ISO 27001 for Startups Without a Security Team

A startup can certify to ISO 27001 without a dedicated security team. The standard is risk-based and scales to your size, so a 20-person company certifies a narrow scope, assigns existing people to the required roles, and runs a focused set of controls. A consultancy and a compliance platform cover the work headcount would otherwise do.

What does ISO 27001 actually demand of a 20-person company?

ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS). It does not prescribe a fixed list of technology or a minimum team size. It asks you to define a scope, assess your risks, and run a management system that treats those risks and improves over time. For a small company, that scales down to a proportionate programme rather than an enterprise one.

The standard is built on two parts. The management-system clauses set the requirements an auditor certifies you against: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A then lists 93 controls grouped into four themes, organisational, people, physical and technological. You decide which controls apply to your scope and record the reasoning in a Statement of Applicability, so a 20-person SaaS company justifies a far smaller set than a bank would.

Scope is the lever that keeps the work proportionate. You certify the systems that handle sensitive data and support the core product, not every laptop and side project. A narrow, honest scope is easier to build, easier to audit, and still answers the question a buyer is asking. The full structure of the 2022 standard is covered in our guide to ISO 27001:2022.

How do you cover the required roles without dedicated headcount?

ISO 27001 requires that responsibilities are assigned and that leadership owns the ISMS. It does not require those responsibilities to sit with full-time security staff. In a small company, the named owner is usually a founder, a CTO or an engineering lead who already understands the systems in scope, supported by whoever handles people and operations.

What matters to an auditor is that the roles are defined, that someone is accountable, and that the work actually happens. A part-time owner with clear responsibilities and outside support satisfies the standard. The gap a 20-person team usually has is not commitment but capacity and prior experience of an audit, which is the part an external partner is there to supply.

The roles you cannot fill internally without bias are the independent ones. The standard requires an internal audit, and an internal audit cannot be carried out by the person who built the thing being audited. That independence is the most common reason small teams bring in outside help rather than attempting the whole programme alone.

How does the platform-plus-consultancy delivery model work?

A compliance platform and a consultancy do two different jobs, and a small team benefits from both. The platform automates the mechanical work: collecting evidence, monitoring controls, tracking which tasks are done and flagging what has drifted. It removes a large share of the manual effort that would otherwise fall on people you do not have.

The platform does not design your management system, make the judgement calls about scope and risk, or sit across the table when the auditor asks why a control applies. That is the consultancy’s part. A consultant defines the scope with you, runs the risk assessment, writes the policies that fit how you actually work, and prepares you for the certification audit. The platform proves the controls are running; the consultancy builds and runs the programme being proved.

For a startup without a security team, this combination is what replaces headcount. The platform handles volume, the consultancy handles judgement, and your involvement drops to hours rather than weeks. Atoro delivers ISO 27001 this way and has completed more than 200 certifications across security and compliance. You can see the detail of our ISO 27001 implementation service.

What is a realistic timeline and what drives the cost?

How long certification takes depends on how much of a management system you already have. A company starting from nothing needs time to define scope, run the risk assessment, write policies, put controls in place and let them operate long enough to produce evidence before an audit is worthwhile. A company with security practices already in place moves faster because much of the substance exists and only needs to be documented and tested.

There is no fixed price for ISO 27001, and any single figure quoted online is misleading. The real cost is driven by a handful of factors: the size of your organisation, the breadth of the scope you certify, how mature your existing controls are, the number of systems and locations in play, and the accredited certification body’s own audit fees, which are separate from any consultancy cost. The largest variable is usually internal effort, which is exactly what the platform-plus-consultancy model is designed to reduce.

Why is the internal audit a requirement, and who can run it?

ISO 27001 requires an internal audit and a management review before you can be certified. The internal audit checks that your ISMS works as documented and meets the standard; the management review is where leadership looks at the results and decides what to change. Both have to happen before an accredited body will carry out its own assessment, and a missing or weak internal audit is one of the most common reasons certification slips.

The internal audit has to be independent of the work it examines. The person who wrote the policies and built the controls cannot audit their own work objectively, which is a real problem in a 20-person company where the same few people did everything. Bringing in an independent internal auditor solves it and gives leadership an honest picture before the certification body arrives. Atoro offers this as a standalone ISO 27001 internal audit for teams that have built the system and need it tested.

Once the internal audit and management review are done, certification follows the standard route. An accredited certification body carries out a Stage 1 audit of your documentation and a Stage 2 audit of how the system works in practice. Pass both and you receive your certificate, maintained through surveillance audits over a three-year cycle.

ISO 27001 for startups FAQs

Can a startup get ISO 27001 certified without a security team?

Yes. ISO 27001 is risk-based and scales to your size. A small company certifies a narrow scope, assigns the required responsibilities to existing people such as a founder or CTO, and uses a consultancy and a compliance platform to cover the work a dedicated team would otherwise do.

What is ISO 27001?

ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS). It sets out how an organisation should manage information security risk through a management system that is assessed and certified by an accredited body.

How many controls does ISO 27001 have?

Annex A of ISO 27001:2022 lists 93 controls grouped into four themes: organisational, people, physical and technological. You select and justify which controls apply to your scope in a Statement of Applicability, so a small company applies far fewer than a large enterprise.

Who owns ISO 27001 in a small company?

The standard requires responsibilities to be assigned and leadership to own the ISMS, but not that the owner is full-time security staff. In a startup the owner is usually a founder, CTO or engineering lead, supported by whoever handles people and operations, with outside help for the independent work.

Is an internal audit required for ISO 27001?

Yes. ISO 27001 requires an internal audit and a management review before certification. The internal audit must be independent of the work it examines, so the person who built the controls cannot audit them, which is why small teams often bring in an independent internal auditor.

How long does ISO 27001 certification take for a startup?

It depends on how much management system you already have. A company starting from nothing needs time to define scope, assess risk, write policies and let controls operate before an audit is worthwhile. A company with existing security practices moves faster because the substance already exists and needs documenting and testing.

How much does ISO 27001 cost for a small company?

There is no fixed price. Cost is driven by your organisation’s size, the breadth of scope, how mature your controls are, the number of systems and locations, and the certification body’s audit fees, which are separate from consultancy cost. The largest variable is usually internal effort.

How does the platform-plus-consultancy model work?

A compliance platform automates evidence collection and control monitoring, removing manual effort. A consultancy designs the management system, runs the risk assessment, writes the policies and prepares you for the audit. The platform proves the controls run; the consultancy builds and runs the programme being proved.