Skip to content

Lessons from taking a startup to ISO 27001 for under €10,000

ISO 27001 is sold as slow and expensive. For an early-stage startup we brought it in for under €10,000, returned roughly 5x in value — and left them SOC 2-ready almost for free.

Abazantum 13 July 2026 8 min read

ISO 27001 has a reputation: slow, expensive, a binder of policies nobody reads. For a large enterprise it can certainly become that. For an early-stage startup it does not have to — and it shouldn’t, because done well it is one of the highest-return investments a young company can make.

We recently took an early-stage startup through to certification for under €10,000 all-in, and the return was not the certificate. It was roughly 5x the cost in value — unblocked enterprise deals, reduced risk, and a business that ran better. As a bonus, the same work left them most of the way to SOC 2. Here is how, and what we learned.

Why bother at a startup’s stage?

The trigger is almost always sales. A startup lands in the pipeline of a larger customer, and the security questionnaire arrives — 200 questions, a demand for evidence, and a deal that stops moving until there is an answer. ISO 27001 turns that recurring interrogation into a single credible answer.

But the certificate is the least interesting part. The real value is that the controls behind it are simply good operating hygiene a startup should have anyway. You are not buying a badge; you are buying the discipline, and the badge is proof you have it.

How we kept it under €10,000

The cost of ISO 27001 is mostly a series of choices. Make them well and the number stays small.

  • Scope tightly. The single biggest cost lever is the scope of the information security management system (ISMS). We scoped it to the product and the systems that build and run it — not every laptop and process in the company. A tight, honest scope keeps the audit short and the evidence manageable.
  • Do the ISMS in-house, with guidance — not day-rate consultancy. The expensive way to do ISO 27001 is to hand it to a consultancy at a daily rate to write policies you don’t understand. We did the opposite: the startup’s own team owned the ISMS, with us providing the framework, templates and expert steer. Ownership costs less and lasts longer.
  • Use what you already have. A modern startup already holds most of the raw materials — cloud configuration, infrastructure-as-code, CI/CD, identity and access management, logging. ISO 27001 is largely about documenting and tightening what exists, not buying a shelf of new tools.
  • Spend where it’s unavoidable: the audit. The one cost you cannot design away is the accredited certification body’s Stage 1 and Stage 2 audit. For a small, tightly-scoped organisation that is a few thousand euro, and it was the majority of our sub-€10,000 total.

Most of what makes ISO 27001 expensive is optional. The scope, the consultants and the tooling are choices; only the audit is fixed.

The lessons that mattered

Keep the risk assessment real. The risk assessment is the spine of the whole system, and it is where projects go to die under their own methodology. We kept a lightweight, genuinely-used risk register — real threats, real owners, real decisions — instead of a 200-page process. Auditors respond far better to a simple risk process that is clearly lived than an elaborate one that is clearly theatre.

Make evidence a by-product, not a scramble. The teams that dread audits are the ones that reconstruct a year of evidence the week before. We wired evidence into how the startup already worked: access reviews fall out of the identity provider, change history out of the pull-request trail, monitoring out of the tooling already running. Compliance you have to perform is expensive; compliance that is a side effect of good engineering is nearly free.

Treat the controls as engineering, not paperwork. MFA everywhere, least privilege, sensible logging, tested backups, a real joiner/mover/leaver process, vendor due diligence, a secure development lifecycle — these are the controls, and they are just good engineering. Implementing them genuinely reduced the startup’s risk. That is the point.

Culture beats documentation. The certificate lasts three years with annual surveillance audits; the ISMS only survives if the team owns it. We spent as much effort on getting engineers to own their controls as on writing any policy.

Where the 5x came from

The under-€10,000 spend returned several times its cost, and almost none of it was the certificate itself:

  • Unblocked revenue. Enterprise deals that had stalled on security review moved again. A single unblocked contract dwarfed the entire cost of certification.
  • Shorter sales cycles. “Here is our ISO 27001 certificate and scope” replaced weeks of back-and-forth on questionnaires.
  • Lower real risk. Fewer ways to be breached, and a smaller blast radius when something does go wrong — the value of which is invisible right up until the day it isn’t.
  • Easier diligence. Investors and enterprise procurement both take a certified ISMS as a signal that the company is run seriously. Diligence got shorter and calmer.
  • Better engineering. The discipline — access hygiene, change control, incident response — made the team faster and steadier, not slower.

Add those up and the certificate is almost a rounding error against the value of the work behind it.

The SOC 2 dividend

Here is the part most startups miss: doing ISO 27001 gets you most of the way to SOC 2 at the same time.

SOC 2 and ISO 27001 are different instruments — SOC 2 is an AICPA attestation report favoured by US buyers; ISO 27001 is an internationally-recognised management-system certification — but underneath, the control sets overlap heavily. The large majority of SOC 2’s Security (Common Criteria) requirements map directly onto controls you build for ISO 27001: access control, change management, risk assessment, vendor management, monitoring, incident response, and the rest.

That means once the ISMS exists, SOC 2 is an incremental add, not a fresh project. The main differences to plan for:

  • Attestation vs certification. SOC 2 is a report written by a CPA firm; ISO 27001 is a certificate from an accredited body.
  • A period of operating effectiveness. SOC 2 Type II tests that controls worked over a window (typically 3–12 months) — so you need evidence accumulating over time, which the “evidence as a by-product” habit above already gives you.
  • Audience. US enterprises tend to ask for SOC 2; international and regulated buyers tend to ask for ISO 27001.

Sequenced well, one body of work makes a startup credible to both US and international enterprise buyers. You do the hard part once — build a real ISMS — and then meet each market with the instrument it recognises.

The takeaway

ISO 27001 is not a tax on startups; it is leverage. Scope it tightly, own it internally, treat the controls as engineering, and spend only where you must. Do that and a startup can be certified for a few thousand euro, get several times that back in unblocked revenue and reduced risk, and stand up SOC 2 as a follow-on rather than a restart.


If you are a startup facing security questionnaires — or want ISO 27001 and SOC 2 done pragmatically, without the bloated price tag — get in touch.

Have a hard problem in financial technology?

Whether you are shaping a strategy, proving a concept or rescuing a programme, we would like to hear about it.