ISO 27001 cost for SaaS: what is published, stage by stage
No vendor prices ISO 27001 against a funding round, and no accredited certification body publishes a rate card. What a SaaS company can genuinely read is the compliance-platform layer, and only up to roughly 100 people. Below that line there are real published bands. Above it, everything is a private offer. Here is what is published, where it stops, and the scope decisions that actually drive the quote you get.
Updated July 2026
What is published for your stage
Pick a stage to set a headcount, or move the slider directly. We show the compliance-platform list prices published on AWS Marketplace for that band, and we separate them from the parts of a SaaS compliance budget that nobody publishes. The stage is only a shortcut to a headcount: no vendor and no certification body publishes a price against a funding round.
ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope, whether or not they are members of the organisation. For a SaaS company that usually means contractors, fractional staff and agency engineers inside the scope count toward the total.
Published list prices
AWS Marketplace, checked July 2026Each figure below is a separate pricing dimension on a 12-month contract, read off the vendor's public AWS Marketplace listing. AWS publishes no combined total, so where we add two dimensions together we say so and show the working.
Vanta
FLOOR- Essentials Package1-20 employees, per 12-month contract$14,000
Listing says: "Pricing is tiered based on company size and program complexity."
Check the listingDrata
- Platform Feecapacity for a 100 FTE org, per 12-month contract$25,000
- ISO 27001 frameworkper 12-month contract$7,500
Secureframe
- Access the Secureframe Platformup to 100 employees, per 12-month contract$7,500
- First Frameworkchoice of any framework, per 12-month contract$7,500
Sprinto
FLOOR- Starter Platformup to 100 employees, per 12-month contract$7,500
- First Compliance Frameworkstarting at $2,000 each, per 12-month contract$2,000
Listing says: "starting at $2000 each"
Check the listingScytale
FLOOR- Software Platformbundles one framework, per 12-month contract$7,500
Listing says: "starting price (get quote)"
Check the listingQuote-only: the certification audit
We do not print an audit fee for any stage, because no certification body publishes one. Accredited bodies quote per engagement, and the audit-duration tables that shape the quote are published in ISO/IEC 27006-1:2024 Annex C, which ISO sells rather than publishes openly. A stage label carries no pricing information at all: two Series A companies with the same headcount and different scopes are different audits.
What actually drives the number a SaaS company gets quoted:
Which environments sit inside the boundary
Production, staging and development are separate decisions. An environment inside the ISMS scope brings its own access control, change management and logging evidence with it. This is the scope lever a SaaS company controls most directly.
Contractors and fractional staff
ISO/IEC 27006-1:2024 counts people doing work under your control inside the scope whether or not they are employees. A 30-employee company running 20 contractors inside its scope is not a 30-person audit.
Multi-tenancy and the data boundary
An auditor will ask you to demonstrate the tenancy boundary at the application, database and infrastructure layers rather than assume it. Whether that documentation already exists changes the work, not the published price of anything.
Sub-processors inside the scope
The supplier register, supplier risk assessments and contractual evidence are required regardless of stage. The number of vendors you actually run is a function of how you build, not of what you raised.
Regions and delivery mode
Where scoped activity happens, whether multi-site sampling applies, and how much of the audit runs remotely rather than on site. Travel and expenses sit outside audit time and are usually quoted separately.
Where the published bands actually fit a SaaS company
These are the employee bands the vendors themselves publish on their AWS Marketplace listings, read off the listings and checked July 2026. Note what the table does not contain: a column for the audit, and a total. Neither exists in published form.
| Platform | Band the listing publishes | Published dimensions |
|---|---|---|
| Vanta | 1-20 employees, per 12-month contract | $14,000 Essentials PackageThe listing prices packages by employee band rather than naming a separate ISO 27001 framework line. |
| Secureframe | up to 100 employees, per 12-month contract | $7,500 platform, plus $7,500 first frameworkThe First Framework dimension is described as a choice of any framework, so ISO 27001 sits at that figure rather than a framework-specific one. |
| Sprinto | up to 100 employees, per 12-month contract | $7,500 Starter platform, frameworks from $2,000The framework dimension is described on the listing as starting at $2,000 each, so $2,000 is a floor for the ISO 27001 line rather than a fixed figure. |
| Drata | capacity for a 100 FTE org, per 12-month contract | $25,000 platform fee, plus $7,500 ISO 27001Drata's listing prices every framework at the same flat figure: SOC 2, GDPR, ISO 27001, HIPAA, PCI DSS, CCPA, CMMC, MS SSPA and NIST CSF are each listed at $7,500. |
Read off each vendor's public AWS Marketplace listing, checked July 2026. Each figure is a separate 12-month contract dimension; AWS publishes no combined total, so we do not present one. Where a listing calls a figure a starting price it is a floor, and we label it as one.
The published bands run out at roughly 100 people
This is the single most useful thing a growing SaaS company can know about its compliance budget, and it is almost never said plainly. Every published band on this page has a ceiling. Vanta publishes an employee range only for Essentials, at 1-20. Secureframe and Sprinto both publish platform dimensions up to 100 employees. Drata publishes its platform fee as capacity for a 100 FTE organisation. Past those lines the listings simply stop.
So a SaaS company crossing roughly 100 people crosses out of published pricing entirely, on both layers at once. The platform becomes a private offer and the audit was always a private offer. Budgeting for that transition before you hit it is worth more than any estimate anyone could give you for what sits on the other side. See the mid-market page for what changes once you are there.
Why a SaaS ISMS is shaped differently
The production estate is in someone else's data centre. Much of the physical layer in Annex A.7 is inherited from the cloud provider, whose own certifications and shared responsibility documentation your auditor can accept. Inheritance is not a free pass: you document what you inherit, hold the provider's certification evidence, and maintain the supplier relationship that justifies relying on it. What inheritance removes is the implementation work, not the governance work.
The technological controls in Annex A.8 are not inherited at all. Identity and access management, cryptography, secure development, vulnerability management, system monitoring, secure configuration, network controls, backup, logging, and separation of environments are yours regardless of how certified your provider is. The provider secures the infrastructure; the application layer is your responsibility. This is why a cloud-native SaaS does not get a smaller ISMS, it gets a differently weighted one.
And the environment topology turns scope into a live decision rather than a formality. A typical SaaS runs production, staging and development at minimum, often more once you add regions, preview environments, and per-tenant instances. Each one is inside the boundary or outside it, and that decision is the largest lever a SaaS buyer holds over the audit they are quoted for.
The dev, staging and production scope decision
The defensible scope positions are production only, production and staging with development excluded, or all three inside the boundary. We do not publish a cost gradient between them, because pricing that gradient would require the audit-time tables in ISO/IEC 27006-1:2024 Annex C, which ISO sells and we have not read. What we can tell you is how an auditor decides whether your boundary is real.
Does the excluded environment hold customer data?
Anonymised samples derived from real customer data, integration fixtures built from production exports, or customer logs replayed for debugging all count. If the anonymisation is not robust and irreversible, the environment comes into scope.
Can changes flow across the boundary ungated?
If an artefact built in the excluded environment can reach staging or production without a documented change-management gate, the boundary is not real and the auditor will say so.
Is there an access path to in-scope data?
Developer read access to production logs for debugging is the classic example. If people in the excluded environment can reach in-scope data, the exclusion does not hold.
The order of operations matters more than the estimate. Engineer the data and access boundary first, then declare the scope: make development fully synthetic, automate the synthetic-data generation, enforce a deployment gate, and remove standing production-access paths. A scope statement that describes a boundary you have actually built survives Stage 1. A scope statement that describes an intention does not, and a scope revised after Stage 1 is the most common reason a quote moves.
What a SaaS buyer should actually ask for
- Write the scope statement before you contact anyone. Name the environments, the regions, and the products inside the boundary. Every quote you receive is only as comparable as the brief behind it.
- Count contractors. ISO/IEC 27006-1:2024 counts people doing work under your control inside the scope whether or not they are employees. Agency engineers and fractional staff count.
- Ask each body for the audit days it determined. Days are the quantity the standard requires them to determine. A body that will state its days is a body you can hold to a scope.
- Price the full three-year cycle. Initial audit, surveillance in the intervening years, recertification before expiry. A cheap year one with unstated surveillance is not a cheap programme.
- Ask the platform what happens at your next headcount band. The published band you are buying into has a ceiling. Find out what is on the other side of it before you sign a multi-year deal.
- Get travel and expenses quoted separately. They sit outside audit time and are a real line for any on-site work.
SaaS-specific work that budgets routinely miss
Multi-tenancy assumed, not documented
An auditor will ask you to demonstrate the tenancy boundary at the application, database and infrastructure layers rather than take it as read. If that documentation does not exist, it gets written during the audit window by the people least available to write it.
Sub-processor management
ISO 27001 requires a documented supplier register, supplier risk assessments, and contractual evidence of supplier security controls. A SaaS company runs on other people's SaaS, so this register is longer than founders expect and it has to be maintained, not just built.
Scope expansion on the next product
Certify one product, launch a second, and the second is outside your certificate until a scope extension brings it in. The planning question is what the scope statement needs to say in two years, asked before you scope the first audit.
The buyer questionnaire load after certification
A certificate does not end vendor-risk questionnaires; it gives you better answers to them. The response work is ongoing and lands on the same people who ran the implementation. Budget the capacity, not just the project.