DEV Community

Cover image for What ISO 27001 Really Costs an Indian Software Company
Sanjay Katariya
Sanjay Katariya

Posted on

What ISO 27001 Really Costs an Indian Software Company

When companies budget for ISO 27001, they often focus on one number: the certification body’s fee.

That is usually not the biggest cost.

The real investment is the time your engineering, security, management, and operations teams spend building an Information Security Management System (ISMS), closing control gaps, collecting evidence, and preparing for audits.

For a mid-sized Indian software company, understanding that internal effort before starting can prevent a major budgeting mistake.

The Five Costs Behind ISO 27001

ISO 27001 certification costs generally fall into five areas:

  1. Gap assessment
    This identifies where your current security practices fall short of ISO 27001 requirements.

  2. Building the ISMS
    Policies, risk assessments, access controls, supplier reviews, incident processes, secure development practices, and other controls need to be documented and operational.

  3. Tooling
    ISO 27001 does not require specific software. However, gaps may require better asset management, centralised logging, endpoint controls, or access-review systems.

  4. Stage 1 and Stage 2 audits
    This is the certification body's direct cost. ISO/IEC 27006-1:2024 determines audit time based largely on the effective number of people within scope.

  5. Surveillance audits
    Certification runs on a three-year cycle, with surveillance audits after the initial certification.

A useful rule: ask the certification body for the audit-day count before asking for the final price.

The Cost Most Proposals Leave Out

The biggest hidden cost is your own team’s time.

ISO/IEC 27001:2022 contains 93 Annex A controls. Each needs to be considered and justified through the Statement of Applicability.

For a software company with roughly 60–150 employees, our working model estimates:

Scoping and gap assessment: 5–10 person days

Risk assessment and treatment: 10–15 days

Policies and procedures: 20–30 days

Engineering and control-gap remediation: 30–60 days

Evidence collection: 10–20 days

Internal audit and corrective actions: 5–10 days

That puts the internal workload at roughly 80–145 person days, spread across the implementation period.

For many companies, that internal effort can cost more than the certification audit itself.

What Makes ISO 27001 More Expensive?

The biggest variable is scope.

A company certifying one product and its supporting delivery team will usually face a smaller implementation than one putting every department, office, application, and employee into scope.

Other major cost drivers include:

Headcount: More people within scope generally means more audit time.

Multiple offices: Additional locations can increase audit complexity.

Cloud vs on-premise infrastructure: Cloud providers may already provide evidence for certain infrastructure controls, while on-premise environments put more responsibility directly on your organisation.

Existing processes: Companies already performing access reviews, change management, incident logging, backups, and supplier assessments have less work to build from scratch.

Narrowing scope can therefore reduce cost—but it should be done deliberately. The certification scope appears on the certificate, and enterprise procurement teams can check whether it actually covers what they are purchasing.

How Long Does ISO 27001 Take?

For a first certification with a meaningful scope, nine to twelve months is a realistic planning window.

The reason is not simply documentation.

Stage 2 examines whether controls are actually operating. Auditors need evidence such as access-review records, training records, incident logs, supplier reviews, internal audits, and management reviews.

You cannot create months of operational evidence overnight.

That is why adding more consultants does not necessarily turn a nine-month implementation into a three-month one.

ISO 27001 vs SOC 2

Both help customers evaluate security, but they work differently.

ISO 27001 results in certification against an international information-security management standard. It uses 93 Annex A controls and includes Stage 1, Stage 2, surveillance, and recertification audits.

SOC 2 produces an auditor's report under AICPA standards. Organisations define controls against selected Trust Services Criteria, and a Type 2 report examines their operation over a defined period.

Which one matters more depends heavily on what your customers and procurement teams actually request.

Doing both simply because they are well-known security frameworks can consume substantial engineering time without necessarily helping sales.

What ISO 27001 Does Not Solve

ISO 27001 is an information security management system certification.

It is not CERT-In empanelment.

It also does not automatically establish Indian data residency.

If a tender specifically requires an audit by a CERT-In empanelled organisation, ISO 27001 does not replace that requirement.

Similarly, data residency depends on your hosting architecture and contractual requirements—not simply whether your organisation holds an ISO certificate.

Should a Mid-Sized Software Company Pursue It?

Start with your sales pipeline rather than the certificate.

Look at your last 8–12 enterprise opportunities.

How many were delayed or lost because of a security certification requirement, security questionnaire, or procurement requirement?

If ISO 27001 repeatedly appears as a buying requirement, certification can become a commercial enabler.

If customers are not asking for it, committing nine months and potentially more than 100 internal person days deserves much closer scrutiny.

Accucia’s Current Position

Accucia is currently implementing an ISO 27001 information security management system.

An auditor has been appointed, with certification targeted for Q1 2027. Accucia is not ISO 27001 certified today, and ISO 9001 is also currently in progress.

That distinction matters.

ISO 27001 should not be treated as another logo for a website footer. It is an operating system for information security—and the largest investment is often not the certificate.

It is the work required to make the organisation ready to earn it.

Read full blog

Top comments (0)