ISO 27001 certification cost is not a single fee. It is five separate line items spread across a three-year cycle: certification body audit fees, implementation and remediation, internal audit, tooling, and internal staff time. Most organizations budget only the first and are then surprised in year two, when surveillance audits arrive and the certificate has to be maintained rather than merely obtained.

This guide breaks down each line item, explains the mechanism that actually determines what a certification body charges you, and sets out what to budget across the whole cycle rather than just the first invoice.

A note on the numbers below. Ranges quoted here reflect general market observation and published sources. They are not a quotation and they are not a benchmark. Pricing varies by region, scope, headcount, and certification body, and the only figure that matters to your budget is the one on the proposals in front of you. Treat these ranges as a structure for asking better questions, not as a price list.

What determines ISO 27001 certification body fees?

The certification body's fee is set by audit days, not by a menu price. The number of audit days is calculated from tables in ISO/IEC 27006, the standard that governs bodies auditing and certifying information security management systems, driven primarily by the number of people in scope of your ISMS and adjusted for complexity factors. Your fee is audit days multiplied by the body's day rate.

This is the single most useful thing to understand about ISO 27001 pricing, because it tells you which lever actually moves the number.

Headcount in scope drives days. Not total company headcount, headcount within the ISMS scope. A 400-person company certifying one product line with 60 people in scope pays for a 60-person audit, provided the scope boundary is genuine and defensible.

Complexity factors adjust days up or down. Number of sites, number of distinct technology platforms, regulatory context, whether processes are outsourced, and whether the ISMS is integrated with other management system standards.

Day rates vary by certification body and region. Published 2026 market rates sit broadly around 1,500 to 2,200 US dollars per day in the United States and roughly 1,000 to 1,500 pounds per day in the United Kingdom. Premium global brands sit at the top of that band, and regional accredited bodies at the bottom.

Multi-site organizations can sample rather than visit everywhere. Under IAF mandatory document MD 1, certification bodies may audit a sample of sites rather than all of them, which materially changes the cost picture for distributed organizations.

The practical implication: two organizations of identical size can receive quotes that differ by a factor of two, and the difference is usually scope definition and choice of body, not quality of audit. Scoping the ISMS tightly around what your customers actually require is the highest-leverage cost decision available to you, and it happens before you request a single quote.

The five ISO 27001 certification cost components

ComponentWhat it coversWho you payWhen
Certification body feesStage 1 and Stage 2 audits, report writing, certificate issuanceAccredited certification bodyYear 1
Implementation and remediationClosing gaps: policies, controls, tooling changes, process designInternal team, consultants, or bothBefore Stage 2
Internal auditThe Clause 9.2 internal audit programInternal function or outsourced firmAnnually, ongoing
ToolingGRC platform, evidence collection, monitoring, penetration testingVendorsOngoing
Internal staff timeThe largest and least budgeted itemNobody invoices you for itThroughout

That last row is the one that wrecks budgets. Preparing for certification consumes engineering, IT, HR, and leadership time across several months. It does not appear on any invoice, which is precisely why it is routinely omitted from cost estimates, including most of the ones you will find ranking for this topic. If you are building a business case, cost the internal hours. They are usually comparable to the certification body fee and sometimes larger.

The full three-year cycle

ISO 27001 certificates run on a three-year cycle. Year one carries the Stage 1 and Stage 2 certification audit. Years two and three carry annual surveillance audits, which are shorter, typically running around one third of the initial audit effort. Year four carries a recertification audit, which is a fuller exercise closer in scale to the original certification audit.

Here is the shape of the cycle, using a small to mid-sized software organization with a contained scope as the illustration:

YearCertification body activityOther recurring costsRelative cost
Year 1Stage 1 and Stage 2Implementation, remediation, first internal audit, toolingHighest
Year 2Surveillance audit 1Internal audit, management review, tooling, ongoing maintenanceRoughly one third of year 1 audit fees, plus maintenance
Year 3Surveillance audit 2Internal audit, management review, tooling, ongoing maintenanceSimilar to year 2
Year 4RecertificationInternal audit, management review, tooling, remediation of driftApproaching year 1 audit fees

Two things follow from this table that a first-year-only estimate hides.

Maintenance is not free and it is not optional. The ISMS has to keep running. Risk assessments get refreshed, the Statement of Applicability gets reviewed, internal audits happen, management reviews happen, and evidence gets collected continuously. An organization that goes quiet after the certificate arrives shows up at surveillance with a twelve-month gap in records, and surveillance audits find that immediately.

Year four is a real budget event. Recertification is not a formality and it is not priced like a surveillance audit. Plan for it in year three.

Why the published cost range is so wide

Search this topic and you will find numbers from a few thousand to well over a hundred thousand. Both ends are real. The range is wide because published figures rarely state which components they include and which they exclude, and because the underlying variables genuinely differ by an order of magnitude.

Five variables account for almost all of the spread:

Scope. One product, one team, one cloud environment is a fundamentally different audit from a multi-entity, multi-site, multi-jurisdiction ISMS. Scope drives audit days, which drives fees, and it also drives implementation effort.

Starting maturity. An organization that already holds a SOC 2 report, or already runs access reviews, change management, vendor risk assessment, and incident response as real processes, is buying documentation and evidence discipline rather than a security program. An organization starting from nothing is buying both.

Build versus buy on implementation. Full-service consultancy sits at one end, internal build with templates at the other, and the difference can be tens of thousands. Note that internal build is not free, it just moves the cost from an invoice line to staff time.

Certification body choice. Premium global brands charge premium day rates. A smaller accredited body performs an audit of equivalent standing, because the accreditation is what confers recognition, not the logo.

Region. Day rates, consultant rates, and salary costs all vary substantially between markets.

If you want a usable number rather than a range, the fastest route is a scoping conversation followed by two or three quotes from accredited bodies. A gap assessment before you request quotes usually pays for itself, because it lets you scope accurately and quote the real gaps instead of guessing.

How long does ISO 27001 certification take?

For an organization starting with a reasonable security baseline but no formal ISMS, six to twelve months to Stage 2 is a realistic planning assumption. Starting from a low baseline, twelve to eighteen months is more common. The compressing constraint is not documentation. It is that your ISMS has to have operated long enough to produce records.

This is the timeline fact that most cost content omits, and it matters more than any price. A Stage 2 auditor samples evidence of the ISMS operating. If your risk assessment was completed three weeks ago, your first internal audit happened last week, and you have held no management review, there is nothing to sample. Certification bodies generally expect the management system to have been running for a period, commonly cited as around three months minimum, before Stage 2 is meaningful, and many will want longer.

You cannot buy your way past this. You can shorten implementation with money. You cannot shorten the operating record, because it is made of elapsed time.

The practical sequence:

  1. Scope definition and gap assessment
  2. Risk assessment, risk treatment plan, Statement of Applicability
  3. Implementation and remediation of gaps
  4. The ISMS runs and generates records
  5. Internal audit under Clause 9.2 and management review under Clause 9.3
  6. Stage 1, documentation and readiness review
  7. Remediation of Stage 1 findings
  8. Stage 2, the certification audit
  9. Closure of any nonconformities, then certificate issuance

Steps 5 and 6 are non-negotiable prerequisites. An internal audit and a management review must have happened before Stage 1, because Stage 1 examines those records. Organizations that treat the internal audit as a post-certification activity discover this at the worst possible moment.

Why a cheap quote is a risk, not a saving

There is a floor below which an accredited ISO 27001 certification cannot be delivered, because audit days are set by ISO/IEC 27006 and days cost money. A quote materially below the market floor for your headcount means one of three things: the scope has been narrowed to something your customers will not accept, the audit days have been understated, or the body issuing the certificate is not accredited.

The third is the one that has changed the risk calculation recently. Following the 2026 allegations against compliance automation vendor Delve, which included claims that certifications were routed through unaccredited bodies and that auditor conclusions were generated before evidence was reviewed, enterprise buyers have started checking the provenance of certificates rather than accepting them at face value. Delve disputed aspects of the allegations. The market effect, however, was immediate: a certificate is now a starting point for a procurement conversation rather than the end of one.

An unaccredited certificate has a specific commercial failure mode. It looks identical to a real one, costs less, and passes unexamined for as long as nobody examines it. When a sophisticated buyer does examine it, the deal it was purchased to unlock is the thing it costs you.

How to check accreditation before you sign. Certification bodies are accredited by national accreditation bodies, for example ANAB in the United States and UKAS in the United Kingdom, which are themselves signatories to the International Accreditation Forum multilateral arrangement. Two checks, both free:

  1. Search the certification body on IAF CertSearch, the global database of accredited management system certifications.
  2. Check the body's listing directly with its national accreditation body, for example ANAB in the United States or UKAS in the United Kingdom, and confirm the accreditation covers ISO/IEC 27001 specifically rather than some other standard.

Ask any prospective certification body which accreditation body accredits them for ISO/IEC 27001, and verify the answer independently. A legitimate body answers this in one sentence and expects the question.

Where the money is actually saved

Cost reduction on ISO 27001 comes from four places, none of which involve paying less for the audit.

Scope discipline. Certify what your customers require, not everything you own. This is the largest single lever and it is entirely within your control. It has to be a genuine boundary, not a paper one, because Stage 1 examines scope.

Reusing what exists. Auditors care that controls exist and operate, not that they were authored for ISO 27001. Existing SOC 2 controls, NIST CSF mappings, GDPR records of processing, and even informal runbooks all count as inputs. Organizations that rebuild their control set from scratch for ISO 27001 are usually paying twice for work they already did.

Finding gaps before the certification body does. A nonconformity raised at Stage 2 costs remediation time, a corrective action cycle, and in some cases a follow-up audit visit. The same gap found at internal audit costs a ticket. This is the entire economic argument for a serious Clause 9.2 program, and it is why internal audit is a cost line that reduces total cost rather than adding to it.

Right-sizing the certification body. Accreditation confers recognition. Brand confers brand. Decide deliberately which you are buying, because you are paying differently for each.

Frequently asked questions

How much does ISO 27001 certification cost for a small company?

For a small organization with a contained scope, published market ranges commonly place first-year total cost, including certification body fees, implementation, and tooling, somewhere between roughly 10,000 and 40,000 US dollars, with certification body audit fees making up a minority of that. The spread within that band is driven almost entirely by starting maturity and by whether implementation is done internally or by consultants. Get quotes; the ranges are orientation, not pricing.

Is ISO 27001 certification a one-time cost?

No. The certificate runs on a three-year cycle with annual surveillance audits in years two and three and a recertification audit in year four. Between audits, the ISMS must be maintained, which means recurring internal audit, management review, risk assessment refresh, and evidence collection. Budget ISO 27001 as an ongoing program cost, not a project cost.

How much do ISO 27001 surveillance audits cost?

Surveillance audits are shorter than the initial certification audit, commonly around one third of the effort, and are priced accordingly. The exact figure follows from audit days at your certification body's day rate, the same mechanism that sets your Stage 1 and Stage 2 fees.

Does ISO 27001 cost more than SOC 2?

They are not directly comparable, because ISO 27001 produces a certification against a management system standard and SOC 2 produces an attestation report against the Trust Services Criteria. In practice, first-year costs are often in a similar range for a comparable scope, but the cost profiles differ: ISO 27001 carries a predictable three-year cycle with surveillance audits, while SOC 2 Type 2 carries an annual examination over an observation period. Which one to pursue first is usually a commercial question about who your buyers are and where they are, not a cost question.

Can I get ISO 27001 certified without a consultant?

Yes. Nothing in the standard requires external help with implementation. What the standard does require, under Clause 9.2, is an internal audit conducted with objectivity and impartiality, which means auditors cannot audit their own work. In a small team where the same people own every control, that independence requirement is difficult to satisfy internally, which is why many organizations implement in-house and outsource only the internal audit.

What is the cheapest way to get ISO 27001 certified?

Narrow the scope to what your customers actually require, reuse controls and evidence you already have, run a gap assessment before committing to anything so you are pricing real gaps rather than guessing, and select a right-sized accredited certification body rather than a premium brand. What is not a legitimate cost reduction is an unaccredited certificate, which saves money only until a buyer checks it.

How do I know if a certification body is accredited?

Check IAF CertSearch, the global database of accredited management system certifications, and check the body's listing with its national accreditation body such as ANAB or UKAS. Confirm the accreditation specifically covers ISO/IEC 27001. Both checks are free and take a few minutes.

Related reading: how much does a SOC 2 audit cost in 2026, how much does SOC 2 readiness cost in 2026, ISO 27001 vs SOC 2: which framework first, and ISO 27001 internal audits explained, Clause 9.2.