ISO 27001 Starter
Get your information security management system up and running
Where does the Starter fit?
An ISO 27001 project proceeds in stages. The Starter is the first step, a lightweight and concrete way to get moving before bigger investments. You can start with the Starter and proceed at your own pace, or jump straight into the GAP analysis if that fits your situation better.
A lower barrier to getting started
ISO 27001 certification feels like an overwhelming project to many SMEs: the standard is broad, the requirements abstract, and the starting point unclear. The Starter is designed to lower that barrier: with a smaller investment you get moving, understand what it’s about, and build a foundation worth continuing from.
The Starter also prepares you for the GAP analysis. Once the basics are in place and the first documents exist, you get significantly more out of the GAP analysis, and it proceeds faster.
What does the package include?
1. Onboarding and training
The first meeting builds a shared understanding.
- The structure and key terminology of the ISO 27001:2022 standard
- What an ISMS (Information Security Management System) means in practice
- How the standard’s requirements apply specifically to your company
- The stages of the certification process and a realistic timeline for an SME
- Common pitfalls and how to avoid them
2. Risk management
Risk management is the heart of ISO 27001. The first meeting lays the groundwork, the second finalizes the results.
Meeting 2 – Risk mapping
- Identifying information assets: what data is processed and where it resides
- Identifying threats and vulnerabilities in the company’s context
- Risk matrix: likelihood × impact
- Prioritizing risks and assigning ownership
Meeting 3 – Risk treatment
- Risk treatment decisions (accept, reduce, transfer, avoid)
- Selecting Annex A controls and the Statement of Applicability (SoA)
- Drafting the risk treatment plan
- Reviewing the risk register
3. Documentation and processes
The third meeting brings the project together and produces concrete documents.
- Information security policy: management’s commitment in written form
- Defining the ISMS scope
- Roles and responsibilities: who owns information security?
- Identifying and describing key processes
- Basics of the incident management process
- A planning template for the internal audit
- The agenda and structure for the management review
What do you get, concretely?
Risk register
A working Excel-based tool for managing risks
Statement of Applicability (SoA)
Annex A control selections with justifications
Information security policy
A template ready for management to sign
ISMS scope description
A document to submit to auditors
Roles and responsibilities matrix
Clarity on who does what
Process descriptions
The key ISMS processes described
Action plan
A prioritized list of next steps toward certification
Who is this service for?
Ideal customer
- An SME with under 50 employees
- A customer or contract partner requires ISO 27001 certification
- Security matters are “unmanaged” or handled inconsistently
- No prior experience with management systems
- Management is committed to the project but doesn’t know where to start
- Wants to get familiar with an ISO 27001 project before bigger investments
May not be a fit if
- The organization already has a working ISMS and only needs fine-tuning
- A fully outsourced ISMS implementation is needed (offered separately)
- A GAP analysis has already been done, in that case we recommend proceeding straight to implementation
How does the project proceed?
Meetings are held remotely (Teams/Meet) or at your premises, as agreed.
Week 1–2
Meeting 1: Onboarding and training (3 h)
Week 3
Meeting 2: Risk mapping (3 h)
Week 4–5
Interim task: you identify your organization’s information assets independently
Week 5–6
Meeting 3: Risk treatment + documentation (3 h)
Week 6+
You receive the action plan and documents
Price and terms
- Total price
- €2,500 (excl. VAT)
- Billing
- Monthly, based on work carried out
- Meetings
- 3, totaling 12 hours
- Documents
- Delivered within 5 business days of the final meeting
- Language
- English (documents in English or Finnish, as agreed)
Frequently Asked Questions
How long is the journey from here to certification?
Typically 6–18 months depending on the organization’s size and starting point. The Starter package lays the foundation: the actual certification audit is purchased separately from an accredited certification body.
Do we need IT expertise?
No. The service is designed for management and business people. Technical depth is added later if needed.
What happens after the Starter?
The natural next step is the ISO 27001 GAP analysis (€5,850 (excl. VAT)), which reviews all the standard’s requirements and controls and systematically assesses the ISMS’s maturity. After the Starter you already have baseline documents and a shared understanding, so the GAP analysis proceeds more efficiently. If you need ongoing support without your own security manager, we also offer the Security Manager service (€3,000 / month (excl. VAT)).
Do we get all documents with editing rights?
Yes. All documents produced are yours and are delivered in an editable format (Word/Excel).
Why wouldn’t we just do this ourselves from the standard?
The standard is broad and abstract, doing it yourself typically stretches from months into years. In the Starter, the same journey is guided in 6 weeks, and the result is documents an auditor actually expects, not just documents.
Do we get a certificate from this?
No: nobody sells a certificate, it’s issued by an accredited auditor. The Starter gives you the foundation on which certification is possible. Without this foundation the audit fails.
Next step
Get in touch and we’ll schedule a free 30-minute scoping call. We’ll go through your situation and confirm the Starter package is the right fit for you.
ISO 27001 consulting is based on the requirements of the ISO/IEC 27001:2022 standard.