Answer two short questions about the size and complexity of your organisation and get an instant indicative investment range for building your information security management system through to certification, from the SME project of CHF 20,000 to a corporate project. Indicative, not a binding offer.
The investment in an ISO 27001 certification depends mainly on your company size and the complexity of your data processing and IT. The calculator captures both and maps you to the right project size.
ISO 27001 is the internationally recognised standard for information security. A project typically covers a baseline assessment, building the information security management system with policies, risk management and Annex A controls, internal audits, and support through the stage-1 and stage-2 certification audits of an accredited certification body. Effort and investment depend on scope, number of sites, IT maturity and existing security controls.
The calculator below gives you an honest first tendency, not a binding offer. We prepare the exact quote after a short scoping conversation. Running the ISMS after certification, with internal audits and re-certification, is available as an ongoing service from CHF 30,000 per year.
Choose company size and complexity. You instantly see the matching project size and the entry investment.
Your indicative estimate
Choose size and complexity above to see your estimate.
from CHF 20,000
from CHF 22,000
from CHF 25,000
from CHF 30,000
on request
SME project
Mid-market project
Corporate project
Indicative, not a binding offer. Includes support to certification; ongoing operation (from CHF 30,000/year) is optional. We prepare the exact quote after a short scoping conversation.
For a tailored estimate and a fixed-price quote, please use the quote form or the contact form.
We reply within one business day with your tailored quote. If it is urgent, book a call directly.
Four factors explain most differences. The calculator covers the two most important; we clarify the rest in the scoping conversation.
More employees, sites and business units in scope mean more processes, assets and evidence. Scope is the single strongest cost driver of an ISMS project.
An established IT with documented processes starts closer to the goal. Complex landscapes with many systems, cloud services and interfaces increase effort and the scope of Annex A controls.
Existing policies, an asset inventory or first technical controls shorten the project. We build on what is already there instead of starting from scratch.
Regulated industries such as finance or healthcare require additional controls and evidence. Extensions like ISO 27017, 27018 or 27701 for cloud and privacy increase the scope in a targeted way.
An SME project with a simple scope starts at around CHF 20,000 for the ISMS build through to certification. Mid-market and corporate are higher and calculated individually by scope. On top come the fees of the accredited certification body, billed separately. The calculator above gives you an indicative estimate in two questions.
For SMEs, 6 to 9 months to certification is typically realistic, depending on scope, maturity and internal capacity. Larger or complex projects take correspondingly longer. We plan the stages so your team stays able to operate.
No. The calculator provides an indicative estimate, not a binding offer. We prepare the exact quote after a short scoping conversation in which we clarify sites, IT maturity and certification depth.
Running the ISMS with internal audits, management reviews and preparation for surveillance and re-certification audits is available as an ongoing service from CHF 30,000 per year. This keeps the certificate continuously valid without a full-time internal role.
In a short scoping conversation we assess your specific case and give you a binding project offer.