Skip to content
Services · Security Development

ISO 27001 Starter

Get your information security management system up and running

€2,500 (excl. VAT)12h consulting, 3 meetingsFor SMEs, under 50 employees
Service path

Where does the Starter fit?

An ISO 27001 project proceeds in stages. The Starter is the first step, a lightweight and concrete way to get moving before bigger investments. You can start with the Starter and proceed at your own pace, or jump straight into the GAP analysis if that fits your situation better.

Why this service?

A lower barrier to getting started

ISO 27001 certification feels like an overwhelming project to many SMEs: the standard is broad, the requirements abstract, and the starting point unclear. The Starter is designed to lower that barrier: with a smaller investment you get moving, understand what it’s about, and build a foundation worth continuing from.

The Starter also prepares you for the GAP analysis. Once the basics are in place and the first documents exist, you get significantly more out of the GAP analysis, and it proceeds faster.

What does the package include?

3 h

1. Onboarding and training

The first meeting builds a shared understanding.

  • The structure and key terminology of the ISO 27001:2022 standard
  • What an ISMS (Information Security Management System) means in practice
  • How the standard’s requirements apply specifically to your company
  • The stages of the certification process and a realistic timeline for an SME
  • Common pitfalls and how to avoid them
3 h + 3 h(2 meetings)

2. Risk management

Risk management is the heart of ISO 27001. The first meeting lays the groundwork, the second finalizes the results.

Meeting 2 – Risk mapping

  • Identifying information assets: what data is processed and where it resides
  • Identifying threats and vulnerabilities in the company’s context
  • Risk matrix: likelihood × impact
  • Prioritizing risks and assigning ownership

Meeting 3 – Risk treatment

  • Risk treatment decisions (accept, reduce, transfer, avoid)
  • Selecting Annex A controls and the Statement of Applicability (SoA)
  • Drafting the risk treatment plan
  • Reviewing the risk register
3 h

3. Documentation and processes

The third meeting brings the project together and produces concrete documents.

  • Information security policy: management’s commitment in written form
  • Defining the ISMS scope
  • Roles and responsibilities: who owns information security?
  • Identifying and describing key processes
  • Basics of the incident management process
  • A planning template for the internal audit
  • The agenda and structure for the management review

What do you get, concretely?

Risk register

A working Excel-based tool for managing risks

Statement of Applicability (SoA)

Annex A control selections with justifications

Information security policy

A template ready for management to sign

ISMS scope description

A document to submit to auditors

Roles and responsibilities matrix

Clarity on who does what

Process descriptions

The key ISMS processes described

Action plan

A prioritized list of next steps toward certification

Who is this service for?

Ideal customer

  • An SME with under 50 employees
  • A customer or contract partner requires ISO 27001 certification
  • Security matters are “unmanaged” or handled inconsistently
  • No prior experience with management systems
  • Management is committed to the project but doesn’t know where to start
  • Wants to get familiar with an ISO 27001 project before bigger investments

May not be a fit if

  • The organization already has a working ISMS and only needs fine-tuning
  • A fully outsourced ISMS implementation is needed (offered separately)
  • A GAP analysis has already been done, in that case we recommend proceeding straight to implementation

How does the project proceed?

Meetings are held remotely (Teams/Meet) or at your premises, as agreed.

Week 1–2

Meeting 1: Onboarding and training (3 h)

Week 3

Meeting 2: Risk mapping (3 h)

Week 4–5

Interim task: you identify your organization’s information assets independently

Week 5–6

Meeting 3: Risk treatment + documentation (3 h)

Week 6+

You receive the action plan and documents

Price and terms

Total price
€2,500 (excl. VAT)
Billing
Monthly, based on work carried out
Meetings
3, totaling 12 hours
Documents
Delivered within 5 business days of the final meeting
Language
English (documents in English or Finnish, as agreed)

Frequently Asked Questions

How long is the journey from here to certification?

Typically 6–18 months depending on the organization’s size and starting point. The Starter package lays the foundation: the actual certification audit is purchased separately from an accredited certification body.

Do we need IT expertise?

No. The service is designed for management and business people. Technical depth is added later if needed.

What happens after the Starter?

The natural next step is the ISO 27001 GAP analysis (€5,850 (excl. VAT)), which reviews all the standard’s requirements and controls and systematically assesses the ISMS’s maturity. After the Starter you already have baseline documents and a shared understanding, so the GAP analysis proceeds more efficiently. If you need ongoing support without your own security manager, we also offer the Security Manager service (€3,000 / month (excl. VAT)).

Do we get all documents with editing rights?

Yes. All documents produced are yours and are delivered in an editable format (Word/Excel).

Why wouldn’t we just do this ourselves from the standard?

The standard is broad and abstract, doing it yourself typically stretches from months into years. In the Starter, the same journey is guided in 6 weeks, and the result is documents an auditor actually expects, not just documents.

Do we get a certificate from this?

No: nobody sells a certificate, it’s issued by an accredited auditor. The Starter gives you the foundation on which certification is possible. Without this foundation the audit fails.

Next step

Get in touch and we’ll schedule a free 30-minute scoping call. We’ll go through your situation and confirm the Starter package is the right fit for you.

Book a scoping call

ISO 27001 consulting is based on the requirements of the ISO/IEC 27001:2022 standard.