Skip to content

Resources/Cost/7 min read

How much does ISO 27001 certification cost in the UK?

The short answer

A UK company with 10 to 50 staff pays £4,000 to £15,000 in certification body fees for the initial ISO 27001 audit, depending on complexity and auditor day rates of £1,250 to £1,800. The three-year cycle including two surveillance audits and recertification adds roughly 60% on top.

  • Dimitar YotovHead of Compliance
  • Gautham SenthilnathanCEO & Co-Founder

Last updated

The certification body (CB) fees for a small UK tech company are £4,000 to £15,000 for the initial audit, covering Stage 1 and Stage 2 combined. That buys you 4 to 8 auditor days at a UKAS-accredited day rate of roughly £1,250 to £1,800 [1][2]. The three-year certification cycle, including two surveillance audits and a recertification, comes to about £12,000 to £25,000 in CB fees alone.

This article is about the certification body's invoice, not the total cost of getting certified. If you want the full picture, including implementation time, consultants and tooling, read how much it costs to get ISO 27001 certified.

Audit day calculation

Your CB does not pick a number out of the air. Every accredited certification body follows IAF MD 5, the International Accreditation Forum's mandatory document that maps your headcount to a minimum number of auditor days [3]. UKAS, the UK's accreditation body, enforces this. Non-accredited bodies are not bound by it, which is one reason their quotes are sometimes suspiciously low.

The MD 5 table works on "effective personnel", meaning the number of people whose work falls inside your ISMS scope, including contractors and part-time staff counted as full-time equivalents. Here is a simplified version of the initial audit day ranges for common company sizes:

Effective personnelStage 1 (days)Stage 2 (days)Total initial (days)
1 to 101 to 1.52 to 33 to 4.5
11 to 251.5 to 23 to 44.5 to 6
26 to 452 to 2.54 to 56 to 7.5
46 to 652.5 to 35 to 67.5 to 9
66 to 8536 to 79 to 10
86 to 1253 to 47 to 810 to 12

These are approximate ranges derived from IAF MD 5 Annex B [3]. The CB can adjust upward for complexity (multiple sites, highly regulated data, bespoke development environments) or downward if your scope is narrow and your technology stack is simple. The adjustments are auditable: UKAS expects the CB to document why it deviated and by how much.

We once reviewed a quote from a CB that allocated 12 auditor days for a 15-person SaaS company with a single cloud environment. When we asked, they had applied a "cloud complexity" uplift that doubled the MD 5 baseline. That is the kind of thing you should push back on.

The day rate

The auditor day rate is the multiplier that turns those audit days into pounds. In 2026, UKAS-accredited auditor day rates in the UK sit at roughly £1,250 to £1,800, up from about £1,000 to £1,100 two or three years ago [1][2]. High Table's 2026 market guide attributes the increase to a shortage of qualified ISO 27001 lead auditors and the extra work involved in auditing against the 2022 revision, which added 11 new controls and restructured Annex A from 114 controls in 14 domains to 93 controls in 4 themes [1][4].

The arithmetic is simple: a 20-person company with 5 initial audit days at £1,400 per day pays £7,000 in audit fees, while at £1,800 per day the same company pays £9,000. That range matters, and it is worth getting two or three quotes.

The CB invoice

The day rate times the number of days is the headline, but the invoice usually has a few more lines:

Fee typeTypical rangeNotes
Audit fees (day rate x days)£4,000 to £14,000The bulk of the cost
Certificate issuance fee£200 to £600One-off, per certificate cycle
Administration or management fee£300 to £1,200Some CBs bundle this; others add it on top
Travel and expenses£0 to £1,500Remote audits reduce this; some CBs include it
Scope-change fee£200 to £500Charged if you change scope mid-cycle

Ask for a fully loaded quote. A headline of "£5,000 for Stage 1 and Stage 2" can become £7,500 once the management fee, certificate fee, and auditor train tickets are added. If a CB cannot give you a single bottom-line number for the initial certification, that tells you something about how the next three years will go.

The three-year cycle

ISO 27001 certification runs in three-year cycles. After the initial audit, you have two surveillance audits (roughly one per year) and then a recertification audit in year three. Surveillance audits are shorter: IAF MD 5 specifies roughly a third of the initial audit duration per year, so if your initial was 6 days, each surveillance is about 2 days [3]. Recertification is approximately two-thirds of the initial.

For a small company, the three-year cycle in CB fees looks roughly like this:

YearAudit typeApproximate daysApproximate cost
Year 0Initial (Stage 1 + Stage 2)5 to 6£6,250 to £10,800
Year 1Surveillance 12£2,500 to £3,600
Year 2Surveillance 22£2,500 to £3,600
Year 3Recertification3 to 4£3,750 to £7,200

Over three years, that is £15,000 to £25,000 in CB fees for a small company. Some CBs offer a discounted three-year package. Take it, but read the cancellation terms: switching CBs mid-cycle is possible (it is called a transfer audit) but involves extra paperwork and sometimes extra audit time.

UKAS-accredited versus non-accredited CBs

This matters more than most people realise. A UKAS-accredited certification body has been assessed against ISO/IEC 17021-1 (the standard for bodies providing audit and certification of management systems) and is subject to ongoing UKAS surveillance [5]. The certificate it issues carries the UKAS mark and is recognised by every IAF member body worldwide, which covers most countries your customers operate in.

A non-accredited CB can still issue an ISO 27001 certificate, and it will be cheaper — sometimes dramatically so, perhaps £2,000 to £4,000 for a small company. But that certificate is not backed by any accreditation body, which means:

  • Enterprise customers and procurement teams often reject it. Their RFPs specify "accredited certification" or "UKAS/equivalent".
  • It will not satisfy regulatory expectations where ISO 27001 is referenced (for example, as evidence of UK GDPR Article 32 compliance [6]).
  • The audit itself may be less rigorous, which sounds like a benefit until you realise the whole point is that an independent auditor pressure-tested your controls.

We have seen companies pay for a non-accredited certificate, win a contract, then get told by the customer's security team that it does not count — and they end up paying twice. If your budget is tight, delay certification rather than going non-accredited.

Reducing the CB bill

You cannot negotiate the number of audit days below the IAF MD 5 minimum, and you should not want to. But you can influence the total cost:

  • Scope tightly. If only 15 of your 40 staff handle customer data and sit inside your ISMS scope, your effective headcount for MD 5 purposes is 15, not 40. A narrower scope means fewer audit days.
  • Use remote auditing. Most CBs now offer fully remote Stage 1 audits, and many will do Stage 2 remotely for single-site, cloud-native companies. That eliminates the travel line on the invoice.
  • Get three quotes. Day rates vary by £200 to £400 between CBs for the same scope. All three quotes should be from UKAS-accredited bodies.
  • Ask for the three-year price. Some CBs discount the cycle if you commit upfront.

At Calibre we scope in hours and show the MD 5 calculation we used, so you can check our arithmetic against the standard yourself.

FAQ

No. The certificate is valid for three years, but only if you pass annual surveillance audits. The certification body charges for each surveillance and for the recertification in year three. Budget for the full cycle, not just year one.

Yes. It is called a transfer audit. The new CB reviews your existing certificate, conducts its own assessment, and issues a new certificate under its accreditation. There is usually a small amount of extra audit time to cover the handover.

UKAS charges accreditation fees and conducts its own surveillance of the CB, and accredited auditors must meet qualification and CPD requirements under ISO/IEC 17021-1 and ISO/IEC 27006-1 [5][7]. Those costs flow into the day rate. In return, your certificate is internationally recognised and stands up to procurement scrutiny.

We scope in hours based on IAF MD 5 and provide a fixed-price quote after a short scoping call. The calculation is transparent: you see the headcount, the complexity adjustments and the day rate.

Sources

  1. 1.High Table. (2026). "ISO 27001 Certification Cost Guide 2026". https://hightable.io
  2. 2.Iseo Blue. (2026). "UK ISO 27001 Audit Day Rates 2026". https://iseoblue.com
  3. 3.International Accreditation Forum. (2023). "IAF MD 5:2023 Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems". https://iaf.nu/en/iaf-documents/
  4. 4.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection. Information security management systems. Requirements". https://www.iso.org/standard/27001
  5. 5.UKAS. (2026). "Certification Body Accreditation". https://www.ukas.com/accreditation/standards/management-systems-certification-bodies/
  6. 6.UK Government. (2018). "Data Protection Act 2018 / UK GDPR". https://www.legislation.gov.uk/ukpga/2018/12/contents
  7. 7.ISO/IEC. (2024). "ISO/IEC 27006-1:2024 Requirements for bodies providing audit and certification of information security management systems". https://www.iso.org/standard/82908.html

Found this useful? Pass it on.

Certification, without the drag.

A process built for how modern teams actually work, run by tech-first auditors, and honest about what you do and don't need.