ISO 27001 Certification Cost: How the Price Is Calculated
ISO 27001 certification is priced on audit days, and audit days come from your scope. Here's how the number is calculated, what recurs over the three-year cycle, and what to ask for in a quote.
The short answer
ISO 27001 certification has no list price, because an accredited certification body charges for audit days, not for the certificate. The days come from the number of people in your ISMS scope (about 5 days for up to 10 people, 8.5 for 26–45, 12 for 86–125), then adjust for sites and complexity.
The certificate lasts three years, so budget for the initial audit, two surveillance audits (roughly a third of the initial time each), and a recertification audit (roughly two-thirds). Your own staff time, tooling, and any consultant sit on top of that.
At Accredify Global you get a free scope review and one fixed-fee proposal based on your day count, with no hidden costs added afterwards.
Why You Won't Find One Standard Price
Search for the price of ISO 27001 certification and you'll find ranges so wide they're hard to use. That isn't evasion by whoever is quoting them; it reflects how the fee is built. An accredited certification body doesn't price a certificate. It prices audit time: the number of auditor days needed to assess your information security management system (ISMS), at its day rate, plus any travel or expenses.
That's why a 12-person SaaS team and a 400-person manufacturer with three sites get very different quotes for the same standard, and why a price given before anyone has looked at your scope is a guess. That's also why Accredify Global quotes on audit days rather than from a rate card: a single published number would be wrong for most companies that read it, and the day count is what you can check.
What follows is how the number is put together, so you can sanity-check any quote you receive, ours included. If you're earlier in the process, how to get ISO 27001 certified covers the steps; this page covers only the money.
The Biggest Driver: Audit Days
ISO/IEC 27006, the standard that governs how certification bodies audit against ISO 27001, ties the initial audit time to the number of people within the scope of your ISMS. Fewer people in scope means fewer audit days; more people means more. The table shows the baseline for the initial certification audit, Stage 1 and Stage 2 combined.
| People within ISMS scope | Baseline initial audit time |
|---|---|
| 1–10 | 5 days |
| 11–15 | 6 days |
| 16–25 | 7 days |
| 26–45 | 8.5 days |
| 46–65 | 10 days |
| 66–85 | 11 days |
| 86–125 | 12 days |
| 126–175 | 13 days |
| 176–275 | 14 days |
| 276–425 | 15 days |
| 426–625 | 16.5 days |
Baselines, not quotes. The certification body can adjust time up or down for complexity, number of sites, and risk, within limits its accreditation body checks. Larger scopes continue up the same table. Headcount means the people whose work falls inside the ISMS scope, not necessarily everyone on payroll.
Two things follow from this. First, scope is the lever: a company of 1,000 whose ISMS covers only its engineering and IT teams is audited on the people in scope, not the full headcount. Second, audit time grows more slowly than headcount: going from 10 to 25 people in scope adds two audit days, while going from 200 to 400 adds only one.
Budget the Three-Year Cycle, Not Just Year One
An ISO 27001 certificate is valid for three years, and keeping it means paying for audits in every one of them. The first-year quote is the largest single line, but it isn't the whole commitment.
Initial certification audit (Year 1)
Stage 1 reviews your documentation and scope, often in one to two days. Stage 2 tests whether the controls actually operate. The baseline table covers both.
Surveillance audits (Years 2 and 3)
Annual audits that confirm the system keeps working. They typically take roughly a third of the initial audit time.
Recertification audit (end of Year 3)
A full reassessment before the certificate expires, typically around two-thirds of the initial audit time.
As a worked example, take a team of 26–45 people in scope. The baseline is 8.5 audit days initially, about 3 days in each surveillance year, and about 6 days at recertification: roughly 20 audit days across the full cycle, in four audits.
Ask any certification body to put surveillance and recertification in writing with the first quote. If a quote covers only Year 1, you're comparing part of a price.
What Else Moves the Number
Scope
Which products, teams, locations, and systems the ISMS covers. A narrow, well-justified scope costs less than a company-wide one, but it still has to match what your customers expect the certificate to cover.
Number of sites
Additional locations in scope can add audit time. Remote-first teams with no physical sites in scope are often simpler to audit.
Complexity and risk
Heavy custom development, layered cloud infrastructure, outsourcing, or regulated data can lead a certification body to adjust time upward. A simple environment can adjust it downward.
Readiness
If Stage 2 finds major nonconformities, closing them can require a follow-up audit. A system that is actually ready avoids paying twice for the same days.
Costs That Aren't the Certification Body's Fee
The audit fee is one part of what getting certified takes. The rest sits inside your own company, and it's where budgets most often slip.
Staff time
Someone has to own the ISMS, run the risk assessment, collect evidence, and sit through audits. For smaller teams it's often the biggest line.
Implementation help
Policies, risk treatment, and control gaps need work before the audit. Some teams do it in-house; others bring in a consultant. A consultant is optional, and it can't be the same organization as your certification body.
Tooling
Evidence collection, access reviews, and the security controls the audit expects, whether you already own them or need to buy them.
Internal audit and management review
ISO 27001 requires both before certification, so they belong in the first-year effort rather than as an extra.
None of these appear on a certification body's quote, which is why two companies comparing "total cost" can be comparing different things. Put the audit fee and the internal costs in separate columns before you compare.
Want to see how your own headcount and scope translate into audit days? A short scoping call gives you a realistic day count and a fixed-fee proposal.
Book a scoping callWhat This Means for Startups and Small Teams
Small teams sit at the low end of the audit-day table, but they can also over-scope themselves out of it. A 30-person company that puts the whole organization in scope starts from a baseline of 8.5 days; the same company scoping only the product and infrastructure that handle customer data may land in a lower band.
The right scope is the one an enterprise customer will accept, not the smallest one you can defend. If your buyers' security questionnaires ask about HR or support tooling, a scope that leaves them out may need widening later. For how this plays out in SaaS specifically, see ISO 27001 for SaaS companies. And if a customer is asking for a report rather than a certificate, ISO 27001 vs. SOC 2 covers which one they actually mean.
How to Compare ISO 27001 Quotes
- 01Audit days, by stageThe quote should state the days for Stage 1 and Stage 2 and the headcount assumption behind them. A price with no day count can't be checked against anything.
- 02Surveillance and recertificationAsk for the days or fees for Years 2 and 3 and the recertification audit in writing, so you're comparing the whole cycle.
- 03What's excludedTravel, expenses, and follow-up audits after major nonconformities are the usual places a fixed number grows. Ask how each is handled.
- 04Accreditation scopeConfirm the body is accredited for ISO 27001 specifically, not just another standard. The check is covered in what an accredited certification body is; a quote far below every accredited one is the pattern it warns about.
- 05ImpartialityA body that offers to build your ISMS and also certify it is auditing its own work, which accreditation rules don't allow for the same client.
Have a quote you want to sanity-check?
A free scope review shows how your headcount and scope translate into audit days.
Get a day count and a fixed fee, not a range
Accredify Global is accredited under UAF, an IAF MLA signatory, across ISO 9001, 27001, 42001, 14001, 45001, 13485, and more. After a short scoping call you receive one fixed-fee proposal, with no hidden costs added after scoping.
Book your free scope review →Frequently Asked Questions
How much does ISO 27001 certification cost?
It depends on audit days, which depend on the number of people in your ISMS scope, plus the complexity and number of sites involved. As a baseline, ISO/IEC 27006 puts the initial audit for 26–45 people in scope at 8.5 days and for 86–125 people at 12 days. The certification body multiplies the agreed days by its rate, so the same standard can produce very different totals for different companies.
Why do ISO 27001 quotes vary so much?
Quotes differ on audit days, on what the quoted number includes, and on which years it covers. Some quote only the initial audit; others include surveillance and recertification. A very low quote can also come from a body that isn't accredited, which is the first thing to check.
What do I pay after the first year?
Annual surveillance audits in Years 2 and 3, typically roughly a third of the initial audit time each, and a recertification audit at the end of Year 3, typically around two-thirds of the initial time. Internal costs such as staff time and tooling continue throughout.
Can I reduce the cost by narrowing scope?
Yes, if the narrower scope is still what your customers expect the certificate to cover. Fewer people and locations in scope means fewer audit days. A scope drawn only to lower the price can fail a customer's security review and have to be widened later.
Do I need a consultant, and does that change the cost?
A consultant isn't required to get certified. Some teams implement the ISMS themselves; others use a consultant to move faster. Either way, the consultant's work is separate from the certification body's audit, and the same organization can't do both for the same client.
Is the cheapest ISO 27001 quote the best choice?
Not by default. Check that the body is accredited for ISO 27001 on IAF CertSearch, that the day count is realistic for your headcount, and that Years 2 and 3 are quoted. A certificate from a non-accredited body can be rejected by the same procurement teams it was bought to satisfy.