ISO 27001 Certification Switzerland, Process, Timeline, Costs
Introduction
An ISO/IEC 27001:2022 certification in Switzerland realistically takes 12 to 18 months from project start to certificate issuance. The process follows a normatively defined sequence: preparation of the Information Security Management System (ISMS), internal audit, management review, Stage 1 audit, Stage 2 audit, followed by annual surveillance audits and a three-year recertification cycle. The certificate itself is issued by accredited certification bodies (CBs), which in Switzerland are accredited by the Swiss Accreditation Service (SAS) against ISO/IEC 17021-1.
This article covers:
- The full certification process with time milestones
- The role and selection of accredited Swiss certification bodies (SQS, SGS, TÜV SÜD, KPMG, BSI)
- Stage 1 and Stage 2 audits, content, duration, typical findings
- Surveillance and recertification cycles
- Realistic cost ranges for SMEs (10–50, 50–250, 250+ employees)
- Common reasons for delays and how to avoid them
Intended audience: CISOs, ISMS managers, executive sponsors, and project leads who need to budget, plan, or steer an ISO 27001 certification. The figures draw on SIDD's experience from more than 100 Swiss ISMS engagements.
Prerequisites and preparation phase
Before the external certification body comes on site, the ISMS must be ready both in documentation and in operation. The preparation phase typically takes 6 to 12 months and covers seven pillars:
- Scoping (Clause 4): define the ISMS scope, which sites, which business processes, which IT systems. Too wide a scope extends the project; too narrow risks later expansion.
- Context, interested parties (Clauses 4.1, 4.2): external and internal factors, regulatory requirements (e.g. FINMA Circular 2023/1, NIS2 for EU subsidiaries), customer and stakeholder expectations.
- Leadership and policy (Clause 5): approval of the information security policy by senior management, appointment of an ISMS manager.
- Risk management (Clause 6.1): risk methodology aligned with ISO 31000, risk register with likelihood and impact, treatment plan.
- Statement of Applicability (Clause 6.1.3 d): selection and justification of the 93 Annex A controls (ISO 27001:2022).
- Operational implementation (Clause 8): rolling out the selected controls in process, technology, and documentation.
- Performance evaluation (Clause 9): first internal audit, first management review, both are prerequisites for booking the certification audit.
Once all seven pillars are cleanly in place, you are audit-ready. Empirical observation: 80 % of project delays stem from underestimating Clauses 4 and 6, not from the Annex A controls.
Selecting the certification body
Only accredited certification bodies may issue an ISO/IEC 27001 certificate that is internationally recognized (IAF MLA / EA MLA). Active accredited CBs in Switzerland include SQS, SGS Switzerland, TÜV SÜD Schweiz, BSI Group, and Bureau Veritas. KPMG and EY work in part through accredited partner organizations. SAS accreditation should be explicitly verified, it is publicly searchable in the SAS registry.
Selection criteria from practice:
- Sector expertise: does the CB field auditors with experience in your sector (FinTech, MedTech, industrial, public sector)?
- Language coverage: can audits be performed in German, French, or Italian?
- Recognition in target markets: if you sell to large German or British buyers, they sometimes prefer local CBs (TÜV, BSI).
- Cost structure: day rate CHF 1,800–3,000 depending on auditor seniority.
- Availability: 3–6 month waiting times between inquiry and Stage 1 are currently common.
Important: the certification body must not also advise you or design your ISMS (separation of consulting and certification under ISO/IEC 17021-1). When a provider offers both, it is an indicator of missing or restricted accreditation.
Stage 1 audit, documentation review and readiness
The Stage 1 audit serves as a formal check whether the ISMS is ready for certification. It typically takes place on site (or remotely for pure software companies), lasts 1–3 auditor days, and ends with a Stage 1 report that is a precondition for Stage 2.
Stage 1 scope:
- Completeness of ISMS documentation: policy, scope statement, SoA, risk register, treatment plan, procedural instructions.
- Internal audit results: was a full internal audit performed? Were corrective actions launched?
- Management review: are minutes and decisions on file?
- Understanding of the organization: do key roles understand the scope, the policy, and their responsibilities?
- Site walk-through: spot check of physical controls.
Typical Stage 1 findings that lead to a Stage 2 postponement:
- Scope statement too vague (e.g. all IT systems), without explicit delineation of which sites or subsidiaries.
- SoA without justification for excluded controls.
- Internal audit only partially performed (not all of Clauses 4–10 and not all Annex A areas covered).
- Management review formal, without documented decisions on risk and resources.
Stage 1 to Stage 2 typically takes 4–12 weeks, time to close identified gaps. Anyone underestimating Stage 1 and arriving with incomplete documentation risks a full repetition with additional auditor days.
Stage 2 audit, effectiveness check
The Stage 2 audit verifies the effectiveness of the ISMS in practice, not just the existence of documentation. Duration: 3–10 auditor days, depending on headcount, scope complexity, and number of sites. Headcount-driven scaling follows IAF MD 5 (binding minimum audit durations).
Example minimum audit duration per IAF MD 5 for ISMS Stage 1 + Stage 2 combined (excluding travel):
- Up to 10 effective employees: 4 days
- 11–25: 5 days
- 26–45: 6 days
- 46–65: 7 days
- 66–85: 8 days
- 86–125: 9 days
- 126–175: 10 days
- 176–275: 11 days
- 276–425: 12 days
- 426–625: 13 days
The effective headcount can be reduced by justified reduction factors (e.g. homogeneous workplaces, high automation) by up to 30 %.
In Stage 2 the auditor samples how the controls are applied across the four ISO 27001:2022 themes: organizational (A.5), people (A.6), physical (A.7), technological (A.8). Typical sampling: 5–10 employees are interviewed (awareness, access procedures, incident reporting), 10–20 tickets / change requests are traced, logs are checked for completeness, access systems are walked through physically. Findings are classified as Major Nonconformity (certification blocked until closure), Minor Nonconformity (corrective action with deadline), or Observation (recommendation).
Surveillance and recertification cycles
The certificate is valid for three years. During that period surveillance audits take place annually, the first 9–12 months after Stage 2, the second 9–12 months after the first. In the third year the recertification audit takes place, covering the full Stage 2 scope and producing a new three-year certificate.
Surveillance audit scope (typically 1/3 of Stage 2 duration):
- Verification of closure of all open nonconformities from the previous year
- Sampling of the core controls (critical risks from the current risk register)
- Internal audit plan and results since the previous audit
- Management review minutes
- Incident reports and improvement actions (Clause 10)
- Material changes in scope, personnel, IT infrastructure
Important: surveillance audits must not be postponed indefinitely. Anyone shifting the date by more than 6 months risks temporary certificate suspension by the CB. For recertification the auditor must repeat the full Clauses 4–10 coverage and assess effectiveness across the entire three-year cycle. The recertification audit typically lasts 2/3 of the original Stage 2 duration.
Cost structure and realistic ranges
The total cost of an ISO 27001 certification has three components: (a) internal effort, (b) external consulting, (c) certification body fees. The mix varies with maturity and in-house capacity.
Small SMEs (10–50 employees), lean scope:
- Internal effort: 80–150 person-days
- External consulting: CHF 30,000–60,000
- CB fees initial audit: CHF 15,000–25,000 (Stage 1 + Stage 2)
- Annual surveillance: CHF 6,000–10,000
- Recertification year 3: CHF 12,000–18,000
Mid-sized SMEs (50–250 employees):
- Internal effort: 200–400 person-days
- External consulting: CHF 60,000–120,000
- CB fees initial audit: CHF 25,000–50,000
- Annual surveillance: CHF 10,000–18,000
- Recertification year 3: CHF 18,000–35,000
Larger mid-market (250–1,000 employees):
- Internal effort: 500–1,200 person-days
- External consulting: CHF 120,000–250,000
- CB fees initial audit: CHF 50,000–120,000
- Annual surveillance: CHF 18,000–40,000
- Recertification year 3: CHF 35,000–80,000
The most common cost drivers are: multi-site, multi-language scope; high share of custom software (vs. standard SaaS); regulated sector with additional audit requirements (FINMA, pharmaceuticals); outsourcing complexity (many sub-processors with their own TOMs). A blanket ISO 27001 for CHF 20,000 offer is practically not credible in Switzerland.
How SIDD supports you
SIDD accompanies Swiss companies from scoping through certificate issuance and across the three-year cycle. Our ISO 27001 / ISMS implementation engagement covers gap analysis, risk workshop, SoA development, implementation roadmap, preparation of internal audit and management review, plus support through Stage 1 and Stage 2, without acting as the certifier ourselves (separation per ISO/IEC 17021-1). Where needed we also provide an external CISO / ISB in a part-time role who owns the ISMS operationally and steers the annual surveillance audits.
Complementary mandates we frequently integrate: penetration tests for effectiveness checks of A.8 controls, continuous vulnerability scanning for A.8.8 (Technical Vulnerability Management), and awareness workshops for A.6.3. The ISMS documentation, risk register, and audit trails are maintained in the Priverion platform.
For a free initial estimate of your effort and timeline, send us key facts (employees, sites, sector) via the contact form. For a binding fixed-price engagement, request a quote.
