ISMS as a Service: what you buy and what stays with you

You cannot subscribe to an ISMS. You can subscribe to templates. To a compliance platform. To an external information security officer with a monthly allotment of hours. All of that is legitimate, some of it very sensible. But the management system itself, the part that gives ISMS as a Service its name, only comes into being when your organization makes decisions, documents them and then acts on them. That part appears in no offer we have seen so far.

This is not hair-splitting. The difference between an ISMS your organization owns and one your service provider administers for you decides whether, two years from now, you have a working security program or a binder with a logo on it.

Why the offer sounds so good right now

The pressure is real. Enterprise customers send security questionnaires before they even talk to you. Tenders demand ISO 27001 as the ticket to entry. On top of that comes the silent filter: some deals you lose without ever hearing about them, because procurement screens you out without a certificate before any conversation takes place. And anyone who falls under the ISG, the Swiss Information Security Act, must have an ISMS in place by the end of 2026. We sorted out who is affected in our post on the ISG ISMS obligation; it is fewer companies than the advertising suggests.

Into this situation comes an offer that sounds roughly like this: we build your ISMS, we run it, we walk you through the certification audit. Effort on your side: a few workshops and the signatures.

That this offer sounds good is no accident. It promises to separate two things you urgently want separated right now: the certificate, which you need for revenue, and the work, for which you have no capacity. Except an ISMS is exactly the connection between those two things. A certificate attests that your organization manages information security. If it does not, the certificate attests to something that does not exist.

Full transparency: ODCUS builds ISMS with clients, it is one of our three services. So read this text with that lens. We have an interest in you taking the build seriously. But we have no subscription to defend that promises to take the operation off your hands.

What you can buy

So this does not come across as a takedown of an entire industry: a large part of ISMS as a Service is honest, useful work. Four things you can buy.

Method. Someone who has built many ISMS knows which sequence works, which documents an auditor reads at all and which controls are oversized for an SME. That experience saves months and prevents the most expensive pattern of all: a system designed for a corporation that suffocates an SME. We described what a right-sized system looks like in our post on building a pragmatic ISMS.

Templates and structure. Nobody needs to write an information security policy from a blank page. Good templates are a fair part of the price, as long as they are adapted to your organization and not the other way around. The same goes for compliance platforms: useful as a filing system and reminder machine, as long as nobody mistakes the dashboard for the management system.

The role of the external information security officer. For many SMEs this is the right construction: the experience is missing internally, the budget does not allow a full-time position, so the subject-matter responsibility comes from outside. That works as long as it stays clear that the external officer prepares, reviews and recommends, while the decisions are made in-house.

Speed and audit experience. Someone who knows the certification process saves you detours and negotiates with the certification body as an equal. That too is worth money. What all of this may cost depends heavily on the setup; you will find a sober assessment in our post on ISO 27001 costs for SMEs.

All four services have something in common: they make the build faster and better. None of them replaces what comes afterwards.

What you cannot buy

Three things cannot be outsourced, no matter what the contract says.

The risk decisions. An ISMS lives on the question of which risks you treat and which you consciously accept. No service provider can make those decisions for you, because he does not bear the consequences. If your risk register contains decisions your management has never discussed, you have a fiction of a management system, signed by people who do not know what they have accepted.

Management commitment. The standard requires it, but the more practical reason is this: an auditor notices within the first hour whether management knows its own ISMS. He needs no trick questions for that, the normal ones are enough: what were your biggest risks this year? What did you decide? Whoever can only point at the consultant has already given the answer.

The operation. An ISMS consists to a smaller degree of documents and to a larger degree of routines: revoking access when someone leaves. Vetting suppliers before they receive data. Reporting incidents, including the embarrassing ones. These routines run in your departments. A service provider can design them and train them. Your people have to carry them out.

In our experience, the difference rarely shows in the certification audit. You can pass that with a well-built paper ISMS and a well-rehearsed consultant. It shows in the year after, and the pattern is always the same.

The surveillance audit comes up. The consultant from back then is no longer on the mandate or is brought back for two expensive days. The auditor is interested in what has happened since the certificate: the internal audit that was carried out, the incidents that were handled, the management review with agenda and resolutions. And now there sits a management team opening its own management system for the second time in its life. What follows is a week of archaeology in a binder someone else built, and an action plan that will look exactly the same next time.

The other place it becomes visible is the first real incident. The reporting chain is in the manual, clean, with escalation levels. Only nobody knows it, because it was never rehearsed. For operators of critical infrastructure this has been more than a matter of style since April 2025: cyberattacks must be reported to the BACS within 24 hours, with fines possible since October 2025. A process only the external consultant knows will not hold that deadline. The consultant does not read your alerts at three in the morning.

The three questions before you sign

When an offer for ISMS as a Service is on your desk, you do not need a market study. Three questions are enough.

First: who on our side makes the risk decisions, by name and role? If the provider's answer boils down to him taking that over, then the offer is, put plainly, a document delivery. Even that can be worth its price, you should only know what you are buying.

Second: which processes does who run internally after the build, and how many hours per month does that cost? A serious provider has a concrete answer to this, including the uncomfortable number of hours. If the answer amounts to "practically no effort", it describes an ISMS that is not being operated. For orientation: behind a living ISMS sit recurring tasks such as the internal audit, the management review, maintaining the risk register and following up on measures. Some of that you can give to an external party. But someone in-house has to demand these tasks and understand the results.

Third: what happens in the surveillance audit one year after the contract ends? The question sounds hypothetical but is the sharpest test. It forces the provider to say what remains of his system when he is no longer there. The good providers answer with a handover plan: which roles are filled internally by when, which knowledge is handed over how.

This, by the way, is also how you recognize a good external mandate: it dismantles itself by design. Knowledge moves inside, roles are handed over, and what remains external in the end is only what you consciously want external, such as the independent view for the internal audit.

One side signal that reveals more than any reference list: the pricing model. A pure subscription with no defined end has a built-in interest in keeping you dependent. A project price for the build plus a clearly delimited, smaller mandate for the operation shows that the provider plans for the handover. That is no proof of quality, but a usable hint about whose problem is meant to be solved permanently here: yours, or that of his utilization.

Subscribe or build?

ISMS as a Service is no scam label, only an imprecise name for something useful: experience, method and an external role you could not afford as a full-time position. Go ahead and buy that. But buy it as what it is: help with building and running a system that belongs to your organization and is lived by it.

If you are reviewing such an offer right now, or want to know how much ISMS your company needs in the first place, talk to us. A first conversation is non-binding, and sometimes the result is: less than the provider wants to sell you.

And if an ISMS as a Service is already running at your company, one question to close: would your management know, without the consultant in the room, which three risks it accepted this year?