ISO 27001 for MSPs: a practical guide

What ISO 27001 certification involves for MSPs, realistic costs, how long it takes, and how it sits alongside Cyber Essentials and CAF.

ISO 27001 is the most-named, least-understood compliance framework in the MSP world. UK MSPs hear about it from prospects, from clients, from insurers, from peers, and most never read past the marketing.

Here's what ISO 27001:2022 actually is, what it tests, what it costs, and where it fits in the broader proof landscape MSPs now operate in.

What is ISO 27001 actually testing?

ISO 27001:2022 is an international standard for an Information Security Management System. The standard is published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The "2022" is the latest version, released October 2022, replacing the 2013 version (with a transition deadline of October 2025).

The standard tests two things.

The Information Security Management System itself

That means the documented set of policies, processes, and review cycles your business uses to manage information security risk. Risk register, risk treatment plan, statement of applicability, internal audit programme, management review cadence, corrective action process. The ISMS is the management system. It's the meta-layer that runs the controls.

93 Annex A controls

These are organised into 4 themes: organisational (37 controls), people (8), physical (14), and technological (34). Each control is a thing the standard expects you to either implement, partially implement, or formally exclude with justification. The Statement of Applicability is where you document which controls apply and how.

The 2022 update reduced the 2013 control list (114 controls) into the 4 simplified themes and added 11 new controls (mostly cloud, threat intelligence, secure development, data masking, ICT readiness for business continuity).

ISO 27001 is risk-based. There's no fixed list of "you must have MFA." The standard asks you to identify your risks and select controls that mitigate them. Annex A is the menu of available controls.

Who actually needs ISO 27001 if they're an MSP?

Three categories of MSP.

Category 1: MSPs serving regulated or enterprise clients

If your client base includes financial services, healthcare, legal, government, or anything that procures via formal supplier risk frameworks, ISO 27001 is increasingly a hard requirement on tenders. Without it you don't get past the procurement gate.

Category 2: MSPs preparing for sale or significant external investment

Due diligence on an MSP exit looks different now than 5 years ago. ISO 27001 is the cleanest way to demonstrate operational maturity to a buyer. The cost of getting certified is small relative to the valuation impact at exit (most MSP brokers cite a 0.5x to 1.5x EBITDA multiple uplift for well-run, certified businesses).

Category 3: MSPs hitting £8m+ ARR who are about to compete in NIS2 or DORA scope

As UK and EU regulation matures, ISO 27001 becomes the de facto baseline for "you're serious."

The MSPs who don't need it yet: under £2m ARR, owner-led, mid-market commercial client base, no immediate exit plan. Cyber Essentials Plus is enough at that stage, and the operational return on ISO 27001 doesn't yet justify the investment.

(The Assurix Trustmark sits next to ISO 27001 with a different design. It's MSP-specific and faster to achieve, with continuous monitoring between annual audits. Many MSPs run both: Trustmark for live operational proof, ISO 27001 for procurement gates. They cover overlapping but distinct ground.)

How long does ISO 27001 actually take to get?

For most UK MSPs, 6 to 12 months end to end on a first attempt.

The common timeline:

The MSPs that finish in 6 months are usually the ones who already have a strong evidence trail and good operational discipline. The MSPs that take 12+ months are usually trying to build the ISMS from scratch in parallel with running the business, with no dedicated owner.

The single biggest predictor of timeline is whether you assign a named ISMS owner with at least 30% of their week protected for it. Without that, ISO 27001 stretches.

Score your readiness in 2 minutes

12 questions. 5 minutes. See where your MSP stands.

Score your readiness in 2 minutes

What's the difference between ISO 27001 and Cyber Essentials Plus?

Three differences that matter commercially.

Scope

CE+ is a narrow technical baseline of 5 controls (firewalls, malware, patching, access control, secure config). ISO 27001 covers all 93 Annex A control areas plus the management system around them. CE+ tests configuration. ISO 27001 tests configuration plus governance plus risk management plus continuous improvement.

Recognition

CE+ is UK-only and recognised mostly within UK government and UK supply chain procurement. ISO 27001 is international and recognised by insurers, multinationals, and procurement teams across the EU, US, and beyond.

Audit method

CE+ is a hands-on technical test. An assessor runs scans, reviews configs, validates 6 things over 1-2 days. ISO 27001 is a process audit. An auditor reviews documentation, interviews staff, samples evidence over 4-10 days depending on business size.

Cost and time

CE+ is roughly £1,500 to £3,000 per year and takes 4 to 8 weeks to achieve. ISO 27001 is roughly £8,000 to £25,000 per year (audit cost plus internal time) and takes 6 to 12 months on first pass.

The right answer is usually both. CE+ is the floor. You need it for any UK procurement gate that mentions cyber. ISO 27001 is the layer above. You get it when the client base or the regulatory scope demands it.

(The Assurix Trustmark is a third option, MSP-specific. It's a separate certification with continuous live monitoring between annual audits. 100 percent required to pass, no partial credit. Aligned with the NCSC Cyber Assessment Framework, plus operational maturity controls. MSPs hold it for the commercial signal it sends to MSP buyers.)

How much does ISO 27001 cost an MSP?

Three cost layers.

Layer 1: Certification body fees

£4,000 to £15,000 per year depending on body and business size. UKAS-accredited bodies (Lloyd's Register, BSI, DNV, NQA, etc.) cost more than non-accredited bodies, but the certificate is more credible. For most MSPs, UKAS-accredited is the right answer.

Layer 2: Internal time

200 to 600 hours over the first year, roughly half of that loaded onto whoever owns the ISMS. After year 1, ongoing internal time drops to roughly 100 to 200 hours per year.

Layer 3: Tooling and consultancy

Most MSPs use either a dedicated ISO consultant (£8,000 to £20,000 one-off) or a GRC platform (£5,000 to £15,000 per year). Some do it themselves on SharePoint, but the time cost climbs.

Total first-year cost for an MSP getting ISO 27001 from scratch: typically £20,000 to £50,000 fully loaded. Year 2 and onwards drops to £10,000 to £20,000 per year for ongoing maintenance.

The financial return shows up in 3 places: tender wins, supplier-risk pass-throughs, and (anecdotally) cyber insurance renewal pricing. Most MSPs we work with at Assurix recoup the first-year cost within 2 to 3 deals.

Should an MSP get ISO 27001 or the Trustmark first?

Depends entirely on the client base.

If the client mix skews towards UK-procurement-led, regulated, or enterprise buyers, ISO 27001 first. The procurement gate is harder, and ISO is the lingua franca.

If the client mix skews towards SME, mid-market, owner-managed, Trustmark first. The Trustmark is MSP-specific and signals operational maturity in a way SMEs actually understand. ISO 27001 doesn't move the needle in that conversation.

If the answer is genuinely "both," Trustmark first because it's faster (4 to 8 weeks of effective effort vs 6 to 12 months) and the policy work it forces will compound into ISO 27001 readiness.

Pure cost optimisation isn't the right frame. The frame is which signal moves your specific buyer.

Frequently asked questions

Is ISO 27001 a one-off cost or ongoing?

Ongoing. Annual surveillance audits and a full re-audit every 3 years. Plus internal time on the ISMS continuously.

Can I claim ISO 27001 readiness while pursuing certification?

Yes, but be specific. "We're working towards ISO 27001 with target certification Q4 2026" is fair. "We're ISO 27001 aligned" is meaningless and most procurement teams will see through it.

Does ISO 27001 cover GDPR compliance?

Partially. ISO 27001 controls cover the security half of GDPR (data protection by design, breach response, supplier due diligence). It doesn't cover the legal half (lawful basis, data subject rights, data protection impact assessments). You need both.

Can I drop CE+ once I have ISO 27001?

Generally no. UK government procurement still asks for CE+ specifically. Holding both costs around £2,000 a year extra and saves you the procurement headache.

What's the certification body market like?

Concentrated. Lloyd's Register, BSI, DNV, NQA, BAB, Bureau Veritas cover the bulk of UK MSP certifications. Get 3 quotes, ask about lead time on Stage 2 audits, check their prior MSP-vertical experience.

The closing principle

Pick the certification that matches the buyer in front of you, do the work properly, and treat the audit as a forcing function for operational discipline. The fastest way to keep the discipline current between certificates is to let a Trustmark do the live measurement. That's what Assurix is for.

Score your readiness

12 questions. 5 minutes. See where your MSP stands.

Score your readiness

Related reading