ISO 27001, SOC 2 and small businesses: what you need and what you can skip

What these certifications are, when a small business genuinely needs one, what they cost in money and attention, and what to do instead until then.

4 minread 841words last updated

The short answer

ISO 27001 and SOC 2 are the two assurance frameworks small technology-adjacent businesses get asked about. ISO 27001 is an international standard for an information security management system: you define scope, assess risks, select and implement controls, operate the system, audit it internally, review it at management level, and an accredited body certifies it after an audit, with surveillance audits over a three-year cycle. SOC 2 is different in kind: an attestation report written by an accountant, assessing your controls against trust services criteria, either at a point in time or over a period, and it is most often requested by North American customers. Neither is required by law. Both are commercial requirements imposed by customers, and that is the only sound reason to pursue either. The cost is dominated not by audit fees but by the work of building and then operating the system, which is substantial for a team under twenty people. Until a customer actually requires certification, a documented security summary with real controls and evidence answers most questionnaires at a fraction of the cost.

Comparing the options

ISO 27001SOC 2Documented security summary
What it isCertification of a management systemAuditor’s report on controlsYour own evidence pack
Who asks for itEuropean and international enterprise, public tendersOften North American customersMost small and mid-sized customers
CycleCertification plus surveillance over three yearsUsually annualUpdated quarterly
Main costBuilding and operating the systemPreparing and evidencing controlsTime to write and keep current
Time to achieveTypically six to twelve months for a small businessSimilar preparation; type two requires an observation periodDays
Ongoing burdenSignificant and permanentSignificant and annualLight
What it provesYou run a system that manages security riskYour controls operated as describedYou have thought about it and can evidence it

Deciding

  1. Wait for a real requirement: a tender, a contract clause, or repeated customer demand.
  2. Ask which framework the customer needs, and whether a questionnaire plus a penetration test would satisfy them.
  3. Scope narrowly to the service the customer buys.
  4. Cost it fully: preparation, tooling, audit, internal time, ongoing operation.
  5. Build the security summary first either way; it is the foundation and it may be enough.
  6. Use a compliance platform if you proceed, and be clear that it automates evidence, not the underlying controls.
  7. Assign an owner with the authority and the hours; this cannot be spare-time work.
  8. Plan for the ongoing cycle before committing, because certification lapses without it.

What to do instead, for now

Write the security summary that describes how you host, control access, manage secrets, update, back up, monitor, respond to incidents, handle personal data and test. Collect the evidence for each. Commission a penetration test if the data or the customers justify it, and keep the report and the retest. Put the basic controls genuinely in place: second factors everywhere, least privilege, patching, tested backups, logging, an incident plan. That package answers most questionnaires, costs a fraction of certification, and is exactly the groundwork certification would require anyway.

What this means for you

ISO 27001 and SOC 2 are commercial requirements rather than legal ones, and the cost is dominated by building and operating the system rather than by the audit. Pursue one when a customer genuinely requires it, scope it narrowly, cost the ongoing cycle honestly and assign a real owner. Until then, build the controls, write the security summary, keep the evidence and answer questionnaires well, which is both cheaper and the foundation you would need anyway. This is general information rather than legal or compliance advice.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Do we need ISO 27001 to sell to larger clients?

Sometimes, and less often than people assume. Many enterprise procurement processes accept a completed security questionnaire with evidence, a penetration test summary and clear policies. Certification becomes necessary when it is stated as a requirement in tenders you intend to win, or when several customers ask in a year. Pursuing it speculatively, before any customer has asked, is a large investment made on a guess.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 is an international standard for an information security management system, certified by an accredited body after an audit, valid for three years with surveillance audits. SOC 2 is an attestation report produced by an accountant against trust services criteria, usually annually, and is more common with customers in North America. Which one to pursue is determined by which your customers ask for, not by which is better.

What does it actually cost?

For a small business, expect the audit fees to be the smaller part. The larger costs are the months of work building the management system, the tooling, the internal time, and then the ongoing operation: risk assessments, internal audits, management reviews, evidence collection and the annual cycle. Compliance automation platforms reduce the effort but add their own subscription. Budget in person-months as well as euros.

Sources

  1. ISO: ISO/IEC 27001 Information security management (accessed 2026-09-12)
  2. AICPA: System and Organization Controls, the SOC suite of services (accessed 2026-09-14)