← All insights

ISO 27001 for a 20-person company: when it's worth it, when it isn't

ISO 27001 is a real, useful standard — but it's also a £15,000-plus, six-to-nine-month project that most 20-person UK businesses don't need. Here's the honest test for when it's worth the money, and what to do instead when it isn't.

Editorial illustration of a balance-scale weighing a small olive-green Cyber Essentials-style checkmark against a larger purple ISO 27001-style padlock, sitting at equilibrium — the decision the article helps you make.

What ISO 27001 actually is

ISO 27001 is the international standard for an Information Security Management System — an ISMS. That's an important framing. It isn't a technical checklist of security products to install. It's a management framework. It says, in effect: your business should identify what information matters, assess the risks to it, decide what to do about those risks, write it down, get everyone to follow it, and prove — with evidence — that you're doing what you said you'd do.

The current version is ISO/IEC 27001:2022. The 2013 edition is gone; every certification issued or renewed after 31 October 2025 must be against the 2022 standard (BSI Group). The 2022 edition brought the control set down from 114 to 93, restructured into four themes — People, Organisational, Technological and Physical — and added modern controls covering threat intelligence, cloud services, secure coding, data masking and configuration management (Teleport).

Certification is granted by a certification body, ideally UKAS-accredited, after a two-stage audit. It lasts three years, with annual surveillance audits in between and a full re-audit at year three. That three-year cycle is important, because it's where the ongoing cost lives, and it's the bit people miss when they compare quotes.

Why people ask us about it

There are usually three reasons a 20-person business ends up asking whether they need ISO 27001. It's worth being honest about which one is driving the question, because that changes the answer.

A customer put it in a contract. A big client — often an enterprise, a public-sector body, or a company in financial services — has added ISO 27001 to a supplier questionnaire or a renewal. This is the most common reason, and it's the one worth taking seriously.

A broker or insurer mentioned it. Cyber insurance renewals have become fussier over the last two years. Sometimes the underwriter asks for ISO 27001. Almost always what they'd actually accept is Cyber Essentials Plus plus evidence of a few specific controls, and asking the broker directly gets you there without the certification.

Somebody told the owner it was "the gold standard". This is the most expensive reason. ISO 27001 is a proper standard, but "gold standard" is marketing language, and it's usually used by people who sell the certification. If nobody has actually asked for it in writing, this is the version of the question that most needs a second opinion.

The honest cost of certifying a 20-person UK business

The number the consultant quotes and the number you'll actually pay are not the same number. So it's worth walking through what a real first year looks like for a 20-person business in Greater Manchester.

The UKAS-accredited audit itself is fairly predictable. Audit days are set by ISO 27006, the standard that governs how auditors do their job, and at 20 people you're looking at seven audit days between Stage 1 and Stage 2 combined. At current UK day rates — around £1,250 per day for a UKAS-accredited auditor — that's roughly £8,750 in audit fees alone (IT Governance).

Then there's implementation. Unless you already have someone in-house who's done this before, you'll either buy a toolkit and do it yourself (cheapest but slow), hire a consultant on day rates (most common, most variable), or subscribe to an ISMS platform like Vanta, Drata or ISMS.online (fast but eats the annual budget). Realistic consultancy support for a 20-person business runs £6,000–£15,000 in year one (Clausewise).

You'll also need penetration testing (£2,000–£4,000), the ISO 27001 standard document itself (roughly £120), and some tooling depending on how much you already have in place. And then there's the internal staff time — usually the biggest hidden cost. Somebody in the business, typically an operations manager or the owner, will spend a proper chunk of six to nine months on this. That's real payroll and real distraction.

Year one total for a 20-person UK business, done properly: £12,000–£25,000, with most landing between £15,000 and £20,000 (Connection Technologies, AIS Tech).

Then year two and three are surveillance audits at £2,000–£4,000, plus another pen test, plus internal maintenance time. And year three is a full re-audit at close to the original cost. Budget £5,000–£10,000 per year on top of the year-one hit to keep the certificate live.

Cyber Essentials Plus, for comparison, costs a 20-person business roughly £2,000–£4,000 in year one, is done in weeks not months, and covers the technical controls the vast majority of your customers actually care about (AIS Tech). It's the same 10× gap that keeps showing up in the numbers.

When ISO 27001 is worth it

I'm not against ISO 27001. There are situations where it's the right call — sometimes it's the only call — and the money spent is well spent. In our experience with UK SMBs, it flips to being worth it in a fairly specific set of circumstances.

A named customer has it in writing. Not "we'd like to see robust security", but a signed contract, tender or supplier questionnaire that specifies ISO 27001 certification as a condition of the work. If losing that customer materially hurts the business, the maths becomes simple. A £15,000–£20,000 spend to protect a £200,000-a-year account is an easy decision.

You're selling into regulated sectors as a data processor. If you're a software supplier to the NHS, a payroll bureau, a firm handling significant volumes of personal or financial data on behalf of larger regulated clients, ISO 27001 usually stops being optional. It becomes the vocabulary of the tenders you're bidding for, and the absence of it costs you deals whether or not any single contract names it.

You're selling internationally, particularly into the EU or the US. ISO 27001 is the internationally recognised standard, in a way Cyber Essentials — a UK scheme — is not. If your growth plan involves selling to enterprise buyers in Germany, France or the US, ISO 27001 is the credential that travels.

You're heading for a sale, funding round, or NIS2 supply-chain scope. Due diligence for acquisitions and investment increasingly touches information security seriously. And NIS2 — the EU cybersecurity directive that has knock-on effects on UK suppliers to EU-regulated operators — is starting to push formal ISMS expectations down the supply chain. If any of that's on the horizon within the next 18 months, ISO 27001 is a defensible investment.

Even in those cases, the sensible order is: get Cyber Essentials Plus first, run it for a year to bed in the basics, then start ISO 27001 with much of the groundwork already in place. The two dovetail. Cyber Essentials is not wasted effort on the way to ISO — most of the technical controls it forces you to implement (patching, MFA, access control, malware protection) are lifted straight into ISO 27001's Annex A.

When it isn't

This is the harder conversation, because saying "you don't need ISO 27001" to a business owner who's been told they do can feel like we're doing them out of something. We're not. We're doing them out of a £20,000 project that will absorb six months of their operations manager's time and won't actually change what any of their real customers do next.

No one has asked for it in writing. If you can't point to a specific contract, tender or supplier questionnaire that requires ISO 27001, you don't need ISO 27001. "We might win bigger contracts one day" is not a good enough reason to spend £20,000 today. Better to keep the money and revisit when a real prospect appears.

Your customers are UK SMBs, professional services, or the general public. If you're a Manchester accountancy practice, a legal firm, a distribution business, a manufacturer selling to UK trade — your customers overwhelmingly care about Cyber Essentials or Cyber Essentials Plus, not ISO 27001. Central-government contracts explicitly reference Cyber Essentials. Most SMB-to-SMB procurement asks about Cyber Essentials. The gap between what your customers want and what ISO 27001 delivers is wider than the marketing implies.

You'd struggle to maintain it. ISO 27001 isn't a one-off. It's an annual cycle of surveillance audits, internal audits, management reviews, risk assessments, control reviews and evidence collection. If you don't have someone in the business who owns it — either a dedicated compliance function or a senior operations person with capacity — you'll get certified, then quietly stop doing the work, then find yourself scrambling before the surveillance audit each year. A lapsed certificate is worse than not having one; it turns up on procurement questionnaires as "certification withdrawn."

Your risk profile doesn't warrant it. ISO 27001 is a risk-management framework. It works best when there are meaningful risks to manage. A 20-person business running a straightforward Microsoft 365 estate, with no bespoke software, no customer data processing at scale, and no international footprint has a genuinely modest risk surface. Wrapping that in a 93-control ISMS is disproportionate. Cyber Essentials Plus covers the ground that matters.

What we usually recommend for a 20-person business

For most Greater Manchester businesses in this size bracket, the sensible security stack looks like this, in order:

  1. Cyber Essentials, then Cyber Essentials Plus within 12 months. This is the productised, government-backed scheme. It's cheap, fast, and it covers the five technical controls that stop the vast majority of routine attacks: firewalls, secure configuration, access control, malware protection, and patch management. We've covered what Cyber Essentials actually requires and when a business genuinely needs it in more detail.
  2. A written incident response plan, tested annually. Half a day, a half-decent template, and a tabletop exercise once a year. This is the single most useful non-technical security investment a small business can make, and it's the thing that separates a bad afternoon from a business-ending week when something does go wrong. We wrote about what good incident response looks like for a 20-person business.
  3. A serious look at edge devices and network segmentation. This is the layer where most real breaches now come from, and it's cheap to fix if you know what to fix. Our recent piece on why attackers get in through the firewall and VPN, not the password walks through what to check.
  4. Microsoft 365 Business Premium as the baseline platform. MFA, conditional access, endpoint management and reasonable email security — bundled, and cheaper than the sum of its parts. It's the platform we sit nearly every client on, because it moves you from "we probably have security" to "we can prove we have security" without a management-system project.
  5. Annual review with your IT provider or a genuine consultant. Not a sales meeting. A proper look at what changed, what nearly went wrong, and what needs to move next.

That stack, done well, will get you through 90-plus per cent of the security questionnaires a UK SMB actually faces, at a total cost measured in low thousands per year rather than tens of thousands.

What we do at Inology

We hold both ISO 9001 and ISO 27001 at organisation level. That was a deliberate choice for us because we sit on top of dozens of clients' most sensitive infrastructure — an MSP is exactly the kind of business that should hold ISO 27001, because we are a data processor at scale, and our customers are entitled to see proof that we manage information security properly, not just claim we do.

But that same reasoning is what tells us most of our clients don't need it themselves. A 20-person accountancy in Stockport doesn't sit on top of dozens of other businesses' data. They sit on top of their own, they use tools that are already ISO 27001-certified upstream (Microsoft, Xero, Iris), and the meaningful security work they need to do is the productised, five-control kind. We help them do that well. When one of them genuinely needs ISO 27001 — and every year one or two do — we'll say so and we'll help them scope it properly. But it's not a default.

If you've been told you need ISO 27001 and you're not sure whether that's real, the honest first step is to look at who's asked and what they've asked for, in writing. That question usually answers itself. We're happy to have that conversation with any Manchester or Greater Manchester business trying to work out whether the request in front of them is a genuine requirement or a nice-to-have that would cost more than it's worth. For most, the right destination is Cyber Essentials done properly, and the £20,000 stays in the business.

FAQ

Do I need ISO 27001 or is Cyber Essentials enough?

For most 20-person UK businesses, Cyber Essentials or Cyber Essentials Plus is enough. It's the standard that UK customers, the public sector and cyber insurers actually ask for. ISO 27001 becomes the right choice when a named customer requires it in writing, when you're a data processor for regulated clients, when you're selling internationally, or when you're heading for a sale or acquisition due-diligence process within the next 18 months.

How much does ISO 27001 cost a 20-person UK business in year one?

Realistically £12,000 to £25,000 in year one when done properly. That's the UKAS-accredited audit (roughly £8,750), consultancy support (£6,000–£15,000 depending on route), a penetration test (£2,000–£4,000), the ISO standard itself and modest tooling. On top of that, expect £5,000–£10,000 per year in surveillance audit fees, ongoing pen testing and internal maintenance time. A full re-audit falls in year three.

How long does ISO 27001 certification take?

Six to nine months is the honest range for a 20-person business with no prior ISMS in place. Faster is possible with a strong consultant and a fixed scope, but the standard requires you to show controls have been running long enough to generate real audit evidence — typically at least three months before Stage 2. Anyone promising you certification in eight weeks is either working from a heavily pre-built platform or cutting corners you'll pay for at the next surveillance audit.

What's the difference between ISO 27001 and ISO 27001:2022?

ISO 27001:2022 is the current version of the standard. The 2013 edition was retired on 31 October 2025 — any certification issued or renewed after that date must be against the 2022 edition. The 2022 version has 93 controls (down from 114) organised into four themes: People, Organisational, Technological and Physical. It adds modern controls for threat intelligence, cloud security, secure coding and data masking. If you're starting now, you're starting on the 2022 edition.

Can I use my Cyber Essentials work toward ISO 27001 later?

Yes — that's genuinely useful. Most of what Cyber Essentials Plus forces you to implement (MFA, patching, access control, malware protection, secure configuration) lifts straight into ISO 27001's Annex A controls. So getting Cyber Essentials Plus first isn't wasted effort — it's the foundation that makes an ISO 27001 project shorter and cheaper if and when you get there. We'd usually recommend running Cyber Essentials Plus for at least a year before starting an ISMS build.

Does ISO 27001 make us secure?

Not directly — and that's worth understanding. ISO 27001 certifies that you have a management system for information security, not that your controls are the best possible ones. A business can be ISO 27001 certified and still have real security gaps if the risk assessment underneath the certification was thin, or if the controls it chose weren't strong enough for its actual threat profile. Certification is evidence of process. Real security comes from what you decide to do inside that process. For most SMBs, the technical controls that Cyber Essentials Plus tests directly move the needle further than the paperwork.

Been asked about ISO 27001 and not sure if it's real?

Send us the request — the contract clause, the supplier questionnaire, the broker's email — and we'll give you a straight answer: do you actually need to certify, or is Cyber Essentials Plus the right destination? No sales pitch, no scaremongering.

Talk to a human