Articles about ISMS certification usually open with the case for certifying. In practice, though, there are situations where not certifying is the rational choice.
You answer each customer security questionnaire as it arrives. You produce evidence when asked. Business gets done. The real questions are how long that holds, and at what point certification becomes the cheaper option.
This article assembles the material for that yes/no decision: the true cost of questionnaire handling, the true cost of running a certified ISMS, where they cross, and how to spot the situations where no certificate is disqualifying. For the overall picture, see What Is an ISMS (ISO/IEC 27001)?.
Disclaimer: This article is general information. Cost varies substantially with organisation size, scope, and certification body. Base decisions on your own quotes and your customers' actual requirements.
Making the Cost of Questionnaires Visible
"Certification is expensive, questionnaires are free" misses the point. Questionnaires cost real money, and most of it is invisible on any budget line.
Decompose one questionnaire:
| Task | What it involves | Who does it |
|---|---|---|
| Reading the questions | Every customer's format and granularity differs; tens to hundreds of items | Head of IT or engineering |
| Establishing facts | "How long are logs retained?" "What encryption?" — checking the implementation | Engineering and infrastructure |
| Writing answers | Explaining items you cannot mark "not applicable" | Senior staff |
| Attaching evidence | Procedures, architecture diagrams, screenshots | Senior staff |
| Follow-up questions | One to three rounds of back-and-forth after submission | Same |
| Internal approval | Sign-off on an external submission | Executives |
Three problems follow.
1. The responder is always the same person. Only someone who knows the implementation can answer — so the time consumed belongs to the person you least want to interrupt.
2. Answers drift. What you told customer A and what you told customer B diverge over time and across people. That is awkward when someone cross-checks.
3. Nothing accumulates. Individual answers are not assets. When the responder leaves, the investigation starts again from zero.
There are conditions where questionnaires stay cheap: one or two customers, an annual refresh, and information of low sensitivity. Certifying under those conditions can be over-investment.
Understanding how the sender designs these forms lightens the load — Security Check Sheets for Vendors is written from the buyer's side.
The Cost of Certification, and What It Accumulates
Certification concentrates cost in year one, then continues as maintenance. Compare across three years, not one.
| Item | Year 1 | Year 2 onward |
|---|---|---|
| Audit fees (to the certification body) | Stage 1 and stage 2, priced by auditor-days | Annual surveillance; recertification in year three |
| Consulting support | Documentation, project management, training, internal audit | Operational support, risk assessment refresh, internal audit |
| Internal effort | Heaviest here: decisions, reviews, training attendance | Maintaining records, supporting internal audit |
Pottech's pricing is from ¥1.2M/year for first certification support and from ¥0.8M/year for ongoing operational support (excluding tax; assuming up to roughly 50 people and use of our document templates; certification body fees are separate). Commentary suggests audit fees in the region of ¥600k for a handful of staff and ¥1M at around 100 people, but that needs verification at source. See The Full Cost of ISMS Certification.
The number looks heavy, but the decisive difference from questionnaire handling is that it accumulates.
- With a risk assessment and asset register, "where is which information held?" is answered immediately
- With procedures and a Statement of Applicability, "is that rule documented?" is answered with evidence
- With internal audit reports, "is it actually operated?" has backing
In other words, the documents produced on the way to certification become the master source for questionnaire answers. This is the largest practical effect, and why certified companies report that questionnaires got lighter.
See ISMS Documentation: How Much to Build and ISMS Timeline: What Six Months Actually Looks Like.
Thinking About the Break-Even Point
There is no universal answer to "how many questionnaires before certifying wins." But you can build the formula.
Annual cost of questionnaire operation
= questionnaires per year × hours per questionnaire × loaded hourly rate
+ follow-up rounds
+ opportunity cost of inconsistent or late answers (hard to quantify, real)
Annual cost of certified operation
= consulting + audit fees + internal effort
− the reduction in questionnaire effort (reusable evidence)
That final term is the one that matters. Certification does not end questionnaires; customers keep sending their own forms. It cuts the time each one takes — so the more of them you receive, the more it tells.
| Situation | Tendency | Call |
|---|---|---|
| One or two customers, annual refresh | Questionnaires are cheaper | Defer certification |
| Customer count growing, several to a dozen questionnaires a year | Crossover approaching | Start the documentation first; certify when a customer requires it |
| Actively pursuing hospitals, pharma, government | Certification tends to become a precondition | Put it in the plan |
| Certification named in a tender or procurement specification | Questionnaires cannot substitute | Required |
Most companies sit in the second row. The useful move there is to refuse the binary. Build the risk assessment, the asset register, and the core procedures first: questionnaires get lighter immediately, and the remaining work if you do certify shrinks. Documentation has standalone value.
See Building an Information Asset Register and Running a Risk Assessment.
Where the Absence of a Certificate Is Disqualifying
Before any cost comparison, check whether substitution is possible at all. If it is not, the arithmetic is moot.
Likely disqualifying
- A procurement specification or tender states "must hold ISO/IEC 27001 certification." No answer text substitutes. Whether it is a scoring item or a mandatory requirement changes everything — if mandatory, you cannot bid
- A hospital subject to the three-ministry guidelines requires equivalent evidence from its suppliers. Because the hospital carries the obligation, its staff may have no discretion to waive it
- A parent or group procurement standard requires certification above a contract size threshold
Usually fine without
- The customer judges on its own questionnaire, with certification only a scoring bonus
- No personal or medical information is involved and the risk is contained
- An existing relationship where track record and observed operation carry weight
The first thing to do is ask the customer directly: mandatory requirement, or scoring item? Procurement documents are written inconsistently, and misreading them produces either over-investment or a lost bid. See When ISMS Becomes a Condition of Trade.
For why hospitals ask in the first place, see The Three-Ministry Guidelines.
Conclusion
- Questionnaires are not free — they consume the time of the person you least want to interrupt, and nothing accumulates
- Certification concentrates cost in year one; compare three-year totals
- Certifying does not end questionnaires. What it does is cut the time each one takes
- The break-even is not about count alone — model your responder's rate and the number of follow-up rounds
- Refuse the binary: build the documentation first and neither outcome wastes it
- Before any arithmetic, confirm whether the requirement is mandatory or a scoring item
Pottech supports ISMS certification with a focus on healthcare, including staged approaches — "documentation first, certification when a customer requires it." We supply templates for procedures, registers, and training material and lead project management and dealings with the certification body.
See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- Information Security Guidelines for SMEs | IPA
Note: costs vary substantially with organisation size, scope, and certification body. Pottech's pricing is as published on ISMS Certification Support. Figures quoted for market audit fees come from general commentary — confirm actual amounts through competitive quotes.