ISO 27001 certification cost runs roughly EUR 10,000 to more than EUR 100,000, with UK organisations in broadly the same range in GBP. The number moves with company size, scope, and audit days, across four budget areas: preparation, implementation, the audit, and ongoing maintenance. The audit fee is the smallest of the four. The largest, in almost every programme, is internal team time, the line most cost pages skip. Ahead: what drives the number, the four cost phases, cost by size, the three-year cycle, three ways to get certified, the hidden hours, how to bring the total down, and how a compliance and risk management platform like Copla scopes a budget before you commit.
What ISO 27001 certification costs, in short
ISO 27001 certification cost lands somewhere between EUR 10,000 and more than EUR 100,000 in the EU, and UK organisations sit in broadly the same range in GBP. Four budget areas make up that number:
- Preparation and gap analysis
- Implementation and documentation
- The certification audit itself
- Ongoing maintenance once you’re certified
By size, budgets typically start from about EUR 30,000 under 50 people, EUR 60,000 for 50 to 150, and EUR 100,000 for 150 or more.
The certification body’s audit fee is only ever a slice of that total. Internal time and implementation absorb the rest.
What drives the cost of ISO 27001 certification
What decides whether certification costs EUR 15,000 or EUR 95,000? Mostly the number of people and sites inside the ISMS scope. Certification bodies calculate audit days under ISO/IEC 27006-1:2024, and the count isn’t just headcount: it weighs the effective number of people doing distinct work, so many people in simple, near-identical roles don’t count the same as an equal number of specialists. More people or sites in scope means more audit days, the single biggest driver of the certification body’s invoice.
Security maturity matters too: strong existing controls mean less to build before Stage 1. So does scope width, since a tighter scope means fewer systems, fewer ISO 27001 Annex A controls, and less evidence to produce. The certification body’s accreditation route adds variation too: a body accredited by a recognised national accreditation body typically costs more than a non-accredited alternative. The two certificates can look identical on the page, but only one carries external assurance that the assessment itself met a recognised standard, which is exactly what a bank, insurer, or enterprise procurement team checks for during due diligence. So does whether a consultant or platform carries part of the work.
Audit days scale with the people and complexity inside the ISMS scope, under a fixed methodology, which is why two companies the same size can end up with very different quotes.
The four cost phases
Every certification breaks down into the same four phases, whatever the company’s size.
Preparation starts the clock: a gap analysis against the standard’s clauses and Annex A controls, then a risk assessment deciding which controls actually apply, almost entirely on internal time. One small external cost hides here too: the standard document itself isn’t free, and a copy has to be purchased before anyone can assess against it.
Implementation is where the ISMS gets built: policies, controls, a risk register, and the evidence an auditor will eventually ask to see. The mandatory ISO 27001 policies alone take real drafting time, again mostly internal hours, sometimes with a consultant for the harder documents.
The certification audit, Stage 1 then Stage 2, is where the external spend shows up. In the UK, UKAS-accredited certification bodies typically charge in the region of GBP 1,000 to 1,500 per audit day. In the EU, rates vary by national accreditation body under the European co-operation for Accreditation.
Maintenance covers the surveillance audits and ongoing effort that keeps the ISMS current, detailed below.
| Phase | External spend | Internal effort |
|---|---|---|
| Preparation and gap analysis | Low to none | High |
| Implementation and documentation | Low, unless a consultant is used | High |
| Certification audit (Stage 1 and 2) | The main external cost | Moderate (audit support, interviews) |
| Maintenance (surveillance and upkeep) | Lower, recurring | Ongoing, lower than the initial build |
UKAS accredits these certification bodies; it doesn’t set their rates.
The certification body’s line is the one number most budgets fixate on, and it’s usually the smallest of the four.
ISO 27001 certification cost by company size
Company size is the clearest predictor of ISO 27001 certification cost, because it drives almost everything else: more people means a wider set of ISO 27001 requirements to satisfy in practice, more systems in scope, more audit days, and more evidence to produce and keep current. A longer timeline adds directly to the total, too: more months of internal hours, and more calendar time for a consultant or platform engagement, before the certificate is in hand.
| Company size | Typical timeline | Indicative internal cost |
|---|---|---|
| Under 50 people | 4 to 6 months | From about EUR 30,000 |
| 50 to 150 people | 6 to 9 months | From about EUR 60,000 |
| 150+ people | 9 to 12+ months | From about EUR 100,000 |
These figures are dominated by internal team time, not certification body fees, and UK organisations sit in broadly the same range in GBP. Each step up the table brings more systems to secure, more locations to visit, and more evidence to keep current across all of them, which is why the number moves in bigger jumps than headcount alone would suggest. None of these numbers are a quote: a company running three business units against one running a single product will move within its band, sometimes outside it.
The three-year certification cycle
ISO 27001 certification cost is often quoted as a single figure, as if the certificate were a one-time purchase. It isn’t. Certification runs on a three-year cycle, and the figures above only cover year one.
Year one carries Stage 1 and Stage 2, the full certification audit. Years two and three each carry a surveillance audit instead: a lighter check that samples a rotating set of controls rather than re-testing everything. Surveillance typically costs one-third to one-half of the original Stage 2 audit. At the end of year three, a recertification audit reassesses the whole ISMS and restarts the cycle, typically priced close to the original Stage 1 and Stage 2 combined.
None of that happens on its own between visits. Keeping the ISMS running, evidence current, internal audits done, management review held, typically takes somewhere in the range of 20 to 30 hours a quarter. Some teams cover that with existing staff; others bring in ongoing CISO support to carry the judgment calls a surveillance audit actually tests for.
The certificate is a three-year commitment, not a single invoice.
Three ways to get certified, and what each costs
Pricing this out surfaces three recurring shapes, and each trades cash for hours differently.
A do-it-yourself toolkit costs the least upfront: templates and a checklist, run by whoever on the team has the time. A consultant costs more upfront but takes hours off your team’s plate, at least until the engagement ends and the knowledge goes with it: that trade tends to pay off most on a first certification with no one in-house who has done this before, and least once the business needs the same judgment again at the next surveillance audit. A compliance platform with CISO support changes the shape again: a more predictable cost, hours absorbed by automation and a named person’s oversight, and the judgment stays inside the business rather than leaving with a contractor.
| Route | Cash outlay | Internal hours | Who owns the judgment |
|---|---|---|---|
| DIY toolkit | Lowest | Highest | Entirely your team |
| Consultant | Higher, external | Lower while engaged | Leaves with the consultant |
| Platform plus CISO | Predictable, ongoing | Absorbed by automation and oversight | Stays in-house, with expert backup |
Copla runs the third model, with a dedicated CISO working inside the ISO 27001 compliance software itself, reviewing evidence and making the calls a template can’t.
What separates the three routes is less the sticker price than who still owns the judgment once the toolkit, the consultant, or the platform goes quiet.
The cost most budgets miss: Internal team hours
The certification body’s invoice is the cost everyone budgets for, because it arrives as one visible number on one bill. Internal labour is the cost almost nobody puts a figure on, and it’s the one that actually decides the total.
Based on Copla’s client implementations, a first-time ISMS without automation runs to 800 or more hours of internal work, roughly:
- Business impact analysis and gap analysis: 200+ hours
- Risk assessment and treatment planning, and the Statement of Applicability: 200+ hours
- Vendor due diligence: 150+ hours
- Internal audits, awareness training, and certification body coordination: 100+ hours
- Business continuity and disaster recovery: 80+ hours
- Mandatory policies: 50+ hours
- Monitoring and logging setup: 50+ hours
Copla typically prices that internal time at a blended EUR 6,000 to EUR 8,000 per full-time person per month, a reasonable EU/UK internal rate once salary, overheads, and opportunity cost are counted together. Priced that way, the hours alone can rival or exceed everything the certification body charges, which is the real reason the by-size figures above land where they do.
There’s a second cost inside those hours that rarely makes it into any budget line: the work those people would otherwise be doing. Someone spending 200 hours on risk assessment is 200 hours not spent on their actual job, and that displaced output never appears on an invoice either. Larger teams absorb this by spreading the load across more people; smaller ones often feel it as a genuine productivity dip in the run-up to Stage 1.
None of that counts the tooling underneath it, either. Certification assumes a working baseline of security tools already in place or bought alongside it: MFA, endpoint protection, backup and recovery, vulnerability scanning, centralised logging. That spend doesn’t show up on the certification body’s invoice or in the hours above, and for a business starting from a thin security stack, it can be the largest cash outlay in the whole programme.
A budget that only prices the audit has priced a fraction of what certification actually costs.
How to reduce ISO 27001 certification cost
The number moves. Three places it moves in your favour, roughly in order of how much control you have over each:
- Tighten the scope. Certifying only the systems, teams, and locations that genuinely need to be in scope cuts audit days directly, and removes a proportional share of the evidence-gathering work behind them.
- Automate evidence collection and monitoring. This is the ongoing-maintenance workload from the section above, done with far less manual admin behind it. PwC’s 2025 Global Compliance Survey found that 43% of organisations investing in compliance technology report measurable gains in productivity, efficiency, or cost.
- Reuse controls across frameworks instead of rebuilding them. One Copla client’s programme mapped roughly 500 controls across three frameworks and found only about 100 of them were genuinely unique, meaning up to 80% of the remaining work was duplication that a single build could have covered once.
The biggest savings rarely come from cutting corners. They come from refusing to do the same work three times.
Get a scoped estimate
Every range in this guide is still a range. Your actual number depends on your headcount, your scope, the systems you run, and how much of this you want to own internally versus hand off. A scoped estimate replaces the guesswork with a figure built around your business specifically. Book a demo with Copla to see what ISO 27001 certification cost actually looks like for your organisation.
FAQ
-
Do we need to budget for a penetration test or vulnerability scan on top of certification? +
Usually, yes, as a separate line. ISO 27001 doesn’t mandate penetration testing by name, but Annex A’s technical controls typically call for some form of vulnerability and security testing as evidence, and most organisations buy that as a distinct service rather than finding it bundled into the certification audit fee.
-
Is VAT included in ISO 27001 certification quotes? +
Usually not. Certification body quotes are typically presented net of VAT, in line with standard B2B invoicing practice in both the EU and UK, so budget for VAT on top of any figure you’re quoted. Confirm the treatment with the certification body directly, since local VAT rules vary.
-
How much does ISO 27001 cost for an individual versus a company? +
The two aren’t comparable, because they’re different credentials. An individual becomes a Lead Implementer or Lead Auditor through training and an exam, priced as course and exam fees. A company becomes certified through the process this guide covers, an ISMS audit, not a training course. See getting ISO 27001 certified as an individual for the individual route’s own figures.
-
Are cheaper non-accredited certificates worth it in the EU or UK? +
Rarely, for a regulated financial entity or an enterprise buyer. A certificate from a body accredited by a recognised national accreditation body carries international recognition. One that isn’t accredited may cost less but usually won’t satisfy the due diligence teams that asked for ISO 27001 in the first place. Check accreditation before comparing price.
-
Can you get a fixed-price quote, or is it always custom? +
The audit fee can be quoted close to fixed once scope and headcount are set, but the total programme cost is inherently custom. Preparation, implementation, and internal hours all depend on your starting maturity and how much help you bring in, which is exactly what a scoped estimate is for.
-
What does it cost if we get nonconformities at the Stage 2 audit? +
Nonconformities are normal, and minor ones rarely add to the certification body’s fee. They’re usually closed with an agreed corrective action plan while the certificate stays valid. A major nonconformity can trigger a follow-up audit, typically billed at the same day rate as the original visit, though the larger cost in practice is usually the delay while the root cause gets fixed.