SME package
from CHF 20,000 / Projekt
One site, clearly defined scope. Gap analysis, documentation, internal audit and certification support. Certification in 6 to 9 months.
From gap analysis to certification: we build your ISMS, accompany the audit and hand over a functioning system, typically within 6 to 9 months. Certified through our accredited certification body CIS Cert (Quality Austria Group, ISO/IEC 17021).
Working for regulated industries and SMEs
Competitive advantage
Not all consultants can certify. We work with CIS Cert, an ISO/IEC 17021-accredited body. Your certificate is internationally recognised and accepted by clients, insurers and regulators.
An information security management system (ISMS) is the structured framework with which you manage the confidentiality, integrity and availability of your information.
Five stages from the first workshop to the certificate, typical duration 9–18 months.
2–6 weeks, assessment of existing strengths and weaknesses against the ISO 27001 requirements.
4–8 weeks, definition of the scope, ISMS policy, action plan to close the gaps.
4–10 months, security controls (Annex A), policies, procedures, training, risk treatment.
2–4 weeks, review of conformity by an independent SIDD auditor, management review.
4–8 weeks, Stage 1 and Stage 2 audit by an external certification body, handover of the certificate.
There is no one-size-fits-all answer, the costs depend on company size, maturity level and scope. Rough ranges:
| Company size | Investment range (consulting + certification) |
|---|---|
| Small (<50 employees, simple business model) | CHF 20'000 – 50'000 |
| Medium (50–250 employees) | CHF 50'000 – 120'000 |
| Large (>250 employees, complex IT) | CHF 120'000 – 200'000+ |
Three typical fixed-fee packages, depending on size and scope:
SME package
from CHF 20,000 / Projekt
One site, clearly defined scope. Gap analysis, documentation, internal audit and certification support. Certification in 6 to 9 months.
Enterprise package
CHF 50,000 – 200,000 / Projekt
Multiple sites or complex IT. Risk management, 93 Annex A controls, supplier security, internal audit and external certification.
Ongoing operation
from CHF 30k / year
ISMS operation after certification: internal audits, re-certification and an external ISO/CISO role.
Drivers: scope (locations, business units), maturity level, existing security measures, desired depth of certification. Calculate the rate that fits your situation with our ISO 27001 project calculator.
Operating an ISMS requires continuous effort: internal audits, security incident analysis, updating risk assessments, training, monitoring of technical controls, maintaining documentation. We reduce the operational effort through standardised templates, platform support and, optionally, by taking on the ISO role as your external information security officer.
See also our services External CISO/ISO/Information Security Officer for ongoing support and ISO 42001 AI Governance for AI use.
At SIDD, a BSI-trained lead auditor guides your ISMS from the gap analysis through to the certificate, with a dedicated InfoSec team, well-maintained evidence tooling and a clear separation of consulting and auditing.
The development of your ISMS is led by an ISO/IEC 27001 lead auditor (BSI-trained). We know the certification body's expectations from the auditor's perspective and align Annex A controls, the Statement of Applicability and evidence to be certification-ready from the outset.
SIDD builds your ISMS and supports the internal audit; the external certification is carried out by an independent body. This Separation of consulting and auditing keeps your certificate audit-credible and avoids conflicts of interest.
We maintain the asset inventory, risk treatment and control evidence on our own Priverion Platform, as audit-ready, versioned tooling instead of loose slides and Excel spreadsheets. During the audit, evidence is available in a structured and retrievable form.
Lawyers holding doctorates and an in-house information security and software engineering team work under one roof. This lets us combine the organisational requirements of ISO 27001 with genuine depth of technical implementation, for example in hardening, logging and access controls, rather than mere documentation.
Gap analysis, roadmap, implementation, internal audit and external certification form one continuous, managed process with a fixed sequence and clear responsibilities. At any time, you know where your ISMS stands and which step follows on the way to certification readiness.
You receive a named, senior-led point of contact and an initial response within 24 hours. SIDD has held mandates since 2017 and reliably supports ISMS mandates through re-certifications and surveillance audits.
Implementing an ISMS under ISO 27001 covers context and scope, risk management, the Statement of Applicability and the 93 Annex A controls. Our ISMS consulting supports you from the first gap analysis to an audit-ready information security management system.
A focused project usually leads to the certificate within six to nine months: gap analysis, implementation, internal audit and external certification by an accredited body (CIS Cert, Quality Austria Group). We set the exact timeline after the gap analysis.
SMEs can achieve ISO 27001 with proportionate effort, too. We tailor the scope to your actual risks, build on existing processes and templates and keep the documentation as lean as the standard allows.
Double benefit
An ISMS under ISO 27001 covers around 90% of the technical and organisational measures (TOMs) that the revised DSG requires. So you achieve two goals with one project: data-protection compliance and a recognised security certificate.
For FINMA-supervised companies, banks and in B2B sales, the certificate is often the entry ticket: it answers security questionnaires and RfP requirements before they are even asked.
Information-security and ISMS projects in aviation, HealthTech and other regulated industries.
Aviation · Information security
Building information-security governance, supplier security and multi-jurisdiction compliance, supported by SIDD.
Read the case studyHealthTech · ISMS + pentest
Penetration test, vulnerability scan and implementation of technical and organisational measures, with demonstrated revised-DSG compliance.
Read the case studyOur tool: LexCommand
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your ISMS, concretely, LexCommand drafts the Statement of Applicability, policies and Annex A evidence as tracked changes with sourced content, and maps your controls across revFADP, GDPR, NIS2 and DORA at the same time, so overlapping duties surface together.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
For SMEs typically 9–12 months, for larger organisations 12–18 months. Accelerated by a clear scope, management commitment and an existing security baseline.
We are independent of certification bodies. Depending on the region and requirements, we recommend BSI, DNV, TÜV, SQS or LRQA. In the roadmap call, we discuss the right choice for your use case.
In theory, yes. In practice, our templates and the ISMS tool save months of work. We deliver a Statement of Applicability that can be used directly for the Stage 1 audit.
Annual surveillance audits, re-certification every three years. We can optionally stay on board as an external information security officer function, see external CISO/information security officer/ISO.
These extensions (cloud, PII, privacy management) attach to an ISO 27001 ISMS. We integrate them into the scope or support their build-out afterwards.
ISO 27001 covers information security, not data protection. For GDPR mandates, you additionally need a Data Protection Officer (EU) oder DPO Switzerland. We offer both from a single source.
Book a consultation if you know what you need, or request a free gap analysis if you want to understand your starting point first.