What are the costs for ISO 27001 certification in a small service company?

0
13
Asked By CuriousCactus42 On

Hey everyone, we're kicking off our Governance, Risk, and Compliance (GRC) program and looking into tools and resources. As we're creating our budget, it would be super helpful to know the average cost for ISO 27001 certification for a professional services company with about 40 employees. We're planning to conduct audits virtually. Most of our team works from home but we have a single headquarters. What are the typical costs from certification bodies, and how much should we expect to pay for internal auditor consultants? Thanks!

5 Answers

Answered By BudgetWiseBear On

If you're in a similar size range, I suggest checking out Secureframe. They work with many small to medium businesses, though I'm not sure what their current pricing for ISO 27001 is.

Answered By ResourcefulRaccoon55 On

We help organizations with ISO 27001 implementation. I recommend reaching out to iso27001standards.com for a no-obligation proposal. They can provide a tailored estimate for your needs!

Answered By PracticalPenguin32 On

Based on our experience with a similar company, here are our costs: $4,000 yearly for a GRC platform, $10,000 for compliance guidance and internal audit from our GRC vendor, and $9,000 for the third-party external audit. After the first year, we’ll be looking at $3,500 for recertification in the next two years. That GRC platform might feel a bit pricey, but it helps with SOC2 as well. You might consider skipping the GRC platform if you have the capability to do the internal audit yourself, but I'm concerned the external auditor could charge more if they find your controls are poorly organized.

Answered By CandidCat76 On

Could you specify what country and currency you’re looking at? It can vary widely depending on those factors.

Answered By InquisitiveTurtle89 On

It's tough to give an exact figure, but in my experience, the auditing cost where I work was typically around $30K. However, we ended up paying $15K since we used a GRC automation platform which costs about $8K yearly. Keep in mind that this doesn’t include any extra licensing fees or the cost of employee time needed for the audit.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.