For a company under 50 people, anywhere in the world, budget $10,000 to $50,000 in the first year. The certification body's audit fees account for $5,000 to $15,000 of that. The rest splits across your own staff time, any consultant you hire and whatever tooling you pick. The range is wide because two companies with the same headcount can make very different choices about how much help they buy.
The four cost buckets
Every ISO 27001 project has four spending categories. Only one of them is non-negotiable.
1. Certification body fees
This is the audit itself: Stage 1 (documentation review), Stage 2 (implementation audit), and then surveillance audits in years two and three. Accredited certification bodies calculate audit duration using IAF MD 5, a mandatory formula from the International Accreditation Forum that converts headcount, number of sites and complexity into a minimum number of auditor days [1]. A 25-person single-site software company comes out at roughly 6 auditor days for the initial certification cycle.
What varies is the day rate. In 2026, expect roughly: £1,250 to £1,800 in the UK, $1,500 to $2,500 in the US, and materially less in India or parts of Eastern Europe [2]. The same audit scope produces a $9,000 quote from a London CB and a $12,000 one in New York. Surveillance audits each year run about 40% of the initial fee.
2. Consultant fees (optional)
A consultant builds or reviews your ISMS (information security management system): risk assessment, Statement of Applicability, policies, procedures, the bits that take domain knowledge. Day rates for experienced ISO 27001 consultants sit between $1,000 and $2,500 depending on geography and seniority [2]. Most small companies use 10 to 25 days, so $10,000 to $50,000.
One thing worth knowing: your certification body cannot also be your consultant. That is an impartiality breach under ISO/IEC 17021-1 [3]. If a firm offers to consult and then certify you, walk away, because a legitimate accreditation body will flag it and the certificate may not survive.
3. Tooling and platform costs
You can run an ISMS in a shared drive and a spreadsheet. Plenty of companies do. But a compliance platform (Vanta, Drata, Sprinto, OneTrust and the rest) automates evidence collection, maps controls to your cloud infrastructure and generates your risk register. These cost $7,000 to $25,000 a year for a small company. The platform does not replace understanding what the standard requires; it replaces copying screenshots into folders.
4. Internal staff time
This is the hidden majority of the cost. Someone senior has to own the ISMS: define the scope (clause 4.3), identify interested parties (clause 4.2), run the risk assessment (clause 6.1.2), write or approve policies, conduct an internal audit (clause 9.2) and hold a management review (clause 9.3). For a small company, that is 150 to 300 hours spread over three to six months [4]. If you cost that person's time at $100 an hour, you are looking at $15,000 to $30,000 in absorbed salary even if you never write a cheque.
I once audited a 15-person fintech that got to Stage 2 in nine weeks. The CTO wrote every policy herself over evening sessions, used a free risk-register template, and spent about $6,000 on the CB. Total outlay under $8,000. She looked tired, but the ISMS was hers and the surveillance audit went smoothly because she understood every line. That is the floor.
Cost by company size
| Company size | CB fees (initial cycle) | Realistic year-one total |
|---|---|---|
| 1-10 staff | $4,000 - $8,000 | $10,000 - $25,000 |
| 11-50 | $6,000 - $15,000 | $15,000 - $50,000 |
| 51-250 | $12,000 - $30,000 | $50,000 - $150,000 |
| 251+ | $30,000+ | $120,000+ |
Source: market guides from High Table [2] and Iseo Blue [5], cross-checked against IAF MD 5 auditor-day tables. Treat as indicative, not quoted rates.
DIY vs consultant-assisted
| DIY | Consultant-assisted | |
|---|---|---|
| Typical total cost (under 50 staff) | $10,000 - $20,000 | $25,000 - $60,000 |
| Calendar time | 4-8 months | 2-5 months |
| Internal hours | 250-400 | 80-150 |
| Risk of major nonconformity at Stage 2 | Higher if first time | Lower with experienced guidance |
| Who owns the ISMS after? | You, completely | You, but you may need the consultant to explain your own risk register |
The DIY path works best when someone on the team has compliance experience or has been through an ISO audit before. The consultant path makes sense when the deadline is tight (a customer contract with a certification clause) or when the founding team is entirely engineering and nobody wants to learn what clause 6.1.2 actually asks for.
A middle option that I see more often now: hire a consultant for 3 to 5 days of gap analysis and template review, then do the rest internally. You get the architecture right without paying for someone to sit in your office writing policies you will not read.
The three-year view
ISO 27001 is a three-year certification cycle. Year one is the initial audit. Years two and three are surveillance audits, each about 40% of the initial CB fee. Year four is recertification, roughly 70% of the original. So a company paying $10,000 in CB fees at Stage 1/Stage 2 should budget $4,000 per surveillance year and $7,000 for recertification.
Internal costs drop after year one because the ISMS exists. But they do not drop to zero: you still need an annual internal audit, a management review, and someone minding the risk register. Budget 50 to 100 hours a year of staff time.
The ROI case
The ISO Survey 2024 counted 96,709 valid ISO 27001 certificates worldwide at the end of 2024, up from 48,671 a year earlier [6]. That is not because companies developed a sudden affection for management systems. It is because enterprise procurement now asks for the certificate as routine, and because the regulatory floor keeps rising: NIS2 in the EU, DORA for financial services, the UK Cyber Security and Resilience Bill. Against IBM's 2025 global average breach cost of $4.4 million [7], a $30,000 certificate that forces you to actually fix your access control starts to look reasonable.
At Calibre we sit in the CB column of that cost table. We publish the auditor-day calculation behind every quote so you can check it against MD 5 yourself, and we run the certification decision in days rather than the six to ten weeks a traditional body takes to convene its review committee. More on the UK-specific costs in how much ISO 27001 costs in the UK, and a full breakdown of the process in how to get ISO 27001 certification in the UK.
FAQ
The audit duration does not; the auditor day rate does. Expect the UK and US to be the most expensive. A certificate from any certification body accredited by an IAF-member accreditation body is recognised worldwide, so geography is not a constraint on which CB you choose.
Broadly similar for a small company in year one, but SOC 2 Type II tends to cost more over time because the CPA firm re-performs a full examination every 12 months, whereas ISO surveillance audits are shorter. See ISO 27001 vs SOC 2.
Yes. Scope is your decision under clause 4.3. Certify the product and the team that supports it rather than the whole organisation, if that is what your customers actually need to see on the certificate.
The certification body's fee is never free, because accredited audits require qualified auditors and oversight. You can minimise the rest by doing the implementation yourself. I cover this in detail in is ISO 27001 certification free.
Sources
- 1.IAF. (2023). "IAF MD 5:2023 - Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems". https://iaf.nu/en/iaf-documents/
- 2.High Table. (2026). "ISO 27001 Certification Cost Guide [2026 update]". https://hightable.io/iso-27001-certification-cost/
- 3.ISO/IEC. (2015). "ISO/IEC 17021-1:2015 - Conformity assessment - Requirements for bodies providing audit and certification of management systems". https://www.iso.org/standard/61651.html
- 4.Iseo Blue. (2026). "How long does ISO 27001 take?". https://iseoblue.com/how-long-does-iso-27001-take/
- 5.Iseo Blue. (2026). "ISO 27001 Certification Cost UK [2026]". https://iseoblue.com/iso-27001-certification-cost/
- 6.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html
- 7.IBM Security and Ponemon Institute. (2025). "Cost of a Data Breach Report 2025". https://www.ibm.com/reports/data-breach

