Skip to content

Resources/Cost/7 min read

How much does ISO 27001 cost?

The short answer

ISO 27001 costs a small company $10,000 to $50,000 in the first year worldwide, with the biggest share being internal staff time (150 to 300 hours), not the certification body's audit fee. Year-two and year-three surveillance costs are roughly 40% of the initial audit fee each.

  • Gautham SenthilnathanCEO & Co-Founder

Last updated

Between $10,000 and $50,000 in your first year for a company under 50 people, anywhere in the world. The number I see founders fixate on is the certification body's audit fee, but that is typically only a quarter to a third of the real spend. The rest is your own people's time building and running the ISMS (information security management system), plus whatever you choose to spend on tooling or a consultant. The audit is the MOT; the work is the car.

The four line items

Every ISO 27001 budget breaks down into four things. Two are mandatory (your time and the audit), two are optional (tooling and consultancy). Here is what each looks like in 2026.

Line itemSmall company (1-50 staff)Mid-size (51-250)
Internal staff time150-300 hours400-1,000+ hours
Certification body audit$5,000-$15,000$12,000-$30,000
Compliance tooling$0-$25,000/yr$10,000-$50,000/yr
Consultant (optional)$10,000-$40,000$30,000-$100,000+
Realistic year-one total$10,000-$50,000$50,000-$150,000

Those ranges assume a single site and a cloud-based tech company. Add physical manufacturing, multiple offices, or heavily regulated data and the numbers climb, because audit duration climbs.

Internal time is the biggest cost

I need to say this clearly because it is the part people underestimate by the largest margin. Building an ISMS from nothing takes 150 to 300 hours for a small company. That means writing a risk assessment, choosing which of the 93 Annex A controls apply and documenting why in a Statement of Applicability (SoA), writing or adapting half a dozen policies, running an internal audit, holding a management review, and generating three months or so of records that prove the system actually operates.

If a senior engineer earning $150,000 a year does this over three months at half time, the salary cost alone is roughly $18,000. Nobody invoices you for that, so it never shows up in a "cost of ISO 27001" blog post, but it is real money and real opportunity cost.

Companies that already have their house in order — access control documented, incidents logged, some kind of risk register — cut that time in half, while companies starting from a blank Google Drive should expect to double it.

The certification body fee

This is the only cost set by a formula. Accredited certification bodies follow IAF MD 5, a mandatory document from the International Accreditation Forum that converts headcount, number of sites and operational complexity into a minimum number of auditor days [1]. A 25-person SaaS company with one office and a cloud estate works out at roughly 5 to 6 auditor days for the initial certification (Stage 1 documentation review plus Stage 2 implementation audit).

What varies by country is the day rate. In 2026, rough market figures are:

Country/regionAuditor day rate
UK (UKAS-accredited)£1,250-£1,800 ($1,600-$2,300)
US (ANAB-accredited)$1,500-$2,500
Germany (DAkkS)EUR 1,200-EUR 1,800
India$400-$800

Sources: High Table 2026 cost guide [2], Iseo Blue 2026 market report [3], ISO27001Cost.com [4]. These are market surveys, not official figures.

Because audit duration is formula-driven, the cheapest route to a legitimate certificate is to pick an accredited CB in a lower-cost market. The certificate carries equal weight: a UKAS, ANAB, DAkkS or JAS-ANZ certificate is mutually recognised through the IAF multilateral recognition arrangement [5]. I cover the UK-specific numbers in a separate article.

At Calibre we publish the auditor-day calculation behind every quote so you can check our arithmetic against MD 5 yourself.

Consultants and tooling

Neither is mandatory. The standard does not require you to hire a consultant or buy a platform. But most companies under 50 people do one or the other, because nobody on staff has implemented an ISMS before and the learning curve costs time.

A typical ISO 27001 consultant in the UK or US charges $1,000 to $2,000 a day and a small implementation takes 10 to 25 days of their time [2][3]. I go into more detail on what consultants charge and what you get.

Compliance platforms (Vanta, Drata, Sprinto, Scrut and several others) run $7,000 to $25,000 a year and handle evidence collection, policy templates and control mapping. They save time, but they do not replace judgement — someone still has to own the risk assessment and make real decisions about which controls apply and how.

One thing worth knowing: the certification body that audits you cannot also consult for you. That is an impartiality rule under ISO/IEC 17021-1, clause 5.2 [6]. If someone offers you a package deal for "consultancy plus certification", ask who holds the accreditation and who is doing the advice, because they cannot be the same legal entity.

Cost drivers

Five things, in order of how much they move the number:

  1. Headcount in scope. IAF MD 5 maps directly from employee count to audit days. Going from 25 to 75 people adds two to three auditor days, which is $3,000 to $7,000 on the CB invoice alone.
  2. Multiple sites. Each site needs at least a sample visit. Remote-only companies have a genuine advantage here.
  3. Scope creep in the ISMS. Certifying your entire company when the customer only needs your SaaS product in scope adds policies, controls and audit time you did not need.
  4. Starting from scratch. If you have no access control list, no incident log, no risk register, you are paying for foundational security work, not just certification paperwork.
  5. Over-documentation. I once audited a 15-person startup that had written 47 policies. They needed about 12. Every extra policy is a policy someone has to maintain, review, and answer questions about in the audit.

The three-year view

ISO 27001 is a three-year cycle, not a one-off. After the initial certification you sit two surveillance audits (years one and two), each about a third of the initial audit length, then a full recertification audit in year three.

YearCB fee (small company)Internal effort
1 (initial)$5,000-$15,000150-300 hours
2 (surveillance)$2,000-$6,00040-80 hours
3 (surveillance)$2,000-$6,00040-80 hours
4 (recertification)$4,000-$12,00080-150 hours

By year two the ISMS should be running, so the internal time drops sharply. The companies that find year two expensive are the ones that built the system for the auditor rather than for themselves, and now have to pretend to follow policies they never actually adopted.

The ROI case

The ISO Survey 2024 counted 96,709 valid ISO 27001 certificates worldwide at end-2024, nearly double the 48,671 a year earlier [7]. That is not a wave of enthusiasm for management systems — it is procurement departments adding ISO 27001 to vendor questionnaires and regulators raising the floor (NIS2 in the EU, the UK Cyber Security and Resilience Bill, DORA for financial services).

Against IBM's 2025 figure of $4.4 million as the global average cost of a data breach [8], and the UK average of £3.29 million, a $30,000 certificate that forces you to actually review your access lists and test your backups is a sensible trade. Whether it is worth more or less than SOC 2 depends on where your customers are: ISO 27001 is the international standard; SOC 2 is a US framework. Most UK and European buyers ask for ISO.

FAQ

Yes. Clause 4.3 gives you the choice. If your customer only cares about your SaaS product, certify the product and the team that builds and operates it. A 12-person scope is cheaper to audit than a 50-person one.

No. The standard itself costs about CHF 129 (roughly $145) to buy from ISO [9], and the certification audit requires paying an accredited CB. I explain why it cannot be free in a separate piece.

The audit duration is the same everywhere because IAF MD 5 applies globally. The day rate varies. A certificate from any IAF-recognised accreditation body (UKAS, ANAB, DAkkS, JAS-ANZ, and others) is accepted internationally.

A founder or CTO with some security background, a $7,000 compliance platform, and a CB quoting at the lower end of the market. I have seen that come in under $15,000 total for a 10-person company, but it took about 200 hours of the founder's evenings and weekends.

Sources

  1. 1.IAF. (2023). "IAF MD 5:2023 Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems". https://iaf.nu/en/iaf-documents/
  2. 2.High Table. (2026). "ISO 27001 Certification Cost [2026 update]". https://hightable.io/iso-27001-certification-cost/
  3. 3.Iseo Blue. (2026). "ISO 27001 Cost Guide 2026". https://iseoblue.com/iso-27001-cost/
  4. 4.ISO27001Cost.com. (2026). "How Much Does ISO 27001 Cost?". https://iso27001cost.com/
  5. 5.IAF. (2024). "IAF Multilateral Recognition Arrangement (MLA)". https://iaf.nu/en/accreditation-body-members/
  6. 6.ISO/IEC. (2015). "ISO/IEC 17021-1:2015 Conformity assessment - Requirements for bodies providing audit and certification of management systems - Part 1". https://www.iso.org/standard/61651.html
  7. 7.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html
  8. 8.IBM Security and Ponemon Institute. (2025). "Cost of a Data Breach Report 2025". https://www.ibm.com/reports/data-breach
  9. 9.ISO. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection". https://www.iso.org/standard/27001

Found this useful? Pass it on.

Certification, without the drag.

A process built for how modern teams actually work, run by tech-first auditors, and honest about what you do and don't need.