ISO 27001 · ISMS setup · BSI Lead Auditor

ISO 27001 Certification for Swiss SMEs · End-to-End

From gap analysis to certification: we build your ISMS, accompany the audit and hand over a functioning system, typically within 6 to 9 months. Certified through our accredited certification body CIS Cert (Quality Austria Group, ISO/IEC 17021).

  • Certification through accredited body CIS Cert
  • In-house ISO 27001 Lead Auditor, no third-party auditor required
  • ISMS build, operation and certification from one provider
ISO 27001 consulting and ISMS build-up
ISO 27001 Lead Auditor (BSI)
Swiss provider, Zurich
Fixed fee
Free 30-min consultation
Quote within 24h
Active since 2017

Working for regulated industries and SMEs

CIPP/E · CIPM IAPP certified
ISO 27001 Lead Auditor (BSI)
Aligned with the FDPIC Revised FADP · Art. 10
HQ Baar, ZG Swiss brand
CH · EU · UK · US Mandates worldwide

Competitive advantage

Not all consultants can certify. We work with CIS Cert, an ISO/IEC 17021-accredited body. Your certificate is internationally recognised and accepted by clients, insurers and regulators.

Philipp Staiger

Responsible for this mandate

Philipp Staiger

M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)

Guides ISO 27001 certification projects from the scope workshop through to Stage 2 audit support. Interface to executive management, IT, data protection and the external certification body.

LinkedIn profile

Why an ISMS based on ISO 27001?

An information security management system (ISMS) is the structured framework with which you manage the confidentiality, integrity and availability of your information.

  • Risk reduction, Identify, assess and treat threats before damage occurs.
  • Legal compliance, Support for GDPR, the revised FADP (Swiss DSG), the FINMA outsourcing circular, NIS2 and DORA.
  • Competitive advantage, The certificate as a signal of trust towards customers, partners and in vendor reviews.
  • Efficiency gains, Processes and resources for information security are optimised.
  • Faster sales cycle, Supplier assessments are dramatically accelerated with the certificate.
  • Reputation gain, ISO 27001 is the internationally recognised language of information security.

The roadmap to certification

Five stages from the first workshop to the certificate, typical duration 9–18 months.

Gap analysis

2–6 weeks, assessment of existing strengths and weaknesses against the ISO 27001 requirements.

Plan & Scope

4–8 weeks, definition of the scope, ISMS policy, action plan to close the gaps.

Implementation

4–10 months, security controls (Annex A), policies, procedures, training, risk treatment.

Internal audit

2–4 weeks, review of conformity by an independent SIDD auditor, management review.

Certification

4–8 weeks, Stage 1 and Stage 2 audit by an external certification body, handover of the certificate.

How does SIDD support the development of an ISMS?

  • Gap analysis, assessment of existing strengths and weaknesses.
  • Action plan, definition and implementation of the necessary measures.
  • Training & awareness, raising employee awareness, fostering a security culture.
  • Documentation, creating and updating policies, procedures and evidence.
  • Audit support, preparation, execution and follow-up of internal and external audits.
  • Optional: software support through the Priverion Platform for efficient risk and control management.

What does an ISO 27001 ISMS cost?

There is no one-size-fits-all answer, the costs depend on company size, maturity level and scope. Rough ranges:

Company sizeInvestment range (consulting + certification)
Small (<50 employees, simple business model)CHF 20'000 – 50'000
Medium (50–250 employees)CHF 50'000 – 120'000
Large (>250 employees, complex IT)CHF 120'000 – 200'000+

Three typical fixed-fee packages, depending on size and scope:

SME package

from CHF 20,000 / Projekt

One site, clearly defined scope. Gap analysis, documentation, internal audit and certification support. Certification in 6 to 9 months.

Ongoing operation

from CHF 30k / year

ISMS operation after certification: internal audits, re-certification and an external ISO/CISO role.

Drivers: scope (locations, business units), maturity level, existing security measures, desired depth of certification. Calculate the rate that fits your situation with our ISO 27001 project calculator.

How much effort does running the ISMS take?

Operating an ISMS requires continuous effort: internal audits, security incident analysis, updating risk assessments, training, monitoring of technical controls, maintaining documentation. We reduce the operational effort through standardised templates, platform support and, optionally, by taking on the ISO role as your external information security officer.

See also our services External CISO/ISO/Information Security Officer for ongoing support and ISO 42001 AI Governance for AI use.

Why SIDD?

At SIDD, a BSI-trained lead auditor guides your ISMS from the gap analysis through to the certificate, with a dedicated InfoSec team, well-maintained evidence tooling and a clear separation of consulting and auditing.

BSI-trained lead auditor

The development of your ISMS is led by an ISO/IEC 27001 lead auditor (BSI-trained). We know the certification body's expectations from the auditor's perspective and align Annex A controls, the Statement of Applicability and evidence to be certification-ready from the outset.

Advisory and certification kept separate

SIDD builds your ISMS and supports the internal audit; the external certification is carried out by an independent body. This Separation of consulting and auditing keeps your certificate audit-credible and avoids conflicts of interest.

Our own Priverion Platform

We maintain the asset inventory, risk treatment and control evidence on our own Priverion Platform, as audit-ready, versioned tooling instead of loose slides and Excel spreadsheets. During the audit, evidence is available in a structured and retrievable form.

Depth of implementation, not just documentation

Lawyers holding doctorates and an in-house information security and software engineering team work under one roof. This lets us combine the organisational requirements of ISO 27001 with genuine depth of technical implementation, for example in hardening, logging and access controls, rather than mere documentation.

A clear path to certification

Gap analysis, roadmap, implementation, internal audit and external certification form one continuous, managed process with a fixed sequence and clear responsibilities. At any time, you know where your ISMS stands and which step follows on the way to certification readiness.

Reliable across re-audits

You receive a named, senior-led point of contact and an initial response within 24 hours. SIDD has held mandates since 2017 and reliably supports ISMS mandates through re-certifications and surveillance audits.

ISMS Implementation & Setup

Implementing an ISMS under ISO 27001 covers context and scope, risk management, the Statement of Applicability and the 93 Annex A controls. Our ISMS consulting supports you from the first gap analysis to an audit-ready information security management system.

ISO 27001 Certification in 6 to 9 Months

A focused project usually leads to the certificate within six to nine months: gap analysis, implementation, internal audit and external certification by an accredited body (CIS Cert, Quality Austria Group). We set the exact timeline after the gap analysis.

ISO 27001 for SMEs, Lean Scope

SMEs can achieve ISO 27001 with proportionate effort, too. We tailor the scope to your actual risks, build on existing processes and templates and keep the documentation as lean as the standard allows.

ISO 27001 as an accelerator for FADP and B2B tenders

Double benefit

An ISMS under ISO 27001 covers around 90% of the technical and organisational measures (TOMs) that the revised DSG requires. So you achieve two goals with one project: data-protection compliance and a recognised security certificate.

For FINMA-supervised companies, banks and in B2B sales, the certificate is often the entry ticket: it answers security questionnaires and RfP requirements before they are even asked.

References from regulated industries

Information-security and ISMS projects in aviation, HealthTech and other regulated industries.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your ISMS, concretely, LexCommand drafts the Statement of Applicability, policies and Annex A evidence as tracked changes with sourced content, and maps your controls across revFADP, GDPR, NIS2 and DORA at the same time, so overlapping duties surface together.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions before engaging us

How long does an ISO 27001 certification take?

For SMEs typically 9–12 months, for larger organisations 12–18 months. Accelerated by a clear scope, management commitment and an existing security baseline.

Which certification body do you recommend?

We are independent of certification bodies. Depending on the region and requirements, we recommend BSI, DNV, TÜV, SQS or LRQA. In the roadmap call, we discuss the right choice for your use case.

Can we document the Annex A SoA ourselves?

In theory, yes. In practice, our templates and the ISMS tool save months of work. We deliver a Statement of Applicability that can be used directly for the Stage 1 audit.

What happens after certification?

Annual surveillance audits, re-certification every three years. We can optionally stay on board as an external information security officer function, see external CISO/information security officer/ISO.

What about ISO 27017, 27018, 27701?

These extensions (cloud, PII, privacy management) attach to an ISO 27001 ISMS. We integrate them into the scope or support their build-out afterwards.

Do I additionally need a separate Data Protection Officer (DPO)?

ISO 27001 covers information security, not data protection. For GDPR mandates, you additionally need a Data Protection Officer (EU) oder DPO Switzerland. We offer both from a single source.

Ready to start?

Book a consultation if you know what you need, or request a free gap analysis if you want to understand your starting point first.

30-minute consultation with Philipp Staiger, free and no obligation Book an appointment