<!-- Generated by scripts/pseo/generate.js — edit scripts/pseo/data/pricing/iso-27001-without-platform.js, not this file. -->
# ISO 27001 Without a GRC Platform: Full Implementation + Audit Pricing — Agency

> Agency delivers complete ISO/IEC 27001:2022 implementation and certification audit with no GRC platform — run in structured spreadsheets — from $12,500 for companies with 1–20 employees and from $18,750 for 21–100, with custom quotes at 101+; Stage 1 and Stage 2 audits and first-year certification-body fees are included, and the certificate is issued by an independent accredited certification body. Agency is a master reseller of Vanta and Drata, has served 1,000+ companies, is rated 4.9/5 on G2, and operates a U.S.-based team.

- Canonical page: https://getagency.com/lp/iso-27001-without-platform
- Company: Agency (https://getagency.com)
- Currency: USD
- Pricing type: standard published pricing through Agency — final price confirmed in Order Form/SOW
- Pricing last updated: August 2026

## Pricing

### ISO 27001 without-a-platform pricing

| Company headcount | ISO 27001 full package (from) | What determines the final price |
|---|---|---|
| 1–20 employees | $12,500 | Additional services selected |
| 21–100 employees | $18,750 | Additional services selected |
| 101+ employees | Custom quote | Scope and additional services |

*USD · full package · Pricing last updated August 2026*

### Direct-answer block: In summary

- ISO 27001 full package, no GRC platform: from $12,500 for companies with 1–20 employees, from $18,750 for 21–100, custom quote for 101+.
- The package covers full ISO/IEC 27001:2022 implementation — ISMS scoping, risk assessment, Statement of Applicability, policies, controls — in Agency-provided spreadsheets.
- Stage 1 and Stage 2 certification audits and first-year certification-body fees are included; the certificate is issued by an independent accredited certification body.
- Final pricing depends on additional services; year-two surveillance is quoted separately.
- Prefer a platform? Vanta is $7,200 per year and Drata $6,500 per year for companies with 1–20 employees, through Agency.

## In plain terms

The full ISO 27001 package — complete implementation plus the certification audit, run in structured spreadsheets with no GRC software — starts at $12,500 for companies with 1–20 employees and from $18,750 for companies with 21–100 employees; companies with 101 or more employees receive a custom quote. Final pricing depends on the additional services you select.

Agency is a master reseller of Vanta and Drata, has served 1,000+ companies, is rated 4.9/5 on G2, and operates a U.S.-based team.

## Why skip the platform?

GRC platforms automate evidence collection, and for many teams that automation is worth every dollar. But platforms carry a recurring subscription plus their own implementation, upkeep, and integration-maintenance overhead — connectors break, dashboards need triage, and someone still owns the work the platform surfaces.

Spreadsheet-based compliance trades software spend for employee time: a team member uploads evidence continuously into structured workbooks Agency provides and maintains. For a company with a stable stack and a single framework, that trade often wins outright. For fast-growing teams with many integrations or multiple frameworks, platform economics usually win — in which case see [Vanta pricing through Agency](https://getagency.com/lp/vanta-pricing) and [Drata pricing through Agency](https://getagency.com/lp/drata-pricing) for the platform path. There is no wrong answer here, only a math problem specific to your team.

## What the package includes

Full implementation of ISO/IEC 27001:2022 — ISMS scoping, risk assessment, the Statement of Applicability, policies, and controls — delivered and maintained in structured workbooks Agency provides.

The certification audit path is part of the package: Stage 1 and Stage 2 certification audits and first-year certification-body fees are included in the package price, with final pricing depending on the additional services you select. Your certificate is issued by an independent accredited certification body — ISO develops the standard; accredited certification bodies certify against it.

## What’s included

- **Scope** — complete ISO/IEC 27001:2022 implementation and the certification audit path for the stated headcount band, no GRC software required.
- **Deliverables** — ISMS scoping, risk assessment, Statement of Applicability, policies, controls, and the structured evidence workbooks the program runs in.
- **Support** — Agency builds and maintains the workbooks and prepares your team for Stage 1 and Stage 2.
- **Timeline coverage** — implementation through Stage 2 certification; year-two surveillance support quoted separately.
- **Platform compatibility** — none needed; the package can migrate onto Vanta or Drata later without redoing the ISMS.

## What’s priced separately

- Additional services beyond the core package — penetration testing, additional standards, and expanded scope move the final price.
- Year-two surveillance audits and ongoing maintenance — quoted at the end of the certification year.
- A GRC platform, if you later choose one — see [Vanta pricing](https://getagency.com/lp/vanta-pricing) and [Drata pricing](https://getagency.com/lp/drata-pricing) through Agency.

## Who this is for

- **1–20 employees:** Small teams with a stable stack that need the certificate, not another subscription — from $12,500 all-in.
- **21–100 employees:** Established teams that prefer employee-run evidence over integration upkeep — from $18,750 all-in.
- **101+ employees:** Larger organizations where scope drives the number — custom-quoted.

## What moves the price

Three things: additional services (penetration testing, extra assessments), scope complexity (locations, products, data classes inside the ISMS boundary), and additional standards run alongside ISO/IEC 27001:2022. The headcount band sets the floor; the Order Form states exactly what your number includes.

## Conditions

Published “from” prices are the lowest currently available price for the defined qualifying scope — the headcount bands shown — not a typical or guaranteed price. Final pricing is confirmed in your Order Form/SOW, and per the published program terms, a fully executed MSA and Order Form/SOW are required before any benefit under the Program can be claimed.

## Worked examples

**Illustrative example, not a quote.** 15-person company: full ISO/IEC 27001:2022 implementation plus Stage 1 and Stage 2 certification audits, from $12,500 — everything in Agency-provided spreadsheets, no platform subscription.

**Illustrative example, not a quote.** 60-person company: the same full package from $18,750 (≈+50% over the 1–20 band), with the final number set by the additional services selected.

## How this compares

The platform route means a recurring GRC subscription plus implementation plus the audit, bought separately. The spreadsheet route collapses that to one package — from $12,500 for companies with 1–20 employees, implementation and certification audit included — plus your team member’s ongoing evidence time. Which is cheaper over three years depends on your integration count and framework roadmap; the honest comparison is on this page and on the [Express Comply](https://getagency.com/lp/express-comply-pricing) page for the platform-based managed alternative.

## Frequently asked questions

### How much does ISO 27001 cost without a GRC platform?

Through Agency, the full spreadsheet-based package — complete ISO/IEC 27001:2022 implementation plus the certification audit — starts at $12,500 for companies with 1–20 employees and from $18,750 for companies with 21–100 employees, with custom quotes at 101+. Final pricing depends on additional services selected.

### Can you get ISO 27001 certified using spreadsheets?

Yes. Certification bodies audit your ISMS — the scoping, risk assessment, Statement of Applicability, policies, controls, and evidence — not your tooling. Structured workbooks that keep that evidence current and traceable satisfy the same requirements a GRC platform does.

### What does the package include?

Full ISO/IEC 27001:2022 implementation — ISMS scoping, risk assessment, Statement of Applicability, policies, and controls — plus the certification audit path, all run in structured spreadsheets Agency provides and maintains. From $12,500 for companies with 1–20 employees.

### Does the price include Stage 1 and Stage 2 audits?

Yes. Stage 1 and Stage 2 certification audits and first-year certification-body fees are included in the package price — from $12,500 for companies with 1–20 employees and from $18,750 for 21–100 — with final pricing depending on the additional services you select.

### Is the certification body accredited?

Yes. Your certificate is issued by an independent accredited certification body. ISO itself does not certify companies — it develops the standard; accredited certification bodies audit against it and issue certificates, which is why accreditation is the thing to check.

### Is it cheaper than using Vanta or Drata?

It depends on your team. The spreadsheet package is from $12,500 all-in for companies with 1–20 employees; the platform route through Agency prices Vanta from $7,200 per year and Drata from $6,500 per year for the same band, plus implementation and audit. Few integrations and one framework favor spreadsheets; many integrations or multiple frameworks usually favor a platform.

### Who does the evidence collection?

Your team member uploads evidence continuously into the structured workbooks Agency provides and maintains — Agency builds the system, defines what each control needs, and reviews what comes in. That employee time is the trade for skipping the platform subscription.

### What about maintaining certification in year two?

ISO/IEC 27001:2022 certification runs on a three-year cycle with annual surveillance audits. Year-two surveillance support and ongoing maintenance are quoted at the end of the certification year, once the ISMS’s real operating cadence is known.
