Back to Columns
ISMS & Certification11 min read

ISMS for Small Organisations: Certifying With Fewer Than 50 People

September 14, 2026

ISMS for Small Organisations: Certifying With Fewer Than 50 People
Share this article

Most writing about ISMS assumes an organisation of several hundred people: departments, an IT function, an audit office.

Healthcare startups and small vendors look nothing like that. Twenty people in total, eight engineers, two in back office is a normal shape. Read the standard's requirements at that size and phrases like "segregate duties" and "ensure the independence of the audit" look physically impossible.

The conclusion first: small organisations can and do certify. The standard is size-agnostic. But copying what a large organisation does will jam. This article separates what size helps with from what it hurts, how to document role overlap, and which roles can legitimately go outside. For the overall picture, see What Is an ISMS (ISO/IEC 27001)?.

Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Whether a particular overlap of roles is acceptable is ultimately the certification body's judgement.

What Size Helps With

Being small is not only a handicap. The parts that give large organisations the most trouble simply do not exist.

1. Scope is naturally narrow

One site, one business line, and there is nothing to argue about. Large organisations can spend months on "which departments" and "what about the overseas office." See Defining ISMS Scope.

2. Asset inventory is actually achievable

At several hundred people, just establishing who uses which SaaS is a project. At twenty, you can ask everyone. See Building an Information Asset Register.

3. Decisions happen fast

Executives are close by, and policy and objectives get settled in one meeting rather than three weeks of circulation and inter-departmental alignment.

4. Few legacy exceptions

There is less accumulated practice to grandfather in, so rules can be defined cleanly.

Together, these mean effort scales roughly with headcount. Audit fees are priced by auditor-days, so a small organisation's audit is genuinely shorter. See The Full Cost of ISMS Certification.

Two Walls Specific to Small Organisations

Two obstacles decide feasibility in practice.

WallThe problemHow large organisations avoid it
No separation of dutiesThe same person requests and approves, or writes the code and deploys itDepartmental boundaries separate them naturally
No independent internal auditYou would be auditing your own work, which is not an auditAuditors come from an audit office or another department

The first shows up as:

  • The engineer who wrote the code also runs the production deploy
  • The same administrator both requests and approves account creation
  • The person taking backups also verifies them

What the standard asks for is not more headcount but that you do not leave a state in which one person's fraud or error would go undetected. Design compensating measures and be able to explain them, and that requirement is satisfied.

The second is stricter. Auditing the system you built and run, and reporting "no findings," is not an audit. This is where small organisations most often stall. See Running Internal Audits.

Documenting Role Overlap Defensibly

Auditors do not ask whether roles overlap. They ask how you recognise the risk it creates and what compensates for it. Explained in writing, overlap itself is not rejected.

Three parts to the explanation:

  1. State who holds which roles — organisation chart and a table of duties
  2. Identify the specific risk the overlap creates — recorded in the risk assessment
  3. Define compensating measures and keep records — procedure plus operating records

Examples of compensating measures:

Where separation is impossibleCompensating measure
Developers deploy to productionMandatory peer review of pull requests, automatic deploy logging, monthly log review by an executive or third party
One administrator requests and approves accountsEvery issue and removal recorded in a register, reconciled quarterly by a different person
Same person takes and verifies backupsScheduled restore tests reported to executives, with date and result recorded
The security lead also does the hands-on workManagement review where executives independently evaluate effectiveness, minuted

The common shape is: keep records, and create an occasion for a second pair of eyes. Where real-time separation is impossible, after-the-fact review prevents a single person's error from sitting undetected.

And without records the explanation collapses. "We do review it in practice" does not pass an audit; the operating record is the evidence. See Running a Risk Assessment, Risk Treatment and Acceptance, and Adapting Procedure Templates. On the technical side, Security by Design for Medical Systems is also relevant.

Which Roles Can Go Outside

The key to certifying at small scale is knowing exactly which roles must stay in-house.

RoleResponsibilityOutsourceable?
Top managementIntegrating the ISMS, providing resources, owning risk, management reviewNo — the executive team
ISMS managerOverall construction and operationNo — appointed internally
ISMS officersSupporting operation in each areaNo — appointed internally
Internal audit managerPlanning and improving audits, documenting resultsYes
Internal auditorsPerforming auditsYes

That internal audit can be outsourced is decisive at this size, because it dissolves the independence wall. What remains internal is the executive team plus the appointment of an ISMS manager and officers.

The other realistic lever is narrowing scope. Confine it to what customers actually require rather than the whole company, and both assets and documents shrink. But the scope is printed on the certificate and read by customers, so confirm it covers their requirement — see When ISMS Becomes a Condition of Trade.

If the prior question — whether to certify at all — is still open, see When Not to Certify. For small organisations, building documentation without certifying yet is sometimes the rational path.

Conclusion

  1. The standard is size-agnostic. Small organisations can certify — but not by copying large-organisation practice
  2. Size helps with narrow scope, achievable inventory, fast agreement, few legacy exceptions; effort scales with headcount
  3. Two handicaps: no separation of duties and no independent internal audit
  4. Overlap is not rejected. What is asked is the recognised risk, the compensating measure, and the record
  5. The pattern for compensation is keep records and create a second pair of eyes — substitute after-the-fact review
  6. Internal audit can be outsourced. Only top management and the ISMS manager and officers must stay internal

Pottech supports ISMS certification with a focus on healthcare. Our first-certification programme assumes an organisation of up to roughly 50 people using our document templates — designed for exactly the scale this article addresses. We can also serve as your internal audit manager and internal auditors, leaving only the executive team and your ISMS manager and officers to appoint internally.

See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.

References and Sources

Note: interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standard itself and the publications of the accreditation and certification bodies. Whether a given overlap of roles is acceptable is decided in the individual audit.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.