
ISO 27001 for Swiss SMEs: Effort, Costs, Roadmap
What ISO 27001:2022 demands, when certification pays off for a Swiss SME, which costs are realistic — and a roadmap over twelve months.
ISO 27001 long had the reputation of being something for banks and data centres. That has changed: today the question about the certificate is standard in tenders, in supplier questionnaires and in the security annexes of framework agreements — and it increasingly hits Swiss SMEs with 30 to 200 employees. This post puts into perspective what the standard demands, what it costs and what a realistic path looks like.
In short: ISO 27001 is the international standard for an information security management system (ISMS). What gets certified is not the technology but the system: know your risks, define measures, implement, check, improve. For an SME the path is feasible in nine to eighteen months; the biggest cost block is your own working time, not the audit.
What ISO 27001:2022 demands
The standard has two parts. The main body (clauses 4 to 10) describes the management system: context and scope, leadership and policy, risk assessment and treatment, resources and competence, operation, performance evaluation with internal audits and management review, and improvement. Annex A lists 93 controls in four themes: organisational (37), people (8), physical (14) and technological (34). Which of them apply is decided by the risk assessment — recorded in the Statement of Applicability, the central document of every audit.
Certification happens in two stages: the stage 1 audit checks the documentation and readiness, the stage 2 audit the implementation on site. The certificate is then valid for three years, with annual surveillance audits. In Switzerland, certification is done by bodies accredited by the Swiss Accreditation Service (SAS) — a certificate from a non-accredited body is worthless on paper.
When it pays off for an SME
The standard does not pay off because it is nice, but when it meets a concrete requirement:
- Customers ask for it. As soon as the second major customer sends a questionnaire, a certificate is cheaper than answering five different questionnaires every year.
- NIS2 hits the supply chain. The ten areas of measures under Art. 21 can be demonstrated almost completely with an ISO ISMS — the connection is described in NIS2 and Switzerland.
- Regulated customers. Whoever supplies banks, insurers or hospitals is examined as an outsourced service provider — the examiners know ISO 27001 and accept it as evidence.
- Insurance and tenders. Cyber insurers ask about the same measures; public tenders increasingly require the certificate.
It pays off less if nobody asks for it and the organisation would not live the ISMS. A certificate maintained only for the audit costs money every year and protects nothing.
A sensible middle way: first do a gap assessment against the standard, without certification as the goal. That costs a few days, shows how far the path really is and delivers a list of measures that answers the next customer questionnaire even without a certificate. The decision for the audit is then made on the basis of numbers, not gut feeling.
Effort by size
The effort depends less on headcount than on scope and starting position. Rough figures from experience:
- 20 to 50 employees, IT largely in the cloud: one person with 20 to 30 percent of their time over nine to twelve months, plus management, HR and IT at specific points.
- 50 to 150 employees, own servers, several sites: an information security officer at 50 percent over twelve to eighteen months, plus a core team from IT, HR, facilities and procurement.
- Several countries or production: considerably more — here a tightly drawn scope for the first certification pays off, to be extended later.
The most common mistake is choosing the scope too large. For the first certification, the area customers actually examine is often enough: the service they buy and the systems it touches.
Estimating costs realistically
Every quote differs, but the blocks are always the same. As orders of magnitude for an SME with 50 employees:
| Block | Order of magnitude | Remark |
|---|---|---|
| Internal working time | 400–800 hours | The biggest item, often underestimated |
| External support | CHF 15,000–40,000 | Optional, shortens the learning curve |
| Certification audit (stage 1 + 2) | CHF 8,000–20,000 | Depends on scope and sites |
| Surveillance audit per year | CHF 3,000–8,000 | For two years, then recertification |
| Technical measures | Varies widely | MFA, backup, EDR are often due anyway |
| GRC tool | CHF 0–10,000 per year | Open source or suite |
The technical measures deliberately have no figure: whoever has hardened Microsoft 365 cleanly and owns tested backups already has most of it. What all of this may cost overall is shown by the security budget check as a guide value by industry and size.
Twelve months: a roadmap
Quarter 1 — foundation. Define the scope, involve management and have the information security policy signed. Create the asset inventory: systems, data, suppliers, owners. Define the risk method and carry out the first risk assessment — deliberately coarse, fifteen to thirty risks are enough.
Quarter 2 — measures. Create the Statement of Applicability: for each of the 93 controls, decide whether it applies and why. Transfer the gaps into a plan of measures with owners and deadlines. Kick off the big technical items — they need lead time.
Quarter 3 — implementation and evidence. Implement measures, collect proof, run training, evaluate suppliers. Document processes that so far existed only in people’s heads: onboarding and offboarding, changes, incidents, backup tests.
Quarter 4 — check and certify. Internal audit by someone who did not implement it themselves. Management review with key figures. Fix nonconformities, then stage 1 and stage 2 audit. There are usually four to eight weeks between the two audits.
What the auditor wants to see
The standard demands surprisingly few documents — but these must exist, be current and fit together. The list that is requested in every stage 1 audit:
- Scope of the ISMS with justification of the boundaries
- Information security policy, approved by management
- Risk method plus the results of the risk assessment and the risk treatment plan
- Statement of Applicability with justification per control
- Security objectives and how they are measured
- Evidence of competence and training
- Operational records: changes, incidents, supplier evaluations, access reviews, backup tests
- Programme and results of the internal audits
- Minutes of the management review
- Nonconformities and corrective actions
Whoever maintains these ten points in one system instead of ten folders has half passed the audit. The auditor is not looking for a perfect organisation — they are looking for one that knows where it stands and can prove it.
The mistakes that cost the most
- Buying documents instead of writing them. Templates save time, but an auditor notices immediately when the policy does not fit the organisation — and the employees notice it too.
- Parking the ISMS with IT. The standard demands that management leads. Without its involvement, resources, decisions and ultimately credibility are missing.
- Inventing risks to justify measures. It works the other way round: first the risks, then the measures.
- Excel as the ISMS. For the first months that works, after that you lose track of the relationships between risks, measures and evidence. Why, is in CISO Assistant: GRC Without the Excel Graveyard; alternatives are shown in the comparison of open-source GRC tools.
- Stopping after the certificate. The surveillance audit comes after twelve months and checks whether the system was lived: internal audits, management review, incidents, improvements.
What is different after the certificate
The real gain is not the paper. It is that the organisation for the first time has a shared list of its risks, that responsibilities are clarified and that an incident follows a process instead of panic. The next customer’s questionnaire becomes an hour of routine work. And if something does happen — how that typically unfolds is shown in Anatomy of an attack — everyone knows what to do.