ISO 27001 Certification: What It Takes and What It Costs
Certification is an audit of a management system, not of your controls. The Statement of Applicability, the two-stage audit, and the three-year surveillance commitment people underestimate.
GuardsArm Team
Security Experts
ISO 27001 certifies a management system, not a set of controls. That distinction explains most of what surprises organisations going through it: the auditor spends less time than expected checking whether your firewall is configured well, and more time checking that you decided what risks matter, did something about them, measured whether it worked, and can show the paperwork.
Scope is the most consequential decision
You define what the ISMS covers — a product, a business unit, a location, or everything. A narrow scope is faster, cheaper and easier to maintain. It is also less useful, and customers increasingly read the scope statement rather than accepting the certificate at face value.
Scope too narrowly and you get a certificate that excludes the service the customer is buying. Scope too broadly and the programme takes twice as long. The usual sensible answer is the service the customer cares about, plus the supporting functions that genuinely touch it.
The Statement of Applicability
The SoA lists every Annex A control, states whether it applies, and if not, why. It is the document auditors return to constantly and the one most often produced carelessly.
An exclusion needs a defensible reason tied to your scope and risk assessment. "Not applicable because we do not do that" is fine when true and evidenced. "Not applicable" against a control you simply have not implemented is a finding waiting to happen.
The audit, in two stages
That operating-history requirement catches people. You need internal audits, a management review and records showing the system ran before Stage 2. Three months of evidence is a realistic minimum; there is no way to compress it to zero.
What it costs
Certification body fees are usually the smallest line. The real costs are:
| Cost | Note |
|---|---|
| Certification body | Scales with scope and headcount; three-year cycle |
| Internal effort | Consistently the largest, and consistently underestimated |
| Consultancy | Optional; most useful for the risk assessment and SoA |
| Tooling | Optional. A platform helps with evidence, not with judgement |
| Remediation | Whatever the gap analysis found |
| Ongoing operation | Internal audit, management review, continual improvement — forever |
That last row is the one that determines whether certification survives. An ISMS built by a project team that then disbands will fail its first surveillance audit.
Where it sits against other frameworks
If you are choosing rather than committed, see SOC 2 vs ISO 27001. Briefly: ISO 27001 is the international standard and is expected by European and Asian buyers; SOC 2 dominates North American software procurement. For healthcare specifically, neither replaces HIPAA obligations — they demonstrate a managed approach, but the Security Rule applies regardless, and its risk analysis requirement is separate. See HIPAA risk analysis.
Where to start
Write the scope statement first, in one sentence, and show it to whoever is asking you to certify. If a customer is driving this, confirm the scope you intend would satisfy them. Discovering after twelve months that the certificate excludes the service they buy is the most expensive mistake available here.
GuardsArm supports ISO 27001 programmes including scoping, risk assessment and Statement of Applicability development. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “ISO 27001 Certification: What It Takes and What It Costs”
Talk to the GuardsArm team about how these services apply to your environment.


