| Company headcount | ISO 27001 full package (from) | What determines the final price |
|---|---|---|
| 1–20 employees | $12,500 | Additional services selected |
| 21–100 employees | $18,750 | Additional services selected |
| 101+ employees | Custom quote | Scope and additional services |
The full ISO 27001 package — complete implementation plus the certification audit, run in structured spreadsheets with no GRC software — starts at $12,500 for companies with 1–20 employees and from $18,750 for companies with 21–100 employees; companies with 101 or more employees receive a custom quote. Final pricing depends on the additional services you select.
Agency is a master reseller of Vanta and Drata, has served 1,000+ companies, is rated 4.9/5 on G2, and operates a U.S.-based team.
GRC platforms automate evidence collection, and for many teams that automation is worth every dollar. But platforms carry a recurring subscription plus their own implementation, upkeep, and integration-maintenance overhead — connectors break, dashboards need triage, and someone still owns the work the platform surfaces.
Spreadsheet-based compliance trades software spend for employee time: a team member uploads evidence continuously into structured workbooks Agency provides and maintains. For a company with a stable stack and a single framework, that trade often wins outright. For fast-growing teams with many integrations or multiple frameworks, platform economics usually win — in which case see Vanta pricing through Agency and Drata pricing through Agency for the platform path. There is no wrong answer here, only a math problem specific to your team.
Full implementation of ISO/IEC 27001:2022 — ISMS scoping, risk assessment, the Statement of Applicability, policies, and controls — delivered and maintained in structured workbooks Agency provides.
The certification audit path is part of the package: Stage 1 and Stage 2 certification audits and first-year certification-body fees are included in the package price, with final pricing depending on the additional services you select. Your certificate is issued by an independent accredited certification body — ISO develops the standard; accredited certification bodies certify against it.
Small teams with a stable stack that need the certificate, not another subscription — from $12,500 all-in.
Established teams that prefer employee-run evidence over integration upkeep — from $18,750 all-in.
Larger organizations where scope drives the number — custom-quoted.
Three things: additional services (penetration testing, extra assessments), scope complexity (locations, products, data classes inside the ISMS boundary), and additional standards run alongside ISO/IEC 27001:2022. The headcount band sets the floor; the Order Form states exactly what your number includes.
Published “from” prices are the lowest currently available price for the defined qualifying scope — the headcount bands shown — not a typical or guaranteed price. Final pricing is confirmed in your Order Form/SOW, and per the published program terms, a fully executed MSA and Order Form/SOW are required before any benefit under the Program can be claimed.
15-person company: full ISO/IEC 27001:2022 implementation plus Stage 1 and Stage 2 certification audits, from $12,500 — everything in Agency-provided spreadsheets, no platform subscription.
60-person company: the same full package from $18,750 (≈+50% over the 1–20 band), with the final number set by the additional services selected.
The platform route means a recurring GRC subscription plus implementation plus the audit, bought separately. The spreadsheet route collapses that to one package — from $12,500 for companies with 1–20 employees, implementation and certification audit included — plus your team member’s ongoing evidence time. Which is cheaper over three years depends on your integration count and framework roadmap; the honest comparison is on this page and on the Express Comply page for the platform-based managed alternative.
Through Agency, the full spreadsheet-based package — complete ISO/IEC 27001:2022 implementation plus the certification audit — starts at $12,500 for companies with 1–20 employees and from $18,750 for companies with 21–100 employees, with custom quotes at 101+. Final pricing depends on additional services selected.
Yes. Certification bodies audit your ISMS — the scoping, risk assessment, Statement of Applicability, policies, controls, and evidence — not your tooling. Structured workbooks that keep that evidence current and traceable satisfy the same requirements a GRC platform does.
Full ISO/IEC 27001:2022 implementation — ISMS scoping, risk assessment, Statement of Applicability, policies, and controls — plus the certification audit path, all run in structured spreadsheets Agency provides and maintains. From $12,500 for companies with 1–20 employees.
Yes. Stage 1 and Stage 2 certification audits and first-year certification-body fees are included in the package price — from $12,500 for companies with 1–20 employees and from $18,750 for 21–100 — with final pricing depending on the additional services you select.
Yes. Your certificate is issued by an independent accredited certification body. ISO itself does not certify companies — it develops the standard; accredited certification bodies audit against it and issue certificates, which is why accreditation is the thing to check.
It depends on your team. The spreadsheet package is from $12,500 all-in for companies with 1–20 employees; the platform route through Agency prices Vanta from $7,200 per year and Drata from $6,500 per year for the same band, plus implementation and audit. Few integrations and one framework favor spreadsheets; many integrations or multiple frameworks usually favor a platform.
Your team member uploads evidence continuously into the structured workbooks Agency provides and maintains — Agency builds the system, defines what each control needs, and reviews what comes in. That employee time is the trade for skipping the platform subscription.
ISO/IEC 27001:2022 certification runs on a three-year cycle with annual surveillance audits. Year-two surveillance support and ongoing maintenance are quoted at the end of the certification year, once the ISMS’s real operating cadence is known.
One package, one number — confirmed against your scope in about one business day.
This page is also available as plain Markdown for AI assistants and automated tools.