A 10–40 person SaaS company running in one or two clouds is the easiest kind of organisation to certify — small scope means most of the 93 Annex A controls apply in their simplest form. The hard part comes after the audit: someone has to own the ISMS once the deal that drove certification has closed.
You’re 15 people, everything runs in AWS or Azure, and a customer’s procurement team just made ISO 27001 a condition of the contract. The useful news is structural: you are the easiest kind of organisation there is to certify.
ISO 27001’s Annex A lists 93 controls across four themes. You assess all 93 and record which apply in your Statement of Applicability — but how much work each one takes depends on what you’re securing. For a cloud-only SaaS team, most of them collapse to their simplest form.
| Annex A theme | Controls | What it looks like at a 15-person cloud-only SaaS |
|---|---|---|
| Organisational | 37 | Policies sized to a company that fits in one meeting room; a supplier register that’s mostly your cloud and SaaS stack |
| People | 8 | Onboarding, offboarding and screening for a headcount you can list from memory |
| Physical | 14 | Laptops, screens, maybe one office. Datacentre physical security belongs to your cloud provider’s control set, not yours |
| Technological | 34 | The real work: access control, logging, monitoring, backups and vulnerability management across your cloud accounts |
Compare that with a 100-person company carrying an office network, on-premises servers and a decade of accumulated tooling. Their auditor asks the same 93 questions and gets much longer answers. Yours mostly reduce to: one cloud, one identity provider, one deploy pipeline — show me.
The certification process is the same at any size: a Stage 1 documentation review, then a Stage 2 audit of interviews and evidence. A small scope makes both short. Fewer people to interview, fewer systems to sample, fewer suppliers to trace. It’s also why startups sit at the bottom of the market cost ranges: readiness and implementation consulting spans roughly A$15,000–55,000 ex GST at Australian market rates, and a single-cloud startup lands near the low end. The full component-by-component breakdown is in what ISO 27001 actually costs in Australia, and the schedule in how long certification takes.
If the demand arrived attached to a specific deal — it usually did — start with a customer is asking for ISO 27001, what now, which covers what to tell the customer while you get there.
The certificate isn’t the end state. ISO 27001 certifies a management system: surveillance audits run every year and full recertification every three. In between, the ISMS has to keep producing evidence — access reviews done, logs monitored, risks reassessed, an internal audit completed, a management review held.
At enterprise scale there’s a team for that. At startup scale, the person who ran the certification project was usually the CTO between releases, and by the time the certificate arrives, the deal that justified the effort has closed. Ownership evaporates. Twelve months later the surveillance audit asks for a year of operating evidence, and there are three months of it.
That’s the honest trade of being small: the tight scope that made certification cheap also means there’s no slack in the org chart to run it. Decide who owns the ISMS before Stage 2, not after. If the answer is “nobody can”, make that a deliberate resourcing decision now rather than a discovery at the surveillance audit.
One more wrinkle: if your product is AI on top of being a startup, buyers add a second layer of questions about training data, model access and behaviour. That layer has its own page — ISO 27001 for AI companies.
Startups compensate for feeling small by over-documenting. They download enterprise policy templates and end up with a 30-page access control policy for a 12-person team: approval chains that don’t exist, roles nobody holds, review boards that will never meet.
At audit, that’s a liability, not padding. The auditor tests what you wrote. Every claimed process is something you must evidence; every invented role is a nonconformity waiting to be found. Write the system you actually run — short policies, real names, the tools you genuinely use. Small and true beats big and aspirational, in the audit and in the security.
Tools hand you a to-do list. We do the list — and run the security behind it. For a startup that’s the whole point: our governance capability covers the ISMS build, policies and evidence kept live, and the same engagement runs the monitoring, log retention and vulnerability management your auditor expects to see operating — without you hiring for it. Already bought Vanta or Drata? We make it work and run the security it doesn’t. Secure60 is ISO 27001:2022 certified ourselves, and we hold it the way we’d hold yours: as a system that runs, not a plaque.
Are we too small for ISO 27001?
No — small is an advantage. The standard scales to scope: fewer people, systems and suppliers mean shorter answers to the same 93 Annex A controls and a faster audit. Teams smaller than yours certify all the time.
Does our cloud provider's ISO 27001 certificate cover us?
No. It covers their infrastructure — the datacentres, the hardware, their operations. Your configuration, access control, code, data handling and people are your ISMS, and that’s what your auditor assesses.
How long does certification take for a startup?
Less than the published averages, because scope drives the schedule and yours is small. See how long ISO 27001 certification takes for the stage-by-stage timeline.
Do we need a full-time security hire to get certified?
Not to get certified — but someone must own the ISMS afterwards. Surveillance audits are annual and the evidence has to be produced continuously. That owner can be internal, or a provider that runs it for you.
Is a compliance platform enough on its own?
It tracks controls and collects some evidence, but someone still implements the controls, runs the risk assessment and fronts the auditor. See consultant, platform, or one provider that does both.
What will certification cost us?
Startups land at the bottom of the market ranges, because headcount and scope drive every component. See what ISO 27001 actually costs in Australia for the breakdown by company size.