ISO 27001 is the international standard for information security management. It’s well respected, and in the right context it’s genuinely valuable. It’s also one of the most common ways a small organisation burns a year and tens of thousands of dollars without getting measurably more secure.
Whether you need it comes down to one question: is anyone asking for the certificate?
When ISO 27001 certification makes sense
Certification makes sense when someone else requires it. Typically:
- Your customers demand it. If you’re selling software or services to enterprise or government, ISO 27001 certification is increasingly a condition of doing business. If it unlocks contracts, it pays for itself.
- You operate in a regulated supply chain. Some industries and tenders specify it outright.
- You’re scaling fast and need a formal management system. At a certain size, the discipline of a certified ISMS - documented scope, risk treatment, internal audit, management review - earns its keep.
In these cases, the certificate is the product. You’re buying a trusted, independently audited signal that you take security seriously.
When certification is an expensive distraction
If nobody is asking for the certificate, think carefully before chasing it. For a school, not-for-profit, or typical small to medium business:
- The cost is real. Between consultants, audits, surveillance audits, and staff time, certification commonly runs to tens of thousands of dollars upfront, with an ongoing commitment every year after.
- The standard is a management system, not a to-do list. ISO 27001 tells you to identify risks and treat them appropriately. It doesn’t tell you to turn on MFA, test your backups, or patch your servers. You can be certified and still miss practical controls, and you can have excellent practical security with no certificate at all.
- The paperwork can crowd out the work. Small teams have limited hours. Hours spent writing ISMS documentation for an auditor are hours not spent closing actual gaps.
For most small organisations, the board doesn’t need a certificate. They need confidence that the fundamentals are in place, evidence of where the gaps are, and a prioritised plan to close them.
The practical alternative
That’s what Foundation Cyber Security is built for. It’s a framework of 47 practical controls covering strategy, protection, response, and recovery - written in plain language, designed to be completed by your own IT manager, and producing the outputs leadership actually asks for:
- A maturity assessment across all 47 controls
- A prioritised task list - what to fix first and why
- A risk report you can take to the board
- A framework alignment report
That last one matters here. Every Foundation control is mapped to ISO 27001, alongside CIS Controls v8, NIST 800-53, and the Essential Eight.
Foundation now, ISO 27001 later
The two aren’t in competition. Because Foundation maps to ISO 27001, completing a Foundation assessment is a genuine head start if certification becomes necessary down the track. You’ll arrive with your risks documented, your controls implemented and evidenced, and a clear picture of what the ISMS needs to formalise. Consultants charge a lot to build exactly that groundwork.
So the sequencing for most small organisations is simple:
- Get the actual security outcomes now with a practical framework
- If a customer or regulator later requires ISO 27001, step up from a position of strength
Find out where you stand first
Whichever path you take, it starts with knowing your current posture. Take the free 5-question Quick Security Check for a 2-minute read on where you sit. Or create a free account on the Foundation platform and assess your organisation against all 47 controls - ISO 27001 alignment included in your report.