ISO 27001 for SMEs, A Simplified Scope Approach
Introduction
ISO 27001 is often portrayed as disproportionately complex for SMEs, a standard for banks and corporations that overwhelms small businesses. That holds only if ISO 27001 is implemented from the corporate textbook: hundred-page policies, risk registers with 500 entries, three-tier ICS procedures. The standard itself does not require this. Clause 0.2 of ISO/IEC 27001:2022 explicitly states that the ISMS should be designed proportionally to the size, complexity, and risk profile of the organization. An SME with 30 employees can run a fully certified ISMS with a documentation base of 40–60 pages, if the scope is disciplined and the risk treatment is pragmatic.
This article covers:
- Defining a lean scope for SMEs
- Owner-driven risk assessment instead of elaborate methodology
- The minimum documentation set (mandatory documents per ISO 27001:2022)
- How cloud-native architectures reduce effort
- What Swiss auditors actually expect from SMEs
- Practical templates and patterns from more than 100 SIDD engagements
Intended audience: managing directors, CTOs, and compliance leads in SMEs with 10–250 employees who want a pragmatic ISMS build without corporate overhead.
Lean scope as the lever
The single biggest effort lever is the scope. Clause 4.3 of ISO 27001:2022 requires: the organization shall determine the boundaries and applicability of the information security management system to establish its scope. The scope defines which business areas, sites, IT systems, and functions are covered by the ISMS. All standard requirements and all Annex A controls must be met for this scope, not for the entire company.
For SMEs we recommend three scope strategies:
- Product scope: only the business-critical area (e.g. the SaaS product + support + the related engineering teams). Administration, accounting, HR tooling remain outside scope as long as they do not contribute to delivering the certified product.
- Site scope: only a main site. Foreign subsidiaries, joint ventures stay separate.
- Function scope: a single function (e.g. data provisioning for public authorities) that is certification-relevant.
Important: the scope must be purpose-fit. Certifying the SaaS product while excluding the office WiFi network used by the engineering team for development creates an inconsistent boundary. Auditors check whether the scope is a sensible unit and whether interfaces to out-of-scope are documented (e.g. accounting system out of scope; contains no certification-relevant data).
A clearly delineated scope reduces audit days (IAF MD 5 is based on scope headcount, not total headcount), documentation breadth, and ongoing maintenance. Realistic savings: 30–50 % over an unfocused full scope.
Owner-driven risk assessment
Clause 6.1 requires a risk assessment, the method is left open. Corporates often use quantitative methods with Monte Carlo simulation and ALE calculation. SMEs do not need this. A qualitative, owner-driven assessment with a 5×5 matrix (likelihood × impact) is fully normatively compliant.
Practical flow:
- Asset list: list of central information assets (customer data, source code, configurations, contracts). For a 30-employee SME, typically 15–30 asset classes.
- Risk identification: per asset, 3–5 material risks (e.g. source code is exfiltrated by an external attacker). In total, 50–100 risks for a typical SME.
- Risk assessment: the owner (= asset accountable) estimates likelihood (1–5) and impact (1–5). Risk score = product (1–25).
- Risk treatment: for risks above a defined threshold (e.g. score ≥ 12), a treatment is chosen (modification, sharing, acceptance, avoidance). For modification: which Annex A controls address the risk?
- Residual risk approval: the owner signs off on the residual risk; for acceptance above threshold, senior management approval is required.
The entire risk assessment fits, for an SME, on a single Excel table with 80–150 rows. Auditors accept this provided the methodology is documented (a 2-page Risk Assessment Procedure) and owner accountability is clear. Complicated methods bring no audit-relevant added value for SMEs.
Minimum documentation set
ISO/IEC 27001:2022 explicitly requires only a limited set of documented information. The standard lists these mandatory documents:
- Scope statement (Clause 4.3)
- Information security policy (Clause 5.2)
- Risk assessment process (Clause 6.1.2)
- Risk treatment process (Clause 6.1.3)
- Statement of Applicability (Clause 6.1.3 d)
- Risk treatment plan (Clause 6.1.3 e)
- Information security objectives (Clause 6.2)
- Evidence of competence (Clause 7.2)
- Documented information required for effectiveness (Clause 7.5)
- Operational planning and control (Clause 8.1)
- Risk assessment results (Clause 8.2)
- Risk treatment results (Clause 8.3)
- Monitoring and measurement results (Clause 9.1)
- Audit program and results (Clause 9.2)
- Management review results (Clause 9.3)
- Nonconformities and corrective actions (Clause 10.2)
For an SME this consolidates into 12–18 documents totaling 40–80 pages: 1 ISMS policy (5 pages), 1 Risk Assessment Procedure (3 pages), 1 Excel with risk register + SoA + treatment plan (3 tabs), 1 audit program (2 pages), 1 management review template (2 pages), 1 CAPA register (Excel), and 5–10 procedural instructions for the most common processes (onboarding, offboarding, incident, change, backup, vendor onboarding).
What the standard does not require, you do not need to document. Skip 60-page policy compendia, separate policies for every A.5 control, and overlapping procedural text. The standard asks for effectiveness, not volume.
Cloud-native as effort reduction
SMEs that have fully outsourced IT to cloud providers (Microsoft 365, Google Workspace, AWS, Azure, Salesforce) benefit from shared-responsibility logic: the provider covers the lower stack layers (hardware, network, hypervisor, partly OS and platform) including the associated Annex A controls.
Concrete effort reductions through cloud-native:
- A.7 Physical Controls: with full cloud outsourcing, the A.7 scope reduces to the office (entry, desk policy, screen lock). Data center controls (A.7.1, A.7.5, A.7.8) drop out.
- A.8.1 User Endpoint Devices: cloud workplace providers (Microsoft Intune, Jamf, Google Endpoint) handle configuration baselines and drift detection. You configure, the provider enforces.
- A.8.20 Network Security: with pure SaaS / IaaS the classic network segmentation in terms of firewalls and VLANs falls away. Your task: Conditional Access, Zero Trust, identity as the perimeter.
- A.5.30 ICT Readiness for Business Continuity: cloud providers have documented BC/DR plans with SLAs; you adopt these as evidence.
- A.8.13 Backup: cloud-native backup (e.g. Microsoft 365 Backup, AWS Backup) replaces own backup infrastructure.
Precondition: you must document the shared responsibility. Per Annex A control: who carries what? Which contract / SOC 2 report / ISO 27001 extract of the provider proves the provider's responsibility? This cloud responsibility matrix is mandatory evidence in the Stage 2 audit for A.5.23 (Cloud Services).
A fully cloud-native SME can be ISO 27001 certified at under 50 % of the effort of a comparable on-premise company.
What Swiss auditors actually expect
Across more than 100 SME audits SIDD has accompanied, specific audit expectations emerge. They are not the spectacular topics (forensic logs, threat-hunting platforms) but the fundamentals:
- Clear scope: the auditor understands in 2 minutes what is in the ISMS and what is not.
- Risk register with owner and treatment: every risk has an owner and a decision.
- SoA with justifications: no generic best practice phrases.
- Internal audit with documented findings: including nonconformities and their treatment.
- Management review with decisions: not just a formal meeting but decisions.
- Awareness training with proof: full coverage of all staff within the last 12 months.
- User access reviews: at least semi-annually, documented.
- Incident management: even if no incidents have occurred, the procedure must exist and be tested (tabletop exercise).
- Vendor list: with risk classification of the important providers.
What auditors do not expect from SMEs:
- Quantitative risk calculations with ALE.
- SIEM platforms with a 24/7 SOC.
- Own threat-intelligence programs.
- Three-layer ICS model.
- Corporate policy stacks with dozens of sub-policies.
If SMEs cover these fundamentals cleanly, Stage 2 certification is a predictable exercise. Anyone mimicking the corporate path generates effort without audit advantage.
Practical patterns and templates
From SME practice, the following patterns prove robust:
- One-page policy: a 1-page ISMS policy with vision, scope, responsibilities, and a commitment to continual improvement. Signed by senior management. Auditors do not expect 30-pagers.
- Excel-first for risks and SoA: a single Excel file with three tabs: risk register, risk treatment plan, SoA. Linked through references instead of duplication.
- Quarterly operations review: a 60-minute session with senior management and the ISMS manager: incidents, open actions, risk updates. Extended to a formal management review (Clause 9.3) in Q4.
- Awareness as self-learning: instead of expensive platforms, an annual 30-minute video + knowledge quiz suffices (tools like Hoxhunt, KnowBe4, or homegrown). Proof via HRIS or LMS.
- Vendor management via a list: Excel with supplier, data categories, risk class (A/B/C), last review, contract status, ISO 27001 / SOC 2 evidence. 10–40 entries for a typical SME.
- CAPA as a table: an Excel with NC IDs, source, description, owner, due date, status. Replaces expensive ticket systems.
These patterns are not cheap-and-cheerful but audit-tested. We deploy them in mandates for software startups, regulated SMEs, and mid-market firms, with consistently successful certifications.
How SIDD supports you
SIDD specializes in ISO 27001 implementations for Swiss SMEs. Our ISMS / ISO 27001 engagement is designed from the ground up for 10–250 employees: lean scope, owner-driven risk assessment, minimum documentation set. We supply policy templates, risk register templates, and SoA templates tailored to your business model, not corporate templates that are oversized for SMEs.
For ongoing operation we recommend our external CISO / ISB service as a part-time model with 4–8 days per month, that covers the audit program, CAPA steering, management review, and vendor management. The Priverion platform replaces expensive GRC suites and is tailored to SME needs. Complementary: awareness workshops for A.6.3 and compact penetration tests for effectiveness evidence of A.8 controls.
Schedule a free 60-minute scoping conversation via the contact form, we deliver a rough effort and cost estimate and a recommendation for the optimal scope strategy. For a binding fixed-price proposal, request a quote.
