
ISO 27001 cost comes in three parts: building the information security management system (ISMS), which is mostly staff time plus any outside help and security fixes; the certification body's audits; and the yearly work of keeping the system running. The only fixed price is the standard itself, which ISO lists at CHF 155 as of October 2026. Certification bodies quote their audit fees from the audit time the certification rules require, so published figures vary by certifier.
We help companies build and run the controls behind an ISMS through our vCISO services, which cover risk priorities, written policies and reporting to leadership. We are not a certification body, and we publish no prices. This guide keeps consulting and certification fees apart and ends with a worksheet for comparing quotes. For the requirements themselves, use our ISO 27001 checklist.
How much does ISO 27001 certification cost?
Every ISO 27001 budget has the same lines. What differs is who sets each price, and only one of them is published:
| Cost line | What it pays for | Who sets the price | When you pay |
|---|---|---|---|
| The standard | ISO/IEC 27001:2022, the requirements; optionally ISO/IEC 27002:2022, guidance for each control | ISO's published list price | Once, per user license |
| Staff time | Leadership, an ISMS owner, risk and process owners, management review and support for audits | Your payroll | Every month, heaviest in the first year |
| Implementation help, if you want it | Gap assessment, risk assessment facilitation, policies, the Statement of Applicability and evidence planning | A consultant or managed provider | A project, then ongoing if you keep them |
| Security fixes | Whatever the gap assessment finds: MFA, device management, logging, backups, vulnerability scanning, awareness training | Vendors and providers | One-time work plus subscriptions |
| Internal audit | An objective check of the ISMS before the certification body arrives, then on a schedule | Your staff or an outside auditor | At least yearly |
| Certification audits | The initial certification audit, surveillance audits and recertification | The certification body, from audit time | Initial audit, then each year of the cycle |
| Extras | Compliance software, a penetration test, travel for on-site audit days | Vendors | Varies |
What do the ISO 27001 standards cost?
ISO sells its standards per user. As of October 2026, its store lists:
- ISO/IEC 27001:2022, the requirements, 19 pages: CHF 155. The IEC, which publishes the standard jointly with ISO, lists the same price.
- Amendment 1:2024, climate action changes, which applies to the 2022 edition: free.
- ISO/IEC 27002:2022, 152 pages of guidance on each control: CHF 227.
- ISO's practical guide to ISO/IEC 27001 for small and medium-sized enterprises: CHF 44.
Only ISO/IEC 27001 states requirements an auditor tests; the others are guidance. Buy the standard before anything else, because quotes and templates are only as good as your reading of the clauses they claim to cover.
What drives the certification body's fee?
ISO certifies no one. Its certification page says certification is performed by external certification bodies. Bodies that work to ISO/IEC 17021-1, the international requirements for management system certifiers, add ISO/IEC 27006-1:2024 for information security. Its Annex C is normative and covers audit time, so they follow a defined method for the number of auditor days. Ask for the days behind any quote.
IAF ID 14:2023, the International Accreditation Forum's guidance on audit time for integrated and multi-site audits, lists the main factors certification bodies weigh:
- The effective number of personnel within the scope.
- The risk and complexity of the organization's products, processes or activities.
- The number of sites to be audited.
- Whether the ISMS is audited together with other management systems, such as a quality system.
The same guidance summarizes the ISMS method from the previous edition, ISO/IEC 27006:2015: grade the business and organizational factors, grade the IT environment, combine them into a factor, and multiply the days from an audit time chart by that factor. The 2024 edition was updated for remote audits and for organizations with few or no physical sites, which can reduce travel costs. A tighter scope, fewer people and fewer sites mean fewer auditor days.
What are the ISO 27001 audit stages, and when do you pay?
- Initial certification audit. IAF ID 14 treats the initial audit as one done in two stages, with the audit time being the sum of both. The certification body agrees the dates and scope with you in advance.
- Surveillance audits. ISO/IEC 27006-1 sets out surveillance activities while the certificate is valid, so the audit fee recurs.
- Recertification. A recertification audit renews the certificate at the end of the cycle; IAF ID 14 names it, with the initial audit, as an example of an audit done in two stages.
Microsoft's own certificate shows the rhythm: its Microsoft 365 certificate to ISO/IEC 27001:2022 covers 2024 to 2027, and Microsoft says auditors review its Office 365 services at least once a year. Budget the certification body as a recurring cost, not a single project.
Consulting or certification: what are you paying for?
Keep the two apart in your budget and in your choice of firms. Implementation fees pay for building the ISMS: the scope, the risk assessment, the policies, the controls and the evidence. Certification fees pay an independent body to audit it. ISO/IEC 17021-1 is built on the competence, consistency and impartiality of certification bodies, so the firm that builds your ISMS should not be the one that certifies it.
ISO's advice on choosing a certifier is short: evaluate several certification bodies, check that each uses the relevant conformity assessment standard, and check accreditation, which provides independent confirmation of competence even though it is not compulsory. You can confirm an accredited certificate in the IAF CertSearch database. Ask every certification body for the audit days behind its quote, split by initial audit, each surveillance audit and recertification, and for its daily rate and travel terms.
A SOC 2 report is a different purchase: an attestation by a CPA firm rather than a certificate, as our SOC 2 audit cost guide explains. If customers ask for both, build the controls once and evidence them for each.
How much staff time does ISO 27001 take?
No primary source publishes hours, because they depend on scope and starting point. The roles, though, follow from the clauses. Clause 5 puts leadership, commitment and the information security policy with top management. Someone must run the ISMS day to day. Risk owners take part in the risk assessment in clause 6.1.2 and the treatment decisions in clause 6.1.3. Process owners produce the records that prove each control works. Clause 9.2 needs an internal audit, and clause 9.3 a management review by top management.
The first year carries the most work: the risk assessment, writing and approving policies, fixing gaps and the first internal audit and management review. After certification the work settles into a monthly rhythm of reviews, records and corrective actions.
ISO 27001 budget worksheet
Copy this into a spreadsheet. The questions in the second column are the ones to answer before you ask anyone for a price.
| Line | Questions to settle first | One-time or recurring | Your figure |
|---|---|---|---|
| Scope | Which sites, teams, systems and services are in? How many people work within the ISMS? | Sets every other line | |
| Standards | ISO/IEC 27001 at CHF 155; do you also want ISO/IEC 27002 at CHF 227? | One-time | |
| Gap assessment | Against all of clauses 4 to 10 and every Annex A control, or a sample? | One-time | |
| Implementation help | Does the quote include writing policies and the Statement of Applicability, or templates only? Who attends the audits? | Project, then optional retainer | |
| Security fixes | Which gaps need new tools, and which need configuration of tools you already pay for? | One-time plus subscriptions | |
| Internal audit | Who performs it, and are they independent of the work being audited? | Yearly | |
| Certification body | Audit days for the initial audit, each surveillance audit and recertification; remote or on site; travel | Initial, then yearly | |
| Staff time | Hours for the ISMS owner, process owners and leadership reviews | Ongoing | |
| Extras | Compliance software, penetration testing, training content | Varies |
How do you keep ISO 27001 cost down?
- Scope to what customers need. A scope that covers the service your customers buy, rather than every department, cuts both implementation work and auditor days.
- Choose controls by risk. ISO/IEC 27002 says determining controls depends on decisions that follow a risk assessment. Do not buy tools for controls your risk assessment does not call for.
- Reuse what you run. Access reviews, backups, patching and incident records you already keep for cyber insurance or SOC 2 can serve as ISMS evidence.
- Keep one evidence calendar so records exist when the auditor samples them, instead of being rebuilt the week before.
- Compare certification bodies on audit days, accreditation and remote options, not only the bottom line.
How does NetSys help with ISO 27001?
We align client environments to frameworks including ISO 27001, the NIST Cybersecurity Framework and CIS Controls. Through our vCISO service, a senior security lead sets risk priorities, writes the policies, handles vendor and insurer questions and reports to leadership, while your IT team, another provider or NetSys engineers carry out the fixes. For managed clients, much of the evidence comes from systems we already run, such as identity, devices, email and backups. Mapping a program to a framework is not a certification, and NetSys claims none: an independent certification body audits you. Agreements run month to month.
Want help scoping before you collect quotes? Book a call and we will walk through your scope, your gaps and the questions to put to certification bodies.
Frequently asked questions
What does an ISO 27001 cost estimate cover?
It should cover the standard, staff time, any implementation help, security fixes, internal audits and every certification body audit across the cycle: the initial audit, surveillance audits and recertification. An estimate that lists only the certification audit leaves out most of the first-year cost.
Who maintains the ISMS after certification?
An ISMS owner inside the company runs it, with top management reviewing it at planned intervals under clause 9.3. Risk and process owners keep their parts current, and an outside provider can run controls and evidence. Certification does not end the work, because surveillance audits check that the system is still operating.
How do we validate the ISMS before paying for the certification audit?
Run a full internal audit against clauses 4 to 10 and the controls in your Statement of Applicability, hold a management review, and close or plan every nonconformity it finds. A gap assessment by someone who did not build the controls gives you an independent view before the certification body's auditors arrive.
How much does an ISO 27001 audit cost?
Certification bodies set their own fees, so there is no official price. Their quotes rest on audit days, which ISO/IEC 27006-1 makes them determine using its audit time rules, mainly driven by the people in scope, complexity and the number of sites. Get several quotes and compare the days and day rates.
Can a small business get ISO 27001 certified?
Yes. The standard says its requirements are generic and intended to apply to all organizations, regardless of type, size or nature. A small company usually has a simpler scope, fewer people and one site, which keeps audit time down; the clause 4 to 10 requirements still apply in full.
Do we have to buy the ISO 27001 standard?
To implement it properly, yes. The requirements text is copyrighted and sold by ISO, at CHF 155 for ISO/IEC 27001:2022 as of October 2026, while Amendment 1:2024 is free. Summaries and checklists, including ours, help you plan, but the auditor works from the standard itself.
Sources and further reading
- ISO: ISO/IEC 27001:2022: price, pages, Amendment 1:2024, the SME guide and the certification FAQ, checked October 2026.
- ISO: ISO/IEC 27002:2022: price and length, checked October 2026.
- ISO: Certification: ISO does not certify, how to choose a certification body, and IAF CertSearch, checked October 2026.
- ISO/IEC 27006-1:2024: requirements for ISMS certification bodies, with its contents from the official preview, checked October 2026.
- IAF ID 14:2023, Guidance on the Determination of Audit Time for Integrated Audit of Multi-Site Management Systems (PDF): audit time factors, two-stage audits and the ISO/IEC 27006:2015 method, checked October 2026.
- Microsoft Learn: ISO/IEC 27001 offering: Microsoft's certificate period and annual audits, checked October 2026.
Related reading
ComplianceISO 27001 vs ISO 27002: The Certifiable Standard and the Control Guide
Read Article
ComplianceNIST vs ISO 27001 vs CIS Controls: Key Differences and Which to Use
Read Article
ComplianceISO 27001 Checklist: Requirements, Annex A Controls and Audit Readiness
Read ArticleAlso on this topic: vCISO vs CISO: What Mid-Sized Companies Need · Email Encryption Cost for Small Business
Discuss vciso services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
