The verdict in three sentences
Achieving ISO 27001 certification for a B2B SaaS in Dublin means an investment of EUR 43,000 to 118,000 excl. VAT in 2026, split between consulting, the certification audit and technical work. The realistic timeline is 6 to 12 months, because the auditor requires evidence that the system has been running for several months, not just documents. For a vendor losing enterprise tenders, the stake is often EUR 50,000 to 300,000 of deals unlocked per year.
Why enterprise buyers now require it
In 2026, procurement teams and CISOs at large groups demand verifiable security from their SaaS suppliers. The NIS 2 directive pushes in-scope entities to control their supply chain, and the 200-question security questionnaire is often replaced by a simple requirement: a valid ISO 27001 certificate, or disqualification. A SaaS without certification can stay in the race with a very thorough file, but each tender then costs 5 to 15 days of answers and client audits.
The full budget, item by item
| Item | 2026 range (excl. VAT) | Scope |
|---|---|---|
| Consulting (consultant or firm) | EUR 15,000 to 40,000 | Risk assessment, statement of applicability, policies, internal audit |
| Compliance platform (optional) | EUR 6,000 to 15,000/year | Control tracking, automatic evidence collection |
| Technical work | EUR 20,000 to 60,000 | Logging, encryption, access, DR plan, hardening |
| Certification audit (stages 1 and 2) | EUR 8,000 to 18,000 | Accredited body, 4 to 8 audit days |
| Surveillance audits (years 2 and 3) | EUR 4,000 to 8,000/year | Keeping the certificate |
| Internal time | 0.3 to 0.5 FTE for 6 to 12 months | Security lead, CTO, team |
| Total first year | EUR 43,000 to 118,000 | Excluding internal time |
The range depends mostly on starting maturity. A SaaS already hosted on a major cloud, with CI/CD and tested backups, sits at the low end. A product born as an MVP, with shared production access and no centralised logging, starts at the high end.
The technical work that weighs most
ISO 27001:2022 lists 93 security controls in its Annex A. For a SaaS vendor, a handful of them account for most of the technical effort.
| Workstream | Annex A requirement | What must be delivered | Indicative cost (excl. VAT) |
|---|---|---|---|
| Logging and monitoring | A.8.15, A.8.16 | Centralised logs, kept 12 months, alerts | EUR 5,000 to 15,000 |
| Access management | A.5.15 to A.5.18, A.8.2 | SSO, MFA, quarterly access review, logged production access | EUR 4,000 to 12,000 |
| Encryption | A.8.24 | Data at rest and in transit, key management | EUR 3,000 to 8,000 |
| Backups and DR | A.8.13, A.5.30 | Tested restore, RTO 4 h, RPO 1 h | EUR 4,000 to 15,000 |
| Secure development | A.8.25 to A.8.29 | Code review, dependency scanning, security testing | EUR 3,000 to 7,000 |
| Penetration test | A.8.8 | Annual application pentest | EUR 5,000 to 12,000 |
An often underestimated point: the auditor asks for operating evidence. An access review must have been done, dated and logged, and a restore test must have taken place. That is why you need 3 months of running the management system before the certification audit.
Mini case study
Ciara, founder of a Dublin SaaS for supplier contract management (EUR 2.1 million of annual recurring revenue), lost 4 tenders in one year for lack of certification, worth EUR 260,000 a year in total.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Her budget: EUR 28,000 of consulting, EUR 38,000 of technical work (logging, SSO and MFA, DR plan, pentest), EUR 12,000 of audit, i.e. EUR 78,000 excl. VAT in year one, then EUR 6,000 a year for surveillance. If she wins only 2 of 4 similar-sized deals, about EUR 130,000 a year of recurring revenue, the project pays back within 7 to 8 months after certification. She also cuts time spent on client security questionnaires by about 60%. A 2026 order of magnitude, depending on the real win rate.
FAQ
Can you get certified in under 6 months?
It is possible for an already mature SaaS, with a minimum of 3 months of running the system before the audit. In practice, 6 to 9 months is the most common timeline for a team of 15 to 50 people.
ISO 27001 or SOC 2?
In Europe, ISO 27001 is the standard expected by 80% of enterprise buyers. SOC 2 is mainly requested by North American clients. The two share about 70% of their controls.
Is an automated compliance platform essential?
No, but it saves 30 to 40% of evidence collection time for EUR 6,000 to 15,000 a year. It pays off beyond 20 employees.
Is a certified hosting provider enough?
No. The certification of AWS, Azure or OVHcloud covers the infrastructure, not your application, access or processes. It does however reduce the scope by 15 to 20 controls.
What does keeping the certificate cost?
Budget EUR 4,000 to 8,000 a year for surveillance audits, plus internal time and an annual pentest of EUR 5,000 to 12,000. Full recertification happens every 3 years.
Let's scope your project. We assess your gap against ISO 27001 and price the technical workstreams (indicative budget of EUR 20,000 to 60,000 excl. VAT, 6 to 12 months to certification). Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.