What does a gap analysis against ISO 27001, the Cybersecurity Act and NIS2 cost

What does a gap analysis against ISO 27001 and the Cybersecurity Act (NIS2) cost?

A defined gap analysis against ISO 27001 or the Swedish Cybersecurity Act (NIS2) normally costs from around SEK 25,000 excluding VAT. Scope, depth and purpose decide. How to compare quotes.

Summary: A defined gap analysis against ISO 27001 or the Swedish Cybersecurity Act (NIS2) normally costs from around SEK 25,000 excluding VAT with us. The price is driven above all by scope, depth of analysis and what the result will be used for.

The short answer

For around SEK 25,000 excluding VAT, a smaller organisation can get a defined analysis against one set of requirements: document review, interviews, documented gaps per requirement and a prioritised action plan. More parts of the organisation, more systems, several sets of requirements or verification that controls actually work increase the effort. That is why comparing what is included matters more than the price on the first line.

We usually quote defined engagements at a fixed price once the scope is set, or as an estimated number of hours when the scope cannot be fixed in advance. Our standard hourly rate is SEK 800–1,600 excluding VAT depending on the service, its scope and the consultant’s role and experience. How we think about it is described in How we price.

What decides the price

  • Requirement set and number of requirements. An analysis against ISO/IEC 27001 reviews the requirements on the management system and how the organisation’s risk treatment and choice of controls relate to Annex A. Not every control in Annex A applies automatically. For the Cybersecurity Act (NIS2) the analysis needs to take the act, the ordinance and the regulations relevant to the organisation into account.
  • Number of systems, processes and sites. The more environments and suppliers that carry the requirements, the more interviews and samples are needed.
  • How much is already documented. The documentation does not need to be perfect. But the more that is already collected and current – policies, a risk register, responsibilities and earlier analyses – the more efficiently the review can be carried out.
  • Depth. A document-based analysis with one management interview sits close to the entry level. Interviews per process, sampling to see that controls actually work and technical verification in the environment cost more and give a different kind of certainty in the answer.
  • Purpose and report form. A priority list for management is one thing. Groundwork that has to hold up in front of a certification auditor or a supervisory authority requires traceability per requirement and takes longer to write.

When several sets of requirements overlap, the common parts can be analysed once. That normally reduces duplicated work compared with carrying out entirely separate analyses.

What is included, and what is not

Our offer gap analysis against ISO 27001, NIS2 or DORA includes a documented current state, gaps per requirement, a prioritised action plan and a review with management. The scope is a defined engagement of a few days to about a week depending on size.

The measures themselves are not included: policies to be written, controls to be implemented, training to be held. That is the next step, priced on its own once the analysis has shown what is needed. For those aiming at certification, ISO 27001 from gap analysis to certification is that route. What a gap analysis should contain to be usable is covered in gap analysis against NIS2, CRA, GDPR and ISO 27001.

How to compare quotes

Two quotes with different prices are rarely comparable until the scope is the same. Ask everyone for the same thing:

  • Which sets of requirements, which parts of the organisation and which systems the analysis covers, in writing.
  • How many interviews are included and with which roles.
  • What evidence is reviewed: whether the assessment rests on what someone says in an interview, on documentation, or also on samples that verify that practices and controls are actually in use.
  • Who does the work. An hourly rate says little if the person behind it is not stated.
  • What the report looks like: gaps per requirement with priority and owner, or a summary.
  • Fixed price or estimate, and what happens if the scope turns out to be larger.

More questions to ask before you sign are in 10 questions to ask before choosing a consultancy.

How long does it take?

For a defined engagement the consulting effort itself is often a few days to about a week. A larger organisation, several sets of requirements or extensive sampling and technical verification can require more time. The calendar time also depends on how quickly documents can be shared and interviews booked. The result is reviewed with management in a meeting, so the prioritisation becomes a decision and not a report in a folder.

Frequently asked questions

Why from SEK 25,000?

That is what a defined analysis against one set of requirements in a smaller organisation normally costs with us: document review, interviews, gaps per requirement and a prioritised action plan. More sets of requirements, more systems, more interviews and deeper verification add to it. You receive a cost proposal before we start.

Fixed price or time and materials?

Usually a fixed price once the scope is set. When it cannot be fixed in advance, for example when nobody knows how many systems are affected, we quote an estimated number of hours within our standard hourly rate of SEK 800–1,600 excluding VAT, and check with you before going beyond it.

Can one analysis cover ISO 27001 and the Cybersecurity Act (NIS2)?

Yes. The requirements overlap in areas such as risk management, governance, incident management, continuity and supplier governance. We analyse the common parts once and complement them with what is specific to each set of requirements.

Want to know what a gap analysis would cost for you? Read more about our work with regulatory requirements and compliance or contact us, and we will set the scope together and come back with a cost proposal.

The prices in this text are our standard level at the time of publication and do not replace a cost proposal. This text is general information and not legal advice.