How much does ISO 27001 certification cost?
The short answer is that ISO 27001 certification cost depends on the size of your organisation, the scope of your information security management system (ISMS), and how much support you need. As a general guide, many small to medium sized UK organisations invest between £10,000 and £20,000+ to achieve certification, although smaller projects may cost less and larger, more complex organisations may invest more.
That investment is typically made up of three separate elements: consultancy and implementation support, internal time and resources and certification body audit fees. Understanding each of these cost areas is the best way to build an accurate budget and avoid unexpected costs later in the project.
In this guide, we’ll explain what influences the cost of ISO 27001 certification, what you’re actually paying for, how to estimate the likely investment for your organisation, and why it’s important to budget for the full three-year certification cycle, not just the initial audit.
The short answer
Most UK organisations should expect to invest between £10,000 and £20,000+ to achieve ISO 27001 certification. Smaller organisations with a limited certification scope and well-established security controls will typically fall towards the lower end of that range. Larger organisations, businesses operating across multiple locations, or those with more complex information security requirements should expect to invest more.
*Illustrative UK ranges only. Every organisation should be individually scoped before a fixed quotation is provided. External certification costs for initial certification audits only.
There isn’t a single ISO 27001 certification price because no two organisations start from the same position. Some already have mature policies, documented processes and technical controls in place. Others are building their information security management system from the ground up. The scope of certification, the resources available internally and the level of external support required all have a direct impact on the overall investment.
In most cases, three factors have the greatest influence on ISO 27001 certification fees:
- The size of your organisation, including employee numbers, locations and operational complexity.
- The scope of certification, whether you are developing software or delivering services.
- The maturity of your existing controls, documentation and governance, which determines how much implementation work is required before the certification audit.
It’s also important to remember that certification isn’t a single payment. Your total investment is made up of several different cost areas, including certification body audit fees, consultancy and implementation support, and the internal time needed to prepare for certification. The next section breaks down each of these costs so you can see exactly where your budget is likely to be spent.
What are you actually paying for?
Your total investment is usually made up of three separate cost areas. Understanding the difference between them makes it much easier to compare quotations, set a realistic budget and identify where the greatest value can be achieved.
Consultancy and implementation support
Many organisations choose to work with an ISO 27001 consultant to speed up implementation, reduce project risk, and ensure the management system is designed correctly from the outset (i.e. not over complicating or under delivering). The level of support required varies, from guidance on specific areas through to full project delivery.
Typical consultancy activities include:
- Gap analysis to assess your current level of compliance.
- Designing and implementing the Information Security Management System (ISMS).
- Developing policies, procedures and supporting documentation.
- Conducting internal audits before certification.
- Preparing your organisation for the certification audit and addressing any remaining gaps.
- Helping represent your system with you at the external audit.
At twoSB, every project begins with a short scoping exercise, allowing us to recommend the right level of support rather than a one-size-fits-all package.
Internal time and technology
This cost is the hardest to neatly define. Achieving ISO 27001 requires time and input from people across the organisation, particularly those responsible for IT, software development, infrastructure management, operations, HR and senior leadership.
For many organisations, internal staff time represents a material element in the overall project cost, even though it doesn’t appear on an external quotation.
Internal investment often includes:
- Staff workshops and project meetings.
- Gathering evidence to demonstrate compliance.
- Reviewing and approving policies and procedures.
- Security awareness training for employees.
- Using existing software or introducing tools to support areas such as risk management, asset registers or incident management where appropriate.
Implementation insight
twoSB consider that internal engagement in the ISO 27001 management system is one of the factors that is most important to success. A consultancy like twoSB can accelerate the process and ensure resources are efficiently engaged. However, without internal buy-in and ownership, once the initial certification is over the system can quickly slip. Internal resources are not free. Your CTO’s time is precious, and time spent on ISO 27001 is time away from the product. A good consultancy and internal project lead will help defend senior team time, ensuring it is spent where it is most valuable.
Certification body audit fees
Certification body fees are paid directly to the organisation that assesses your ISMS and issues your ISO 27001 certificate. These costs are separate from any consultancy support you choose to engage.
The certification process typically includes:
- Stage 1 audit, which reviews your documentation, scope and readiness for certification.
- Stage 2 audit, where the certification body assesses how your ISMS operates in practice and whether it meets the requirements of ISO 27001.
- Annual surveillance audits, carried out in years one and two after certification to confirm the system continues to operate effectively.
- Recertification, usually required every three years to renew your certificate.
Audit fees vary depending on the size and complexity of your organisation, the scope of certification and the amount of audit time required.
Factors that impact the overall ISO 27001 implementation and certification costs
While every organisation is different, you can make a reasonably accurate estimate by looking at the factors that have the biggest influence on implementation effort and audit time. The more complex your business, the wider the certification scope and the more team members you have, the greater the investment is likely to be.
Use the checklist below as a starting point before requesting a formal quotation.
These factors don’t determine the final ISO 27001 certification price on their own. They’re simply the variables that influence the amount of work required before the certification audit can take place.
One of the quickest ways to establish where your organisation sits is to carry out an ISO 27001 gap analysis. By identifying what’s already in place and where improvements are needed, you can build a realistic project plan and budget, often avoiding unnecessary consultancy costs or delays later in the implementation.
What drives the cost up or down?
Every ISO 27001 project is different, but the factors influencing cost are generally consistent. Understanding what increases or reduces the amount of work involved will help you build a more realistic budget and avoid comparing quotations that aren’t based on the same scope.
Company size and headcount
Company size is one of the biggest factors influencing ISO 27001 certification cost. More employees typically mean more processes, more assets, more departments and more evidence to review during implementation and certification.
Headcount also influences the time required for workshops, staff awareness training, internal audits and certification body audits. However, size alone isn’t the deciding factor. A well-organised business with 100 employees may require less work than a smaller organisation with limited documentation and inconsistent processes.
The scope of your ISMS
The scope of your Information Security Management System (ISMS) has a significant impact on ISO 27001 certification costs.
Some organisations choose to certify the entire business, while others initially focus on a single product, service, department or business unit. A narrower scope can reduce implementation effort and audit time, although it must accurately reflect how the organisation operates and satisfy customer or contractual requirements.
Choosing the right scope is often one of the most effective ways to balance cost with commercial objectives.
Scoping considerations
Although it is possible to play with the scope, for small organisations starting out on the ISO 27001 pathway, it is not generally realistic to leave elements of the business out of the certification. You are likely to have a small team with overlapping roles, and one or two products or services. Carving out aspects of the business to remain out of scope can result in more work and complexity then certifying everything.
As an organisation grows and starts to have distinct offerings, for example a consultancy and a product division, it is more realistic to focus on certifying the activities that clients actually require.
How mature your existing controls are
Organisations that already have documented policies, defined processes and effective security controls are rarely starting from zero. Existing governance, supplier management, incident management, risk assessments and staff training can often be incorporated into the ISMS.
This is why an ISO 27001 gap analysis is often one of the best early investments. By identifying what’s already in place and where genuine gaps exist, you can focus time and budget where they’re needed most rather than creating documentation or processes unnecessarily.
The ongoing cost of continual improvement and certification
One of the most common budgeting mistakes is treating ISO 27001 as a one-off project. While the initial certification audit is the largest upfront investment, maintaining your certificate requires ongoing audits and continual improvement. It’s important to budget for the full certification cycle rather than focusing solely on the first year.
Surveillance audits are generally smaller than the initial certification audit, but they still require preparation, evidence gathering and management involvement. Organisations should also allow time to conduct periodic risk assessments, internal audits, management reviews, apply continual improvements to the ISMS, and reflect any changes to the business in the ISMS.
By the end of the third year, you’ll need to complete a recertification audit to demonstrate that your management system continues to meet the requirements of ISO 27001. This is not simply a repeat of the original audit. It reviews how the ISMS has been maintained, improved and adapted over the previous certification cycle.
Planning for these ongoing costs from the outset provides a far more accurate picture of the cost of ISO 27001 certification. It also helps avoid the common situation where organisations budget for the initial certificate but overlook the investment needed to maintain it over the long term.
UKAS accredited vs non-accredited certification
Not all ISO 27001 certificates carry the same weight. If you’re investing in certification, it’s important to understand the difference between a UKAS accredited certification body and one that isn’t accredited.
Why UKAS accreditation matters
The United Kingdom Accreditation Service (UKAS) is the UK’s national accreditation body. It independently assesses certification bodies to confirm they are competent, impartial and operating to recognised international standards.
When you achieve ISO 27001 certification through a UKAS accredited certification body, customers, regulators and procurement teams have greater confidence that your organisation has been assessed against a recognised and independently verified process.
For government and public sector contracts UKAS accredited certification is the only acceptable option, and the same applies for more sophisticated clients who demand higher standards of credibility.
Building customer confidence
For many organisations, ISO 27001 is about more than demonstrating compliance with a standard. It’s about providing reassurance that information security is taken seriously.
A UKAS accredited certificate can help strengthen customer confidence, particularly when working with enterprise organisations, regulated industries or businesses that carry out detailed supplier due diligence. It provides independent evidence that your information security management system has been assessed by a recognised certification body.
Supporting procurement requirements
Many public sector contracts, larger corporate tenders and supply chain questionnaires ask whether your ISO 27001 certification has been issued by a UKAS accredited certification body. While not every procurement process makes this mandatory, accreditation is often viewed as the benchmark for demonstrating independent assurance.
If certification is likely to play a role in winning new business, it’s worth checking procurement requirements before selecting a certification body. Choosing a non-accredited route may appear less expensive initially, but it can create additional costs if customers later require UKAS accredited certification.
Common misconceptions
A common misconception is that all ISO 27001 certificates are the same. In reality, the value of certification depends not only on meeting the requirements of the standard but also on the credibility of the certification body carrying out the audit.
It’s also important to remember that UKAS accreditation doesn’t make certification more difficult or guarantee a better information security management system. Instead, it provides confidence that the certification process has been carried out independently, consistently and to recognised international standards. For organisations seeking long-term commercial value from ISO 27001, that’s often an investment worth making.
How twoSB approaches ISO 27001 certification costs
Every organisation is different, which is why we don’t believe in fixed-price packages or generic quotations. The right level of support depends on your existing systems, your certification scope and your internal resources. Our aim is to provide the right level of support, no more and no less.
Before we provide a quote we like to have a 15 to 30 minute conversation with you about your organisation and to answer any questions you may have. This allows us to understand how your organisation operates, assess the maturity of your existing controls and identify what is, and isn’t, required to achieve certification. The outcome is a clear proposal with defined costs, timescales and deliverables, giving you confidence in the investment before the project begins.
Our approach is based on right-sized engagements. Some organisations need end-to-end implementation support, from gap analysis through to certification. Others have strong internal resources and simply need experienced guidance, internal auditing or certification readiness support. We tailor every project accordingly.
Just as importantly, we focus on avoiding unnecessary work. Rather than replacing processes that already work well, we build on existing policies, documentation and governance wherever possible. This reduces duplication, makes implementation more efficient and helps create an Information Security Management System that your team will continue to use long after certification has been achieved.
A typical ISO 27001 project with twoSB includes:
- Gap analysis and implementation planning.
- ISMS design and documentation.
- Practical implementation support.
- Internal auditing and certification readiness.
- Ongoing advice as your organisation and security requirements evolve.
Where an organisation has very little formal information security documentation in place, we typically suggest skipping the gap analysis – you already know you don’t have ISMS elements in place! Instead we start planning and delivering the implementation with you so progress can be achieved quickly.
If you’re trying to build a business case or compare quotations, the best place to start is with an accurate understanding of your own organisation. Contact us and we’ll provide a realistic assessment of the work involved, the likely investment and the most appropriate route to ISO 27001 certification, with no obligation and no upselling.
See how we’ve helped organisations achieve ISO 27001 certification in our client case studies.
Frequently asked questions
How much does ISO 27001 certification cost?
The total cost of ISO 27001 certification depends on factors such as the size of your organisation, the scope of your Information Security Management System (ISMS), the maturity of your existing controls and how much external support you require. As a general guide, many UK organisations invest between £10,000 and £20,000+, including certification body fees, implementation support and internal resources.
What affects ISO 27001 certification fees?
Certification body fees are influenced by the size and complexity of your organisation, the number of sites being certified, the scope of the ISMS and the amount of audit time required. These fees are separate from consultancy costs and internal project resources.
Can I achieve ISO 27001 without a consultant?
Yes. There is no requirement to use a consultant, and some organisations successfully implement ISO 27001 using internal resources alone. However, many choose to work with an experienced consultancy to reduce project risk, avoid unnecessary delays and ensure the management system is implemented efficiently and aligned with the standard.
How long does ISO 27001 certification take?
Most organisations achieve ISO 27001 certification within three to nine months, depending on their size, existing security controls and the resources available to the project. Organisations with mature governance and well-documented processes can often progress more quickly than those starting from scratch.
Is ISO 27001 worth the cost?
For many organisations, yes. Beyond strengthening information security, ISO 27001 can improve customer confidence, support procurement requirements, demonstrate compliance with contractual expectations and create more consistent internal processes. The long-term commercial benefits often outweigh the initial investment.
How much do surveillance audits cost?
Surveillance audits take place annually after initial certification and are generally less expensive than the Stage 1 and Stage 2 certification audits. The exact cost depends on the size and complexity of your organisation and the certification body’s audit requirements. It’s important to budget for these ongoing audits as part of the full three-year certification cycle.
Is UKAS accreditation important?
For most organisations, UKAS accredited certification provides greater credibility because the certification body has been independently assessed for competence and impartiality. Many larger organisations and public sector procurement processes either mandate or strongly prefer UKAS accredited certification.
What is included in ISO 27001 implementation costs?
Implementation costs typically include activities such as gap analysis, ISMS design, documentation, risk assessment, policy development, staff workshops, internal audits, certification readiness and project management. The exact scope varies depending on your organisation’s existing systems and the level of external support you require.
Get an accurate ISO 27001 cost for your organisation
Every organisation is different, which is why the most accurate way to estimate your ISO 27001 certification cost is through a structured scoping exercise. Whether you’re building a business case, comparing quotations or planning your certification project, we’ll provide a realistic, fixed-fee proposal based on your organisation, not a generic package or ballpark estimate.