In my last post, I wrote about why we pursued ISO 27001 and what it changed inside Mailbutler. This one is different. This is about what nobody tells you before you hire an ISO 27001 certification agency: what it's actually like to work with one, what went wrong for us, and what I'd tell another founder before they sign anything.
Short version: I wouldn't hire the same agency again. But the certification itself was absolutely worth it — once we stopped outsourcing our thinking.
Choosing an ISO 27001 certification agency
None of us had ever gone through an ISO 27001 process before. Every search result said the same thing: don't do this alone, get an agency. That made sense to me at the time — we were a small team with zero certification experience, and the idea of a guided roadmap sounded like exactly what we needed.
We compared a few agencies. Calls, pricing, references. The offerings all looked similar: template documentation, a roadmap to follow, general consulting, and a self-service platform to manage the whole thing. Pricing was similar too — somewhere in the €10,000–15,000 per year range, with a two-year commitment. For a company our size, that's a serious upfront bet.
We picked a German agency out of Munich. Good reputation, professional pitch. It felt like the safe choice.
The kickoff, the platform, and the templates
The kickoff call was smooth. They walked us through their platform: a timeline, document management, risk and asset tracking tools, even an "academy" with basic security training for the team. It looked comprehensive. It also, in hindsight, looked like a product built to keep you inside their ecosystem.
We started with their template documents. At first they seemed helpful — a starting point is a starting point. But it didn't take long to notice the real problem:
The templates were built for everyone, which meant they fit no one. The same documentation set they hand a 500-person corporate goes to a five-person startup. We were drowning in policies and procedures that had nothing to do with how we actually work.
We pushed through anyway. Then came the internal audit.
Where it fell apart
The audit was the moment everything became obvious. Almost none of the over-engineered processes we'd copied from their templates matched our reality. We walked away with a long list of non-conformities — essentially, a list of everything that didn't hold up.
At that point we started over. We wrote our own policies. Our own procedures. Lightweight, but genuinely secure, tailored to a company our size rather than a fictional enterprise customer.
And the agency didn't help much here. Their support ticket system was slow, and when answers did come back, they were generic — the same boilerplate advice regardless of what we'd actually asked.
There was one moment that stuck with me. We were already using Microsoft SharePoint, and it covered everything ISO 27001 actually requires for document management. When we asked about using it instead of their platform, they pushed back with reasons that were vague at best.
I think they just wanted us on their platform for the lock-in.
We built our ISMS in SharePoint anyway. It worked fine.
What we did instead
Once we stopped trying to force our company into their template, the certification suddenly looked much more manageable than we'd assumed. That's the real lesson here: ISO/IEC 27001 doesn't tell you how to run your ISMS — it tells you what areas need to be covered. It's a framework, not a checklist. That distinction gives you a lot more freedom than most certification agencies let on — and it's the single biggest thing I wish someone had told us before we hired ours.
We ended up managing:
- Our ISMS documentation in SharePoint, which we already used daily
- Risk tracking in a simple spreadsheet
- Asset tracking the same way
- Yearly audits through an independent certified freelancer instead of the agency
- Security awareness training through a specialized provider, separate from the agency's academy
Nothing exotic. Nothing that needed a €10,000-a-year platform behind it.
To be fair, not everything about the agency was wasted. Having a structured annual internal audit was genuinely valuable — it's the one thing I'd keep from the whole engagement. My only regret is that we didn't get that first audit earlier, even a partial one covering a few areas. It would have shown us we could scale everything down months before we actually figured that out ourselves.
What I'd tell another founder
If you're a founder or exec staring down an ISO 27001 project right now, here's what I actually believe, not what the sales calls from a certification agency will tell you:
- Start smaller than feels responsible. Scope your ISMS to your company's actual size and risk profile from day one — don't accept a template built for a corporation.
- Ask your network before you ask an agency. Founders who've already worked with an ISO 27001 certification agency will give you a far more honest picture than any sales call will.
- You don't need a certification agency at all, necessarily. The framework itself doesn't require one. What it requires is time — time to write policies that reflect how you actually operate, not how a template imagines you should.
- Use the tools you already have. If your existing stack — SharePoint, Notion, whatever — covers the requirement, use it. Don't let anyone talk you into a platform for platform's sake.
- And yes, use AI. Writing ISMS policies and procedures from scratch sounds daunting. It really isn't, especially now — AI is genuinely good at helping you draft this kind of documentation quickly, as long as you're the one deciding what actually applies to your business.
Our contract with the agency runs out at the end of the year, and we won't be renewing it. We'll keep our ISMS exactly where it is — lean, in the tools we already use, audited annually by an independent freelancer. Looking back, I don't regret pursuing ISO 27001 for a second. I just regret assuming for so long that we needed someone else to tell us how to do it.
If you're going through this right now, or thinking about starting, I'd genuinely like to hear how it's going for you — drop a comment below, or reach out directly.