forumNew topic

Do I need to get ISO 27001 certification? Customers are asking for it, but is it very expensive?

BBurcu A***MemberCommunity member
Joined
May 2024
Message
146
#1

A customer asked us for ISO 27001 certification. We currently have no certifications. How much does the certification cost? How many months/years does it take? Is there any benefit to the company or is it just paperwork?

What does ISO 27001 check? What do we need to do regarding our current business? Are there management system changes required?

Who checks if our current network/system configuration meets the certification standards?

DDilara A***Member
Job title
Data entry clerk
Sector
Insurance
Organization type
a company within a holding
Joined
Oct 2024
Message
99
Most Helpful#2

ISO/IEC 27001 Information Security Management System (ISMS) certification. Cost: audit fee $10k-30k (initial), annual surveillance $3k-10k. Timeline: 6-12 months (documentation, implementation, audit cycle). Benefit: customer confidence, competitive advantage, regulatory compliance (GDPR alignment), risk reduction. Audit type: Gap analysis (0-1 month, estimate scope), implementation (3-6 months, policy/procedure documentation, security control deployment), pre-audit (2-4 weeks), certification audit (1-2 weeks, on-site inspection by accredited auditor). Control areas (14 main areas): Asset management, Access control, Cryptography, Physical/environmental security, Operations security, Communications security, System acquisition/development, Supplier relationships, Information security incident management, Business continuity, Compliance. Implementation: Designate ISMS owner, form security committee, document current state (baseline), map to ISO 27001 requirements, remediate gaps (new tools, policy updates), train employees, internal audit, management review, external audit. KVKK alignment: ISO 27001 Technical + Organizational measures fulfill KVKK Article 32 requirement.

RRecep S***Member
Job title
Production planning
Sector
Retail
Organization type
sole proprietorship
Joined
Sep 2023
Message
103
#3

iso 27001 takes 6-12 months costs 15k-30k lira but if the customer wants it go to a consultant they'll guide you. write policies in the company set up access control, do training pass the audit. compliance advantage is huge...

UUğur E***MemberCommunity member
Joined
Jan 2023
Message
17
#4

ISO 27001 implementation roadmap: Months 1-2 (awareness + planning: form security committee, scope ISMS, select CAB - Conformity Assessment Body), Months 3-4 (baseline assessment + gap analysis), Months 5-8 (documentation: Information Security Policy, Asset register, Risk assessment template, Incident response plan, Access control procedures), Months 9-10 (technical controls: 2FA, encryption, network segmentation, logging), Month 11 (internal audit + management review), Month 12 (external audit + certification). Auditor selection: accredited by national accreditation body (Turkey: TÜRKAK). Control evidence: documentation (policies), technical logs (firewall, access events), interview records (employee attestation).

MMurat T***MemberCommunity member
Joined
Apr 2025
Message
53
#5

ISO 27001 if the customer wants it, just do it, competitive advantage. Find a consultant finish in 6-12 months. Can set up a solid system for 20k lira. Then 3k-5k surveillance audit per year... Also ensures compliance with KVKK...

NNagihanMember
Job title
Recruitment Specialist
Organization type
workshop
Joined
May 2024
Message
98
#6

ISMS implementation framework: Plan (scope, stakeholders, timeline), Do (documentation, controls, training), Check (internal audit, management review), Act (corrective actions, continuous improvement). Documentation requirement: 12 mandatory policies (ISMS, access, cryptography, incident response, etc.), plus supporting procedures. Evidence gathering: logs (monthly), audit trails (quarterly), incident reports (as-occurs). Auditor qualifications: accredited by national body (TÜRKAK for Turkey), ISO 27001 Lead Auditor certification required. Cost-benefit: initial investment ($20k) + ongoing (6k/year) vs. customer value (contract wins, reduced breach risk).

MMehmet Y***MemberCommunity member
Joined
Oct 2023
Message
6
#7

I have a question, don't want to go off-topic though. Solutions that work at a small scale collapse when you grow; I learned this late.

Just leaving this note, it might be useful.

OOrhan Z***MemberCommunity member
Joined
May 2023
Message
254
#8

Let me share my experience. Your time to detect an issue directly determines its cost.

Taking measures without an inventory leaves doors you haven't seen open. Proven by experience.

İİlker G***Member
Job title
Board member
Sector
Livestock
Organization type
regional distributor
Joined
Apr 2026
Message
341
#9

Saved.

KKübra B***Member
Job title
Data entry clerk
Sector
Chemistry
Organization type
sole proprietorship
Joined
May 2023
Message
129

Doki · SEO consulting · 2023

#10

i've been down this road let me tell you and the harder it is to reverse a decision, the slower you should make it.

proven by experience.

ŞŞerife K***MemberCommunity member
Joined
Jul 2024
Message
186
#11

My perspective changed after experiencing that. If you get three different answers on a topic, the question was asked wrong.

Just leaving this note, it might be useful.

EElif C***MemberCommunity member
Joined
Feb 2023
Message
374
#12

My perspective changed after experiencing that. Just because everyone does it doesn't mean it's right.

Mistakes made on the security certification iso 27001 cost side are usually reversible but expensive. This is my opinion, I'm not claiming it's absolute truth.

OOsman K***VeteranCommunity member
Joined
Feb 2026
Message
279
#13

let me summarize whats been said so far then when we decide without measuring, we always end up in the same place.

good luck with that.

CCem D***Member
Job title
Human Resources Specialist
Sector
Accounting & advisory
Organization type
8-person team
Joined
Feb 2026
Message
84
#14

Noted, thanks.

NNuri G***MemberCommunity member
Joined
Jun 2025
Message
158
#15

I have a question. The biggest time-waster for us was not knowing who had the final say.

Hasty decisions become decisions you have to fix six months later. This is my opinion, I'm not claiming it's absolute truth.

UUfuk B***MemberCommunity member
Joined
Sep 2024
Message
114
#16

There is something to watch out for. The real issue isn't the number but what it's based on.

If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

CCaner A***Member
Job title
Technical service technician
Sector
Agriculture
Organization type
sole proprietorship
Joined
Nov 2022
Message
157
#17

I'm a small business, let me explain from my side. If you scold false alarms nobody will report again.

Hope this helps.

YYaseminMember
Job title
SME owner
Joined
Jul 2024
Message
98
#18

Let me write how it's done in practice. Solutions that work at a small scale collapse when you grow; I learned this late.

When making a decision, first look at what data you have on hand.

BBurak A***Member
Job title
IT manager
Sector
E-commerce
Organization type
early-stage startup
Joined
May 2023
Message
126
#19

the answer above hits the nail on the head. people defend habits not processes. rseistance comes from there.

if you sccold false alarms, nobody will report again. that's all sorry if I went on too long.

MMerve K***Member
Job title
Clinic manager
Sector
Agriculture
Organization type
sole proprietorship
Joined
Jul 2023
Message
127

Doki · Phishing awareness training · 2024

#20

Let me summarize the topic since several different answers were given. honestly if 2FA is on a stolen password alone is useless.

I'm also curious if anyone does it differently.

Reply