A procurement team asks whether you're ISO 27001 certified. You're not sure what that means, whether you need it, or what saying no will cost you.
This is a plain-language answer. What each certification proves, what it costs, how long it takes, when it's genuinely required, and when it's an expensive way to feel prepared.
What these things actually are
ISO 27001 certifies that you have a management system for information security. That wording matters. It doesn't certify that your software is secure. It certifies that you have a documented, repeatable process for identifying risks, deciding what to do about them, and reviewing that decision periodically.
It's an international standard, recognised everywhere, and it's the default expectation in Europe and the Middle East. An external body audits you and issues a certificate valid for three years, with annual surveillance audits in between.
SOC 2 is an American auditor's report rather than a certificate. An accounting firm examines your controls against five possible criteria — security, availability, processing integrity, confidentiality, privacy — and writes an opinion.
Two flavours, and the distinction is the thing buyers care about:
- Type I — the controls were designed appropriately, as at a point in time. Relatively quick. Buyers know it's the easy one.
- Type II — the controls operated effectively over a period, typically 3–12 months. This is what large customers mean when they say "SOC 2".
The practical difference: ISO 27001 says you have a system for managing security. SOC 2 Type II says an auditor watched your controls work for months. They overlap heavily in the underlying work.
The others you'll encounter: PCI DSS if you handle card data — not optional, it's a contractual requirement from the card networks. HIPAA in US healthcare. TISAX in European automotive. Various national or sector schemes. And the EU AI Act, which isn't a certification but is a regulation with deadlines — more on that below.
What they cost
Real 2026 figures, and note the ranges are wide because size drives everything.
SOC 2 Type II: roughly $30,000–$150,000 all in. Smaller companies commonly $30–50k; large enterprises frequently over $100k.
ISO 27001: audit fees roughly $30–60k, split across the two audit stages. Budget $40–75k for the full three-year cycle at enterprise scale.
Both together: roughly $30–150k in audit fees over 12–24 months. Bundling through one firm typically saves 20–35% versus two separate engagements — worth asking about explicitly.
The cost nobody quotes: your own people. Expect 200–500 hours internally for a first ISO 27001, and 150–400 hours for a first SOC 2 Type II. At loaded cost, that frequently exceeds the audit fee. If your business case only contains the auditor's quote, it's understated by roughly half.
Timelines by size: small organisations (under ~20 people) around 3 months. Mid-size (20–200) around 5–8 months. Large enterprises (200+) 8–20 months.
Plan for 12 months at enterprise scale, and start before you need it. The most expensive version of this is being asked mid-deal.
When you genuinely need one
Clear categories where the answer is yes.
You sell software or services to large enterprises. Their procurement process has a security questionnaire and a certification requirement. No certificate means either no deal or a lengthy exception process that your competitor doesn't need.
You process personal data at scale on someone else's behalf. Your customer is accountable for what you do with it. Certification is how they discharge that responsibility cheaply.
You sell to financial services, healthcare or the public sector. Effectively mandatory. Regulated buyers have supplier requirements they can't waive.
You handle payment cards. PCI DSS isn't a choice.
You're being acquired or raising institutional money. Due diligence will look. Absence isn't fatal but it's a discount.
When you probably don't
Equally clear, and less often said.
You sell to small businesses. They don't ask, and they won't pay more because you have it.
You're pre-product-market-fit. Six figures and a year of attention spent on certification instead of finding customers is a real strategic error. Get the practices right; defer the audit.
Your customers are consumers. They don't read certificates.
You're doing it because a competitor has one. Bad reason. Find out whether your buyers actually ask. Often they don't, and you're solving an imagined objection.
Sharper test: has a real prospect, in a real deal, asked you for it in writing? If yes, it has a price and you can calculate the return. If no, you're buying insurance against an event you haven't observed.
What you get beyond the certificate
Two genuine benefits beyond deal access, and one honest limitation.
It forces decisions you've been deferring. Who has administrator access. What happens when someone leaves. Where backups are and whether restoring them has ever been tested. Most organisations discover several uncomfortable answers during preparation, and fixing them has value independent of the certificate.
It shortens sales cycles. A security questionnaire can add weeks per deal. A certificate replaces much of that with a document. If you're doing volume enterprise sales, this alone can justify the cost.
The limitation, stated plainly: a certificate is not security. It proves you have a process and that an auditor checked it on a given date. Certified organisations get breached. Treating the certificate as the goal rather than the byproduct is how you end up with excellent documentation and poor practice.
How to actually get one
1. Decide which, and don't do both at once. Selling mainly in Europe or the Middle East: ISO 27001. Mainly to US companies, especially tech: SOC 2 Type II. Both markets: start with ISO 27001 and add SOC 2 — the underlying work overlaps substantially and the second is much cheaper than the first.
2. Name an owner with authority. Not an additional duty for someone already at capacity. This person needs to be able to tell an engineering team to change how they work.
3. Do a gap assessment first. A few weeks, modest cost, and it tells you the real scope. Skipping it is how 6-month projects become 18-month projects.
4. Scope tightly. You do not have to certify the whole organisation. Certify the part that serves the customers who are asking. A narrower scope is cheaper, faster, and equally acceptable — as long as it genuinely covers what the customer cares about. Over-scoping is the most common and most expensive mistake.
5. Use tooling, but don't expect it to do the work. Compliance automation platforms genuinely reduce evidence-collection effort. They don't make the decisions or fix the practices.
6. Choose the auditor carefully. They'll be with you for years. Ask for references from companies your size in your sector.
7. Budget for maintenance. Annual surveillance audits for ISO, annual renewal for SOC 2, and continuous evidence collection for both. This is a standing cost, not a project.
The one on the horizon: the EU AI Act
Not a certification, but it belongs in the same budget conversation, and the timeline just moved.
The original deadline for high-risk AI system obligations was 2 August 2026. Under the Digital Omnibus on AI, since confirmed by the Council, standalone high-risk obligations under Annex III now apply from 2 December 2027, a 16-month extension, and high-risk AI embedded in regulated products under Annex I from 2 August 2028.
Three things to take from that:
You have more time than you thought. If you were sprinting toward August 2026, you can breathe.
The obligations themselves didn't change. Documented risk management, data governance, technical documentation, automatic logging, human oversight, and accuracy and robustness safeguards. If you've read this article's earlier sections, you'll notice these overlap heavily with what an ISO 27001 programme already builds. Doing them together is materially cheaper than doing them separately — that's the practical planning insight.
Deferral is not repeal. Prohibited practices have been banned since February 2025 and general-purpose AI transparency requirements since August 2025. Both are already in force.
If you're deploying AI in anything touching credit decisions, insurance underwriting, employment, or access to essential services, this applies to you and the work is substantial. Starting in 2027 will be late.
The transparency provisions are a separate matter, and they are already enforceable. See The EU AI Act Started Enforcing the Easy Part for what applies now and what to close this quarter.
The short version
Get certified if real customers are really asking, in writing. Budget 12 months and the audit fee again in internal time. Scope narrowly. Do ISO 27001 first if you're European, SOC 2 first if you're selling into the US, and the second one afterwards when it's cheap.
And keep the distinction clear: the certificate opens doors. It doesn't make you secure. Those are two separate projects and only one of them ever finishes.
Certification is one line item among several. For how it sits inside a total engagement budget, see What AI and Data Consulting Actually Costs.
Sources: published 2026 cost and timeline data for ISO 27001 and SOC 2 certification from multiple compliance advisory firms — figures are market ranges, not quotes, and vary considerably by scope and auditor. EU AI Act timeline per the Digital Omnibus on AI as confirmed by the Council, and subsequent legal analyses. Cost data accessed 2026-07-26, AI Act timeline updated 2026-08-10. This is general information, not legal advice — confirm your own obligations with qualified counsel.
Fares runs QartMina Labs, an independent backend and AI engineering practice.