AsteronAsteron

    ISO 27001 cost calculator for European healthtech

    Estimate the internal time, tooling and external costs involved in preparing for ISO/IEC 27001:2022 certification. Adjust the assumptions to match your scope, starting point and product complexity.

    The calculator shows its assumptions and does not assume that outsourcing is automatically cheaper.

    Employees included in the certification scope, not necessarily total company headcount.

    60 employees (51-150 employees)

    A subset of policies, risks or controls is already documented.

    Sensitive health data, several suppliers and customer-security requirements.

    Fully loaded monthly cost (€)

    Stage 1 and Stage 2 must be performed by an independent accredited body. The same requirement applies whether you prepare internally or work with Asteron.

    Estimated DIY preparation cost

    Project-owner time300-480 h€13,100-€21,000
    Technical-lead time90-170 h€5,600-€10,600
    Team participation60-150 h€2,100-€5,200
    Administration effort90-160 h€2,500-€4,500
    Internal audit (qualified internal person)20-40 h€880-€1,800
    Estimated preparation cost€24,200-€43,000
    Independent certification-body feeNot estimated - request a quote from an accredited certification body
    Estimated timeline7-10 months

    Planning estimate, not a quote. ISO/IEC 27001 does not prescribe a fixed implementation cost, timeline, number of documents or requirement to purchase a GRC platform. Certification-body fees are separate whether you prepare internally or with Asteron.

    DIY preparation compared with an Asteron ISO 27001 project

    A transparent component comparison. Asteron prepares the ISMS but cannot conduct the certification audit or issue the certificate - the certification body must remain independent.

    Cost or effortDIY preparationAsteron ISO 27001 project
    Internal effortCalculator result25-40 client hours for an eligible standard scope
    Internal-time costCalculator resultNot included in the Asteron professional fee; depends on which client roles participate
    Professional-services feeNone unless external support is addedAsteron professional fee: €26,900
    Estimated preparation cost€24,200-€43,000€26,900 (professional fee) + client-time participation
    GRC or compliance toolingManual tracking (no licence cost)Separate or optional - confirm during scoping
    Internal auditQualified internal personSeparate - not included in the professional fee unless explicitly stated in scope
    Independent certification auditSeparateSeparate
    Timeline7-10 monthsAudit-ready in 12 weeks for an eligible standard scope
    EligibilityBased on entered assumptionsSubject to Asteron eligibility and agreed scope

    The two routes are not automatically equivalent. DIY cost reflects estimated internal time and selected tools; the Asteron figure is a professional-services fee and still requires client participation. Certification-body fees remain separate in both cases.

    What actually drives ISO 27001 cost?

    Cost varies with scope boundaries, current security maturity, technical complexity, the number of legal entities and locations, supplier dependencies, the quality of existing evidence, and how consistently management is available for reviews and decisions. Two organisations of the same headcount can differ significantly on all of these axes.

    What ISO 27001 actually requires

    • ISO/IEC 27001:2022, including Amendment 1:2024, establishes requirements for an information security management system.
    • Annex A contains 93 reference controls. They must be considered against the organisation's risks; not every control is automatically mandatory.
    • The standard does not prescribe a fixed number of policies, a duration or an implementation price.
    • Required documented information should reflect the real ISMS and operating processes.
    • Internal audits must be objective and impartial; auditors may be internal or external, provided they do not audit their own work.
    • A GRC platform is optional. A penetration test is not automatically required solely because a company seeks ISO 27001 certification.

    What remains separate from implementation

    • Independent certification-body Stage 1 and Stage 2 fees.
    • Remediation engineering.
    • Penetration testing when required by risk or contract.
    • Major infrastructure or product changes.
    • Ongoing annual Compliance Operations.
    • Surveillance and recertification audits.

    How the estimate should be used

    Use the result for internal budgeting and to compare delivery models. It is not a certification quote and does not guarantee an audit duration. Actual figures depend on scope choices agreed with your certification body, remediation work and how quickly your team can produce evidence.

    Frequently asked questions

    See how it works for your scope

    We'll walk you through the process, timeline and scope - no commitment required.