ISO/IEC 27001 has a cost structure that surprises most first-time buyers. The certificate fee from the certification body is only one part, and typically not the largest. The bigger spend is building the information security management system, or ISMS, that earns the certificate. This guide breaks the total into its real components so you can budget accurately and avoid underestimating what meeting the ISO 27001 requirements and achieving certification actually involves.

The three components of ISO 27001 cost

ISO 27001 certification cost comes from three distinct areas, and it is important to understand all three before you start planning.

  • The certification body fee. What the independent accredited certification body charges to conduct the certification audit and issue the certificate, plus annual surveillance audits and a recertification audit at the end of a three-year cycle.
  • The implementation cost. Building your ISMS, which includes scoping, risk assessment, the Statement of Applicability, controls, policies, and procedures. This is usually the largest and most variable part of the total ISO 27001 certification cost.
  • Internal time and any tooling. Your team's effort across the project and any platforms used to manage ISMS documentation and evidence.

What drives ISO 27001 certification cost: the three budget components and the key cost levers

What drives the certification body fee

The certification bodies that conduct an ISO 27001 audit set their fees based on several factors:

  • Organisation size. The number of employees and sites in scope affects the audit duration and therefore the cost. Larger scopes mean more audit days.
  • ISMS scope. A tightly scoped system costs less to audit than a broad one. Organisations that scope their ISMS narrowly to the parts of the business that genuinely need to be certified can reduce the certification body fee significantly.
  • The initial certification audit. The initial audit has two stages: a Stage 1 documentation review and a Stage 2 operational audit. Both stages have associated fees from the certification body.
  • Surveillance and recertification. Accredited certification bodies operating under IAF guidelines structure ISO 27001 certificates on a three-year cycle, with annual surveillance audits in years one and two, and a full recertification audit in year three. These ongoing costs are often underestimated in initial budgets. The certification costs do not stop after you receive the certificate.

The accredited certification body fee is the most predictable component of the total ISO 27001 cost. Most established certification bodies publish day rates or will provide a formal quote once they understand your scope. When comparing quotes from different certification bodies, make sure you are comparing like for like: some include Stage 1 in their initial fee, others quote it separately.

What drives the implementation cost

The build cost is where the range is widest and where underestimation is most common. Several factors determine how much ISO 27001 implementation will cost your organisation:

  • Your starting maturity. If you already have access control processes, a risk management framework, security policies, and incident response procedures, implementation is faster and costs less. Starting from scratch costs significantly more, because every control and policy needs to be built rather than documented and refined.
  • The breadth of your ISMS scope. Scope drives build cost. A wider scope means more information assets to assess, more controls to implement, more policies to write, and more staff to train. A narrower, well-defined scope can reduce build cost substantially without undermining the value of the certification.
  • Whether you use a consultant. Many organisations bring in a consultant to run the risk assessment, build the Statement of Applicability, develop controls and policies, and prepare for the certification audit. Consultant fees vary widely, but engaging expert help typically reduces internal time, avoids costly errors, and increases the likelihood of certifying on the first attempt. Factor consultant fees into your build cost estimate from the start.
  • The extent of remediation required. A risk assessment will identify gaps between your current security posture and the Annex A controls that apply to your environment. Closing those gaps has a cost: system upgrades, new tools, process changes, training. The build cost of ISO 27001 is heavily influenced by how much remediation your environment requires.

The build cost is where the difference between a well-scoped and a poorly-scoped ISO 27001 project is most stark. Organisations that scope too broadly spend significantly more on implementation and ongoing maintenance than they need to. Those that scope well spend on what matters.

Want a realistic picture of your ISO 27001 cost before you commit?

Run the free self-assessment to understand your starting maturity, the biggest variable in your total cost.

Start the assessment →

What typically costs how much: a framework for thinking about it

ISO 27001 certification costs vary widely because every organisation is different. Rather than giving figures that may mislead, here is a framework for thinking about each component:

  • Certification body fee: the most predictable component. Get quotes from two or three accredited certification bodies once you know your scope, and ask for multi-year estimates covering the full three-year cycle. A surveillance audit is an annual checkpoint that confirms your ISMS is still operating correctly; surveillance audit fees are generally lower than the initial audit, but the exact amount depends on the certification body, any scope changes, and the number of audit days required. Annual surveillance costs are a significant ongoing portion of the total and should be included in any multi-year budget.
  • Build cost: the most variable component. This depends on your starting maturity, scope, and whether you use a consultant. For a first-time ISO 27001 implementation, internal time is almost always underestimated. Budget conservatively.
  • Internal time: often the hidden cost. Staff time spent on gap analysis, risk assessment, policy development, control implementation, and audit preparation has a real cost even if it does not appear as a line item. Include it in your total cost calculation.
  • Tooling: discretionary. ISMS management platforms and compliance automation tools add cost. For some organisations they reduce internal effort significantly; for others they are unnecessary overhead. Evaluate based on your context.
Cost componentPredictabilityKey driversNotes
Certification body fee (initial)HighOrganisation size, ISMS scope, audit daysGet quotes from 2-3 accredited bodies once scope is defined
Annual surveillance auditsHighScope, audit daysLess than initial fee; budget across 3-year cycle
Recertification audit (year 3)HighSimilar to initial auditOften underbudgeted in year-one plans
ISMS build (consultant + remediation)LowStarting maturity, scope, gap sizeUsually the largest and most variable component
Internal staff timeLowScope, complexity, experienceHidden cost; always underestimated
Tooling (ISMS platform)MediumOrganisation size, complexityDiscretionary; evaluate per your context

How to budget realistically

Treat ISO 27001 as three distinct budget lines from the start: the certification body fee including ongoing surveillance, the build cost, and internal time or tooling. The honest figure for the implementation component comes from a scoping conversation that maps your current state to your target, not from published price lists.

The cost of ISO 27001 certification for a small organisation with a narrow scope and reasonable security maturity will be substantially different from the cost for a large enterprise with a broad scope starting from scratch. Any figure quoted without a scoping conversation is an estimate based on averages that may not apply to you.

When building your budget, factor in the following:

  • The three-year cycle including surveillance audit schedules, not just year one. Many first-time buyers budget only for the initial Stage 2 audit and then face unexpected annual surveillance costs.
  • Internal remediation costs. If your risk assessment identifies significant gaps in your security controls, closing them has a cost that sits outside the consultant or certification body fees.
  • Recertification at year three. The recertification audit cost is similar to the initial certification audit cost and needs to be in your long-term budget.

Controlling the cost without compromising the certification

There are legitimate ways to manage ISO 27001 certification cost without cutting corners that will fail at the audit:

  • Scope tightly. Include only what genuinely needs to be in scope. A precise scope reduces the annual audit fee, the build cost, and the ongoing maintenance burden. Many organisations scope their ISMS more broadly than necessary because they confuse what they would like to certify with what they need to certify.
  • Run a proper risk assessment. A real risk assessment aligned to your actual environment means you implement only the Annex A controls that apply to your risks, not all of them. The Statement of Applicability exists precisely to document which controls apply and why, so use it to avoid implementing controls you do not need.
  • Build controls you would want anyway. The ISO 27001 controls that matter most, such as access management, encryption, incident response, and risk management, are controls that reduce real risk. Build them because they protect your business, not purely to satisfy the standard. That mindset produces a better and cheaper ISMS.
  • Get implementation help early. A well-built ISMS speeds up the certification process as a whole and becomes less painful when the system is correctly designed from the start through the surveillance cycle. Spending on good implementation is often more cost-effective than trying to cut it and then discovering major nonconformities at the Stage 2 audit.
  • Invest in internal capability. If your team understands how to operate the ISMS and can conduct your internal audits, the ongoing cost of ISO 27001 compliance drops significantly. Do not build a system that requires ongoing external consultant involvement for routine operation.

ISO 27002 and its relationship to cost

ISO 27002 is the supporting code of practice for ISO/IEC 27001. It provides guidance on implementing the Annex A controls but does not drive certification directly; ISO 27001 is the certifiable standard. However, organisations implementing the Annex A controls often reference ISO 27002 guidance during implementation, and some consultants include ISO 27002 alignment in their scope. Understanding the relationship between the two standards helps when evaluating what a consultant or certification body is quoting for. ISO 27002 alignment can add implementation time if the scope includes detailed controls guidance beyond what ISO 27001 itself requires, but this is a design choice, not a mandatory cost.

How Onyx approaches ISMS build

Onyx provides ISO 27001 readiness assessment and ISMS implementation services designed to deliver an auditable management system without unnecessary cost. We start with a scoping conversation that maps your environment, current maturity, and target scope to give you an honest picture of what implementation will involve, including the likely certification costs across your three-year cycle.

Our implementation work covers ISO 27001 gap analysis, risk assessment, the Statement of Applicability, Annex A control implementation, policy development, and preparation for the external audit with an independent accredited body. We are not a certification body and do not certify clients; our role is to build the system that earns certification from an independent body. We build systems designed to certify on the first attempt and to be maintained by your team, which reduces ongoing costs.

If you are evaluating whether ISO 27001 certification makes sense compared with SOC 2 or other frameworks, we can advise on how to structure your compliance investment to cover the overlapping controls efficiently, reducing total cost across both programmes.

Want a real ISO 27001 budget, not a generic estimate?

Tell us your size and scope and we will map the cost picture on a 30-minute call. No obligation.

Book a scope call →

The bottom line

ISO 27001 certification cost has three parts: the certification body fee including ongoing surveillance, the build cost, and internal time or tooling. The implementation is usually the largest and most variable part. Budget for the full three-year certification cycle, not just year one. Scope tightly, run a proper risk assessment, and invest in a well-built ISMS that certifies on the first attempt and is cheaper to maintain. For organisations trying to get ISO 27001 certification for the first time, the honest cost figure comes from a scoping conversation, not a price list.

Want a real ISO 27001 budget? Tell us your size and scope and we will scope it on a short call. Book a scope call or take our free security self-assessment. See also how to choose an ISO 27001 consultant, the ISO 27001 certification process, and our ISO 27001 service.

Detailed cost questions organisations commonly ask

What is the initial certification audit cost?

The initial certification audit from an independent accredited body is typically quoted in audit-day rates. Stage 1 and Stage 2 together form the initial formal audit, and the cost depends on your organisation size and ISMS scope. Stage 2 is the longer and more intensive phase, so it usually accounts for the majority of the initial audit fee. Ask each certification body to break down their quote by stage so you can compare clearly.

What do the ongoing surveillance audits cost?

Surveillance audit fees are generally lower than the initial audit because they are focused on confirming the ISMS is still operating rather than building the initial picture, though the exact cost depends on the certification body, scope changes, and audit days. The exact cost varies by body and scope, but budgeting a meaningful ongoing annual amount is essential. The year-one audit fee is not representative of the full three-year cost of maintaining ISO 27001 certification.

How do I calculate the overall cost of ISO 27001?

The overall cost of ISO 27001 includes the initial certification body fee, annual surveillance audit fees, the implementation build cost, remediation costs, and internal time. The total cost across a three-year cycle can be substantially higher than the year-one fee alone. A full cost breakdown needs to factor in all three components over the full cycle rather than just the initial audit fee.

What is the opportunity cost of not getting ISO 27001 certified?

The opportunity cost of delayed or deferred ISO 27001 certification can be significant. Enterprise customers and public sector buyers increasingly require an ISO 27001 certificate as a precondition for contract awards. Organisations without it may lose deals to certified competitors. Factoring this opportunity cost into your ISO 27001 cost analysis often changes the picture materially.

What is the cost if we implement ISO 27001 ourselves?

Implementing ISO 27001 entirely in-house includes internal staff time, any tools needed to manage the ISMS, and the certification body fees. Internal time is often underestimated; gap analysis, risk assessment, policy development, controls implementation, internal audit, and audit preparation can collectively consume hundreds of hours. ISO 27001 internal audits alone typically require trained staff time. Doing this without a consultant reduces the external spend but increases internal time, and the risk of errors that delay the initial certification audit is higher.

What is the cost of getting ISO 27001 certified versus maintaining it?

The cost of getting ISO 27001 certified covers the initial build and the first audit cycle. The ongoing cost of maintaining ISO 27001 certification includes annual surveillance audits, internal audit activity, management review time, and the recertification audit at year three. Maintaining certification over a three-year cycle can be less expensive than the initial certification phase, particularly once the ISMS is mature and operating smoothly.

How does ISO 27002 affect build cost?

ISO 27002 provides detailed guidance on implementing the Annex A controls. Using ISO 27002 guidance as part of your ISMS build can increase thoroughness but also adds time if applied comprehensively. It is a discretionary reference rather than a mandatory cost driver, and a good consultant helps you use it selectively where it adds genuine value.

FAQ

How much does ISO 27001 certification cost?

Total ISO 27001 spend comes from three areas: the certification body fee for the initial audit and annual surveillance, the build cost of constructing your ISMS, and internal time or tooling. Implementation is typically the largest and most variable component, driven by your starting maturity and ISMS scope. Get a scoping conversation before assuming any particular number.

Is the certification body fee the main cost?

Usually not. The audit body fees for the initial audit and surveillance audits are the most predictable part of the total, but the build cost of constructing the ISMS, including risk assessment, controls, policies, and remediation, is typically larger and more variable.

Are there ongoing costs after ISO 27001 certification?

Yes. Accredited certification bodies operating under IAF guidelines structure ISO 27001 certificates on a three-year cycle, maintained through annual surveillance audits and a full recertification audit at year three. These ongoing costs, plus the internal effort to operate the ISMS, must be included in any realistic budget. How much you will spend over three years is a more useful question than the first-year cost alone.

How can I reduce the total cost?

Scope your ISMS tightly to what genuinely needs protecting, run a real risk assessment so you implement only the Annex A controls that apply to your environment, use ISO 27002 guidance selectively, build controls you would want anyway, get implementation help early so you certify on the first attempt, and build internal capability to manage ongoing operation without continual external support.

Does company size affect the total cost?

Yes. The number of employees and sites in scope, and the breadth of the ISMS, affect both the implementation effort and the certification body audit fee. A larger or broader scope costs more across all three components. The relationship between size and cost is why tight scoping matters so much for controlling total ISO 27001 costs.

What is the difference between ISO 27001 and ISO 27002 in terms of cost?

ISO 27001 is the certifiable standard; ISO 27002 provides implementation guidance for the Annex A controls. You are certified against ISO 27001, not ISO 27002. ISO 27002 alignment may add implementation time depending on how deeply your consultant uses it, but it is not a direct driver of audit body fees.