Enquire Us

ISO 27001 Certification Cost

What actually drives the cost of ISO 27001 certification: scope, headcount, sites, Annex A applicability, certification body audit time and the surveillance cycle. Fees are quoted per organisation, so this page explains the drivers rather than quoting prices.

Why this page does not quote a price

ISO 27001 certification does not have a list price, and any site that publishes one is quoting an average of jobs that had nothing to do with yours. Certification body fees are driven by audit time, which accredited bodies must derive using defined rules rather than set freely. Consultancy fees depend on how much of the management system already exists. Both are quoted per organisation after a scoping discussion.

What is useful is understanding the drivers, because most of them are within your control. The list below is what actually moves the number.

The cost drivers

  • Scope of the information security management system. Which entities, products, services and locations sit inside the boundary. This is the single largest lever, because everything else scales from it.
  • Number of persons doing work under the control of the organisation within scope. This is the primary input to certification body audit time under ISO/IEC 27006-1. Contractors and part time staff working within the scope count.
  • Number of sites and whether multi site sampling applies. Several small offices can cost more to audit than one larger one, although sampling rules can reduce this where the sites operate the same system.
  • Complexity of the information processed. Regulated data, personal data at scale, payment data or classified information all push audit time and implementation effort upwards.
  • Annex A applicability. The 93 controls are a reference set, and your risk assessment decides which apply. An organisation that runs its own data centres, does secure development and manages a large supplier estate has far more applicable controls than one that consumes a single cloud platform.
  • Starting maturity. Whether you already have access control, change management, logging, incident response, supplier due diligence and business continuity in a documented and evidenced form.
  • Whether a gap assessment is needed. A formal gap assessment is an additional cost that usually pays for itself by preventing rework and by making the Stage 1 outcome predictable.
  • Internal capability. Whether you have people who can run the risk assessment, write the Statement of Applicability and conduct internal audits, or whether that has to be bought in and then transferred.
  • Travel and geography. On site audit days carry travel and subsistence. Distributed organisations and remote sites cost more, though remote auditing is permitted for parts of the audit under the applicable rules.
  • Technology. Tooling for logging, monitoring, endpoint protection, vulnerability management or governance is often bought during implementation. It is a security cost rather than a certification cost, but it lands in the same budget.

How the fees break down

It helps to keep three budgets separate, because they are paid to different parties and behave differently over time.

  • Certification body fees. Application and contract review, Stage 1, Stage 2, the certification decision, surveillance audits across the three year cycle, and recertification before expiry. Priced in audit days. The number of days is derived under ISO/IEC 27006-1 and is not a matter of negotiation with an accredited body.
  • Consultancy or readiness fees. Gap assessment, risk assessment, Statement of Applicability, documented information, control implementation support, internal audit and management review, and audit support. Priced per engagement against a defined scope of work.
  • Internal cost. The time your own people spend. This is normally the largest single component and it almost never appears in a quotation. Underestimating it is the most common budgeting error we see.

Note that the certification body cannot also provide the consultancy. The accreditation rules that certification bodies work under require consultancy and certification to be kept separate, so a single supplier cannot legitimately quote for both.

The three year view

An accredited ISO 27001 certificate is valid for three years, subject to surveillance audits during that period, normally annually, and a recertification audit before it expires. Budgeting only for initial certification produces an unpleasant surprise in year two.

Over a full cycle the recurring items are the surveillance audit fees, the recertification audit, the internal audit programme, management review, the annual refresh of the risk assessment and Statement of Applicability, awareness training for joiners, and whatever remediation the audits and your own monitoring produce. Scope changes, new sites, acquisitions and new product lines all trigger additional cost and must be notified to the certification body.

Where organisations overspend

  • Scoping too widely at the start. Certifying the whole group when the customer only asked about one platform inflates audit days and implementation effort permanently, not just once.
  • Buying tools before understanding the risk assessment. Technology bought to satisfy a control that turns out not to be applicable is money spent for nothing.
  • Treating documentation as the deliverable. Large document sets that describe work nobody does fail at Stage 2 and have to be rebuilt.
  • Skipping the gap assessment. The saving is small and the risk is a failed Stage 1, which means paying the certification body twice.
  • No internal capability transfer. If nobody internally can run the internal audit programme, the consultancy cost recurs every year instead of tapering.
  • Choosing a body on price alone. An unusually low quotation normally means fewer audit days than the rules require, which is a problem when a customer checks the certificate.

How Univate prices its work

Univate quotes per organisation after a scoping discussion, because that is the only honest way to price this work. We look at the proposed ISMS scope, the number of people and sites inside it, the nature of the information processed, what already exists in documented and evidenced form, and what your internal team can carry.

Certification body fees are separate and are paid directly to the body you appoint. We do not receive commission from certification bodies and we do not issue certificates, because the accreditation rules keep those roles apart. If you want a comparable set of certification body quotations, the practical step is to agree the scope statement first, then send the same scope to each body so the audit day calculation is done on identical inputs.

Cost questions we are asked most often

Why does nobody publish a price for ISO 27001 certification?

Because the two largest components are both organisation specific. Certification body audit time is derived from the requirements in ISO/IEC 27006-1, which scale with the number of persons doing work under the control of the organisation within the ISMS scope and with complexity factors. Consultancy effort depends on how much of the management system and the applicable Annex A controls already exist. Two companies with the same headcount can need very different amounts of work. Any figure quoted without seeing a scope is a guess.

What are the separate fees involved?

There are normally three distinct lines. First, certification body fees, covering application, Stage 1, Stage 2, the surveillance audits during the three year cycle and the recertification audit. Second, consultancy or readiness fees if you use an external partner. Third, internal cost, meaning the time your own people spend, which is usually the largest and least visible item. Technology purchases and travel sit outside all three.

How is certification body audit time determined?

Accredited certification bodies for information security management systems work to ISO/IEC 27006-1:2024 alongside ISO/IEC 17021-1. Audit time is derived primarily from the number of persons doing work under the control of the organisation within the scope of the ISMS, then adjusted for complexity factors such as the number of sites, the nature of the information processed, the technology used and applicable regulatory obligations. It is not set by negotiation, which is why quotations from accredited bodies for the same scope tend to be broadly comparable in audit days.

Does a narrower scope make certification cheaper?

Usually yes, because audit time and implementation effort both follow scope. But scope is a commercial decision before it is a cost decision. A certificate covering one product line will not satisfy a customer who expects the whole service to be covered, and re-scoping later means going back through the certification process. Set the scope your customers will accept, then look at cost.

What costs continue after the certificate is issued?

The certificate is valid for three years and the certification body carries out surveillance audits during that period, normally annually, followed by a recertification audit before expiry. Internally you continue to run the risk assessment, the internal audit programme, the management review and the corrective action process. Budget for the whole three year cycle rather than for the initial certification alone.

Can we reduce cost by using an unaccredited certification body?

Quotations from bodies without accreditation are sometimes lower because they are not bound by the audit time requirements in ISO/IEC 27006-1. The risk is that the certificate may not be accepted. Customers and tender panels increasingly ask for a certificate from a body accredited by a recognised national accreditation body, and accredited certificates can be checked in IAF CertSearch. A certificate that has to be redone is the most expensive outcome available.

Need help achieving this certification? Univate Global delivers end-to-end implementation in 9 markets. Book a free consultation today.

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.