Fixed-price plans

Powered by ValueMentor

Build your ISMS. Prepare for certification. Know your cost upfront.

Implement ISO/IEC 27001 with a structured, expert-led approach from Secusy, powered by ValueMentor. Choose a fixed-price implementation plan based on the size and scope of your organization — we help you define your ISMS, assess risks, prepare documentation, identify required controls, review evidence and prepare for the independent certification audit.

ImplementationFrom $4,500 (Guided)
Certification auditFrom $2,500 (add-on)
DeliveryRemote, delivered globally
Delivered byValueMentor

The definition

What is ISO 27001 implementation?

ISO 27001 implementation is the process of establishing an Information Security Management System that meets the requirements of ISO/IEC 27001. It typically involves defining the ISMS scope, assessing risks, determining appropriate controls, creating required documentation, implementing controls, reviewing evidence, performing internal review activities and preparing for an independent certification audit. ISO/IEC 27001:2022 is the current published edition, with Amendment 1:2024 adding climate-action considerations to the management-system requirements.
  • Implementation

    From $4,500 (Guided)

  • Certification audit

    From $2,500 (add-on)

  • Delivery

    Remote, delivered globally

  • Delivered by

    ValueMentor

ISO 27001 implementation plans

Choose a fixed-price plan based on the size and scope of your organization.

Guided

For startups and small organizations with an internal implementation owner.

$4,500one-time

Package scope
  • Up to 50 employees within certification scope
  • 1 legal entity
  • 1 physical location
  • Up to 3 months implementation support
  • Guided risk assessment
  • ISO 27001 template documentation library
  • Internal audit available as add-on

Timeline depends on your readiness and evidence turnaround.

Enterprise

For larger or more complex organizations with multi-entity or custom scope.

Custom pricing

Suitable for
  • 251+ employees within certification scope
  • Multiple legal entities
  • 4+ physical locations or custom footprint
  • Custom implementation support period
  • Custom risk assessment and documentation scope
  • Scoped internal audit support

Scope, timeline and effort are agreed after discovery.

Compare plans

FeatureGuidedCompleteEnterprise
Best forStartups and small organizations with an internal implementation ownerGrowing organizations wanting hands-on consultant supportLarger or more complex organizations
Employees within certification scopeUp to 50Up to 250251+
Legal entities11Multiple / Custom
Physical locations1Up to 34+ / Custom
Implementation support periodUp to 3 monthsUp to 4 monthsCustom
Risk assessmentGuidedConsultant-facilitatedCustom
ISO 27001 documentationTemplate libraryUp to 15 customized policies/proceduresCustom
Internal auditAdd-onScoped

All plans include a gap assessment, ISMS scope definition, implementation roadmap, control implementation guidance, evidence review and certification readiness review.

Add independent ISO 27001 certification

Implementation and certification are separate. ISO 27001 certification is performed by an independent certification body, which audits the ISMS and makes the certification decision — ISO itself does not certify organizations. ValueMentor can coordinate the engagement with an independent certification body selected for your project.

Guided

For startups and small organizations with an internal implementation owner.

$2,500certification audit add-on

Bundle pricing
  • Implementation — $4,500
  • Certification audit — $2,500
  • Total — $7,000

Complete

For growing organizations wanting hands-on consultant support.

$4,500certification audit add-on

Bundle pricing
  • Implementation — $9,500
  • Certification audit — $4,500
  • Total — $14,000

The certification audit includes the applicable Stage 1 and Stage 2 certification audits for the standard package scope. If you prefer to appoint your own certification body, you can do so and pay its certification fees directly. Certification is subject to successful completion of the independent certification process and closure of applicable nonconformities. Purchasing an implementation service does not guarantee certification.

What we help you implement

ISO/IEC 27001 establishes requirements for creating, implementing, maintaining and continually improving an Information Security Management System, or ISMS. The exact controls required depend on your organization's risks, scope, business activities and applicable requirements. Your implementation can include work across areas such as:

  • ISMS governance and scope
  • Information security risk management
  • Information security policies
  • Asset management
  • Identity and access management
  • People security
  • Supplier security
  • Incident management
  • Business continuity and ICT readiness
  • Backup and recovery
  • Vulnerability management
  • Logging and monitoring
  • Secure development
  • Cloud and infrastructure security
  • Physical security
  • Compliance obligations
  • Measurement and continual improvement

How it works

How ISO 27001 implementation works

  1. Step 1

    Choose your plan

    Select Guided or Complete based on the number of employees, legal entities and physical locations within your intended certification scope.

  2. Step 2

    Kickoff and define your ISMS

    We confirm the certification scope, key stakeholders, business processes, information assets and implementation responsibilities.

  3. Step 3

    Assess your current state

    We perform a gap assessment against ISO 27001 requirements and establish your implementation roadmap.

  4. Step 4

    Build your ISMS

    Develop the required risk management framework, Statement of Applicability, policies, procedures, registers and supporting ISMS documentation.

  5. Step 5

    Implement controls

    Your team implements the required technical and organizational controls based on the identified risks and implementation recommendations.

  6. Step 6

    Review evidence and readiness

    Submit evidence through the implementation process. Our consultants review it and identify remaining gaps. Complete customers also receive an internal audit as part of the package.

  7. Step 7

    Complete the independent certification audit

    If certification is purchased, ValueMentor coordinates the independent certification audit and supports your organization through Stage 1 and Stage 2.

Your role

What you need to provide

Successful ISO 27001 implementation requires participation from your organization. We expect requested information, reviews and actions to normally be completed within five business days. Customer delays may affect the planned implementation and certification timeline but do not increase the consulting effort included within the package.

You will normally provide

  • Appoint an internal ISMS owner or project coordinator
  • Provide requested information about your organization and certification scope
  • Make relevant business and technical stakeholders available
  • Attend scheduled workshops and review meetings
  • Review and approve ISMS documentation
  • Implement recommended technical and organizational controls
  • Collect and upload requested evidence
  • Complete assigned corrective actions
  • Participate in management review and certification activities

Scope boundaries

What is not included

Unless specifically purchased or stated in your plan, the implementation fee does not include — these services can be separately scoped where required:

  • Implementation or configuration of technical security controls
  • Collection of evidence from your systems or departments
  • Penetration testing
  • Vulnerability assessments
  • Software or security product licenses
  • Legal advice
  • Onsite consulting or travel
  • Additional legal entities or locations outside the package boundary
  • Additional policy customization beyond the package allowance
  • Work after the included implementation period
  • Implementation of other compliance frameworks

Compliance

Build once. Reuse your controls across multiple requirements.

Many organizations need to satisfy more than one security, regulatory or customer assurance framework. Add cross-framework mapping to your ISO 27001 implementation to understand how your implemented controls relate to additional requirements — this identifies common controls and remaining gaps, but does not by itself establish or guarantee compliance with another framework.

  • SOC 2

    Trust services attestation

  • HIPAA

    Healthcare privacy & security

  • PCI DSS

    Payment card data protection

  • NIS2

    EU network & information security

  • DORA

    Digital operational resilience

  • Security awareness with Cywareness

    ISO 27001 requires information security responsibilities to be understood across the organization. Add a Cywareness subscription to provide ongoing cybersecurity awareness and training for employees as part of your wider ISMS program.

  • Keep your ISMS working after certification

    ISO 27001 is not a one-time documentation project. Add an ISMS Maintenance subscription for ongoing support with ISMS reviews, risk register updates, policy reviews, internal audits, management review preparation, corrective action tracking and surveillance audit preparation.

Why Secusy + ValueMentor?

Secusy gives you a structured digital path for purchasing and managing your ISO 27001 implementation. ValueMentor provides the cybersecurity and compliance expertise behind the engagement.

Transparent pricing

Know the standard implementation and certification audit costs before you start.

Defined scope

Clear boundaries around employees, locations, entities, deliverables and implementation period reduce surprises during the project.

Expert guidance

Work with cybersecurity and compliance professionals rather than relying only on templates or software.

One platform for your compliance journey

Manage implementation activities, documentation, evidence and related compliance requirements through Secusy.

Questions

Frequently asked questions