ISO 27001 Certification Cost: What the Quote Doesn't Cover
ISO 27001 certification cost is rarely one number. Ask three certification bodies and you will get three totals that do not overlap.
Ask a consultant and a fourth number appears, usually the largest. This is not because anyone is lying to you. It is because “ISO 27001 certification cost” is being used to mean four different things in the same conversation: the audit fee, the documentation, the internal time, and the three years that follow the certificate — not just the day it is issued.
This article separates those four, prices each one against 2026 European market rates, and gives you a worked example you can hold your own quotes against. It does not sell a certification — nobody can. What follows is the honest arithmetic behind the number a certification body eventually gives you, and the much larger number most companies discover only after they have started.
What you’re actually paying for
Nobody sells you an ISO 27001 certificate. An accredited certification body audits your information security management system (ISMS) against the standard and, if it passes, issues the certificate under its own accreditation. That audit is the one cost you cannot avoid, shrink significantly, or do yourself — it is priced by rules the certification body does not set either (more on that below).
Everything else — the policies, the risk register, the Statement of Applicability, the evidence an auditor samples — is documentation and process you have to build before that audit happens. You can build it with a consultant, with your own team, or from a template kit. Nobody certifies the documents; the auditor certifies that the documents match what your organisation actually does. A perfect binder with no operating evidence behind it fails Stage 2 regardless of how much it cost to produce.
That distinction — audit fee versus everything that gets you ready for the audit — is the first thing that makes cost guides confusing, because most of them quote a single number that quietly blends the two.
There’s a second layer worth understanding before any number means anything: certification bodies are themselves accredited, by a national accreditation body — UKAS in the UK, DAkkS in Germany, ACCREDIA in Italy, and so on — that sits inside the IAF Multilateral Recognition Arrangement (IAF MLA). This is what makes an ISO 27001 certificate mean the same thing to a procurement team in Frankfurt as it does to one in Milan. It also explains part of the price spread: certification bodies compete on service and day rate, but not on what the certificate is worth, because the accreditation — not the certification body’s brand — is what a competent due-diligence reviewer actually checks.
The five cost lines a complete quote should have
Almost no single quote covers all five. Certification bodies quote the audit. Consultants quote implementation. Nobody quotes your own team’s time, because it is not an invoice — it is a cost all the same.
| # | Cost line | Who charges it | Easy to underestimate? |
|---|---|---|---|
| 1 | Documentation & implementation | Consultant, internal team, or toolkit | Yes — the biggest hidden line |
| 2 | Independent internal audit | Outsourced auditor or internal (if truly independent) | Often forgotten entirely |
| 3 | Certification body audit — Stage 1 + Stage 2 | The certification body | Underestimated on multi-site or immature ISMS |
| 4 | Surveillance audits — years 1 and 2 | The certification body | Almost always missing from Year 1 budgets |
| 5 | Recertification audit — year 3 | The certification body | Treated as a Year 1 problem, arrives in Year 3 |
Line 1 is where the widest gap between quotes opens up, so it deserves its own section below. Lines 3 to 5 are the certification body’s fee, and they follow a formula that is public — most quotes just don’t show you the formula.
How certification bodies actually calculate the audit fee
Certification bodies do not price the audit by guessing at your company’s complexity over a phone call. Accredited bodies calculate a minimum number of audit days using ISO/IEC 27006-1, the international standard that sets requirements for bodies certifying management systems — not, as a surprising number of published cost guides state, IAF MD 5, which governs quality, environmental and occupational health and safety audits and has never applied to ISMS certification. It works from your effective number of personnel — everyone doing work under the organisation’s control within the ISMS scope, including contractors and freelancers, not your total headcount — mapped against a table of audit days by personnel band.
The current edition, ISO/IEC 27006-1:2024, changed two things certification bodies had relied on for a decade: the number of physical sites is no longer counted separately (audit days are now driven purely by effective personnel, wherever they sit), and freelancers and external staff working within the ISMS scope must be included in the count even if they’re not employees. Certification bodies had until 31 March 2026 to complete the transition, so a quote calculated under the older methodology should already be behind you.
This is why a certification body cannot legally quote you three audit days for a 150-person company, however much you’d like them to: the standard sets a floor. It’s also why asking a certification body “how did you calculate my day count” is a legitimate question, not a difficult one — and one worth asking before you sign, covered in the last section.

The certification body then multiplies that day count by its day rate, which in the European market for 2026 typically runs €800 to €1,500 depending on the certification body’s overhead, seniority of the auditor, and whether the audit is remote or on-site — figures gathered across multiple certification bodies’ published guidance rather than a single source, so treat the range as indicative rather than a quote.
The standard is explicit that the personnel table is a starting point, not the final word: certification bodies must also weigh the complexity of the ISMS — the criticality of the information handled, the type of business, and how the organisation has performed in previous audits — when setting the final duration. Two companies with identical headcount can land on different audit days for this reason: a 60-person company running one product on a single cloud provider sits toward the standard’s minimum; a 60-person company handling payment data across multiple product lines and operating its own infrastructure alongside the cloud can be pushed several days above it. Headcount fixes the starting row in the table; complexity decides how far above the minimum a certification body reasonably lands.
Typical ISO 27001 certification cost by company size
These are Stage 1 + Stage 2 combined, for a single-site organisation with a reasonably mature security baseline going into the audit. Multi-site, immature baselines, and outsourced-heavy infrastructures push toward the top of each range or past it.
This is the actual table certification bodies work from — audit days by effective personnel, as prescribed by ISO/IEC 27006 and reproduced here with the day count converted to a cost range at the €800–€1,500 day rate above. The standard also permits a minimum duration of 70% of the recommended time in limited circumstances, shown alongside it.
| Effective personnel | Recommended audit days (Stage 1 + 2) | Minimum audit days (70%) | Audit fee range (2026, EUR) |
|---|---|---|---|
| 1–10 | 5 | 3.5 | €2,800 – €7,500 |
| 11–15 | 6 | 4.2 | €3,400 – €9,000 |
| 16–25 | 7 | 4.9 | €3,900 – €10,500 |
| 26–45 | 8.5 | 5.9 | €4,700 – €12,750 |
| 46–65 | 10 | 7 | €5,600 – €15,000 |
| 66–85 | 11 | 7.7 | €6,200 – €16,500 |
| 86–125 | 12 | 8.4 | €6,700 – €18,000 |
| 126–175 | 13 | 9.1 | €7,300 – €19,500 |
| 176–275 | 14 | 9.8 | €7,800 – €21,000 |
| 276–425 | 15 | 10.5 | €8,400 – €22,500 |
| 426–625 | 16.5 | 11.5 | €9,200 – €24,750 |
Source: ISO/IEC 27006, as published by IT Governance Europe’s certification cost guidance. The day counts are from the 2015 edition’s table, still the reference most certification bodies quote from; the 2024 revision changed how effective personnel is counted (freelancers included, sites no longer a separate factor) without republishing the day-count table itself, so these figures remain the working baseline as of 2026.

Regional differences within Europe
Day rates aren’t flat across the EU. UK, German, Swiss and Nordic certification bodies tend to sit toward the top of the €800–€1,500 range; certification bodies based in Southern and Central-Eastern Europe are frequently priced lower for the same accreditation and the same audit scope. This is a legitimate reason to get quotes from more than one country if your organisation has no strong preference tied to a specific accreditation body — the certificate carries the same weight under the IAF MLA regardless of which accredited body issued it.
Stage 1 versus Stage 2 — and the gap between them
Stage 1 is a documentation review: does the ISMS exist on paper and does it plausibly cover the standard’s requirements? Stage 2 is the operational audit: does the organisation actually do what the documents say, with evidence — logs, tickets, meeting minutes, training records — sampled to prove it.
Most certification bodies leave 6 to 12 weeks between the two stages, specifically so you can close whatever Stage 1 flags. That gap is where budgets slip: if Stage 1 finds that your risk register hasn’t been through a full review cycle, or that access reviews are described but not evidenced, you’re not paying more to the certification body — you’re spending internal time you didn’t plan for, on a clock the certification body is running.
Major nonconformities found at Stage 2 that can’t be closed on the spot mean a follow-up visit, which is billed as additional audit days. This is the single most common reason final audit spend exceeds the original quote.
Documentation: three paths, three different price tags
This is the line with the widest range in the entire cost structure, because it’s the only one nobody is required to price the same way. A certification body has to follow ISO/IEC 27006. A consultant, an internal team and a template kit vendor don’t — each is solving the same problem with a completely different cost structure, and each carries a different failure mode if it goes wrong.
| Approach | Typical cost | Typical timeline | What you’re trading |
|---|---|---|---|
| Full consultant | €12,000 – €40,000+ | 3–6 months | Highest cost, lowest internal effort, consultant’s judgment embedded in every document |
| Internal team, from scratch | €0 direct cost, high opportunity cost | 6–12 months | Slowest, highest risk of gaps an auditor catches first, but the ISMS is genuinely owned internally |
| Template kit | €500 – €2,000 | 6–10 weeks to adapt | You do the adaptation work; the structure and the mandatory documents are already mapped to the clauses |
None of these three numbers include the certification body’s audit fee — that’s always separate, and always paid directly to the certification body regardless of how you built your documentation. A €590 toolkit and a €35,000 consultant engagement can walk into the same Stage 1 audit; the certification body doesn’t ask how the documents were produced, only whether they hold up.
The realistic honest comparison isn’t cost alone — it’s cost against how much internal expertise you already have. An organisation with nobody who has read the standard cover to cover will spend the consultant fee one way or another, either upfront to a consultant or as extended internal time relearning what the ISO 27001 templates guide already maps out.
Each path also fails differently, and it’s worth knowing the failure mode before you pick one. A consultant engagement fails quietly: the documentation looks complete because someone experienced wrote it, but if the internal team never really absorbs why each control exists, the ISMS stops evolving the day the consultant’s contract ends, and the next audit cycle finds a system frozen at the moment it was handed over. An internal-team-from-scratch effort fails visibly and early: gaps show up at Stage 1 because nobody who wrote the documents had audited one before, and the standard’s less obvious requirements — documented information control, management review inputs, the interested-parties register — get missed first. A template kit fails when it’s treated as a find-and-replace exercise instead of an adaptation: the structure and clause mapping are done, but a risk register copied in with generic entries and never actually populated with your organisation’s real assets and threats will not survive Stage 2 sampling, regardless of how professional it looks in Stage 1.
What drives ISO 27001 certification cost up, beyond headcount
Headcount sets the floor. These push past it:
- Multiple sites or business units in scope — under ISO/IEC 27006-1:2024 this no longer adds audit days automatically the way it once did, but a certification body still factors it into the complexity adjustment and travel logistics, and may still schedule a separate visit per site for remote-auditing eligibility reasons
- Heavy reliance on cloud and outsourced infrastructure — auditors extend scope to your supplier due diligence and contracts, which takes longer to sample
- An immature security baseline — if there’s no existing access control discipline, logging, or incident process, implementation time (not audit time) is what balloons
- Concurrent regulatory obligations — organisations also in scope for NIS-2 often try to run both programmes together, which shortens overall spend but requires documentation built to satisfy both from the start, not retrofitted
- A compressed timeline — rushing Stage 1 with unresolved gaps is the single most reliable way to trigger a paid follow-up visit at Stage 2
Why the same company gets three different quotes
Send the same scope description to three certification bodies and the day counts will be close — ISO/IEC 27006 doesn’t leave much room to disagree — but the commercial terms around those days rarely match. This is where the real spread in quotes comes from, and it’s worth reading past the headline total.
| What varies | What to look for |
|---|---|
| Bundling | Some bodies quote Year 1 only; others bundle all three years into a single fixed contract, which protects you from a Year 4 price increase but locks you in |
| Travel and site-visit fees | Bodies with a local office near you quote lower or zero travel; bodies auditing remotely from another country add it as a separate line |
| Remote vs on-site mix | Post-2023 IAF rules allow a portion of surveillance audits to be remote; not every body offers the maximum allowed remote share, and remote days are usually cheaper |
| Multi-year discount | A three-year commitment at signing is frequently 5–10% cheaper in total than paying Year 1 and re-quoting each surveillance separately |
| Scope creep clauses | Some contracts fix the day rate but not the day count if your headcount grows — read what happens if you cross a complexity band mid-cycle |
None of this changes the ISO/IEC 27006 floor. It changes how much of the number above the floor you end up paying, and whether you find out about it in Year 1 or Year 4.
The three-year cycle: certification doesn’t end at the audit
A quote for “ISO 27001 certification cost” that only covers the initial audit is quoting a third of what you’ll actually spend to hold a valid certificate for three years, which is how the cycle is structured.
| Year | What happens | Typical certification body cost |
|---|---|---|
| Year 1 | Stage 1 + Stage 2 (initial certification) | 100% of the audit fee — see table above |
| Year 2 | Surveillance audit | Roughly 30–40% of the initial audit days |
| Year 3 | Surveillance audit | Roughly 30–40% of the initial audit days |
| Year 4 | Recertification audit | Close to the full initial audit fee again |
Surveillance audits are shorter but not optional, and not free — skipping one lapses the certificate. Budget for them in Year 1, not when the invoice arrives in Year 2.

Hidden costs almost no quote includes
The standard itself. ISO 27001 and ISO 27002 are copyrighted texts you must purchase from ISO or your national standards body — roughly €100–€160 for the pair. Auditors reference clause numbers directly in findings; a summary you found in a blog post, including this one, is not a substitute for the clause text when you’re deciding how to close a nonconformity.
The mandatory independent internal audit. Clause 9.2 requires it before certification and at least annually after. “Independent” has a specific meaning — the person auditing a process can’t have built it. In a company small enough that one person built the whole ISMS, this is an external cost of €1,500–€5,000 per cycle, not an internal task you can assign your way out of.
Employee security awareness time. Not large per person — typically one to two hours annually — but multiplied across the organisation and repeated every year for the life of the certificate, it’s a real recurring line that almost never appears in a Year 1 budget built around getting certified rather than staying certified.
Penetration testing, if your Statement of Applicability includes Annex A control 8.29 and your risk assessment calls for it. €2,000 to €20,000 depending on scope, paid to a separate provider, and easy to miss because it isn’t mentioned by name anywhere in the standard — it falls out of a risk decision, not a checklist.
Tooling, if you decide a spreadsheet-based risk register and manual evidence collection won’t scale past a certain headcount. GRC platforms range from a few hundred euros a month for a lightweight tool to well into five figures annually for an enterprise platform with automated evidence collection — entirely optional at small scale, increasingly hard to avoid past a few hundred employees.
Internal staff time, which is the largest line in almost every real budget and the one that never appears on an invoice. A realistic planning assumption is 15–25% of one person’s time for four to eight months for a small-to-mid organisation building an ISMS for the first time, more if that person is also learning the standard as they go rather than following an existing structure.
Travel and site-visit costs, if your certification body doesn’t offer remote auditing for your sector or region, or if your risk profile requires an on-site Stage 2 regardless of preference — common for organisations handling physical records, industrial control systems, or data centre operations.
A worked example: an 80-person SaaS company
Single site, cloud-native infrastructure, no prior formal ISMS, using a template kit rather than a consultant. 80 effective personnel falls in the 66–85 band, so the standard’s recommended duration is 11 audit days; at a mid-range day rate of roughly €1,150, that puts the audit fee around €12,500.
| Item | Cost |
|---|---|
| ISO 27001 & 27002 standard texts | €140 |
| Documentation — template kit | €590 |
| Internal implementation time (~5 months, part-time) | Not invoiced — plan 20% of one FTE |
| Independent internal audit (outsourced) | €2,800 |
| Certification body audit — Stage 1 + Stage 2 (11 days per ISO/IEC 27006) | €12,500 |
| Year 1 total, invoiced | ≈ €16,000 |
| Year 2 — surveillance audit (~4 days) | €4,600 |
| Year 3 — surveillance audit (~4 days) | €4,600 |
| Year 4 — recertification audit (~10 days) | €11,500 |
Swap the €590 documentation line for a full consultant engagement at this company’s size and Year 1 invoiced cost moves to roughly €28,000–€45,000 — the audit fee doesn’t change; only the documentation line does.

A second example: a 220-person multi-site manufacturer, with a consultant
Different profile entirely — two production sites plus a head office, some industrial control systems in scope, an existing quality management system but no formal ISMS, and a board that wants a consultant’s name behind the implementation for supplier due-diligence reasons. 220 effective personnel falls in the 176–275 band — 14 recommended days — and the complexity factors above (industrial systems, multiple sites, a first-time ISMS) push the day rate toward the top of the range rather than the day count itself, since ISO/IEC 27006-1:2024 no longer adds days purely for site count.
| Item | Cost |
|---|---|
| ISO 27001 & 27002 standard texts | €140 |
| Consultant engagement (documentation + implementation support) | €28,000 |
| Independent internal audit (outsourced) | €4,200 |
| Certification body audit — Stage 1 + Stage 2 (14 days per ISO/IEC 27006, complexity-adjusted rate ~€1,400) | €19,600 |
| Year 1 total, invoiced | ≈ €51,900 |
| Year 2 — surveillance audit (~5 days) | €7,000 |
| Year 3 — surveillance audit (~5 days) | €7,000 |
| Year 4 — recertification audit (~13 days) | €18,200 |
Same standard, same three-year structure, roughly three times the invoiced Year 1 cost of the SaaS example — driven by a higher personnel band, industrial systems widening audit scope, and a consultant engagement instead of a template kit. Headcount moved the day count from 11 to 14; complexity moved the day rate, not a separate site allowance, which is the practical effect of the 2024 revision.
Questions to ask before you sign a certification body quote
- Which accreditation body accredits you, and is it recognised in the markets your customers care about? A certificate from a body with no recognised accreditation is close to worthless in due diligence.
- How many audit days, and how were they calculated? A body that can’t explain its ISO/IEC 27006 calculation in one sentence is worth a second opinion.
- What triggers a follow-up visit, and what does it cost? Get this in writing before Stage 1, not after a nonconformity is raised.
- Is the quote for remote, on-site, or hybrid auditing? Travel costs for on-site multi-day audits are sometimes quoted separately and are easy to miss.
- What’s included in the surveillance and recertification quote, and is it fixed for three years or subject to review?
FAQ
What’s the cheapest realistic way to get ISO 27001 certified? A mature security baseline, an internal team willing to do the documentation work with a template kit rather than a consultant, and a single-site, low-complexity scope. That combination gets Year 1 invoiced cost — audit plus internal audit — into the €10,000–€15,000 range for a small organisation, before internal time.
Why do quotes for the same company vary by 3x between certification bodies? Day rate differences explain some of it, but the larger driver is how conservatively each body applies ISO/IEC 27006’s complexity adjustments. Ask for the day count, not just the total, and compare that first.
Can we skip Stage 1 and go straight to Stage 2? No — it’s a requirement of the certification process for initial certification, not an optional add-on a certification body can waive.
What happens if we let the certificate lapse? You lose it and have to go through initial certification again — Stage 1 and Stage 2, at full cost — rather than a surveillance audit. There’s no discounted path back in.
Does a more expensive certification body mean a more respected certificate? Not directly. What matters to customers doing due diligence is the accreditation body behind your certifier, not the certifier’s day rate. A well-accredited mid-market certification body carries the same weight as a premium one for most commercial purposes.
Is there a cheaper “self-certification” option? No such thing exists for ISO 27001. Any offer of a certificate without an independent accredited audit is not ISO 27001 certification, regardless of what it’s called.
Does running NIS-2 and ISO 27001 together cost less than doing them separately? Usually yes on the documentation side, because a large share of NIS-2 Article 21 measures map onto ISO 27001 controls — see the gap analysis between the two. The certification body audit fee for ISO 27001 doesn’t shrink, since NIS-2 has no certification of its own to combine it with.
Is it cheaper to add a second location to an existing certificate than to certify it separately? Yes, almost always. Adding a site to an existing ISMS scope during a surveillance or recertification cycle typically adds a few audit days rather than triggering a full separate Stage 1 and Stage 2. Certifying the second site as an entirely new ISMS — a different legal entity, for instance — resets you to Year 1 pricing for that entity.
Can we negotiate the certification body’s day rate? The day count is fixed by ISO/IEC 27006; the rate per day and the commercial terms around it — travel, bundling, multi-year discounts — are negotiable, particularly for organisations large enough to be a meaningful account. Smaller organisations have less leverage on rate but more on which certification body they choose in the first place.
Sources
ISO/IEC 27001:2022 and ISO/IEC 27006-1:2024 are published by ISO and must be purchased; this article describes their requirements without reproducing their text. The audit-day table by effective personnel is drawn from ISO/IEC 27006’s published methodology as summarised by IT Governance Europe; day-rate ranges are gathered across several 2026 market sources and are indicative, not quoted figures from any certification body.
None of this changes with who writes your documentation. What changes is the invoice for Line 1 — and that’s the one line in the whole structure you have full control over.