone isn't the determining factor — commitment and focus are.
The audit itself is typically split into two stages: a documentation review (Stage 1) and an on-site assessment of your controls in practice (Stage 2). Most certification bodies will give you time to address any findings between stages.
Is it worth it?
For businesses selling to enterprise customers, regulated industries, or public sector organisations: almost certainly yes. ISO 27001 is increasingly a baseline requirement in procurement, not a differentiator.
For businesses not facing that pressure: it depends. The process of getting certified forces you to think clearly about your security posture, which has value regardless of the certificate. But if you're not facing commercial pressure to certify, a gap assessment and remediation programme might give you 80% of the benefit at 20% of the cost.
The honest answer is: get a gap assessment done first. It'll tell you exactly where you stand and what it would take to get there.
Want to talk through what this means for your business?
Get in touch