Search for what ISO 27001 certification costs and page one hands you £5,000 to £50,000 from one UK breakdown, $5,000 to $35,000 for the audit alone from a US one, and six-figure totals from pages pricing an implementation contractor. The ranges don’t overlap cleanly and none of them is lying. They’re pricing different purchases, and almost nobody says which.
So the useful thing to establish first is which part of the bill is close to arithmetic and which part is entirely your decision.
The audit fee, in structure
The part governed by a standard
The certification body’s fee isn’t a negotiation in the way most buyers expect, because the time a body spends auditing you is constrained by the standard its accreditation depends on.
ISO/IEC 27006-1:2024 gives a base audit time driven by the number of people in scope, set out in Annex C. Read the word base carefully, because this is where most cost pages go wrong. The same annex carries the factors that adjust that base for business complexity and IT environment, and the adjustment moves in both directions. A tightly scoped SaaS company lands under the table figure. A regulated, multi-jurisdiction estate with heavy on-premise infrastructure lands above it, sometimes substantially. Anyone presenting the table as a fixed minimum has skipped the half of the annex that decides your actual number.
The day bands most cost pages reproduce carry over from the earlier ISO/IEC 27006:2015 Annex B structure and run:
| People in scope | Base audit days |
|---|---|
| 1–10 | 5 |
| 11–15 | 6 |
| 16–25 | 7 |
| 26–45 | 8.5 |
| 46–65 | 10 |
| 66–85 | 11 |
| 86–125 | 12 |
| 126–175 | 13 |
| 176–275 | 14 |
Multiply by a day rate and you’ve a defensible estimate of the audit invoice, not a quote. At the £1,250 day rate used in that UK breakdown, a 12-person company sits near £7,500 and a 60-person company near £12,500. A US source puts the day rate at roughly $1,500 and total audit fees at $5,000 to $35,000, with sub-50-employee organisations landing at three to six days and $5,000 to $10,000.
Worth flagging honestly: that same UK source quotes £1,250 per day in its worked examples while stating elsewhere that 2026 rates reach £1,500 per auditor day, and its own table prices 14 days at £20,625, which £1,250 a day doesn’t produce. We aren’t going to resolve someone else’s internal arithmetic for them. Treat £1,250 to £1,500 as the live band, get your own quotes, and notice that a 20% swing across twelve days is real money.
Two structural details catch people out. Stage 1 and stage 2 aren’t billed evenly, and the common certification-body convention puts stage 1 at 20 to 30% of the total and stage 2 at the remaining 70 to 80%. That split is pricing practice rather than anything the standard mandates. And the day count follows people in scope, not company headcount. Those are different numbers, and the gap between them is the largest single lever you control.
Where the published totals stop agreeing
Above the audit fee, every cost is a choice, which is exactly why credible sources land an order of magnitude apart. The UK and US breakdowns line up like this:
| Cost line | UK figure | US figure | Can you skip it |
|---|---|---|---|
| Gap analysis | £3,500 to £10,000 | about $6,000 | Yes, if you do it yourself against the standard |
| Implementation, toolkit route | about £500, 30 to 90 days | not quoted | This is the choice, not a line item |
| Implementation, consultant | £5,000 to £40,000, 6 to 12 months | not quoted | Depends who owns the ISMS |
| Implementation, contractor | £40,000 to £160,000 | not quoted | Only if you are buying speed |
| Internal audit | £3,500 to £10,000 | roughly $7,500 | No, it is required before certification |
| Compliance platform | around £12,000 year one, past £18,000 at 20 to 40 staff | not quoted | Yes, at small scale |
| Penetration testing | £3,000 to £8,000 a year | $5,000 to $20,000 | Depends on your risk treatment plan |
| Awareness training | £30 to £50 per employee per year | not quoted | No |
| Lead Auditor course, 5 days | £2,200 to £2,500 | not quoted | Yes, unless you are auditing internally |
Two notes on reading that table. The UK source quotes gap analysis at £2,500 to £5,000 elsewhere on the same page, so treat it as a wide band rather than a benchmark. And the internal audit line is the same discipline covered in a broader security audit engagement, scoped down to your ISMS controls.
The row that explains the whole disagreement is implementation. A page quoting £5,000 total assumed the toolkit route. A page quoting six figures assumed the contractor route. Both published a real number for a real purchase, and neither said so.
What no table anywhere includes is internal time, which is usually the largest real cost. In a small company that means a CTO or ops director absorbing two to three months part time. Price it at their loaded rate before you decide the self-directed path is free.
The three-year number, which is the one that matters
We run cloud infrastructure and build production systems for clients, and the planning mistake we watch companies make is budgeting year one as though it were the whole cost. It isn’t. ISO 27001 runs on a three-year cycle, and the second and third years arrive whether or not anyone put them in the spreadsheet.
Surveillance audits fall in years one and two. The accreditation convention across management-system schemes is that annual surveillance time runs about a third of the initial certification audit, so the reliable way to size it is to take your own audit fee and divide by three, with a practical floor of about one audit day. Published surveillance ranges are worth checking against that arithmetic, because the £3,000 to £10,000 range on the UK page doesn’t reconcile with a third of its own audit table.
Recertification lands in year three, and this is where a widely repeated number misleads. Vendor pages routinely quote recertification at 100% of the initial cost. The accreditation guidance says otherwise: IAF MD 5, which formally covers quality, environmental and occupational health and safety management systems rather than ISMS, sets recertification audit time at approximately two thirds of what an initial audit would require if carried out today, explicitly not two thirds of what you originally paid. ISMS audit time is governed by ISO/IEC 27006-1, but certification bodies apply the same two-thirds convention by analogy. Since the whole model is days times a day rate, a two-thirds audit can’t honestly cost a full fee. Budget two thirds, ask your body to confirm it in writing, and treat a 100% quote as something to question.
Then there’s the annual cost of keeping the ISMS alive: a retained consultant at £12,000 to £36,000, an internal owner at £40,000 to £60,000, or a fractional CISO at £1,500 to £4,000 a month. The US source frames ongoing internal audit plus surveillance as averaging about $15,000 annually.
A certificate you can’t maintain is worse than no certificate, because the failure surfaces at surveillance in front of the customer who asked for it. If the maintenance line has no owner and no budget, the year-one number isn’t your number.
The levers with arithmetic behind them
Most cost advice on this topic is a list of vendors. Here’s an opinion we’ll defend: the vendor you pick is close to the least important decision on this page, and the four things below will move your total further than any amount of shopping around. Scope beats sourcing.
Cut the scope, not the corners. Audit days follow people and systems inside the boundary you define. Scope reduction can remove up to 30% of audit days, and a tightly scoped cloud-native environment saves half a day to a full day outright. Multi-site organisations get a sampling approach rather than a visit per site, though ISO/IEC 27006-1:2024 revised how multi-site ISMS audit time is calculated in clause C.6, so ask your body to show its working rather than assuming an older rule of thumb.
Ask what the remote portion can be. The 2024 edition changed how remote auditing is treated, and the practical position now varies by body and by what your environment looks like. For a cloud-native company with no server room to walk anyone through, the case for a largely remote audit is strong, and the saving is in travel and expenses that one breakdown puts at £500 to £2,000. The day rate doesn’t change, so confirm the current position with your certification body rather than assuming either the old cap or an unlimited allowance.
Stack certifications instead of sequencing them. Running SOC 2 and ISO 27001 as one integrated audit is reported to save around 30% against doing them separately, and the same source puts adding ISO 42001 to an existing ISO 27001 program at £3,000 to £6,000 in extra audit fees against roughly 40% implementation overlap. Both figures come from a single vendor page, so treat them as directional. The point stands regardless: if two frameworks are on your roadmap inside eighteen months, sequencing them matters more than which body you pick. Our write-up on what a SOC 2 push looks like on a 90-day clock covers the other half of that decision.
Buy the toolkit before the platform. For a micro-business, toolkit versus SaaS over three years is a reported saving of up to £18,000. Platforms earn their keep at the scale where manual evidence collection genuinely stops working, which arrives later than the sales cycle suggests.
What to settle before you collect quotes
Three things decide your number, and none of them is which certification body you pick.
The first is how many people are genuinely in scope, which isn’t headcount but the people who touch information assets inside the boundary you define. Overstate it and you buy audit days you never needed. That boundary question is where our cybersecurity practice spends most of its time with clients who have already been quoted, because it’s the one input that moves every other number on the page.
The second is who owns the ISMS on an ordinary Tuesday in month fourteen. If the answer is nobody, you’re buying a consultant engagement plus a maintenance retainer, and you should stop comparing yourself to the £7,000 self-directed case study.
The third is whether a specific deal is driving this. A named enterprise customer with a contractual deadline changes the calculus, because you’re buying speed, which means consultants and tooling. Certification pursued as general market positioning can take the slow, cheap path, and usually should.
When the quotes arrive, insist each one states its assessed audit days and its day rate as separate lines. Nothing obliges a certification body to volunteer that breakdown, which is exactly why you have to ask. Without those two numbers you can’t tell whether one quote is more expensive because the body charges more or because it scoped you into a higher complexity band, and those two problems have completely different fixes.