Last updated: 25 September 2026
Quick answer: ISO 27001 certification cost depends on four things: the external audit fees charged by your certification body, which scale with audit days and headcount; internal staff time; any consultancy or tooling; and the cost of closing security gaps. Budget for a three-year cycle, not just the first audit, because surveillance and recertification audits recur.
Ask five people what ISO 27001 certification costs and you will get five different numbers. That is not because anyone is hiding the answer. It is because the price is driven by your scope, your size, your starting maturity and how much of the work you do yourself.
This guide breaks ISO 27001 certification cost into its components, explains what drives each one and gives you a worksheet to build your own estimate. It is written for CISOs who need to build the business case and CFOs who need to approve it.
What drives ISO 27001 certification cost?
The biggest drivers are the size and complexity of your scope, your current security maturity and your choice between doing the work internally or buying help. The external audit is usually only one part of the total.
It helps to be clear about who you are paying. According to ISO’s own guidance, ISO does not perform certification or issue certificates. Certification is carried out by independent certification bodies, and ISO recommends checking whether a body is accredited, which provides independent confirmation of its competence. Accredited certificates are what most customers and regulators expect to see.
The standard itself, ISO/IEC 27001:2022, is a paid document, and it has one amendment, ISO/IEC 27001:2022/Amd 1:2024, which adds climate action changes. Buying the standard is a small line in the budget, but you will need it, along with ISO/IEC 27002 for control guidance.
The five cost categories
Almost every ISO 27001 budget breaks down into the same five categories. Use them as the rows of your business case.
| Category | What it covers | Main driver | One-off or recurring |
|---|---|---|---|
| Certification body fees | Stage 1 and stage 2 audits, surveillance audits, recertification | Audit days, set largely by headcount and scope complexity | Recurring every year |
| Internal staff time | ISMS owner, control owners, risk workshops, internal audit, management review | Maturity and scope | Heavy in year one, then ongoing |
| External support | Consultancy, gap assessment, internal audit, training | How much expertise you have in-house | Mostly year one |
| Tools and platforms | GRC software, policy management, evidence storage | Number of frameworks and users | Recurring |
| Remediation | New security controls, technology, process changes | Gap between current state and requirements | Mostly one-off, some recurring |
Common mistake: budgeting only for the certification audit. Internal staff time and remediation can easily exceed the audit fees, especially in the first year.
How are certification audit fees calculated?
Certification bodies price audits largely by the number of auditor days required, multiplied by their day rate. The number of days is not arbitrary: accredited bodies calculate it using rules in ISO/IEC 27006-1.
ISO/IEC 27006-1:2024 sets requirements for bodies that audit and certify information security management systems. As the US accreditation body ANAB explains in its transition notice, the 2024 edition updated the audit time calculations in Annex C and introduced the concept of persons performing certain identical activities, which affects how the effective number of personnel is determined. Since 31 March 2026, ANAB has required its accredited ISMS certification bodies to use the 2024 edition for all clients.
In practice, audit duration depends on:
- the effective number of people working under the organisation’s control within scope;
- the number of sites and whether sampling is allowed for multi-site organisations;
- the complexity of the business, its IT environment and regulatory context;
- outsourced processes and the number of legal entities involved.
Ask several accredited certification bodies for a quote with the audit days broken down by stage. Comparing days is more meaningful than comparing totals, because it shows whether each body has understood your scope.
What does the three-year certification cycle look like?
Certification runs on a three-year cycle. Under ISO/IEC 17021-1, the cycle begins with the certification decision, surveillance audits take place at least once a calendar year except in recertification years, and the first surveillance audit must happen no later than 12 months after the initial certification decision. The initial audit is carried out in two stages.
| Year | Audit activity | Budget note |
|---|---|---|
| Year 1 | Stage 1 (documentation and readiness) and stage 2 (implementation and effectiveness) | Highest audit fees, plus implementation costs |
| Year 2 | First surveillance audit | Shorter audit, ongoing internal effort |
| Year 3 | Second surveillance audit | Shorter audit, ongoing internal effort |
| Year 4 | Recertification audit, starting a new cycle | Longer than surveillance, shorter than initial |
Internal costs: the part most budgets miss
An ISO 27001 information security management system needs people. At minimum you need an ISMS owner, risk and control owners across the business, and senior management who take part in the management review.
Typical internal activities include defining scope, running the risk assessment, writing and approving policies, producing the Statement of Applicability, training staff, collecting evidence, running an internal audit and holding a management review. Our guide to the ISO 27001 Statement of Applicability explains one of the most time-consuming documents in detail.
In practice: track internal hours from the start of the project. It gives the CFO a real number for year one and shows how much the effort drops once the ISMS is running.
Consultancy, tools and remediation
External support
Some organisations run the whole project internally. Others buy a gap assessment, implementation support or an independent internal audit. Be careful about one rule: an organisation that consults on your ISMS should not also certify it, as certification bodies must remain impartial. Keep your consultant and your certification body separate.
Tools
Spreadsheets and shared drives can work for a small scope, but they become expensive in staff time as evidence, risks and policies multiply. A GRC platform with policy management, risk registers and evidence storage reduces the recurring effort, especially if you also need SOC 2, NIS2 or GDPR. Look for cross-framework control mapping so one piece of evidence can support several standards. If customers also ask for SOC 2, our SOC 2 vs ISO 27001 comparison shows how to build one control set for both.
Remediation
This is the most variable category. A mature organisation may need only documentation. Another may need multi-factor authentication, logging, backup testing, supplier reviews or secure development practices. A gap assessment against the 93 Annex A controls is the only reliable way to size it.
If you want to see your gaps before committing budget, start your 14-day free trial and run an ISO 27001 readiness assessment.
ISO 27001 certification cost worksheet
Use this worksheet to build an estimate over the full three-year cycle. Fill in your own figures from quotes and internal rates.
| Line item | How to estimate | Year 1 | Year 2 | Year 3 |
|---|---|---|---|---|
| Certification body fees | Quoted audit days x day rate, plus any travel | Stage 1 + 2 | Surveillance | Surveillance |
| Internal ISMS owner | Hours x loaded hourly cost | Enter | Enter | Enter |
| Control and risk owners | Hours per owner x number of owners x cost | Enter | Enter | Enter |
| Management review | Attendees x hours x cost | Enter | Enter | Enter |
| Consultancy or internal audit | Fixed quote or days x rate | Enter | Enter | Enter |
| Training | Staff awareness plus specialist courses | Enter | Enter | Enter |
| Tools and platforms | Annual subscription | Enter | Enter | Enter |
| Remediation | From gap assessment findings | Enter | Enter | Enter |
| Standards documents | ISO/IEC 27001 and 27002 purchase | Enter | – | – |
Add a contingency line for findings from the stage 1 audit, which can surface work you did not expect.
How can you reduce ISO 27001 costs?
The most reliable savings come from a tight scope, reuse of existing work and fewer surprises at audit.
- Scope deliberately. Certify the services and locations customers care about first. You can extend the scope later.
- Reuse what exists. Many organisations already hold policies, risk registers and supplier reviews for GDPR, NIS2 or SOC 2.
- Get a gap assessment early. It prevents paying for audit days on an ISMS that is not ready.
- Keep evidence continuously. Collecting evidence all year makes surveillance audits faster and cheaper to prepare for.
- Compare quotes on days. A lower quote with too few days may lead to a rushed audit and more findings.
Does it matter that the 2013 version has ended?
Yes, for budgeting it does. Under IAF MD 26, the transition period to ISO/IEC 27001:2022 ended on 31 October 2025, and all certifications based on the 2013 version expired or were withdrawn at that point. Any new certification project should be based on the 2022 edition and its 2024 amendment.
Enactia’s AI-powered GRC platform supports ISO 27001 compliance alongside 50+ other frameworks, which helps spread the cost of an ISMS across several obligations.
Key takeaways
- ISO 27001 certification cost has five parts: audit fees, internal time, external support, tools and remediation.
- Audit fees depend on audit days, calculated under ISO/IEC 27006-1 largely from the effective number of personnel.
- Budget for a three-year cycle with annual surveillance audits and recertification.
- Internal time and remediation can outweigh audit fees in year one.
- Scope carefully and reuse existing compliance work to control costs.
Frequently asked questions
How much does ISO 27001 certification cost?
There is no fixed price. Certification bodies set their own fees, based mainly on the number of audit days needed for your scope and headcount. Total cost also includes internal staff time, any consultancy or tools, and remediation of gaps. The best way to get a reliable figure is to request itemised quotes from several accredited certification bodies.
Who issues ISO 27001 certificates?
Independent certification bodies issue ISO 27001 certificates, not ISO. ISO develops and publishes the standard but does not certify organisations. Choose a certification body accredited by a recognised national accreditation body, because accredited certificates give customers and regulators independent assurance that the auditor itself meets international requirements.
Are surveillance audits included in the certification price?
It depends on the certification body. Some quote the full three-year cycle, while others quote each audit separately. Surveillance audits are required at least once a calendar year outside recertification years, so make sure every quote shows the costs of stage 1, stage 2, both surveillance audits and recertification, broken down by audit days.
Can we get ISO 27001 certified without a consultant?
Yes. Nothing in the standard or the certification rules requires a consultant. Many organisations run the project internally, using the standard, ISO/IEC 27002 guidance and a GRC tool. A consultant can speed things up when in-house experience is limited, but the consultant must not be the same organisation that certifies your ISMS.
Does a larger company always pay more for ISO 27001?
Generally, larger scopes need more audit days, so fees rise with the effective number of personnel, sites and complexity. However, a larger company with a mature security programme may spend less on remediation and consultancy than a smaller company starting from scratch. Scope, maturity and reuse matter as much as size.
Conclusion: budget for the cycle, not the certificate
ISO 27001 certification is an investment in a management system, not a one-off purchase. A credible budget covers the three-year audit cycle, the internal effort to run the ISMS, any outside help and the controls you need to close gaps. Build it line by line, compare certification quotes on audit days, and reuse work across frameworks wherever you can.
To scope your ISO 27001 project or see how to manage it alongside other frameworks, contact us or book a demo or start your 14-day free trial.
