A 10–40 person SaaS company running in one or two clouds is the least complex kind of organisation to certify, because small scope means most of the 93 Annex A controls apply in their simplest form. The harder problem arrives after the audit: someone has to own the ISMS once the deal that drove certification has closed.
ISO 27001’s Annex A lists 93 controls across four themes. All 93 are assessed and the applicable ones recorded in your Statement of Applicability, and the effort each one takes depends on what is being secured. For a cloud-only SaaS team, most reduce to their simplest form.
| Annex A theme | Controls | What it looks like at a 15-person cloud-only SaaS |
|---|---|---|
| Organisational | 37 | Policies sized to a company that fits in one meeting room; a supplier register consisting mostly of the cloud and SaaS stack |
| People | 8 | Onboarding, offboarding and screening across a headcount small enough to enumerate |
| Physical | 14 | Laptops, screens, possibly one office. Datacentre physical security sits in the cloud provider’s control set |
| Technological | 34 | The substantive work: access control, logging, monitoring, backups and vulnerability management across the cloud accounts |
A 100-person company carrying an office network, on-premises servers and a decade of accumulated tooling receives the same 93 questions and produces much longer answers. A single-cloud startup answers most of them with one cloud, one identity provider and one deploy pipeline.
The certification process is identical at any size: a Stage 1 documentation review, then a Stage 2 audit of interviews and evidence. Small scope shortens both, with fewer people to interview, fewer systems to sample and fewer suppliers to trace. Startups therefore sit at the bottom of the market cost ranges: readiness and implementation consulting spans roughly A$15,000–55,000 ex GST at Australian market rates, and a single-cloud startup lands near the low end. The component-by-component breakdown is in what ISO 27001 costs in Australia, and the schedule in how long certification takes.
Where the requirement arrived attached to a specific deal, a customer is asking for ISO 27001, what now covers what to tell the customer in the interim.
ISO 27001 certifies a management system. Surveillance audits run every year and full recertification every three. Between them the ISMS has to keep producing evidence: access reviews completed, logs monitored, risks reassessed, an internal audit performed, a management review held.
At enterprise scale a team carries that. At startup scale, the certification project was usually run by the CTO between releases, and by the time the certificate arrives the deal that justified the effort has closed, so ownership lapses. Twelve months later the surveillance audit requests a year of operating evidence and receives three months of it.
Small organisations face a trade-off here: the tight scope that makes certification inexpensive also leaves no spare capacity in the org chart to run it. Ownership of the ISMS is therefore a decision to take before Stage 2, and where the answer is that nobody internal can carry it, that is a resourcing decision rather than a discovery at the surveillance audit.
Where the product is AI as well as SaaS, buyers add a second layer of questions about training data, model access and behaviour. That layer has its own page — ISO 27001 for AI companies.
Startups frequently compensate for small size by downloading enterprise policy templates, producing a 30-page access control policy for a 12-person team: approval chains that do not exist, roles nobody holds, review boards that will never convene.
The auditor tests what is written. Every claimed process has to be evidenced, and every role that does not exist is a nonconformity. Short policies, real names and the tools in use produce a stronger audit outcome than comprehensive documents describing an organisation that is not there.
Most tools hand you a to-do list; we do the list and run the security behind it. For a startup that is the substance of the engagement: our governance capability covers the ISMS build, policies and evidence kept current, and the same engagement runs the monitoring, log retention and vulnerability management your auditor expects to find operating, without a hire. Where Vanta or Drata is already in place, we run the security those platforms report on. Secure60 holds ISO 27001:2022 certification and maintains it as an operating system rather than a credential.
Are we too small for ISO 27001?
No. Small scope is an advantage. The standard scales to scope: fewer people, systems and suppliers produce shorter answers to the same 93 Annex A controls and a faster audit. Organisations smaller than yours certify regularly.
Does our cloud provider's ISO 27001 certificate cover us?
No. It covers their infrastructure — the datacentres, the hardware, their operations. Your configuration, access control, code, data handling and people constitute your ISMS, and that is what your auditor assesses.
How long does certification take for a startup?
Less than the published averages, because scope drives the schedule and a startup’s scope is small. See how long ISO 27001 certification takes for the stage-by-stage timeline.
Do we need a full-time security hire to get certified?
Not to reach certification. Someone has to own the ISMS afterwards, because surveillance audits are annual and evidence has to be produced continuously. That owner can be internal or a provider.
Is a compliance platform enough on its own?
It tracks controls and collects some evidence. Implementing the controls, running the risk assessment and fronting the auditor remain separate work. See consultant, platform, or one provider that does both.
What will certification cost us?
Startups land at the bottom of the market ranges, because headcount and scope drive every component. See what ISO 27001 costs in Australia for the breakdown by company size.