A major customer demands ISO 27001 certification, or you consider it for market differentiation. Before committing to a 12+ month preparation project (with EUR 8,000 to 25,000 in fees plus internal effort), you want a clear answer: how big is the gap, how long will it take, what does it cost?
Services
ISO 27001 quickcheck
One-week pre-investment clarity audit before committing to a full ISO 27001 preparation project.
Who this fits
Deliverables
| Item | Scope | Format |
|---|---|---|
| Maturity assessment | current state across the 93 controls of ISO 27001:2022 Annex A | gap matrix |
| Gap inventory | where you are, where ISO requires, what is missing | report 8–12 pages |
| Effort estimate | hours of internal work + external consulting needed | line-item breakdown |
| Cost estimate | full preparation project (consulting + auditor + tooling) | range with assumptions |
| Time estimate | from kickoff to certification | timeline 6–18 months |
| Go / no-go recommendation | with justification | one-page summary |
| Handover call | 60-minute Zoom call with management | recorded |
Lead time
1 week from order.
Out of scope
- The full preparation project itself
- Certification audit (TÜV, DEKRA or VdS perform that)
- Tool procurement
- Training of internal ISMS team
Pricing
| Variant | Price |
|---|---|
| List price | EUR 290 |
Payment: full payment on order. Quickcheck price is fully credited against a follow-on preparation project if commissioned within 30 days.
What happens after the quickcheck
Three outcomes are typical:
- Go — full preparation project recommended, lead time 6–12 months for SMEs of 50–250 staff, EUR 8,000–18,000 in consulting fees.
- Wait — gap too large for current capacity. Recommendation to defer 6–12 months and address foundation issues (basic security policy, asset inventory) first.
- No-go — certification not value-positive for your situation. Often: a competing certification (TISAX for automotive, BSI IT-Grundschutz for federal supplier work) fits better. Recommendation accordingly.
→ The quickcheck is honest about all three outcomes. ISO 27001 is not always the right answer.
Discovery call
→ Book a slot · or email alex@alex-sokolov.de