Announcing Copla's third-party risk management solution!

Learn more

ISO 27001 certification cost: The EU and UK breakdown for 2026

Share:

Updated

Sep 18, 2026

10 min. read

ISO 27001 certification cost: The EU and UK breakdown for 2026

Share:

ISO 27001 certification cost: The EU and UK breakdown for 2026

In this article

ISO 27001 certification cost runs roughly EUR 10,000 to more than EUR 100,000, with UK organisations in broadly the same range in GBP. The number moves with company size, scope, and audit days, across four budget areas: preparation, implementation, the audit, and ongoing maintenance. The audit fee is the smallest of the four. The largest, in almost every programme, is internal team time, the line most cost pages skip. Ahead: what drives the number, the four cost phases, cost by size, the three-year cycle, three ways to get certified, the hidden hours, how to bring the total down, and how a compliance and risk management platform like Copla scopes a budget before you commit.

What ISO 27001 certification costs, in short

ISO 27001 certification cost lands somewhere between EUR 10,000 and more than EUR 100,000 in the EU, and UK organisations sit in broadly the same range in GBP. Four budget areas make up that number:

  • Preparation and gap analysis
  • Implementation and documentation
  • The certification audit itself
  • Ongoing maintenance once you’re certified

By size, budgets typically start from about EUR 30,000 under 50 people, EUR 60,000 for 50 to 150, and EUR 100,000 for 150 or more.

What drives the cost of ISO 27001 certification

What decides whether certification costs EUR 15,000 or EUR 95,000? Mostly the number of people and sites inside the ISMS scope. Certification bodies calculate audit days under ISO/IEC 27006-1:2024, and the count isn’t just headcount: it weighs the effective number of people doing distinct work, so many people in simple, near-identical roles don’t count the same as an equal number of specialists. More people or sites in scope means more audit days, the single biggest driver of the certification body’s invoice.

Security maturity matters too: strong existing controls mean less to build before Stage 1. So does scope width, since a tighter scope means fewer systems, fewer ISO 27001 Annex A controls, and less evidence to produce. The certification body’s accreditation route adds variation too: a body accredited by a recognised national accreditation body typically costs more than a non-accredited alternative. The two certificates can look identical on the page, but only one carries external assurance that the assessment itself met a recognised standard, which is exactly what a bank, insurer, or enterprise procurement team checks for during due diligence. So does whether a consultant or platform carries part of the work.

The four cost phases

Every certification breaks down into the same four phases, whatever the company’s size.

Preparation starts the clock: a gap analysis against the standard’s clauses and Annex A controls, then a risk assessment deciding which controls actually apply, almost entirely on internal time. One small external cost hides here too: the standard document itself isn’t free, and a copy has to be purchased before anyone can assess against it.

Implementation is where the ISMS gets built: policies, controls, a risk register, and the evidence an auditor will eventually ask to see. The mandatory ISO 27001 policies alone take real drafting time, again mostly internal hours, sometimes with a consultant for the harder documents.

The certification audit, Stage 1 then Stage 2, is where the external spend shows up. In the UK, UKAS-accredited certification bodies typically charge in the region of GBP 1,000 to 1,500 per audit day. In the EU, rates vary by national accreditation body under the European co-operation for Accreditation.

Maintenance covers the surveillance audits and ongoing effort that keeps the ISMS current, detailed below.

PhaseExternal spendInternal effort
Preparation and gap analysisLow to noneHigh
Implementation and documentationLow, unless a consultant is usedHigh
Certification audit (Stage 1 and 2)The main external costModerate (audit support, interviews)
Maintenance (surveillance and upkeep)Lower, recurringOngoing, lower than the initial build
What each phase costs, split between the certification body’s invoice and your own team’s time.

UKAS accredits these certification bodies; it doesn’t set their rates.

ISO 27001 certification cost by company size

Company size is the clearest predictor of ISO 27001 certification cost, because it drives almost everything else: more people means a wider set of ISO 27001 requirements to satisfy in practice, more systems in scope, more audit days, and more evidence to produce and keep current. A longer timeline adds directly to the total, too: more months of internal hours, and more calendar time for a consultant or platform engagement, before the certificate is in hand.

Company sizeTypical timelineIndicative internal cost
Under 50 people4 to 6 monthsFrom about EUR 30,000
50 to 150 people6 to 9 monthsFrom about EUR 60,000
150+ people9 to 12+ monthsFrom about EUR 100,000
Indicative internal cost and timeline by company size, based on Copla’s client implementations. Treat these as a starting range, not a quote.

These figures are dominated by internal team time, not certification body fees, and UK organisations sit in broadly the same range in GBP. Each step up the table brings more systems to secure, more locations to visit, and more evidence to keep current across all of them, which is why the number moves in bigger jumps than headcount alone would suggest. None of these numbers are a quote: a company running three business units against one running a single product will move within its band, sometimes outside it.

The three-year certification cycle

ISO 27001 certification cost is often quoted as a single figure, as if the certificate were a one-time purchase. It isn’t. Certification runs on a three-year cycle, and the figures above only cover year one.

Year one carries Stage 1 and Stage 2, the full certification audit. Years two and three each carry a surveillance audit instead: a lighter check that samples a rotating set of controls rather than re-testing everything. Surveillance typically costs one-third to one-half of the original Stage 2 audit. At the end of year three, a recertification audit reassesses the whole ISMS and restarts the cycle, typically priced close to the original Stage 1 and Stage 2 combined.

None of that happens on its own between visits. Keeping the ISMS running, evidence current, internal audits done, management review held, typically takes somewhere in the range of 20 to 30 hours a quarter. Some teams cover that with existing staff; others bring in ongoing CISO support to carry the judgment calls a surveillance audit actually tests for.

Three ways to get certified, and what each costs

Pricing this out surfaces three recurring shapes, and each trades cash for hours differently.

A do-it-yourself toolkit costs the least upfront: templates and a checklist, run by whoever on the team has the time. A consultant costs more upfront but takes hours off your team’s plate, at least until the engagement ends and the knowledge goes with it: that trade tends to pay off most on a first certification with no one in-house who has done this before, and least once the business needs the same judgment again at the next surveillance audit. A compliance platform with CISO support changes the shape again: a more predictable cost, hours absorbed by automation and a named person’s oversight, and the judgment stays inside the business rather than leaving with a contractor.

RouteCash outlayInternal hoursWho owns the judgment
DIY toolkitLowestHighestEntirely your team
ConsultantHigher, externalLower while engagedLeaves with the consultant
Platform plus CISOPredictable, ongoingAbsorbed by automation and oversightStays in-house, with expert backup
How the three certification routes compare on cash outlay, internal hours, and who ends up owning the judgment calls.

Copla runs the third model, with a dedicated CISO working inside the ISO 27001 compliance software itself, reviewing evidence and making the calls a template can’t.

The cost most budgets miss: Internal team hours

The certification body’s invoice is the cost everyone budgets for, because it arrives as one visible number on one bill. Internal labour is the cost almost nobody puts a figure on, and it’s the one that actually decides the total.

Based on Copla’s client implementations, a first-time ISMS without automation runs to 800 or more hours of internal work, roughly:

  • Business impact analysis and gap analysis: 200+ hours
  • Risk assessment and treatment planning, and the Statement of Applicability: 200+ hours
  • Vendor due diligence: 150+ hours
  • Internal audits, awareness training, and certification body coordination: 100+ hours
  • Business continuity and disaster recovery: 80+ hours
  • Mandatory policies: 50+ hours
  • Monitoring and logging setup: 50+ hours

Copla typically prices that internal time at a blended EUR 6,000 to EUR 8,000 per full-time person per month, a reasonable EU/UK internal rate once salary, overheads, and opportunity cost are counted together. Priced that way, the hours alone can rival or exceed everything the certification body charges, which is the real reason the by-size figures above land where they do.

There’s a second cost inside those hours that rarely makes it into any budget line: the work those people would otherwise be doing. Someone spending 200 hours on risk assessment is 200 hours not spent on their actual job, and that displaced output never appears on an invoice either. Larger teams absorb this by spreading the load across more people; smaller ones often feel it as a genuine productivity dip in the run-up to Stage 1.

None of that counts the tooling underneath it, either. Certification assumes a working baseline of security tools already in place or bought alongside it: MFA, endpoint protection, backup and recovery, vulnerability scanning, centralised logging. That spend doesn’t show up on the certification body’s invoice or in the hours above, and for a business starting from a thin security stack, it can be the largest cash outlay in the whole programme.

How to reduce ISO 27001 certification cost

The number moves. Three places it moves in your favour, roughly in order of how much control you have over each:

  • Tighten the scope. Certifying only the systems, teams, and locations that genuinely need to be in scope cuts audit days directly, and removes a proportional share of the evidence-gathering work behind them.
  • Automate evidence collection and monitoring. This is the ongoing-maintenance workload from the section above, done with far less manual admin behind it. PwC’s 2025 Global Compliance Survey found that 43% of organisations investing in compliance technology report measurable gains in productivity, efficiency, or cost.
  • Reuse controls across frameworks instead of rebuilding them. One Copla client’s programme mapped roughly 500 controls across three frameworks and found only about 100 of them were genuinely unique, meaning up to 80% of the remaining work was duplication that a single build could have covered once.

Get a scoped estimate

Every range in this guide is still a range. Your actual number depends on your headcount, your scope, the systems you run, and how much of this you want to own internally versus hand off. A scoped estimate replaces the guesswork with a figure built around your business specifically. Book a demo with Copla to see what ISO 27001 certification cost actually looks like for your organisation.

FAQ

  • Do we need to budget for a penetration test or vulnerability scan on top of certification? +

  • Is VAT included in ISO 27001 certification quotes? +

  • How much does ISO 27001 cost for an individual versus a company? +

  • Are cheaper non-accredited certificates worth it in the EU or UK? +

  • Can you get a fixed-price quote, or is it always custom? +

  • What does it cost if we get nonconformities at the Stage 2 audit? +

Share this article

Post on Linkedin
Post on Facebook
Post on X

How useful was this post?

0 / 5. 0

Neilas is a communications manager at Copla, where he covers the operational side of regulatory compliance for financial services and fintech firms. He works closely with Copla’s team of CISOs and compliance experts to translate dense frameworks like DORA, NIS2, and ISO 27001 into language that reflects how compliance actually gets done—not how it reads in the regulation. Neilas writes from the practitioner’s perspective, drawing on real implementation experience from the team to show what works, what doesn’t, and where companies get stuck.

Explore further

  • Compliance & Regulations
  • GRC
  • Guide
  • SOC 2
  • Compliance & Regulations
  • GRC
  • SOC 2
  • Compliance & Regulations
  • GRC
  • Guide
  • ISO 27001