The Google search says ISO 27001 costs £5,000 to £50,000. For a 20-person company, that range is useless. You need a number you can put in a budget.
At Metaluxo we run ISO 27001 programmes for SMEs across the EU. The costs are remarkably consistent for companies between 10 and 30 people. This post breaks down every line item.
Cost breakdown for a 20-person company
| Item | Low | Mid | High |
|---|---|---|---|
| Gap assessment | £2,000 | £4,000 | £6,000 |
| Policy writing and risk assessment | £2,000 | £4,000 | £6,000 |
| Internal audit support | £500 | £1,000 | £2,000 |
| Certification body Stage 1 | £1,500 | £2,500 | £3,500 |
| Certification body Stage 2 | £2,500 | £3,500 | £5,000 |
| Staff time (80 hours @ £50/hour) | £2,000 | £3,000 | £4,000 |
| Tools and platforms | £0 | £500 | £1,500 |
| Total | £10,500 | £18,500 | £28,000 |
Most of our clients land in the £15K–£20K range. The variance comes from how much internal time you have, how clean your existing documentation is, and whether you need help writing policies from scratch.
What drives cost up
- Wide scope. An ISMS that covers three offices, remote workers in five countries, and two product lines costs more to audit than one office and one product.
- No existing documentation. If you have no policies, no risk register, and no asset inventory, the consultant spends more time on discovery.
- Short timeline. A 12-week sprint costs more than a 6-month programme because the consultant must prioritise your work over other clients.
- Multiple frameworks. If you need ISO 27001 and SOC 2 simultaneously, the evidence work overlaps but the audit costs double.
What drives cost down
- Tight scope. One office, one product, one cloud environment.
- Existing policies. If you already have an information security policy, an acceptable use policy, and an asset list, the gap is smaller.
- Internal owner. A technical founder or CTO who can write the first draft of every document reduces consultant hours by 30–40%.
- Off-peak booking. Certification bodies sometimes offer discounts for mid-week, mid-month audits.
Hidden costs to budget for
Year 2 and 3: Surveillance audits cost £1,500–£3,000 per year. Recertification at year 3 costs £3,000–£5,000.
Tooling: A GRC platform is not required for a 20-person company, but many clients upgrade after certification. Budget £500–£2,000/year if you want one.
Training: ISO 27001 requires evidence that staff understand security policies. Online training costs £20–£50 per person. For 20 people, budget £400–£1,000.
Penetration testing: Not required for Stage 1, but expected between Stage 1 and Stage 2. Budget £2,000–£5,000 for a web application and infrastructure test.
The real ROI
The certificate itself is worth nothing. The value is in the deals it unlocks. If ISO 27001 is the difference between winning a £200K enterprise contract and losing it, the £15K cost is a 13x return. If your buyers do not require it, the ROI is harder to justify.
At Metaluxo we run fixed-price ISO 27001 gap assessments for SMEs, typically £4,000–£6,000, with a clear roadmap to certification. If you need a number for your budget, book a free 30-minute consultation and we will give you an exact quote for your scope.
Common questions
Is ISO 27001 worth it for a 20-person company?
Yes, if your revenue depends on enterprise or health-system contracts that require it. If you sell to consumers or small businesses, the ROI is lower.
Can we do ISO 27001 without a consultant?
Technically yes, but most small companies take 12–18 months without guidance versus 4–6 months with a consultant. The certificate costs the same either way.
What is the cheapest way to get ISO 27001?
Write the documents yourself, use a low-cost certification body, and limit the scope to one office and one product. Expect £8K–£12K total.