Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

ISO 27001 cost for SaaS: what is published, stage by stage

No vendor prices ISO 27001 against a funding round, and no accredited certification body publishes a rate card. What a SaaS company can genuinely read is the compliance-platform layer, and only up to roughly 100 people. Below that line there are real published bands. Above it, everything is a private offer. Here is what is published, where it stops, and the scope decisions that actually drive the quote you get.

Updated July 2026

What is published for your stage

Pick a stage to set a headcount, or move the slider directly. We show the compliance-platform list prices published on AWS Marketplace for that band, and we separate them from the parts of a SaaS compliance budget that nobody publishes. The stage is only a shortcut to a headcount: no vendor and no certification body publishes a price against a funding round.

1500+

ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope, whether or not they are members of the organisation. For a SaaS company that usually means contractors, fractional staff and agency engineers inside the scope count toward the total.

Published list prices

AWS Marketplace, checked July 2026

Each figure below is a separate pricing dimension on a 12-month contract, read off the vendor's public AWS Marketplace listing. AWS publishes no combined total, so where we add two dimensions together we say so and show the working.

Vanta

FLOOR
  • Essentials Package1-20 employees, per 12-month contract$14,000

Listing says: "Pricing is tiered based on company size and program complexity."

Check the listing

Drata

  • Platform Feecapacity for a 100 FTE org, per 12-month contract$25,000
  • ISO 27001 frameworkper 12-month contract$7,500
Our sum of the 2 published dimensions$32,500
Check the listing

Secureframe

  • Access the Secureframe Platformup to 100 employees, per 12-month contract$7,500
  • First Frameworkchoice of any framework, per 12-month contract$7,500
Our sum of the 2 published dimensions$15,000
Check the listing

Sprinto

FLOOR
  • Starter Platformup to 100 employees, per 12-month contract$7,500
  • First Compliance Frameworkstarting at $2,000 each, per 12-month contract$2,000
Our sum of the 2 published dimensions$9,500

Listing says: "starting at $2000 each"

Check the listing

Scytale

FLOOR
  • Software Platformbundles one framework, per 12-month contract$7,500

Listing says: "starting price (get quote)"

Check the listing

Quote-only: the certification audit

We do not print an audit fee for any stage, because no certification body publishes one. Accredited bodies quote per engagement, and the audit-duration tables that shape the quote are published in ISO/IEC 27006-1:2024 Annex C, which ISO sells rather than publishes openly. A stage label carries no pricing information at all: two Series A companies with the same headcount and different scopes are different audits.

What actually drives the number a SaaS company gets quoted:

  • Which environments sit inside the boundary

    Production, staging and development are separate decisions. An environment inside the ISMS scope brings its own access control, change management and logging evidence with it. This is the scope lever a SaaS company controls most directly.

  • Contractors and fractional staff

    ISO/IEC 27006-1:2024 counts people doing work under your control inside the scope whether or not they are employees. A 30-employee company running 20 contractors inside its scope is not a 30-person audit.

  • Multi-tenancy and the data boundary

    An auditor will ask you to demonstrate the tenancy boundary at the application, database and infrastructure layers rather than assume it. Whether that documentation already exists changes the work, not the published price of anything.

  • Sub-processors inside the scope

    The supplier register, supplier risk assessments and contractual evidence are required regardless of stage. The number of vendors you actually run is a function of how you build, not of what you raised.

  • Regions and delivery mode

    Where scoped activity happens, whether multi-site sampling applies, and how much of the audit runs remotely rather than on site. Travel and expenses sit outside audit time and are usually quoted separately.

Where the published bands actually fit a SaaS company

These are the employee bands the vendors themselves publish on their AWS Marketplace listings, read off the listings and checked July 2026. Note what the table does not contain: a column for the audit, and a total. Neither exists in published form.

PlatformBand the listing publishesPublished dimensions
Vanta1-20 employees, per 12-month contract$14,000 Essentials PackageThe listing prices packages by employee band rather than naming a separate ISO 27001 framework line.
Secureframeup to 100 employees, per 12-month contract$7,500 platform, plus $7,500 first frameworkThe First Framework dimension is described as a choice of any framework, so ISO 27001 sits at that figure rather than a framework-specific one.
Sprintoup to 100 employees, per 12-month contract$7,500 Starter platform, frameworks from $2,000The framework dimension is described on the listing as starting at $2,000 each, so $2,000 is a floor for the ISO 27001 line rather than a fixed figure.
Dratacapacity for a 100 FTE org, per 12-month contract$25,000 platform fee, plus $7,500 ISO 27001Drata's listing prices every framework at the same flat figure: SOC 2, GDPR, ISO 27001, HIPAA, PCI DSS, CCPA, CMMC, MS SSPA and NIST CSF are each listed at $7,500.

Read off each vendor's public AWS Marketplace listing, checked July 2026. Each figure is a separate 12-month contract dimension; AWS publishes no combined total, so we do not present one. Where a listing calls a figure a starting price it is a floor, and we label it as one.

The published bands run out at roughly 100 people

This is the single most useful thing a growing SaaS company can know about its compliance budget, and it is almost never said plainly. Every published band on this page has a ceiling. Vanta publishes an employee range only for Essentials, at 1-20. Secureframe and Sprinto both publish platform dimensions up to 100 employees. Drata publishes its platform fee as capacity for a 100 FTE organisation. Past those lines the listings simply stop.

So a SaaS company crossing roughly 100 people crosses out of published pricing entirely, on both layers at once. The platform becomes a private offer and the audit was always a private offer. Budgeting for that transition before you hit it is worth more than any estimate anyone could give you for what sits on the other side. See the mid-market page for what changes once you are there.

Why a SaaS ISMS is shaped differently

The production estate is in someone else's data centre. Much of the physical layer in Annex A.7 is inherited from the cloud provider, whose own certifications and shared responsibility documentation your auditor can accept. Inheritance is not a free pass: you document what you inherit, hold the provider's certification evidence, and maintain the supplier relationship that justifies relying on it. What inheritance removes is the implementation work, not the governance work.

The technological controls in Annex A.8 are not inherited at all. Identity and access management, cryptography, secure development, vulnerability management, system monitoring, secure configuration, network controls, backup, logging, and separation of environments are yours regardless of how certified your provider is. The provider secures the infrastructure; the application layer is your responsibility. This is why a cloud-native SaaS does not get a smaller ISMS, it gets a differently weighted one.

And the environment topology turns scope into a live decision rather than a formality. A typical SaaS runs production, staging and development at minimum, often more once you add regions, preview environments, and per-tenant instances. Each one is inside the boundary or outside it, and that decision is the largest lever a SaaS buyer holds over the audit they are quoted for.

The dev, staging and production scope decision

The defensible scope positions are production only, production and staging with development excluded, or all three inside the boundary. We do not publish a cost gradient between them, because pricing that gradient would require the audit-time tables in ISO/IEC 27006-1:2024 Annex C, which ISO sells and we have not read. What we can tell you is how an auditor decides whether your boundary is real.

Does the excluded environment hold customer data?

Anonymised samples derived from real customer data, integration fixtures built from production exports, or customer logs replayed for debugging all count. If the anonymisation is not robust and irreversible, the environment comes into scope.

Can changes flow across the boundary ungated?

If an artefact built in the excluded environment can reach staging or production without a documented change-management gate, the boundary is not real and the auditor will say so.

Is there an access path to in-scope data?

Developer read access to production logs for debugging is the classic example. If people in the excluded environment can reach in-scope data, the exclusion does not hold.

The order of operations matters more than the estimate. Engineer the data and access boundary first, then declare the scope: make development fully synthetic, automate the synthetic-data generation, enforce a deployment gate, and remove standing production-access paths. A scope statement that describes a boundary you have actually built survives Stage 1. A scope statement that describes an intention does not, and a scope revised after Stage 1 is the most common reason a quote moves.

What a SaaS buyer should actually ask for

  1. Write the scope statement before you contact anyone. Name the environments, the regions, and the products inside the boundary. Every quote you receive is only as comparable as the brief behind it.
  2. Count contractors. ISO/IEC 27006-1:2024 counts people doing work under your control inside the scope whether or not they are employees. Agency engineers and fractional staff count.
  3. Ask each body for the audit days it determined. Days are the quantity the standard requires them to determine. A body that will state its days is a body you can hold to a scope.
  4. Price the full three-year cycle. Initial audit, surveillance in the intervening years, recertification before expiry. A cheap year one with unstated surveillance is not a cheap programme.
  5. Ask the platform what happens at your next headcount band. The published band you are buying into has a ceiling. Find out what is on the other side of it before you sign a multi-year deal.
  6. Get travel and expenses quoted separately. They sit outside audit time and are a real line for any on-site work.

SaaS-specific work that budgets routinely miss

Multi-tenancy assumed, not documented

An auditor will ask you to demonstrate the tenancy boundary at the application, database and infrastructure layers rather than take it as read. If that documentation does not exist, it gets written during the audit window by the people least available to write it.

Sub-processor management

ISO 27001 requires a documented supplier register, supplier risk assessments, and contractual evidence of supplier security controls. A SaaS company runs on other people's SaaS, so this register is longer than founders expect and it has to be maintained, not just built.

Scope expansion on the next product

Certify one product, launch a second, and the second is outside your certificate until a scope extension brings it in. The planning question is what the scope statement needs to say in two years, asked before you scope the first audit.

The buyer questionnaire load after certification

A certificate does not end vendor-risk questionnaires; it gives you better answers to them. The response work is ongoing and lands on the same people who ran the implementation. Budget the capacity, not just the project.

Per-platform published pricing

Frequently asked questions

How much does ISO 27001 cost for a SaaS company?
Nobody publishes a total, and no vendor prices ISO 27001 against a funding stage. What is published is the compliance-platform layer, and only for smaller bands. Vanta lists a $14,000 Essentials package for a 1-20 employee band on AWS Marketplace. Secureframe lists $7,500 for platform access up to 100 employees plus $7,500 for a first framework. Sprinto lists $7,500 for its Starter platform up to 100 employees, with frameworks from $2,000. Drata lists a $25,000 platform fee for capacity for a 100 FTE organisation plus $7,500 for ISO 27001. All checked July 2026. The certification audit itself is quoted per engagement and no accredited body publishes a rate card.
Does the dev environment need to be in ISO 27001 scope?
It depends on whether the boundary is real, and this is the scope question SaaS founders most often get wrong. An auditor probes it three ways. Does the excluded environment contain customer data, including samples derived from real data without robust irreversible anonymisation? Can a change flow from the excluded environment into an in-scope environment without a documented gate? Do people working in the excluded environment have an access path to in-scope data, for example read access to production logs for debugging? If any answer undermines the boundary, the environment comes into scope. We do not publish a percentage for what that costs, because the audit-time tables that would price it are not published.
Is ISO 27001 cheaper than SOC 2 for a SaaS company?
On published platform pricing, neither is dearer. Drata's AWS Marketplace listing prices every framework at the same flat $7,500, ISO 27001 included alongside SOC 2, and Secureframe's first-framework dimension is described as a choice of any framework. The audit layers are not comparable on published data at all, because ISO 27001 certification bodies and SOC 2 CPA firms both quote per engagement. The framework choice is driven by which buyers are asking, not by a published price difference.
Does a cloud-native SaaS need fewer ISO 27001 controls?
Not fewer, but a different mix. Annex A has 93 controls across four themes in the 2022 revision. A cloud-native SaaS inherits much of the physical layer in Annex A.7 from its cloud provider, but inheritance is not a free pass: you still document what you inherit, hold the provider's certification evidence, and maintain the supplier relationship. The technological controls in Annex A.8 are not inherited. Identity, cryptography, secure development, vulnerability management, logging and monitoring, and separation of environments are yours to implement whatever your provider is certified for.
Why do the published platform prices stop around 100 employees?
Because the listings stop there. Vanta publishes an employee band only for its Essentials package at 1-20. Secureframe and Sprinto both publish platform dimensions up to 100 employees. Drata publishes its platform fee as capacity for a 100 FTE organisation. Above roughly 100 people every one of these moves to a private offer, so there is no published figure for us to report. That is a finding rather than a gap, and it means a scale-up SaaS is negotiating both its platform and its audit privately.
Do contractors count toward the audit headcount?
Yes, if they are inside the ISMS scope. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation. For SaaS companies this matters more than for most: agency engineers, fractional security leads, contract designers and offshore development partners inside the scope all count. Undercounting here is the most common reason a quote gets revised upward after Stage 1.

Related reading

Updated July 2026