The short version

People ask what the ISO 27001 certification cost is as though there is a price list. There is not, and a fixed package is only comparable when its scope, assumptions and exclusions are clear. ISO 27001 is the international standard for an information security management system, an ISMS, which is the set of policies, risk decisions, and routines that govern how you protect information across the whole organisation. Certifying to it is a programme of work, not a purchase, so the cost reflects how much of that work you still have to do.

It helps to split the spend into three parts: the certification body that audits you and issues the certificate, the internal effort to build and run the management system, and any consultancy you bring in to help. The balance varies. A mature organisation may need limited implementation work; a business building its first ISMS may spend substantially more on internal effort and support than on the audit.

  • Budget for the audit, implementation and internal time as separate components.
  • Three things move the figure most: how big you are, how much you put in scope, and how mature your security already is.
  • ISO 27001 is an ongoing cost, not a one off. Surveillance audits are normally annual, with recertification before the three-year certificate expires.

What actually drives the cost

Two businesses of similar size can pay very different amounts, and both figures can be fair, because they describe different starting points and different scopes. These are the factors that move the number.

  • The size of your organisation. Headcount and the number of sites are the main inputs a certification body uses to set audit time, and audit time drives their fee. A ten person firm on one site is a far smaller audit than a hundred and fifty people across three offices.
  • The scope you certify. You decide what the ISMS covers: the whole company, one division, or a single product and the team behind it. A tight, well chosen scope is cheaper to build, audit, and maintain. An over broad scope inflates every cost that follows, so this is one of the most important early decisions.
  • Your current security maturity. This is the single biggest variable. If you already run things well, with patching, access control, monitoring, and some documented process in place, much of the evidence exists and you are tidying and formalising it. Starting closer to a blank page means building most of the system from scratch, which costs far more in effort.
  • How much you do in house versus buy in. Internal effort has a cost even when no invoice is raised, because your people spend weeks on it instead of their day job. Consultancy converts some of that time into a fee, and good help usually shortens the timeline and reduces the risk of failing the audit.
  • Tools and remediation. Closing gaps can mean new spend: a policy and risk platform, better logging or monitoring, multi factor authentication, or staff training. How much depends entirely on what you already have.

The three costs, separated

Quotes become much easier to read once you split them into these three buckets and ask which the figure in front of you includes. A cheap number that covers only the certificate is not comparable with one that includes the readiness work.

Cost area What it covers Who you pay What moves it
Certification body fees The two stage initial audit and the certificate itself, then annual surveillance and recertification A UKAS-accredited (opens in new tab) certification body (separate from any consultant) Your headcount, number of sites, and scope, which together set the audit days
Internal effort Building the ISMS, writing policies, running the risk assessment, gathering evidence, internal audits, and management review Your own people's time, costed honestly Your current maturity and how much of the work you keep in house
Consultancy or implementation help Gap analysis, building the system with you, preparing for the audit, sometimes acting as your interim security lead A consultant or a managed provider How much you outsource, and how far you are from ready
Tools and remediation Fixing the gaps the assessment finds: software, monitoring, MFA, training Vendors, or bundled into a managed service What controls you already have in place

Base certification versus surveillance and recertification

ISO 27001 certification normally follows a three-year cycle. The initial Stage 1 and Stage 2 audits are followed by surveillance, normally around 12 and 24 months, and recertification before expiry at around 36 months. Agree dates and fees with the certification body. Internal audit, management review and improvement continue throughout; an initial certificate does not remove those operating costs.

The ISO overview of ISO/IEC 27001:2022 (opens in new tab) describes the risk-based management system. ISO publishes the standard; it does not certify your organisation. Your chosen certification body should explain its accreditation, audit programme and certification decision.

What ISO 27001 certification requires: a checklist

The cost only makes sense once you can see what the standard asks for. Certifying to ISO 27001:2022 means putting the following in place and being able to evidence each one.

  • A defined ISMS scope. The boundaries of the information security management system: what it covers, and what it does not.
  • Leadership commitment and an information security policy. Top management ownership of the ISMS, set out in an approved information security policy.
  • A risk assessment and a risk treatment plan. A documented method for identifying information security risks, and a plan for how you treat them.
  • A Statement of Applicability. A document covering the Annex A controls you apply, with the justification for including or excluding each one.
  • The Annex A controls, implemented and evidenced. The controls you have selected put into practice, with records that show they are operating.
  • Documented policies and procedures. The written policies and procedures that govern how the ISMS runs day to day.
  • An internal audit programme. Regular internal audits that check the ISMS against the standard and your own requirements.
  • A management review. A formal review by management of how the ISMS is performing, at planned intervals.
  • Corrective action and continual improvement. A process to address the issues that audits and reviews raise, and to improve the ISMS over time.
  • A two stage external audit. Stage 1 reviews your documentation and Stage 2 assesses the system in action, carried out by a UKAS-accredited (opens in new tab) certification body.

Build the first-year budget

There is no verified UK market average behind this guide. Use our published support range as one supplier’s implementation budget, then obtain the certification body’s own audit quotation. All DSC figures below exclude VAT.

  • Certification body fees: obtain an initial Stage 1/Stage 2 quote and a three-year audit schedule. Audit time reflects the scope, people, sites and complexity; it is not included merely because a consultant quotes for implementation.
  • DSC implementation support: our published ISO 27001 support range is £12,000 to £30,000, depending on scope. Agree the deliverables, responsibilities and exclusions on the ISO 27001 support service and in your proposal.
  • Internal effort is real even though it rarely appears on an invoice. Building an ISMS from a low base can absorb a meaningful share of someone's role for several months. Cost it at their day rate and it is often comparable to the consultancy line.
  • First-year total: add implementation support, certification body fees, internal time and any new tools or remediation. Show ongoing operating and surveillance costs separately so the first-year figure does not conceal the renewal budget.

A gap review establishes scope, existing evidence and the work still required. Use that to produce an implementation proposal, and ask the certification body to confirm its own audit days and fees. A short discovery call can start this process; it cannot replace the full scoping work.

How to keep the cost sensible

Most of the waste in an ISO 27001 programme is avoidable, and it comes from a handful of mistakes. Avoid them and the spend stays proportionate to the value.

  • Scope deliberately. Certify what the buyer or the risk requires, not the whole company by reflex. Scope is the lever with the largest effect on every other cost.
  • Do the gap analysis first. Knowing where you stand before you commit stops you paying to build things you already have, and tells you which gaps carry real risk.
  • Check recognised accreditation. UK buyers often ask for a UKAS-accredited certification body (opens in new tab). Confirm the body’s current ISO 27001 accreditation and the buyer’s terms; recognised overseas accreditation may also be acceptable.
  • Reuse what you have. If you already hold Cyber Essentials, the technical work behind it feeds directly into the standard's controls, so very little of that effort is wasted.
  • Plan for the running cost. Budget for the surveillance and recertification cycle from the start, so year two does not arrive as a surprise.

Our ISO 27001 support helps you build and operate the ISMS. Formal certification is carried out by a separate certification body. Compare the implementation deliverables, audit arrangements and ongoing responsibilities, then confirm that the proposed certificate and scope meet the buyer’s requirements.

FAQ

Common questions

How much does ISO 27001 certification cost in the UK?

DSC’s published ISO 27001 support range is £12,000 to £30,000, excluding VAT, depending on scope. Add the certification body’s audit fees, internal time and any tools or remediation. This is DSC’s support range, not a UK market average or an all-inclusive certification price.

How long does ISO 27001 take to achieve?

For most organisations it is a programme of several months to over a year, not a quick project. You build the management system, run it long enough to generate evidence, then pass a two stage external audit. A firm that already runs security well can move faster, because much of the evidence exists. Starting from a lower base takes longer, because the system has to be built and operated before it can be audited. Plan ISO 27001 as a programme with a realistic timeline, not a deadline you can buy your way past.

How much does ISO 27001 cost for a small business or SME?

DSC’s published ISO 27001 support range is £12,000 to £30,000, excluding VAT, depending on scope. That is implementation support, not an all-inclusive certification fee. A small business should also budget for the certification body’s audits, its own staff time and any required tools or remediation. Existing evidence and a well-defined scope can reduce the implementation work.

Is the certification fee the main cost of ISO 27001?

It may or may not be. The balance depends on existing maturity and how much implementation work you do internally. Compare the certification body’s fees, internal time and outside support separately; a quote covering only the audit is not an implementation budget.

What are the ongoing costs after ISO 27001 certification?

Allow for normally annual surveillance, recertification before the three-year certificate expires, and the ongoing work of running the ISMS. Agree the audit schedule and fees with the certification body. Internal audits, management reviews, risk treatment and improvement continue between external audits.

Can I reduce the cost of ISO 27001?

Yes. Agree a useful scope, review existing evidence and avoid paying twice for controls you already operate. Keep the scope honest about relevant people, processes and dependencies. Confirm the buyer’s requirement for UKAS or other recognised accreditation before commissioning the audit.