Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

SOC 2 & ISO 27001

Can you get ISO 27001 certified without an internal security team?

Reviewed by the Privacy Horizon team · Last reviewed

Quick answer

Yes. ISO 27001 does not require you to employ a dedicated internal security team. It requires an information security management system (ISMS) that is established, owned, and continually improved — work a small company can run with leadership support and outside expertise. Many organizations certify using a virtual CISO and consultants to design the ISMS, document policies, run risk assessments, and prepare for audit, while internal staff handle daily operations. The certification body audits the management system, not your headcount.

On this page

Does ISO 27001 require a dedicated internal security team?

No. ISO 27001 sets no minimum security headcount and never calls for a standalone security department. What it requires is an information security management system (ISMS) — a documented, risk-based way of governing security — together with clear ownership, demonstrable leadership commitment, and evidence that the system operates and improves over time.

The standard asks who is accountable for security, how risks are identified and treated, and whether controls actually work. A two-person company can answer those questions as legitimately as a 2,000-person one, provided the roles, decisions, and evidence are real. Auditors assess the management system you have built, not the size of the team behind it.

  • Leadership commitment and a defined information security policy (Clause 5).
  • A repeatable risk assessment and risk treatment process (Clause 6).
  • Assigned roles and responsibilities — which a small team or an outsourced expert can hold.
  • Operation, monitoring, internal audit, and management review (Clauses 8-10).
  • A Statement of Applicability mapping the Annex A controls you have selected.

How do small companies fill the security expertise gap?

Most small and growing organizations close the gap with fractional expertise and consulting rather than a full-time hire. A virtual CISO (vCISO) supplies the senior security leadership the standard expects — owning the ISMS, setting risk appetite, chairing management reviews, and translating ISO 27001 requirements into a practical program — without the cost of an executive salary.

Alongside that leadership, consultants and your existing staff do the build: scoping the ISMS, running the risk assessment, drafting policies, implementing and documenting controls, and assembling audit evidence. Internal employees still need to participate, because they own the systems and processes being governed — but they do not need to be security specialists. The outside team supplies the methodology and the missing expertise.

  • vCISO: ongoing security leadership, ISMS ownership, risk decisions, and audit liaison.
  • Readiness consulting: gap analysis against ISO 27001 and Annex A control design.
  • Policy and documentation support so the ISMS is auditable, not just aspirational.
  • Technical testing, such as penetration testing, where controls need independent validation.
  • Internal staff: day-to-day operation of controls within their existing roles.

What does the ISO 27001 certification process actually involve?

Certification follows a defined path, and none of its stages depend on having an internal security team. First you scope and build the ISMS, then operate it long enough to generate evidence, then an accredited certification body conducts a two-stage audit. Stage 1 reviews your documentation and readiness; Stage 2 tests whether the ISMS is genuinely implemented and effective.

The certification body must be independent: it audits and certifies, but it cannot build your ISMS or fix gaps for you. That impartiality requirement is why companies separate the roles — an outside advisor or vCISO helps you prepare, and a different accredited body performs the audit. After certification, surveillance audits recur (typically annually) within a three-year recertification cycle, so the program has to keep running. This is where ongoing fractional support is often more practical than a one-time project.

When does an internal security hire eventually make sense?

Outsourced and fractional support is well suited to achieving and maintaining certification, especially early on. As an organization grows, handles more sensitive data, or widens the scope of its ISMS, the volume of day-to-day security work can justify bringing capability in-house — often a security analyst or manager working under continued vCISO or advisory oversight rather than a full standalone team.

A sensible model is hybrid: a vCISO owns strategy, governance, and the audit relationship, while internal staff — dedicated or part-time — run operations. That keeps senior expertise available without forcing a startup to fund a security department before the workload warrants it. The right time to hire is driven by sustained operational load and risk, not by ISO 27001 itself.

What does ISO 27001 readiness cost without an in-house team?

Cost varies widely and turns on factors specific to your organization rather than on whether the team is internal or external. The main drivers are the scope of your ISMS (how many systems, locations, and processes are in scope), your starting maturity, the number of Annex A controls you must implement, and how much remediation the gap analysis surfaces.

Budget separately for two distinct things: readiness work — the consulting, vCISO time, and tooling needed to build and operate the ISMS — and the accredited certification body's audit fees, which the auditor bills directly, not your advisor. The type of engagement matters too: a one-time readiness project costs differently from ongoing fractional support that also covers surveillance audits. Because these variables move the number significantly, we provide a tailored quote after understanding your scope rather than a generic figure.

Frequently asked questions

No. ISO 27001 requires that information security leadership and accountability exist, but it does not mandate a full-time or in-house CISO. A virtual CISO can hold that role, owning the ISMS and demonstrating the leadership commitment the standard expects, while internal staff operate the controls.

Yes. Startups routinely achieve ISO 27001 certification because the standard scales to the size and complexity of the organization. The ISMS only needs to cover your actual scope, and external expertise can supply the methodology and leadership a small team lacks.

No. To preserve impartiality, the accredited certification body that audits and issues your ISO 27001 certificate must be independent and cannot also build or remediate your ISMS. Most organizations use a separate advisor or vCISO for readiness and engage a certification body solely for the audit.

Neither strictly requires an internal security team, and the underlying control work overlaps heavily. SOC 2 reports on controls against the Trust Services Criteria, while ISO 27001 adds a formal management system with ongoing risk assessment and management review. Either can be achieved with outside expertise; the better choice usually depends on which one your customers ask for.

Keep exploring

All SOC 2 & ISO 27001

How Privacy Horizon can help

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.