Implementation
From $4,500 (Guided)
Fixed-price plans
Powered by ValueMentor
Implement ISO/IEC 27001 with a structured, expert-led approach from Secusy, powered by ValueMentor. Choose a fixed-price implementation plan based on the size and scope of your organization — we help you define your ISMS, assess risks, prepare documentation, identify required controls, review evidence and prepare for the independent certification audit.
The definition
From $4,500 (Guided)
From $2,500 (add-on)
Remote, delivered globally
ValueMentor
Choose a fixed-price plan based on the size and scope of your organization.
For startups and small organizations with an internal implementation owner.
$4,500one-time
Timeline depends on your readiness and evidence turnaround.
For growing organizations wanting hands-on consultant support.
$9,500one-time
Timeline depends on your readiness and evidence turnaround.
For larger or more complex organizations with multi-entity or custom scope.
Custom pricing
Scope, timeline and effort are agreed after discovery.
| Feature | Guided | Complete | Enterprise |
|---|---|---|---|
| Best for | Startups and small organizations with an internal implementation owner | Growing organizations wanting hands-on consultant support | Larger or more complex organizations |
| Employees within certification scope | Up to 50 | Up to 250 | 251+ |
| Legal entities | 1 | 1 | Multiple / Custom |
| Physical locations | 1 | Up to 3 | 4+ / Custom |
| Implementation support period | Up to 3 months | Up to 4 months | Custom |
| Risk assessment | Guided | Consultant-facilitated | Custom |
| ISO 27001 documentation | Template library | Up to 15 customized policies/procedures | Custom |
| Internal audit | Add-on | Scoped |
All plans include a gap assessment, ISMS scope definition, implementation roadmap, control implementation guidance, evidence review and certification readiness review.
Implementation and certification are separate. ISO 27001 certification is performed by an independent certification body, which audits the ISMS and makes the certification decision — ISO itself does not certify organizations. ValueMentor can coordinate the engagement with an independent certification body selected for your project.
For startups and small organizations with an internal implementation owner.
$2,500certification audit add-on
For growing organizations wanting hands-on consultant support.
$4,500certification audit add-on
The certification audit includes the applicable Stage 1 and Stage 2 certification audits for the standard package scope. If you prefer to appoint your own certification body, you can do so and pay its certification fees directly. Certification is subject to successful completion of the independent certification process and closure of applicable nonconformities. Purchasing an implementation service does not guarantee certification.
ISO/IEC 27001 establishes requirements for creating, implementing, maintaining and continually improving an Information Security Management System, or ISMS. The exact controls required depend on your organization's risks, scope, business activities and applicable requirements. Your implementation can include work across areas such as:
How it works
Select Guided or Complete based on the number of employees, legal entities and physical locations within your intended certification scope.
We confirm the certification scope, key stakeholders, business processes, information assets and implementation responsibilities.
We perform a gap assessment against ISO 27001 requirements and establish your implementation roadmap.
Develop the required risk management framework, Statement of Applicability, policies, procedures, registers and supporting ISMS documentation.
Your team implements the required technical and organizational controls based on the identified risks and implementation recommendations.
Submit evidence through the implementation process. Our consultants review it and identify remaining gaps. Complete customers also receive an internal audit as part of the package.
If certification is purchased, ValueMentor coordinates the independent certification audit and supports your organization through Stage 1 and Stage 2.
Your role
Successful ISO 27001 implementation requires participation from your organization. We expect requested information, reviews and actions to normally be completed within five business days. Customer delays may affect the planned implementation and certification timeline but do not increase the consulting effort included within the package.
You will normally provide
Scope boundaries
Unless specifically purchased or stated in your plan, the implementation fee does not include — these services can be separately scoped where required:
Compliance
Many organizations need to satisfy more than one security, regulatory or customer assurance framework. Add cross-framework mapping to your ISO 27001 implementation to understand how your implemented controls relate to additional requirements — this identifies common controls and remaining gaps, but does not by itself establish or guarantee compliance with another framework.
Trust services attestation
Healthcare privacy & security
Payment card data protection
EU network & information security
Digital operational resilience
ISO 27001 requires information security responsibilities to be understood across the organization. Add a Cywareness subscription to provide ongoing cybersecurity awareness and training for employees as part of your wider ISMS program.
ISO 27001 is not a one-time documentation project. Add an ISMS Maintenance subscription for ongoing support with ISMS reviews, risk register updates, policy reviews, internal audits, management review preparation, corrective action tracking and surveillance audit preparation.
Secusy gives you a structured digital path for purchasing and managing your ISO 27001 implementation. ValueMentor provides the cybersecurity and compliance expertise behind the engagement.
Know the standard implementation and certification audit costs before you start.
Clear boundaries around employees, locations, entities, deliverables and implementation period reduce surprises during the project.
Work with cybersecurity and compliance professionals rather than relying only on templates or software.
Manage implementation activities, documentation, evidence and related compliance requirements through Secusy.
Questions