Back to Columns
ISMS & Certification11 min read

When Not to Certify: ISMS vs Answering Security Check Sheets

September 14, 2026

When Not to Certify: ISMS vs Answering Security Check Sheets
Share this article

Articles about ISMS certification usually open with the case for certifying. In practice, though, there are situations where not certifying is the rational choice.

You answer each customer security questionnaire as it arrives. You produce evidence when asked. Business gets done. The real questions are how long that holds, and at what point certification becomes the cheaper option.

This article assembles the material for that yes/no decision: the true cost of questionnaire handling, the true cost of running a certified ISMS, where they cross, and how to spot the situations where no certificate is disqualifying. For the overall picture, see What Is an ISMS (ISO/IEC 27001)?.

Disclaimer: This article is general information. Cost varies substantially with organisation size, scope, and certification body. Base decisions on your own quotes and your customers' actual requirements.

Making the Cost of Questionnaires Visible

"Certification is expensive, questionnaires are free" misses the point. Questionnaires cost real money, and most of it is invisible on any budget line.

Decompose one questionnaire:

TaskWhat it involvesWho does it
Reading the questionsEvery customer's format and granularity differs; tens to hundreds of itemsHead of IT or engineering
Establishing facts"How long are logs retained?" "What encryption?" — checking the implementationEngineering and infrastructure
Writing answersExplaining items you cannot mark "not applicable"Senior staff
Attaching evidenceProcedures, architecture diagrams, screenshotsSenior staff
Follow-up questionsOne to three rounds of back-and-forth after submissionSame
Internal approvalSign-off on an external submissionExecutives

Three problems follow.

1. The responder is always the same person. Only someone who knows the implementation can answer — so the time consumed belongs to the person you least want to interrupt.

2. Answers drift. What you told customer A and what you told customer B diverge over time and across people. That is awkward when someone cross-checks.

3. Nothing accumulates. Individual answers are not assets. When the responder leaves, the investigation starts again from zero.

There are conditions where questionnaires stay cheap: one or two customers, an annual refresh, and information of low sensitivity. Certifying under those conditions can be over-investment.

Understanding how the sender designs these forms lightens the load — Security Check Sheets for Vendors is written from the buyer's side.

The Cost of Certification, and What It Accumulates

Certification concentrates cost in year one, then continues as maintenance. Compare across three years, not one.

ItemYear 1Year 2 onward
Audit fees (to the certification body)Stage 1 and stage 2, priced by auditor-daysAnnual surveillance; recertification in year three
Consulting supportDocumentation, project management, training, internal auditOperational support, risk assessment refresh, internal audit
Internal effortHeaviest here: decisions, reviews, training attendanceMaintaining records, supporting internal audit

Pottech's pricing is from ¥1.2M/year for first certification support and from ¥0.8M/year for ongoing operational support (excluding tax; assuming up to roughly 50 people and use of our document templates; certification body fees are separate). Commentary suggests audit fees in the region of ¥600k for a handful of staff and ¥1M at around 100 people, but that needs verification at source. See The Full Cost of ISMS Certification.

The number looks heavy, but the decisive difference from questionnaire handling is that it accumulates.

  • With a risk assessment and asset register, "where is which information held?" is answered immediately
  • With procedures and a Statement of Applicability, "is that rule documented?" is answered with evidence
  • With internal audit reports, "is it actually operated?" has backing

In other words, the documents produced on the way to certification become the master source for questionnaire answers. This is the largest practical effect, and why certified companies report that questionnaires got lighter.

See ISMS Documentation: How Much to Build and ISMS Timeline: What Six Months Actually Looks Like.

Thinking About the Break-Even Point

There is no universal answer to "how many questionnaires before certifying wins." But you can build the formula.

Annual cost of questionnaire operation
  = questionnaires per year × hours per questionnaire × loaded hourly rate
  + follow-up rounds
  + opportunity cost of inconsistent or late answers (hard to quantify, real)

Annual cost of certified operation
  = consulting + audit fees + internal effort
  − the reduction in questionnaire effort (reusable evidence)

That final term is the one that matters. Certification does not end questionnaires; customers keep sending their own forms. It cuts the time each one takes — so the more of them you receive, the more it tells.

SituationTendencyCall
One or two customers, annual refreshQuestionnaires are cheaperDefer certification
Customer count growing, several to a dozen questionnaires a yearCrossover approachingStart the documentation first; certify when a customer requires it
Actively pursuing hospitals, pharma, governmentCertification tends to become a preconditionPut it in the plan
Certification named in a tender or procurement specificationQuestionnaires cannot substituteRequired

Most companies sit in the second row. The useful move there is to refuse the binary. Build the risk assessment, the asset register, and the core procedures first: questionnaires get lighter immediately, and the remaining work if you do certify shrinks. Documentation has standalone value.

See Building an Information Asset Register and Running a Risk Assessment.

Where the Absence of a Certificate Is Disqualifying

Before any cost comparison, check whether substitution is possible at all. If it is not, the arithmetic is moot.

Likely disqualifying

  • A procurement specification or tender states "must hold ISO/IEC 27001 certification." No answer text substitutes. Whether it is a scoring item or a mandatory requirement changes everything — if mandatory, you cannot bid
  • A hospital subject to the three-ministry guidelines requires equivalent evidence from its suppliers. Because the hospital carries the obligation, its staff may have no discretion to waive it
  • A parent or group procurement standard requires certification above a contract size threshold

Usually fine without

  • The customer judges on its own questionnaire, with certification only a scoring bonus
  • No personal or medical information is involved and the risk is contained
  • An existing relationship where track record and observed operation carry weight

The first thing to do is ask the customer directly: mandatory requirement, or scoring item? Procurement documents are written inconsistently, and misreading them produces either over-investment or a lost bid. See When ISMS Becomes a Condition of Trade.

For why hospitals ask in the first place, see The Three-Ministry Guidelines.

Conclusion

  1. Questionnaires are not free — they consume the time of the person you least want to interrupt, and nothing accumulates
  2. Certification concentrates cost in year one; compare three-year totals
  3. Certifying does not end questionnaires. What it does is cut the time each one takes
  4. The break-even is not about count alone — model your responder's rate and the number of follow-up rounds
  5. Refuse the binary: build the documentation first and neither outcome wastes it
  6. Before any arithmetic, confirm whether the requirement is mandatory or a scoring item

Pottech supports ISMS certification with a focus on healthcare, including staged approaches — "documentation first, certification when a customer requires it." We supply templates for procedures, registers, and training material and lead project management and dealings with the certification body.

See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.

References and Sources

Note: costs vary substantially with organisation size, scope, and certification body. Pottech's pricing is as published on ISMS Certification Support. Figures quoted for market audit fees come from general commentary — confirm actual amounts through competitive quotes.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.