Security & Compliance

ISO 27001 Certification Cost: Why Published Numbers Disagree

9 min read

Search for what ISO 27001 certification costs and page one hands you £5,000 to £50,000 from one UK breakdown, $5,000 to $35,000 for the audit alone from a US one, and six-figure totals from pages pricing an implementation contractor. The ranges don’t overlap cleanly and none of them is lying. They’re pricing different purchases, and almost nobody says which.

So the useful thing to establish first is which part of the bill is close to arithmetic and which part is entirely your decision.

The part governed by a standard

The certification body’s fee isn’t a negotiation in the way most buyers expect, because the time a body spends auditing you is constrained by the standard its accreditation depends on.

ISO/IEC 27006-1:2024 gives a base audit time driven by the number of people in scope, set out in Annex C. Read the word base carefully, because this is where most cost pages go wrong. The same annex carries the factors that adjust that base for business complexity and IT environment, and the adjustment moves in both directions. A tightly scoped SaaS company lands under the table figure. A regulated, multi-jurisdiction estate with heavy on-premise infrastructure lands above it, sometimes substantially. Anyone presenting the table as a fixed minimum has skipped the half of the annex that decides your actual number.

The day bands most cost pages reproduce carry over from the earlier ISO/IEC 27006:2015 Annex B structure and run:

People in scopeBase audit days
1–105
11–156
16–257
26–458.5
46–6510
66–8511
86–12512
126–17513
176–27514

Multiply by a day rate and you’ve a defensible estimate of the audit invoice, not a quote. At the £1,250 day rate used in that UK breakdown, a 12-person company sits near £7,500 and a 60-person company near £12,500. A US source puts the day rate at roughly $1,500 and total audit fees at $5,000 to $35,000, with sub-50-employee organisations landing at three to six days and $5,000 to $10,000.

Worth flagging honestly: that same UK source quotes £1,250 per day in its worked examples while stating elsewhere that 2026 rates reach £1,500 per auditor day, and its own table prices 14 days at £20,625, which £1,250 a day doesn’t produce. We aren’t going to resolve someone else’s internal arithmetic for them. Treat £1,250 to £1,500 as the live band, get your own quotes, and notice that a 20% swing across twelve days is real money.

Two structural details catch people out. Stage 1 and stage 2 aren’t billed evenly, and the common certification-body convention puts stage 1 at 20 to 30% of the total and stage 2 at the remaining 70 to 80%. That split is pricing practice rather than anything the standard mandates. And the day count follows people in scope, not company headcount. Those are different numbers, and the gap between them is the largest single lever you control.

Where the published totals stop agreeing

Above the audit fee, every cost is a choice, which is exactly why credible sources land an order of magnitude apart. The UK and US breakdowns line up like this:

Cost lineUK figureUS figureCan you skip it
Gap analysis£3,500 to £10,000about $6,000Yes, if you do it yourself against the standard
Implementation, toolkit routeabout £500, 30 to 90 daysnot quotedThis is the choice, not a line item
Implementation, consultant£5,000 to £40,000, 6 to 12 monthsnot quotedDepends who owns the ISMS
Implementation, contractor£40,000 to £160,000not quotedOnly if you are buying speed
Internal audit£3,500 to £10,000roughly $7,500No, it is required before certification
Compliance platformaround £12,000 year one, past £18,000 at 20 to 40 staffnot quotedYes, at small scale
Penetration testing£3,000 to £8,000 a year$5,000 to $20,000Depends on your risk treatment plan
Awareness training£30 to £50 per employee per yearnot quotedNo
Lead Auditor course, 5 days£2,200 to £2,500not quotedYes, unless you are auditing internally

Two notes on reading that table. The UK source quotes gap analysis at £2,500 to £5,000 elsewhere on the same page, so treat it as a wide band rather than a benchmark. And the internal audit line is the same discipline covered in a broader security audit engagement, scoped down to your ISMS controls.

The row that explains the whole disagreement is implementation. A page quoting £5,000 total assumed the toolkit route. A page quoting six figures assumed the contractor route. Both published a real number for a real purchase, and neither said so.

What no table anywhere includes is internal time, which is usually the largest real cost. In a small company that means a CTO or ops director absorbing two to three months part time. Price it at their loaded rate before you decide the self-directed path is free.

The three-year number, which is the one that matters

We run cloud infrastructure and build production systems for clients, and the planning mistake we watch companies make is budgeting year one as though it were the whole cost. It isn’t. ISO 27001 runs on a three-year cycle, and the second and third years arrive whether or not anyone put them in the spreadsheet.

Surveillance audits fall in years one and two. The accreditation convention across management-system schemes is that annual surveillance time runs about a third of the initial certification audit, so the reliable way to size it is to take your own audit fee and divide by three, with a practical floor of about one audit day. Published surveillance ranges are worth checking against that arithmetic, because the £3,000 to £10,000 range on the UK page doesn’t reconcile with a third of its own audit table.

Recertification lands in year three, and this is where a widely repeated number misleads. Vendor pages routinely quote recertification at 100% of the initial cost. The accreditation guidance says otherwise: IAF MD 5, which formally covers quality, environmental and occupational health and safety management systems rather than ISMS, sets recertification audit time at approximately two thirds of what an initial audit would require if carried out today, explicitly not two thirds of what you originally paid. ISMS audit time is governed by ISO/IEC 27006-1, but certification bodies apply the same two-thirds convention by analogy. Since the whole model is days times a day rate, a two-thirds audit can’t honestly cost a full fee. Budget two thirds, ask your body to confirm it in writing, and treat a 100% quote as something to question.

Then there’s the annual cost of keeping the ISMS alive: a retained consultant at £12,000 to £36,000, an internal owner at £40,000 to £60,000, or a fractional CISO at £1,500 to £4,000 a month. The US source frames ongoing internal audit plus surveillance as averaging about $15,000 annually.

A certificate you can’t maintain is worse than no certificate, because the failure surfaces at surveillance in front of the customer who asked for it. If the maintenance line has no owner and no budget, the year-one number isn’t your number.

The levers with arithmetic behind them

Most cost advice on this topic is a list of vendors. Here’s an opinion we’ll defend: the vendor you pick is close to the least important decision on this page, and the four things below will move your total further than any amount of shopping around. Scope beats sourcing.

Cut the scope, not the corners. Audit days follow people and systems inside the boundary you define. Scope reduction can remove up to 30% of audit days, and a tightly scoped cloud-native environment saves half a day to a full day outright. Multi-site organisations get a sampling approach rather than a visit per site, though ISO/IEC 27006-1:2024 revised how multi-site ISMS audit time is calculated in clause C.6, so ask your body to show its working rather than assuming an older rule of thumb.

Ask what the remote portion can be. The 2024 edition changed how remote auditing is treated, and the practical position now varies by body and by what your environment looks like. For a cloud-native company with no server room to walk anyone through, the case for a largely remote audit is strong, and the saving is in travel and expenses that one breakdown puts at £500 to £2,000. The day rate doesn’t change, so confirm the current position with your certification body rather than assuming either the old cap or an unlimited allowance.

Stack certifications instead of sequencing them. Running SOC 2 and ISO 27001 as one integrated audit is reported to save around 30% against doing them separately, and the same source puts adding ISO 42001 to an existing ISO 27001 program at £3,000 to £6,000 in extra audit fees against roughly 40% implementation overlap. Both figures come from a single vendor page, so treat them as directional. The point stands regardless: if two frameworks are on your roadmap inside eighteen months, sequencing them matters more than which body you pick. Our write-up on what a SOC 2 push looks like on a 90-day clock covers the other half of that decision.

Buy the toolkit before the platform. For a micro-business, toolkit versus SaaS over three years is a reported saving of up to £18,000. Platforms earn their keep at the scale where manual evidence collection genuinely stops working, which arrives later than the sales cycle suggests.

What to settle before you collect quotes

Three things decide your number, and none of them is which certification body you pick.

The first is how many people are genuinely in scope, which isn’t headcount but the people who touch information assets inside the boundary you define. Overstate it and you buy audit days you never needed. That boundary question is where our cybersecurity practice spends most of its time with clients who have already been quoted, because it’s the one input that moves every other number on the page.

The second is who owns the ISMS on an ordinary Tuesday in month fourteen. If the answer is nobody, you’re buying a consultant engagement plus a maintenance retainer, and you should stop comparing yourself to the £7,000 self-directed case study.

The third is whether a specific deal is driving this. A named enterprise customer with a contractual deadline changes the calculus, because you’re buying speed, which means consultants and tooling. Certification pursued as general market positioning can take the slow, cheap path, and usually should.

When the quotes arrive, insist each one states its assessed audit days and its day rate as separate lines. Nothing obliges a certification body to volunteer that breakdown, which is exactly why you have to ask. Without those two numbers you can’t tell whether one quote is more expensive because the body charges more or because it scoped you into a higher complexity band, and those two problems have completely different fixes.

  • iso 27001
  • compliance
  • certification cost
FAQ

Common questions, answered

How much does ISO 27001 certification cost?
Two separate numbers, and conflating them is why the published ranges look chaotic. The certification body's audit fee is your assessed audit days times their day rate: a UK breakdown puts a 26 to 45 person company at 8.5 base days, which at £1,250 a day is roughly £10,600. A US source puts total audit fees at $5,000 to $35,000, with sub-50-employee organisations at three to six days and $5,000 to $10,000. The whole program, including implementation and internal time, runs much wider than either. Always ask which one a quoted figure describes.
Which published ISO 27001 figure should I believe?
The one that states its scope. A £5,000 total assumes a documentation toolkit and a founder doing the work over three months. A six-figure total assumes an external implementation contractor, which one UK breakdown prices at £40,000 to £160,000. Both are real numbers describing different purchases. Before comparing two figures, check whether each includes implementation labour, the certification body, tooling, and your own staff's time, because most published totals silently exclude at least one.
How many audit days does ISO 27001 require?
ISO/IEC 27006-1:2024 gives certification bodies a base audit time driven by the number of people in scope, in Annex C, which also carries the factors that adjust it for business complexity and IT environment. So the table is a starting point rather than a fixed quantity, and a complex regulated estate can land well above it while a tightly scoped cloud-native one can come in under. The published bands start at 5 days for 1 to 10 people and reach 10 days at 46 to 65. Ask your certification body which band it has assessed you into and why.
What does ISO 27001 cost after the first year?
The certificate runs on a three-year cycle. Years one and two carry surveillance audits, and the accreditation convention is that annual surveillance time is about a third of the initial certification audit, so take your own audit fee and divide by three rather than trusting a published range. Year three is recertification, which the accreditation guidance puts at roughly two thirds of what a fresh initial audit would take today, not a full repeat, though several vendor pages quote 100%. On top of that sits whatever keeps the ISMS alive: a retained consultant at £12,000 to £36,000 a year, an internal owner at £40,000 to £60,000, or a fractional CISO at £1,500 to £4,000 a month.
Is compliance automation software cheaper than a consultant?
Cheaper per year, and buying a different thing. A platform in the Vanta or Drata class runs around £12,000 in year one at small scale, and renewal climbs with headcount, with one breakdown noting 20 to 40 staff pushing renewal past £18,000 at 10 to 20% annual increases. What you get is evidence collection, control monitoring and policy templates. What you don't get is a scope decision, a tailored risk treatment plan, or anyone fixing the technical gaps the platform surfaces. Most teams pay for both eventually, staged rather than at once.
Can we get ISO 27001 without a consultant?
Yes, and for a small cloud-native company it's often the right call. A documentation toolkit runs about £500 against a consultant engagement at £5,000 to £40,000, and a lean self-directed path can land year one around £7,000 to £8,000 all in. What you absorb instead is internal time, typically a founder, CTO or ops lead spending two to three months part time. That trade works when someone will genuinely own it and gets expensive when nobody does.

See it on your own data.

Book a 30-minute discovery call and we'll walk through your use case.