An ISMS for SMEs runs into the same expectation as a large enterprise programme, with a fraction of the people. A 30-person company gets sent the same security questionnaire as a 3,000-person one. The buyer rarely adjusts for size.
The good news is that the standard does adjust. An ISMS for SMEs is meant to be proportionate: controls follow your risks, and your risks follow your actual business. A small consultancy with five cloud applications does not need the control set of a bank, and no auditor expects one.
What does not scale down is discipline. Decisions still need recording, access still needs reviewing, and incidents still need logging. Building an information security management system at small scale is mostly about choosing a light structure you can keep running, rather than a heavy one you abandon after certification.
Why Smaller Teams Struggle
Four constraints show up in nearly every small implementation.
- Nobody owns security full time. It sits with an operations lead, a founder or the IT generalist.
- Budgets are tight, so the answer has to use tools you already pay for.
- Roles overlap, which makes textbook separation of duties impossible.
- Templates found online are written for large organisations and collapse under their own weight.
None of these prevent certification. They just rule out the enterprise playbook.
What ISO 27001 Really Requires
Two parts of the standard behave differently, and understanding that saves months.
The management clauses are mandatory regardless of size: context, leadership, planning, risk assessment, competence, documented information, operation, monitoring, internal audit, management review and improvement. A ten-person company still has to do all of them, but the evidence can be short.
The Annex A controls are not a checklist to complete. You select what your risk assessment justifies and record the reasoning in a Statement of Applicability. Excluding a control is legitimate when you can explain why it does not apply, which is exactly how the risk treatment plan is meant to work.
For a small business, a realistic risk register might hold 15 to 30 entries rather than 200. Depth matters more than volume. Auditors read a short register that clearly reflects the business far more favourably than a long generic one.
Scaling Controls Without a Security Team

Separation of Duties With Few People
With six staff you cannot fully separate every conflicting duty. Say so, and apply a compensating control instead: owner review of payments, dual approval for high-risk changes, and logging that a second person actually checks.
Documented compensating controls pass audit. Silent gaps do not.
Using the Platforms You Already Pay For
Most small companies run on cloud services that already include multi-factor authentication, device management, logging, retention rules and admin alerts, often unused.
Turning those on is usually cheaper and faster than buying new tools. Build your access control around one identity provider so joiners and leavers are handled in one place rather than fifteen.
A Lean Document Set
You do not need forty policies. Most small businesses run well on a single top-level policy plus a handful of short standards covering access, devices, incidents, suppliers and backups.
Keep information security policies to a couple of pages each, written in language your team will actually follow. Long documents copied from a template are the most common cause of second-year drift.
Awareness That Fits the Team
Formal training programmes are optional. Evidence of competence is not.
Short quarterly sessions, a phishing test and a documented induction check are enough for most small firms. Record attendance, because security awareness evidence is one of the first things auditors sample.
Want a starting structure instead of a blank spreadsheet? Try Effivity for Free and build your register in an afternoon.
Cost, Effort and Timeline
Certification cost is driven mainly by audit days, which follow headcount and scope complexity. Small, focused scopes are genuinely cheaper.
Typical effort for a company under 50 people runs three to six months from start to certification audit, with one part-time owner and occasional help. The bigger line item is usually attention, not money, and it concentrates in the first eight weeks.
Software costs vary, but a system that keeps records straight prevents the far larger cost of rebuilding evidence before every audit. Effivity's pricing is structured for smaller teams as well as large ones.
A Realistic Starting Path
- Define a tight scope covering the service customers care about.
- List information assets, including cloud applications and the data in them.
- Assess risks in a working session with the people who run the business, using a simple gap analysis to spot what is missing.
- Decide treatments, then record accepted risks with a named owner.
- Turn on the platform controls you already have, and close obvious gaps.
- Write the short policy set and get it approved.
- Run one internal audit and one management review before booking certification.
Independence is the one place to spend a little. Someone who did not build the system should audit it, which for a small team usually means an external reviewer for a day or two.
Where Small Businesses Slip
Three patterns repeat.

Over-documenting at the start. A template pack arrives, gets partly edited, and describes a company that does not exist. Auditors spot the mismatch immediately.
Certification as the finish line. The certificate arrives, the register stops moving, and access reviews quietly lapse. Surveillance audits are specifically designed to find that.
Supplier oversight left out. Small firms depend heavily on outside providers, yet third party and vendor security checks are often the thinnest part of the system. A short review of your five most critical suppliers is enough to start.
Keeping It Running With a Small Team
The real test is month fourteen, when the project energy has gone and the surveillance audit is approaching.
Effivity's information security management software is built to carry that load without extra headcount: an asset register, risk assessment and treatment, Statement of Applicability controls, incident management, supplier reviews with reminder dates, training records, audit management and document control with version history. All 93 Annex A controls are available out of the box, so you start from a structure rather than a blank page.
Get a Free Personalized Demo to see how it works at your size.
Frequently Asked Questions
Yes. The standard scales with risk and scope, and small companies certify regularly with a lean control set and short documentation.
Usually three to six months from start to certification audit, depending on scope, existing practices and how much time the owner can give.
No. Most small companies assign an existing manager as ISMS owner, with senior support and occasional external help.
Often one main policy plus five or six short standards. Fewer, shorter documents that people follow beat a large unused template pack.
Record the limitation and apply compensating controls such as owner review, dual approval and monitored logs. Documented gaps are acceptable.
If customers ask security questions before signing, usually yes. It shortens sales cycles and replaces repeated questionnaire work.