HomeBlogCost Guides

ISO 27001 Certification Cost: Fees, Audit Stages and a Budget Worksheet

Pixel-art illustration of a robot on a pirate ship's deck holding up a glowing blue shield against red bug-shaped threats above stormy waves

ISO 27001 cost comes in three parts: building the information security management system (ISMS), which is mostly staff time plus any outside help and security fixes; the certification body's audits; and the yearly work of keeping the system running. The only fixed price is the standard itself, which ISO lists at CHF 155 as of October 2026. Certification bodies quote their audit fees from the audit time the certification rules require, so published figures vary by certifier.

We help companies build and run the controls behind an ISMS through our vCISO services, which cover risk priorities, written policies and reporting to leadership. We are not a certification body, and we publish no prices. This guide keeps consulting and certification fees apart and ends with a worksheet for comparing quotes. For the requirements themselves, use our ISO 27001 checklist.

How much does ISO 27001 certification cost?

Every ISO 27001 budget has the same lines. What differs is who sets each price, and only one of them is published:

Cost lineWhat it pays forWho sets the priceWhen you pay
The standardISO/IEC 27001:2022, the requirements; optionally ISO/IEC 27002:2022, guidance for each controlISO's published list priceOnce, per user license
Staff timeLeadership, an ISMS owner, risk and process owners, management review and support for auditsYour payrollEvery month, heaviest in the first year
Implementation help, if you want itGap assessment, risk assessment facilitation, policies, the Statement of Applicability and evidence planningA consultant or managed providerA project, then ongoing if you keep them
Security fixesWhatever the gap assessment finds: MFA, device management, logging, backups, vulnerability scanning, awareness trainingVendors and providersOne-time work plus subscriptions
Internal auditAn objective check of the ISMS before the certification body arrives, then on a scheduleYour staff or an outside auditorAt least yearly
Certification auditsThe initial certification audit, surveillance audits and recertificationThe certification body, from audit timeInitial audit, then each year of the cycle
ExtrasCompliance software, a penetration test, travel for on-site audit daysVendorsVaries

What do the ISO 27001 standards cost?

ISO sells its standards per user. As of October 2026, its store lists:

  • ISO/IEC 27001:2022, the requirements, 19 pages: CHF 155. The IEC, which publishes the standard jointly with ISO, lists the same price.
  • Amendment 1:2024, climate action changes, which applies to the 2022 edition: free.
  • ISO/IEC 27002:2022, 152 pages of guidance on each control: CHF 227.
  • ISO's practical guide to ISO/IEC 27001 for small and medium-sized enterprises: CHF 44.

Only ISO/IEC 27001 states requirements an auditor tests; the others are guidance. Buy the standard before anything else, because quotes and templates are only as good as your reading of the clauses they claim to cover.

What drives the certification body's fee?

ISO certifies no one. Its certification page says certification is performed by external certification bodies. Bodies that work to ISO/IEC 17021-1, the international requirements for management system certifiers, add ISO/IEC 27006-1:2024 for information security. Its Annex C is normative and covers audit time, so they follow a defined method for the number of auditor days. Ask for the days behind any quote.

IAF ID 14:2023, the International Accreditation Forum's guidance on audit time for integrated and multi-site audits, lists the main factors certification bodies weigh:

  • The effective number of personnel within the scope.
  • The risk and complexity of the organization's products, processes or activities.
  • The number of sites to be audited.
  • Whether the ISMS is audited together with other management systems, such as a quality system.

The same guidance summarizes the ISMS method from the previous edition, ISO/IEC 27006:2015: grade the business and organizational factors, grade the IT environment, combine them into a factor, and multiply the days from an audit time chart by that factor. The 2024 edition was updated for remote audits and for organizations with few or no physical sites, which can reduce travel costs. A tighter scope, fewer people and fewer sites mean fewer auditor days.

What are the ISO 27001 audit stages, and when do you pay?

  1. Initial certification audit. IAF ID 14 treats the initial audit as one done in two stages, with the audit time being the sum of both. The certification body agrees the dates and scope with you in advance.
  2. Surveillance audits. ISO/IEC 27006-1 sets out surveillance activities while the certificate is valid, so the audit fee recurs.
  3. Recertification. A recertification audit renews the certificate at the end of the cycle; IAF ID 14 names it, with the initial audit, as an example of an audit done in two stages.

Microsoft's own certificate shows the rhythm: its Microsoft 365 certificate to ISO/IEC 27001:2022 covers 2024 to 2027, and Microsoft says auditors review its Office 365 services at least once a year. Budget the certification body as a recurring cost, not a single project.

Consulting or certification: what are you paying for?

Keep the two apart in your budget and in your choice of firms. Implementation fees pay for building the ISMS: the scope, the risk assessment, the policies, the controls and the evidence. Certification fees pay an independent body to audit it. ISO/IEC 17021-1 is built on the competence, consistency and impartiality of certification bodies, so the firm that builds your ISMS should not be the one that certifies it.

ISO's advice on choosing a certifier is short: evaluate several certification bodies, check that each uses the relevant conformity assessment standard, and check accreditation, which provides independent confirmation of competence even though it is not compulsory. You can confirm an accredited certificate in the IAF CertSearch database. Ask every certification body for the audit days behind its quote, split by initial audit, each surveillance audit and recertification, and for its daily rate and travel terms.

A SOC 2 report is a different purchase: an attestation by a CPA firm rather than a certificate, as our SOC 2 audit cost guide explains. If customers ask for both, build the controls once and evidence them for each.

How much staff time does ISO 27001 take?

No primary source publishes hours, because they depend on scope and starting point. The roles, though, follow from the clauses. Clause 5 puts leadership, commitment and the information security policy with top management. Someone must run the ISMS day to day. Risk owners take part in the risk assessment in clause 6.1.2 and the treatment decisions in clause 6.1.3. Process owners produce the records that prove each control works. Clause 9.2 needs an internal audit, and clause 9.3 a management review by top management.

The first year carries the most work: the risk assessment, writing and approving policies, fixing gaps and the first internal audit and management review. After certification the work settles into a monthly rhythm of reviews, records and corrective actions.

ISO 27001 budget worksheet

Copy this into a spreadsheet. The questions in the second column are the ones to answer before you ask anyone for a price.

LineQuestions to settle firstOne-time or recurringYour figure
ScopeWhich sites, teams, systems and services are in? How many people work within the ISMS?Sets every other line
StandardsISO/IEC 27001 at CHF 155; do you also want ISO/IEC 27002 at CHF 227?One-time
Gap assessmentAgainst all of clauses 4 to 10 and every Annex A control, or a sample?One-time
Implementation helpDoes the quote include writing policies and the Statement of Applicability, or templates only? Who attends the audits?Project, then optional retainer
Security fixesWhich gaps need new tools, and which need configuration of tools you already pay for?One-time plus subscriptions
Internal auditWho performs it, and are they independent of the work being audited?Yearly
Certification bodyAudit days for the initial audit, each surveillance audit and recertification; remote or on site; travelInitial, then yearly
Staff timeHours for the ISMS owner, process owners and leadership reviewsOngoing
ExtrasCompliance software, penetration testing, training contentVaries

How do you keep ISO 27001 cost down?

  • Scope to what customers need. A scope that covers the service your customers buy, rather than every department, cuts both implementation work and auditor days.
  • Choose controls by risk. ISO/IEC 27002 says determining controls depends on decisions that follow a risk assessment. Do not buy tools for controls your risk assessment does not call for.
  • Reuse what you run. Access reviews, backups, patching and incident records you already keep for cyber insurance or SOC 2 can serve as ISMS evidence.
  • Keep one evidence calendar so records exist when the auditor samples them, instead of being rebuilt the week before.
  • Compare certification bodies on audit days, accreditation and remote options, not only the bottom line.

How does NetSys help with ISO 27001?

We align client environments to frameworks including ISO 27001, the NIST Cybersecurity Framework and CIS Controls. Through our vCISO service, a senior security lead sets risk priorities, writes the policies, handles vendor and insurer questions and reports to leadership, while your IT team, another provider or NetSys engineers carry out the fixes. For managed clients, much of the evidence comes from systems we already run, such as identity, devices, email and backups. Mapping a program to a framework is not a certification, and NetSys claims none: an independent certification body audits you. Agreements run month to month.

Want help scoping before you collect quotes? Book a call and we will walk through your scope, your gaps and the questions to put to certification bodies.

Frequently asked questions

What does an ISO 27001 cost estimate cover?

It should cover the standard, staff time, any implementation help, security fixes, internal audits and every certification body audit across the cycle: the initial audit, surveillance audits and recertification. An estimate that lists only the certification audit leaves out most of the first-year cost.

Who maintains the ISMS after certification?

An ISMS owner inside the company runs it, with top management reviewing it at planned intervals under clause 9.3. Risk and process owners keep their parts current, and an outside provider can run controls and evidence. Certification does not end the work, because surveillance audits check that the system is still operating.

How do we validate the ISMS before paying for the certification audit?

Run a full internal audit against clauses 4 to 10 and the controls in your Statement of Applicability, hold a management review, and close or plan every nonconformity it finds. A gap assessment by someone who did not build the controls gives you an independent view before the certification body's auditors arrive.

How much does an ISO 27001 audit cost?

Certification bodies set their own fees, so there is no official price. Their quotes rest on audit days, which ISO/IEC 27006-1 makes them determine using its audit time rules, mainly driven by the people in scope, complexity and the number of sites. Get several quotes and compare the days and day rates.

Can a small business get ISO 27001 certified?

Yes. The standard says its requirements are generic and intended to apply to all organizations, regardless of type, size or nature. A small company usually has a simpler scope, fewer people and one site, which keeps audit time down; the clause 4 to 10 requirements still apply in full.

Do we have to buy the ISO 27001 standard?

To implement it properly, yes. The requirements text is copyrighted and sold by ISO, at CHF 155 for ISO/IEC 27001:2022 as of October 2026, while Amendment 1:2024 is free. Summaries and checklists, including ours, help you plan, but the auditor works from the standard itself.

Sources and further reading

vCISO Services

Discuss vciso services for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.