Last reviewed 8 August 2026 by Tom McNamara. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 06-08-2026”.
ISO 27001 certification cost is four separate lines, not one number: implementation effort, certification body fees, tooling, and your own team’s time. Published figures put certification body fees for a small company at €4,500 to €7,000 in Ireland or £6,250 to £11,250 in UK estimates for the initial audit, with surveillance audits on top. The total depends mainly on your headcount, your scope, and how much of the implementation you do yourself.
Three wildly different quotes in your inbox usually means each provider quoted a different combination of these four lines:
| Cost line | What it covers | Honest published range | Source |
|---|---|---|---|
| Certification body fees | Stage 1 and Stage 2 initial audit, then annual surveillance | €4,500 to €7,000 initial (under 10 staff, Ireland); £6,250 to £11,250 by headcount (UK estimate); £1,500 to £2,500 per year surveillance (packaged) | Amtivo; IT Governance / GRC Solutions; Citation ISO |
| Tooling | Documentation templates, evidence collection, monitoring | £295 to £997 one-off toolkits; $4,995 to $15,995 per year platforms | High Table; LowerPlane |
| Your team’s time | Internal effort across the whole project | Not published by any provider; the one line no external quote covers | See below |
Why listen to us
Atoro is an Irish AI governance and cyber compliance consultancy for software companies. We are ISO 27001 certified ourselves, and we were the first consultancy in Europe certified against ISO 42001. We deliver ISO 27001 implementation at a fixed price agreed after scoping, so we wrote this guide to show you the four lines before you compare any quote, ours included.
What actually drives the cost of ISO 27001 certification
Three things move your number more than anything else: how many people and locations sit inside your scope, how mature your security already is, and who does the implementation work.
Headcount and scope set the audit days
ISO/IEC 27006-1:2024 sets the audit time certification bodies must use. Its Table C.1 maps the number of people in scope to mandatory auditor days for the initial audit (Stage 1 plus Stage 2):
| People in scope | Minimum initial audit days |
|---|---|
| 11–15 | 6 |
| 16–25 | 7 |
| 26–45 | 8.5 |
| 46–65 | 10 |
| 66–85 | 11 |
| 86–125 | 12 |
(Source: ISO/IEC 27006-1:2024 Table C.1, corroborated via the European Accreditation FAQ, checked 06-08-2026.)
Those are days, not money; multiply by a certification body’s day rate and you have the fee. It is also why scope matters: scope the product, systems and people that touch customer data and you stay in a cheaper band; scope the whole company and you pay for it.
Your existing security maturity
Two companies of the same size can get implementation quotes that differ several-fold, and the difference is almost always maturity. If your security basics are already documented and followed, implementation is mostly formalising what exists. If not, it means building all of that while your team keeps shipping product, and every quote prices that gap differently.
Who does the work and who certifies it
No accredited certification body publishes a fee schedule. We checked major bodies across the UK, Ireland and the US (BSI, LRQA, NQA, SGS, Bureau Veritas, NSAI, Amtivo, Schellman, A-LIGN, Coalfire and others): every accredited body prices by quotation only (checked 06-08-2026). Amtivo’s published guidance adds that accredited bodies do not charge for quotations, so shopping around costs nothing but time.
Accreditation matters more than the logo on the certificate. In the UK the accreditation body is UKAS; in Ireland it is INAB, whose directory lists the accredited certification bodies. A suspiciously cheap quote often turns out to be a non-accredited certificate: real document, wrong pedigree, and the first thing an enterprise procurement team checks.
The three-year cycle
Certification is not a one-off purchase. It runs a three-year cycle: initial audit, surveillance audits in years two and three, then recertification. Amtivo’s guidance describes annual surveillance audits on top of initial certification, typically much shorter. A quote showing only year one shows you a third of the commitment; demand all three years in writing.
The honest ranges, line by line
Everything below is a published figure with its source named.
Certification body fees (the most predictable line)
- Amtivo (Ireland, INAB-accredited, Dublin) publishes guidance of €4,500 to €7,000 for the initial certification of a small business with fewer than 10 staff at one location (Stage 1 plus Stage 2). Annual surveillance audits run on top, typically much shorter. (Amtivo, checked 06-08-2026.)
- IT Governance / GRC Solutions (UK) publishes an estimated certification-fee table for UKAS-accredited audits: 1 employee means 5 audit days and £6,250; 11 staff, 6 days, £7,500; 16 staff, 7 days, £8,750; 26 staff, 9 days, £11,250. That implies roughly £1,250 per audit day. Treat it as their published estimate, not a certification body’s rate card. (IT Governance / GRC Solutions, checked 06-08-2026.)
- Citation ISO Certification (UK) sells a package: from £131.55 plus VAT per month on a seven-year contract, plus an initial consultancy fee from £4,030 plus VAT. Its indicative table shows £5,000 to £11,000 for initial certification and £1,500 to £2,500 per year for surveillance and recertification support. Worth knowing: Citation ISO bundles consultancy and certification together, a combination UKAS accreditation restrictions do not allow an accredited body to offer, so ask what accreditation stands behind the certificate before you buy. (Citation ISO, checked 06-08-2026.)
Implementation effort (the variable line)
- Consultant day rates. Amtivo publishes guidance of €450 to €1,200 per day for external consultants. (Amtivo, checked 06-08-2026.)
- Opsio publishes tiers: gap analysis at $8,000 to $15,000 one-time, full ISMS implementation at $20,000 to $60,000, and surveillance-audit support at $3,000 to $8,000 per year. (Opsio, checked 06-08-2026.)
- CyberSapiens (Australia) publishes fixed-price end-to-end engagements including the certificate through a partner registrar: AUD $8,000 to $20,000 for organisations of 1 to 50 staff, AUD $12,000 to $30,000 for 50 to 250 staff. (CyberSapiens, checked 06-08-2026.)
- DIY documentation toolkits. Advisera’s 27001Academy toolkit lists at $897 one-time or $100 per month; High Table’s packs run £295 to £997. (Both checked 06-08-2026.)
- The standard itself costs about €137 from ISO. (Amtivo, checked 06-08-2026.)
Tooling and platforms
- LowerPlane is one of the few platforms with list prices: $4,995 per year for its Starter plan (one framework), $9,995 for Growth, $15,995 for Scale, plus $3,000 per additional framework per year. Auditor fees are separate. (LowerPlane, checked 06-08-2026.)
- Of the eleven compliance-platform vendors we checked, six publish no price at all: Vanta, Drata, Sprinto, Secureframe, Scytale and ISMS.online all require a sales conversation first. (Verified on their own pricing pages, 06-08-2026.)
A platform reduces the effort of collecting evidence and monitoring controls: real time saved. It does not remove the implementation itself: somebody still has to decide your scope, run your risk assessment, write policies that fit how you work, and sit in front of the auditor.
Your team’s time
The fourth line never appears on a quote because nobody invoices you for it. Someone inside your company owns the ISMS, gathers evidence, sits through audit interviews and fixes whatever the audit finds. No provider publishes verified figures for this internal effort. Treat it as a real budget line, paid in salaries and delayed roadmap rather than invoices.
A worked example, so the lines add up
Take a 15-person software company at one location. It needs 6 audit days under ISO/IEC 27006-1:2024; on IT Governance’s published estimate that is £7,500 for the initial audit, with surveillance to follow (Citation ISO’s indicative figure is £1,500 to £2,500 per year). Add a toolkit at £295 to £997, or a platform from $4,995 per year, and then the consulting days you actually need at €450 to €1,200 each. That last number is what scoping exists to fix, and it cannot be quoted honestly before someone looks at your setup.
What a cheap quote gets you versus a real one
The cheapness always comes from somewhere:
| Suspiciously cheap | The real thing | |
|---|---|---|
| Price shown | Year one only | The full three-year cycle, both surveillance audits included |
| Implementation | Template documents with your logo pasted in | An ISMS built around how your team actually works |
| Scope | Your whole company, maximising audit days | Tight scope around the product and customer data |
| Ongoing costs | Platform renewals, internal audit and travel discovered later | Surveillance, internal audit and expenses budgeted from day one |
The costs nobody mentions until after you have signed
These five extras are predictable. Budget for all of them.
- Surveillance audits in years two and three. Covered above, but they keep surprising founders. Ask what years two and three cost before you sign year one.
- The internal audit. ISO/IEC 27001:2022 requires you to run internal audits of your own ISMS (clause 9.2). If nobody on your team can run one, you pay someone external, and many first quotes leave this out.
- Travel and expenses. Ask whether travel for on-site audit days is inside the day rate or invoiced on top.
- Extra locations. Every additional site in scope can add audit days; remote-first teams should ask how the certification body treats them.
- Platform renewal pricing. Ask what the renewal costs in year two before you build your evidence collection inside a platform.
How to reduce the cost honestly
You cannot negotiate the audit-day table, but you can shrink everything around it.
- Scope tightly. Certify the product and the systems and people that touch customer data, not the whole company. Fewer people in scope means fewer mandatory audit days and a smaller ISMS to build.
- Do the preparation yourself, buy expertise where it counts. A toolkit gets you documentation for a few hundred pounds. Where outside help earns its fee is gap analysis and audit readiness: the judgement calls about which controls apply and what evidence convinces an auditor.
- Use a platform for evidence collection, not as a substitute for implementation. Once spreadsheets stop holding up, a platform saves real hours on evidence and monitoring. Budget it on top of implementation, not instead of it.
- Get three certification body quotes and compare like for like. Accredited bodies do not charge for quotations (Amtivo’s published guidance). Force every quote onto the same page: same scope, same audit days, all three years.
- Ask for a fixed price. Atoro delivers ISO 27001 implementation at a fixed price agreed after scoping, so the variable line becomes a known number before work starts. Our pricing page explains how that works, and the ISO 27001 implementation service page covers what the engagement includes.
When the number is worth paying
The number is worth paying when a contract requires the certificate. At that point ISO 27001 stops being a compliance cost and becomes the price of admission to revenue you cannot otherwise close.
Put the full three-year cost, all four lines, next to the contract that triggered this, then add the deals behind it in the pipeline. The certificate outlives any single contract: every enterprise security review gets shorter once you hold it. If the contracts are real, the cycle pays for itself. If the requirement is speculative, ask the prospect what they actually need, and when, before you spend anything.
Frequently asked questions
How much does ISO 27001 certification cost in total?
Four lines make up the total: implementation effort, certification body fees, tooling and your team’s time. Published figures put certification body fees for a small company at €4,500 to €7,000 in Ireland (Amtivo) or £6,250 to £11,250 in UK estimates (IT Governance), with surveillance audits extra. Implementation is the variable: a DIY toolkit costs a few hundred pounds; full-service engagements run into the tens of thousands.
How much is ISO 27001 for a 40-person company?
A 40-person company sits in the 26 to 45 bracket of ISO/IEC 27006-1:2024: 8.5 mandatory audit days for the initial audit. On IT Governance’s published estimate, fees land around £11,000 (£11,250 at 26 staff). Everything else depends on your security maturity and who does the implementation.
Is £6,000 for a one-person company madness?
It feels like madness, but the fee is set by mandatory audit time, not by how simple your business is. Even a one-person company needs five audit days under ISO/IEC 27006-1:2024, and five days at typical day rates lands near that figure. You cannot shrink the audit days, but you can shrink everything else: a £295 toolkit, a tight scope, your own preparation.
What is the cheapest way to get ISO 27001 certified?
Buy a documentation toolkit (Advisera’s lists at $897, High Table’s starts at £295), scope tightly around the product and customer data, and do the implementation yourself. Then get quotes from three accredited certification bodies; accredited bodies do not charge for quotations. The one corner not to cut is accreditation: a cheap non-accredited certificate is the one your prospect’s procurement team can reject.
Does a compliance platform like Vanta or Drata include certification?
No. Platforms collect evidence and monitor controls; the audit itself is always performed and priced separately by a certification body. LowerPlane, which publishes its prices, states that auditor fees are separate from its $4,995 per year Starter plan. A platform reduces evidence-collection effort; it does not remove the implementation work or the audit.
Why are my three ISO 27001 quotes so different?
Because each quote bundles different lines and assumptions. One may be audit fees only, another may bundle consultancy, a third may quietly exclude surveillance in years two and three. Ask each provider the same three questions: how many audit days, which accreditation body, what do years two and three cost. The answers make the quotes comparable.
Do I have to pay for ISO 27001 every year?
Yes, in practice. Certification runs a three-year cycle: initial audit, surveillance audits in years two and three, then recertification. Amtivo’s published guidance describes annual surveillance audits on top of initial certification, typically much shorter. Any quote that shows only year one is showing you a third of the commitment.
Can a one-person or very small company get ISO 27001?
Yes. The standard certifies your information security management system, not a minimum headcount, and the audit-day table starts at one person. The honest caveat is cost: five mandatory audit days make the fee feel disproportionate for a solo founder. If the certificate unlocks a contract it can still be worth it; if not, ask your customer what they actually need first. The honest next step is a scoping conversation, not a quote pulled from a rate card. Atoro’s ISO 27001 implementation service starts with scoping precisely so implementation effort becomes a fixed price before you commit. For the ongoing side, surveillance years, evidence collection, internal audit, see our TrustOps service.
Sources
- Amtivo (Ireland), “How much does ISO 27001 certification cost”, https://amtivo.com/ie/resources/insights/how-much-does-iso-27001-certification-cost/ (checked 06-08-2026). Initial certification €4,500–€7,000 (under 10 staff, one location); surveillance extra; consultant day rates €450–€1,200; ISO standard document ~€137; accredited CBs do not charge for quotations.
- IT Governance / GRC Solutions, “ISO 27001 certification costs”, https://grcsolutions.io/iso27001-certification-costs/ (checked 06-08-2026; page returned HTTP 403 to direct fetch, figures captured from indexed page of 27-05-2026 and treated as their published estimate). Fee table by headcount and audit days, £6,250 to £11,250.
- Citation ISO Certification (formerly QMS), “ISO 27001 cost”, https://www.qmsuk.com/iso-standards/iso-27001/iso-27001-cost (checked 06-08-2026). Package from £131.55 + VAT per month on a seven-year contract plus initial consultancy fee from £4,030 + VAT; indicative table £5,000–£11,000 initial, £1,500–£2,500 per year. Bundles consultancy with certification; check the accreditation behind the certificate with UKAS directly.
- ISO/IEC 27006-1:2024, Table C.1 audit-time chart, corroborated via European Accreditation FAQ, https://european-accreditation.org/sp_accordion_faqs/question-48-5-audit-time-determination-to-iso-iec-27006-12024-for-multisite-c-6/ (checked 06-08-2026).
- INAB, directory of accredited management-systems certification bodies, https://www.inab.ie/inab-services/management-systems-certification/directory-of-management-systems-certification-bodies/ (checked 06-08-2026).
- ISO/IEC 27001:2022, clause 9.2 (internal audit requirement).
- Opsio, ISO certification compliance pricing, https://opsiocloud.com/iso-certification-compliance/ (checked 06-08-2026).
- CyberSapiens, ISO 27001 certification pricing, https://cybersapiens.com.au/iso-27001-certification-in-australia/ (checked 06-08-2026).
- LowerPlane pricing, https://lowerplane.com/pricing (checked 06-08-2026).
- Advisera 27001Academy, ISO 27001 documentation toolkit, https://advisera.com/27001academy/iso-27001-documentation-toolkit/ (checked 06-08-2026).
- High Table, ISO 27001 toolkit pricing, https://hightable.io/iso-27001-toolkit-pricing/ (checked 06-08-2026).
- No-price-published verification (all checked 06-08-2026 on the vendors’ own pages): Vanta, https://www.vanta.com/pricing; Drata, https://drata.com/pricing; Sprinto, https://sprinto.com/pricing/; Secureframe, https://secureframe.com/pricing; ISMS.online, https://www.isms.online/pricing/. Certification-body fee-schedule absence checked across BSI, LRQA, NQA, SGS, Bureau Veritas, Alcumus ISOQAR, Interface NRM (UK); NSAI, Amtivo, BQAI (Ireland); Schellman, A-LIGN, Coalfire (US).