Skip to content
Cyber Horizon
Back to Blog
ISO 27001CostCertification

What ISO 27001 Certification Actually Costs in 2026

18 September 2026·10 min read·Cyber Horizon Team

Ask five vendors what ISO 27001 costs and you will get five numbers between £5,000 and £100,000, all of them technically true and none of them useful. The spread exists because people quote different things. There are four separate costs, and only one of them is the certificate.

This is a breakdown for a UK or EU company somewhere between 20 and 250 people — the size at which ISO 27001 usually stops being optional because a customer has started asking. Every figure below is an indicative market range for 2026, not a quote. Your auditor’s day rate and your scope will move them.

The four buckets

Separate these before you budget, because conflating them is how teams end up surprised nine months in.

BucketWhat it buysTypical year-one range
Certification bodyThe accredited audit itself — Stage 1, Stage 2, and the certificate.£6,000 – £14,000
PreparationConsultancy, a fractional CISO, or an implementation partner. Optional.£0 – £30,000
ToolingThe platform holding controls, evidence, risks and policies.£3,000 – £25,000/yr
Internal timeYour people. The largest line, and the one nobody costs.£20,000 – £45,000 equivalent

1. The certification body

This is the only cost that is genuinely non-negotiable, and it is usually the smallest of the four. A UKAS-accredited certification body charges by audit day, typically £1,000–£1,500 per day in the UK in 2026. The number of days is not arbitrary — it is set by ISO/IEC 27006 and the mandatory duration tables, driven mainly by the number of people in scope and the complexity of what you do.

For a single-site software company, a rough shape:

  • 20–50 people: around 5–7 audit days across Stage 1 and Stage 2. Roughly £6,000–£10,000.
  • 50–100 people: around 7–9 days. Roughly £8,000–£13,000.
  • 100–250 people: around 9–12 days, more if you have multiple sites or regulated work. £11,000–£18,000.
  • Surveillance audits in years two and three run at roughly a third of the initial effort — budget £2,500–£5,000 a year.
  • Recertification in year three is a fuller audit again, usually around two-thirds of the original day count.

Accreditation is worth paying for. A certificate from a body that is not accredited by UKAS (or another IAF member) costs less and is worth roughly what you pay for it. Enterprise procurement teams increasingly check the accreditation mark, and a rejected certificate means doing the whole thing twice. Verify your chosen body on the UKAS register before you sign.

2. Preparation — the bucket with the widest spread

This is where the £5,000 and the £100,000 quotes diverge. You have three routes, and the honest answer is that all three work.

Do it yourself. Cost: internal time only. Realistic if someone on your team has run an ISMS before, or if your environment is small and genuinely well understood. The failure mode is not the controls — it is the management-system clauses (4 to 10), which engineers consistently underestimate because they are about documented process, not technology.

Consultancy. Typically £8,000–£30,000 for a guided implementation. The upper end usually means someone is writing your documentation for you. That gets you certified faster and leaves you with a policy set nobody in your company recognises, which becomes visible at the first surveillance audit when the auditor asks who performs a control and nobody can answer.

A fractional or virtual CISO. £1,500–£4,000 a month. Better value than a fixed-price implementation if you also want someone to answer security questionnaires, run vendor reviews and handle the customer calls — because those keep coming after the certificate arrives.

3. Tooling

You can run an ISMS on spreadsheets and a document store. Plenty of companies have certified that way. It works until the second framework arrives, at which point you are maintaining two evidence sets that say the same thing in different words.

Platform pricing in this market generally follows one of two models, and the difference matters more than the headline number:

  • Per-framework pricing — you buy ISO 27001, then pay again when a customer asks for SOC 2, then again for DORA or NIS2. The first year looks cheap and the third does not.
  • All-frameworks pricing — one fee regardless of how many standards you map. Costs more on day one if you only ever need one framework, less from the second onward.
  • Watch for per-seat charges on auditors and read-only reviewers. Some platforms charge full seats for people who only ever look.
  • Check whether integrations are included or an add-on. Automated evidence collection is most of the value; buying it separately changes the maths.

4. Internal time — the real number

This is the cost nobody puts in the business case and everybody pays. A first ISO 27001 implementation at a 40-person company typically consumes 0.3 to 0.5 of a full-time person for six to nine months, plus scattered hours from engineering, HR and whoever owns your cloud.

At a fully loaded £70,000 salary, half a person for seven months is around £20,000. If the person doing it is your Head of Engineering, the real cost is whatever they were not building instead — which is usually the number that actually hurts.

Where that time goes, roughly in order: scoping and the risk assessment, writing or adapting policies, closing the control gaps you find, gathering evidence, running the mandatory internal audit and management review, then the audit itself.

A worked example

A 40-person B2B SaaS company in the UK, single site, AWS, no regulated data, certifying because two enterprise deals stalled on it. Three-year view:

LineYear 1Year 2Year 3
Certification body£8,500£3,000£6,000
Consultancy (light touch)£10,000£0£0
Platform£7,200£7,200£7,200
Internal time (equivalent)£22,000£8,000£10,000
Total£47,700£18,200£23,200

Three-year total of roughly £89,000, of which about £40,000 is internal time and £17,500 is the certificate itself. If those two stalled deals were worth £60,000 a year each, the question answers itself — but notice that the answer came from the revenue side, not from shaving the audit fee.

Where teams overspend

  • Scoping too wide. Scope is the single biggest cost lever you control. Certify the product and the teams that build it; do not sweep in the whole company because it felt tidier.
  • Buying documentation. A £15,000 policy pack written by someone who has never met your engineers will fail its first surveillance audit on evidence of operation.
  • Paying per framework. If there is any chance a customer asks for SOC 2 next year — and there is — model the two-framework cost before signing anything.
  • Leaving evidence to the end. Collecting nine months of screenshots in the fortnight before Stage 2 is where the overtime and the panic live.
  • Treating certification as the finish. Surveillance audits arrive annually forever. Budget for year two before you celebrate year one.

What actually drives the audit day count

Because the certification body bills by day, understanding what sets the day count is the difference between a quote you can influence and one you simply receive. ISO/IEC 27006 governs this, and accredited bodies cannot deviate far from it — which is good news, because it means the number is defensible rather than negotiable-by-charm.

The primary driver is the number of people within the scope of the ISMS. Not your headcount — the people inside the boundary you defined. If you certify the product organisation and exclude a 30-person sales team who touch nothing in scope, that is a genuine reduction, provided you can justify the boundary.

On top of that, adjustments run in both directions:

  • Complexity of the information you handle. Special category data, payment data or classified material increases duration. Ordinary B2B SaaS data does not.
  • Number of sites. One office and one cloud region is the cheapest shape there is. Multiple physical sites can be sampled, but sampling has to be justified.
  • Number of distinct processes and technologies. A single product on one cloud is simpler than four acquired products on three clouds.
  • Existing certifications. If you already hold ISO 9001 or ISO 27701 with the same certification body, integrated audits can reduce duration.
  • Degree of automation. Auditors may reduce time where evidence is systematically produced rather than assembled by hand — this is discretionary, not guaranteed, but it is real.
  • Remote auditing. Much of an audit can be conducted remotely, which removes travel costs even where it does not remove days.

The costs nobody puts in the spreadsheet

The four buckets above are the ones people budget. These are the ones that arrive uninvited, usually in month five, and they routinely add £10,000–£20,000 to a first certification.

CostTypicalWhy it appears
Penetration test£4,000 – £12,000Not strictly mandated by the standard, but A.8.8 and a risk assessment that ignores application security will not survive scrutiny. Customers ask for it regardless.
Remediation engineering£5,000 – £30,000The gap analysis finds things. Centralised logging, MFA on a legacy system, backup testing, secrets management. This is real engineering work, not paperwork.
Security awareness training£1,000 – £5,000/yrA.6.3 requires it and auditors sample completion records. A free slide deck nobody opened will not pass.
Background checks£50 – £150 per hireA.6.1 screening. Cheap individually, visible at scale, and awkward to retrofit for existing staff.
Cyber insurance£2,000 – £10,000/yrNot required by ISO 27001. Frequently required by the customer who asked for ISO 27001.
Legal review£1,000 – £4,000Updated DPAs, supplier terms and the customer contract changes that certification tends to trigger.

Remediation is the one that varies most and the one worth discovering early. Run a gap analysis in month one, not month five — a £30,000 remediation bill is survivable when you find it with eight months to plan, and a crisis when you find it with six weeks.

Is there a cheaper route?

Sometimes. Before committing to ISO 27001, establish what your customer actually asked for, because the answers differ by an order of magnitude in cost.

Cyber Essentials (UK) is a self-assessment against five technical controls, verified externally. Certification costs a few hundred pounds; Cyber Essentials Plus adds a hands-on technical audit for roughly £1,500–£3,000. It is mandatory for many UK public-sector contracts and satisfies some commercial buyers entirely. It is not equivalent to ISO 27001 and will not satisfy an enterprise security review, but if a public-sector tender is the reason you are here, it may be the whole answer.

SOC 2 is an attestation report from a CPA firm rather than a certificate, and it is the default ask from US buyers. Type I costs less than ISO 27001 certification; Type II usually costs comparably or more once the observation window is included. If your customers are US enterprises, SOC 2 may be the better first move — and much of the underlying control work is shared, so the second framework is far cheaper than the first.

A completed questionnaire and a Trust Centre. Genuinely: a meaningful share of “we need ISO 27001” requests come from buyers who actually need confidence, not a certificate. A well-answered questionnaire, a published sub-processor list and a pen test summary sometimes closes the deal for a few thousand pounds. Ask the buyer whether the certificate is a hard procurement gate or a proxy for assurance — the answer is free and occasionally saves £40,000.

Negotiating with a certification body

The day rate has some flex. The day count has very little, and you should be suspicious of a body that offers to cut it materially — that is precisely the corner that gets certificates questioned later.

  • Get three quotes. Day rates between accredited UK bodies vary by 30% or more for identical audit durations.
  • Ask for the three-year cost in writing, not year one. Some bodies price the initial audit keenly and recover it on surveillance.
  • Confirm what travel and expenses are charged, and how much of the audit can be remote.
  • Ask who the auditor will be and whether they have worked in your sector. A cloud-literate auditor saves a day of explaining your architecture.
  • Check the re-audit policy for non-conformities — whether closing a major requires a chargeable return visit or a document review.
  • Verify accreditation on the UKAS register yourself. Do not take the logo on the website as proof.

The honest summary

For a company of 20 to 100 people, a realistic all-in first-year figure is £35,000 to £60,000, including your own time, falling to £15,000–£25,000 a year thereafter. Anyone quoting you £5,000 is quoting one bucket. Anyone quoting £100,000 is selling you the documentation.

The lever that moves this most is not the audit fee. It is how much of the evidence work is automatic and how many frameworks that work counts toward.

One price, 71 frameworks

Cyber Horizon includes every framework on every plan, with pricing published on the site rather than quoted. Evidence collects itself from the tools you already run, and counts toward every standard it satisfies.

See Pricing