ISO 27001 is both a standard and a certification. The standard defines requirements for an Information Security Management System. The certification is formal third-party verification that your ISMS meets these requirements. A certificate without a functioning ISMS is a liability — auditors will find it, and it damages credibility more than having no certificate.

This article gives a practical perspective for SMBs deciding whether and when to pursue ISO 27001. For broader compliance context, see Security and Compliance in Cloud ERP 2026.

What ISO 27001 Actually Requires

ISO 27001:2022 (the current version, updated from 2013) has two main parts:

Main Standard Clauses (Mandatory)

The standard has 10 clauses. Clauses 4-10 are mandatory:

  • Clause 4 — Understanding the organisation and its context (stakeholders, scope)
  • Clause 5 — Leadership (management commitment, information security policy, roles)
  • Clause 6 — Planning (risk assessment, risk treatment plan, objectives)
  • Clause 7 — Support (resources, competence, awareness, communication, documented information)
  • Clause 8 — Operation (implementing the risk treatment plan, supplier management)
  • Clause 9 — Performance evaluation (monitoring, internal audit, management review)
  • Clause 10 — Improvement (nonconformity, corrective action, continual improvement)

Annex A Controls (Select Applicable)

ISO 27001:2022 Annex A lists 93 controls in 4 themes:

  • Organisational controls (37) — policies, roles, asset management, supplier relations, incident management
  • People controls (8) — screening, employment terms, security training, disciplinary process
  • Physical controls (14) — physical security, equipment management
  • Technological controls (34) — access control, encryption, logging, network security, configuration management, backups

You do not need to implement all 93 controls. You must:

  1. Conduct a risk assessment
  2. Decide which controls address your identified risks
  3. Implement selected controls
  4. Document why you excluded any applicable controls (Statement of Applicability)

For an SMB cloud software company, typically 60-80 controls are applicable.

The Certification Timeline

Phase 1: Gap Assessment (2-4 weeks)

Before committing to a full project, conduct a gap assessment — compare your current state against ISO 27001 requirements. This can be done:

  • Internally (if you have an experienced information security person)
  • With an external consultant (recommended for first certification)

Output: gap report listing what you have, what you need, and a prioritised list of work.

Phase 2: ISMS Design and Documentation (6-12 weeks)

Create the required documentation:

  • Information Security Policy
  • Risk Assessment Methodology and Results
  • Statement of Applicability (SoA)
  • Risk Treatment Plan
  • Supporting policies (access control, encryption, incident management, supplier management, etc.)
  • Roles and responsibilities

Tip: do not create documentation for its own sake. The auditor will test whether your documented processes are actually followed. A simple, followed policy is better than a comprehensive, ignored one.

Phase 3: Implementation (6-12 weeks, overlapping with Phase 2)

Implement the controls listed in your Risk Treatment Plan:

  • Technical controls (access management, encryption, logging, patching process, backup)
  • Organisational controls (training, supplier assessments, incident response procedure)
  • People controls (employment contracts updated, security screening for key roles)

This phase is where most of the work happens. For a cloud software company, many technical controls may already be partially in place (version control, change management, access logging).

Phase 4: Internal Audit (2-3 weeks)

Before the certification audit, conduct an internal audit to verify that:

  • All required documents are in place
  • Implemented controls are working as documented
  • Any nonconformities are addressed

Phase 5: Management Review (1 day)

The management body must review the ISMS performance and make documented decisions. This is a formal ISO 27001 requirement and auditors will check for evidence of it.

Phase 6: Stage 1 Audit (half-day to 1 day)

The certification body (BSI, Lloyd’s Register, Bureau Veritas, TÜV, SGS, or similar) reviews your documentation. They will identify any gaps that must be addressed before Stage 2. You typically have 4-8 weeks to address Stage 1 findings.

Phase 7: Stage 2 Audit (1-3 days)

The certification body verifies that your ISMS is implemented and working. They interview staff, review evidence of control operation, and test specific controls. If no major nonconformities are found, you receive ISO 27001 certification valid for 3 years.

Maintenance: The Ongoing Commitment

ISO 27001 certification requires annual surveillance audits (to check the ISMS is still operating) and a full re-certification audit every 3 years.

More importantly, maintaining an ISMS means:

  • Conducting risk assessments at least annually (or after significant changes)
  • Completing annual internal audits
  • Running annual management reviews
  • Maintaining the documented information (keeping policies current)
  • Responding to security incidents per the incident management process
  • Conducting supplier assessments for new critical suppliers

Estimate 0.2–0.5 FTE ongoing effort for an SMB to maintain a functioning ISO 27001 ISMS.

When ISO 27001 Is and Is Not Worth Pursuing

Pursue It When:

  • You sell cloud software to regulated sector clients (financial services, healthcare, public sector) — in 2026, the question increasingly is not “do you have ISO 27001?” but “show me your last surveillance audit report”
  • You are pursuing NIS2 compliance — ISO 27001 is the most recognised evidence of a functioning security management framework
  • You need to respond to enterprise RFPs — large enterprise procurement often requires ISO 27001 as a minimum supplier security standard
  • You are a data processor for clients — ISO 27001 gives clients confidence in your security posture as a processor

Do Not Pursue It When:

  • You cannot commit to maintaining it — a lapsed or cosmetic ISO 27001 is worse than no certification
  • Your customers do not require it and it is not in your 3-year sales strategy — the investment does not generate ROI
  • You are a very early-stage company — first build the product and validate the market; security maturity will follow
  • It is a box-ticking exercise — ISO 27001 certification without a genuine commitment to the underlying ISMS provides false assurance

Modulario ISO 27001

Modulario (AMCEF s.r.o.) holds ISO 27001 certification covering the development, operation, and support of the Modulario cloud ERP/CRM platform. The certificate is available to clients and prospects on request.

For clients’ own compliance needs, Modulario provides:

  • ISO 27001 certificate copy
  • Annual surveillance audit summary
  • ISMS scope statement
  • Security controls summary for due diligence questionnaires

For detailed security documentation, see the security page. For broader compliance context, see Security and Compliance in Cloud ERP 2026.

Frequently Asked Questions

How long does ISO 27001 certification take for an SMB? For a company with 20-100 employees starting from scratch, realistic timelines are: 4-6 months for a well-resourced focused project with external consultant support; 6-9 months for a standard project; 9-18 months if chronically underprioritised. The certification audit consists of Stage 1 (document review, half-day to one day) and Stage 2 (implementation audit, one to three days). Stage 2 is scheduled 4-8 weeks after Stage 1.

How much does ISO 27001 certification cost for an SMB? Total first-year cost for a 20-100 employee company: 8,000–25,000. Breakdown: external consultant 2,000–8 €,000; certification body audit fees 3,000–8 €,000; technology gaps 1,000–5 €,000. Annual surveillance audit: 1,500–3 €,000. For companies with existing NIS2 or GDPR compliance frameworks, the gap to ISO 27001 is significantly smaller.

Is ISO 27001 certification mandatory or just recommended? Mandatory in some contexts: public sector suppliers, defence supply chain, some financial services IT vendor requirements (DORA context). Strongly recommended: cloud software vendors targeting regulated sector clients, companies processing significant personal data as a processor. Not usually required: B2C retail, offline businesses, early-stage startups not targeting regulated sectors.