Zum Inhalt springen
Grundlagen
12 Min. Lesezeit

ISO 27001 Staffing Benchmarks: Count Contractors per ISO/IEC 27006

support@ismscalculator.com|

Contractor and employee badges grouped for audit scope

Most organizations need one dedicated ISMS lead plus a few supporting roles to reach ISO 27001 certification, with headcount scaling from a single part-time coordinator at small sizes to a small internal team in larger companies. The ISMS lead typically spends a substantial portion of their time on this during implementation, reducing their commitment after certification. The catch: your effective headcount for audit purposes includes contractors and freelancers working inside scope, not just payroll staff, and that single fact changes both your audit-day estimate and your budget.


TL;DR:

  • Including contractors and freelancers working on in-scope systems can increase your audit headcount by up to 60 percent, significantly impacting your certification budget.
  • Certification estimates are based on the total people working under your control within the scope, not just your payroll, so scope decisions and scope creep can alter staffing requirements abruptly.
  • Small organizations under 20 employees typically only need a part-time ISMS leader, while larger companies over 100 employees usually require a dedicated team and more complex staffing.
  • Evidence of competence, resource commitments, and documented resource decisions are critical for passing audits, with common issues being untrained staff outside IT or sole reliance on one security expert.
  • Contractors and multiple sites increase audit days proportionally, so clarifying scope and including all relevant personnel before requesting quotes prevents mid-project budget surprises.

Ismscalculator
Estimate Your ISO 27001 Staffing Needs
Get a tailored implementation estimate based on company size, industry, and security maturity, with benchmarks to validate your planning.
Start your estimate

Table of Contents

How Headcount Is Counted for ISO 27001 (and Why It Changes Your Benchmark)

ISO/IEC 27006-1, the standard that governs how certification bodies calculate audit time, defines headcount as people doing work under the organization’s control within the ISMS scope. That definition has nothing to do with your payroll system. A contractor who touches in-scope systems counts the same as a full-time employee when a certification body sizes your audit.

How Headcount Is Counted for ISO 27001 (and Why It Changes Your Benchmark) — overview diagram

This trips up more companies than you’d expect. A 40-employee software company with 25 contractors supporting its production environment isn’t a 40-person audit. It’s effectively a 65-person one, because those contractors are doing work inside the ISMS boundary. Miscounting contractors before requesting quotes is one of the most common reasons certification budgets balloon mid-project. You get a quote based on 40 people, scope creeps to include the contractor-managed infrastructure, and suddenly the audit-day estimate is wrong.

Before you request quotes from vendors or certification bodies, compile a headcount that reflects reality rather than convenience. That means:

  • Counting every contractor, freelancer, and managed-service provider staff member who works inside the ISMS scope, not just those on your payroll
  • Documenting which systems, processes, and locations are in scope, since headcount is meaningless without a scope boundary attached to it
  • Separating “in scope” from “supports the business but sits outside scope” early, because this decision drives both audit days and staffing benchmarks
  • Keeping a simple roster (name, employment type, in-scope systems touched) that you can hand directly to an auditor or a compliance platform for a quote

Published pricing bands from compliance platforms like Vanta, Drata, and Secureframe generally stop scaling predictably around 100 employees. Above that, you’re in private-offer territory, and an accurate headcount becomes the difference between a defensible quote and a guess.

ISO 27001 Staffing Benchmarks by Organization Size

Staffing needs don’t scale in a straight line with employee count. A 15-person company and a 90-person company might both run ISO 27001 with a single dedicated coordinator, while the jump from 100 to 500 employees usually forces a real team structure. Here’s how the roles and time commitment typically break down.

1. Under 20 employees: minimal viable coverage

At this size, you’re usually looking at a part-time ISMS lead, often the founder, head of engineering, or operations manager, paired with shared IT support. There’s rarely a dedicated security engineer. Expect the ISMS lead to spend meaningful hours weekly during implementation, then far less once the ISMS stabilizes.

2. 20 to 100 employees: a dedicated coordinator emerges

Department owners contribute fractional time for their own control areas.

3. 100+ employees: a functioning ISMS team

Above 100 employees, most organizations run a small dedicated team: an ISMS manager, one or more security engineers, a risk assessor, and internal auditors who rotate rather than doing this as a side task. This is also where staffing benchmarks stop being predictable from headcount alone. Industry, number of sites, and regulatory overlap start driving more of the resourcing than raw employee count.

Time allocation shifts sharply between implementation and maintenance.

A real-world illustration: one ISO 27001 program manager job posting breaks the role down as roughly 60% hands-on documentation and evidence preparation, 30% cross-team collaboration, and 10% meetings and reporting. That split matches what most implementers see in practice: the job is less about security architecture and more about relentless evidence gathering.

ISMS program manager time allocation

Pro Tip: Don’t hire a dedicated internal auditor if you’re under 50 employees. Train someone already in finance or operations to run internal audits instead. Auditors care about independence from the process being audited, not a job title.

Each role earns its place for a specific reason. The ISMS lead owns the Statement of Applicability, risk register, and policy set, and answers directly to the auditor during the certification visit. The security engineer implements and maintains technical controls: access management, logging, vulnerability management. The internal auditor exists specifically to test the ISMS independently before the certification body does. IT admins handle evidence collection for technical controls they already operate day to day, which is why their time commitment stays comparatively low even though their systems generate most of the audit evidence.

What Auditors Actually Check Under Clause 7

Clause 7 of ISO 27001 requires the organization to determine and provide adequate resources and demonstrate competence for people doing ISMS work. Auditors don’t take your word for it. They ask for documented proof, and the specific artifacts they request are fairly predictable.

Expect a certification body to request:

  • Meeting minutes from management review sessions that show resourcing decisions were actually discussed and approved
  • Budget approvals or sign-offs tied to security initiatives, not just a line item buried in a general IT budget
  • Written role descriptions for anyone with ISMS responsibilities, including internal auditors and risk owners
  • A competency matrix mapping each ISMS role to required skills and how those skills were verified
  • Training records showing completion dates, not just enrollment
  • Awareness program completion logs covering the whole organization, not a subset

Auditors specifically look for evidence like this because headcount alone doesn’t prove competence or commitment. The most common finding tied to staffing is awareness training that only reached the IT department, leaving sales, HR, and finance untrained on security basics. The second most common: a single “security hero” who holds all the ISMS knowledge with no documented backup, which is a bus-factor risk auditors flag almost every time they see it.

Small organizations without budget for a large team can still demonstrate resource commitment. Document the ISMS lead’s time allocation explicitly in a management review, get a written budget sign-off even if the number is modest, and keep a simple training log. Detailed evidence examples help here, since auditors care more about traceability than the sheer volume of documentation.

How Contractors and Multiple Sites Change Your Audit-Day Estimate

Every contractor or site you add to scope adds audit time, and audit time is billed by the day. A single-site company with 60 employees and no in-scope contractors might need two or three audit days for a stage two audit. Add a second office and 15 in-scope contractors, and that estimate climbs, sometimes past what the original quote assumed.

Scope, remote versus on-site audit proportion, and site count are the specific levers that drive audit days under ISO/IEC 27006-1 Annex C. You control most of these decisions before you ever talk to a certification body.

When deciding what belongs in scope, weigh the operational tradeoff honestly: excluding a system or team from scope reduces audit days and staffing burden, but it also limits what your certificate actually covers, which matters if customers ask pointed questions during procurement. Ask your certification body these seven questions before accepting a quote:

  • How many audit days does this quote assume, and what headcount was it based on?
  • Are in-scope contractors and freelancers included in that headcount?
  • How many sites does the quote cover, and what happens if a site is added later?
  • What percentage of the audit will be remote versus on-site?
  • What triggers a mid-cycle quote revision?
  • How are surveillance audit days calculated after year one?
  • What documentation do you need before finalizing the estimate?

Consultant-Assisted vs In-House: Time and Cost Benchmarks

Most organizations underestimate internal hours by a wide margin. Typical internal effort runs 200 to 500 hours of staff time across the ISMS lead, security engineer, and department owners combined, spread over the implementation period.

The timeline difference is real and it’s driven by hours, not talent. Organizations that bring in a consultant typically certify in 3 to 12 months. Internal-only implementations, run entirely by existing staff learning the standard as they go, commonly stretch to 6 to 12 months or longer. Consultant day rates and full-project packages vary widely depending on scope and region, so treat any single number as a starting point for negotiation rather than a fixed benchmark.

  • A consultant handles the framework, documentation templates, and audit prep, compressing calendar time even though internal staff still do the evidence-gathering legwork
  • Internal-only teams spend a chunk of their 200 to 500 hours simply learning the standard, time a consultant-assisted team skips entirely
  • A rough combined estimate: 15 consultant days plus 300 internal hours often lands a mid-sized company at certification in 6 to 8 months, versus 10 to 12 months attempting the same scope alone

Turning These Benchmarks Into Your Own Staffing Plan

Generic bands only get you so far. ISMS Calculator converts them into a number specific to your organization by asking for your actual headcount, industry, and security maturity level, then applying model reference comparisons against editable assumptions you can adjust yourself.

  1. Enter your employee count and add in-scope contractors separately, since the tool treats them as distinct inputs affecting the estimate
  2. Select your scope options (single site, multiple sites, cloud-only infrastructure) to see how each choice shifts suggested role time allocation
  3. Review the generated role and time-allocation breakdown against the benchmarks in this article to sanity-check it
  4. Export the estimate as a PDF or shareable link and send it to procurement or your executive sponsor for budget approval

What Actually Predicts a Smooth Certification

Three rules of thumb hold up across most implementations: staff the ISMS lead role before you staff anything else, document resource decisions in writing from day one, and count contractors honestly before requesting quotes. Two red flags predict trouble reliably: a single security hero with no documented backup, and awareness training that never left the IT department.

— Martin

Get Your Own Staffing Estimate in Two Minutes

Reading benchmarks is one thing. Knowing where your organization actually lands is another. Ismscalculator gives you a real-time, tailored estimate instead of a generic range, factoring in your company size, industry, and current security maturity so the staffing and cost numbers reflect your situation, not a model reference value.

Ismscalculator

Every input you saw in the benchmarks above (headcount, contractors, scope, role time allocation) maps directly into the calculator’s assumptions, and you can edit any of them if your situation doesn’t match the default. There’s no signup required to run the first pass, and the methodology behind every number stays fully visible, so you can challenge or adjust any assumption before sharing it with your team. Start with the free 2-minute readiness check to see where your gaps are, then open the full cost calculator to generate a detailed, exportable staffing and budget estimate you can hand straight to procurement.

Sources

For the audit-day mechanics behind these benchmarks, ISO/IEC 27006-1 governs how certification bodies calculate time per engagement, which is why quotes vary by accredited body. Pair that with a certification checklist to track staffing tasks against your implementation timeline, and a readiness assessment to catch gaps before an auditor does.

FAQ

Who Counts Toward ISO 27001 Headcount?

Headcount includes everyone doing work under your organization’s control within the ISMS scope, not just payroll employees. That means in-scope contractors and freelancers count toward the total your certification body uses to size the audit.

What’s the Minimum Team Needed for ISO 27001?

A company under 20 employees can often certify with a part-time ISMS lead and shared IT support handling technical controls. Larger organizations need a dedicated coordinator plus part-time security engineering and internal audit resources once they pass roughly 20 to 100 employees.

How Many Hours Does IT Staff Spend on ISO 27001?

That drops further once the ISMS reaches steady-state maintenance.

Do Contractors Increase My Audit Cost?

Yes. Contractors working inside your ISMS scope count toward headcount, and scope and site count are direct drivers of audit days under ISO/IEC 27006-1. Leaving them out of your initial headcount is a common reason quotes get revised upward mid-project.

How Do I Get an Accurate Staffing and Cost Estimate?

Start by compiling an honest headcount that includes in-scope contractors, then run that number through a tool like ISMS Calculator, which generates a tailored staffing and cost estimate based on your size, industry, and maturity level. The free readiness check takes about two minutes and gives you a starting benchmark before you approach vendors or certification bodies.

Bereit, Ihre ISO 27001-Kosten zu schätzen?

Nutzen Sie unseren kostenlosen Rechner für eine maßgeschneiderte Kosten-, Aufwands- und Zeitplanschätzung basierend auf Ihrem Unternehmensprofil.

Schätzung berechnen — kostenlos
Zurück zu allen Artikeln