Skip to content

Resources/Cost/8 min read

How much does ISO 27001 cost in the UK?

The short answer

A UK company of 1 to 50 people should expect to spend £8,000 to £40,000 on its first ISO 27001 certificate, of which £4,000 to £12,000 is the certification body's fee. The rest is internal time, tooling and optional consultancy. Surveillance audits in years two and three cost roughly 40% of the initial audit each.

  • Gautham SenthilnathanCEO & Co-Founder
  • Dimitar YotovHead of Compliance

Last updated

A UK tech company with fewer than 50 staff should budget £8,000 to £40,000 for its first ISO 27001 certificate, all in. The certification body's share of that is usually £4,000 to £12,000 over the initial audit. Everything else is your own people's time, whatever you spend on a compliance platform, and a consultant if you use one. Years two and three are cheaper: a surveillance audit is typically a third to half the length of the initial one.

Those ranges are wide because ISO 27001 is priced by effort, and effort depends on how many people are in scope, how many sites you have, and how complicated your systems are. We'll go through each line item so you can build your own number rather than trusting a range from a blog.

The certification body fee

This is the only part of the cost that is set by a formula. Accredited certification bodies (CBs) work from IAF MD 5, the International Accreditation Forum's mandatory document on audit duration. It maps your headcount and complexity to a minimum number of auditor days. A 20-person SaaS company with one office and a cloud-only estate lands around 5 to 6 auditor days for the initial certification (Stage 1 plus Stage 2), then 2 days for each surveillance audit.

The day rate is the other half of the multiplication. Market guides for 2026 put the UKAS-accredited auditor day rate at roughly £1,250 to £1,800, up from £1,000 to £1,100 a couple of years ago; High Table's 2026 cost guide attributes the rise to a shortage of qualified 27001 auditors and the extra scrutiny that came with the 2022 revision [1][2]. So a small company's initial audit is 5 days × £1,250 = about £6,250, plus a certificate fee and sometimes a "management fee" that CBs use to pad the quote.

Over a full three-year cycle (initial, two surveillances, then recertification) a small company pays a CB something in the region of £12,000 to £18,000. Ask for the three-year figure up front. Some bodies quote a low year-one price and recover it on the surveillances.

At Calibre we scope in hours rather than weeks and publish the auditor-day calculation we used, because founders should be able to check our arithmetic against MD 5 themselves.

Your own time

This is the cost that nobody puts on the invoice and it is nearly always the biggest. Someone has to own the ISMS (the information security management system, the set of policies, risk decisions and records the standard actually certifies). In a startup that is usually the CTO or a senior engineer, part-time, for two to four months before the audit.

A reasonable estimate for a 20-person company doing it for the first time is 150 to 300 hours of internal effort: scoping, risk assessment, writing or adapting policies, running the internal audit and management review, collecting evidence. At a loaded cost of £60 an hour that is £9,000 to £18,000 you don't see but absolutely spend. Companies that already have decent engineering hygiene (SSO, MDM, a ticketing system, code review) come in at the bottom of that range because most of the evidence already exists.

Consultants

Optional. UK ISO 27001 consultants charge £500 to £1,200 a day for freelancers and more for firms, and a typical small-company implementation is 10 to 25 consultant days, so £6,000 to £25,000 [3]. We've written a separate piece on what ISO consultants charge. The short version: a good consultant saves you internal hours and stops you writing policies you don't need. A bad one sells you a 200-page template pack and leaves you to explain it to the auditor.

Tooling

Compliance automation platforms (Vanta, Drata, Secureframe and the like) run roughly £5,000 to £20,000 a year for a small company depending on how many integrations and frameworks you want. They are not required. They do cut evidence collection time sharply, and most CBs, Calibre included, are comfortable auditing directly from them.

You also need the standard itself if you want to read the source text. ISO/IEC 27001:2022 is about CHF 130 from iso.org, roughly £120. Not free, which surprises people. More on that in is ISO 27001 certification free?.

Training

Somebody in your organisation needs to understand the standard well enough to build the ISMS and talk to the auditor. That person does not need to be a certified lead implementer, but training helps.

A two-day ISO 27001 foundation course runs £500 to £900, while the five-day lead implementer and CQI/IRCA-certified lead auditor courses sit at £1,500 to £2,500 each [9]. None of these are required for certification, but clause 7.2 says you must demonstrate competence, and training is the most straightforward way to do it. If your CTO has been running production securely for a decade, that counts. If nobody in the company has ever read the standard, budget for a course.

We once opened a Stage 2 with a startup whose lead implementer had done no training and had clearly read only the table of contents of 27002. He could not explain why he had excluded control 8.28 (secure coding) from a software company's Statement of Applicability. That is the kind of hour that makes an auditor's Tuesday very long.

The three-year certification cycle

ISO 27001 certification is not a one-off purchase. The certificate is valid for three years, with conditions. You sit a Stage 1 (documentation review) and Stage 2 (implementation audit) in year one. In years two and three you sit surveillance audits, each covering roughly a third of the ISMS. At the end of year three you sit a recertification audit, which is shorter than the initial but still a proper Stage 2.

AuditTypical length (small company)Typical CB cost
Stage 1 + Stage 2 (year 1)5-7 auditor days£6,000-£12,000
Surveillance 1 (year 2)2-3 days£2,500-£5,000
Surveillance 2 (year 3)2-3 days£2,500-£5,000
Recertification (year 4)4-5 days£5,000-£9,000

Over a full first cycle a small company pays the CB something like £11,000 to £22,000. The internal cost of keeping the ISMS alive between audits is harder to pin down, but budget 3 to 5 hours a month for the ISMS owner plus a couple of days each for the internal audit and management review [8][10].

Total cost by company size

These are 2026 market figures compiled from UK cost guides [1][2][4] and consistent with what we see on quotes. First year, including CB fees, internal time and typical tooling or consultancy. Take them as ranges, not quotes.

Company sizeCB fee (initial)Internal effortConsultant/toolingRealistic year-one total
Micro, 1-10 staff£3,500-£6,000£5,000-£10,000£0-£8,000£8,000-£20,000
Small, 11-50£5,000-£12,000£9,000-£18,000£5,000-£20,000£12,000-£40,000
Medium, 51-250£10,000-£25,000£20,000-£50,000£15,000-£50,000£40,000-£120,000
Large, 251+£25,000+£50,000+£30,000+£100,000+

Once you have the certificate, ongoing cost drops. Budget the surveillance audit fee (roughly 40% of the initial), plus a few hours a month to keep the ISMS running, plus your tooling subscription.

The ROI

Two figures we quote to every founder who flinches at the price. IBM's 2025 Cost of a Data Breach report puts the average UK breach at £3.29 million, and the 2026 edition at £3.13 million [5]. And the government's Cyber Security Breaches Survey 2025/2026 found 43% of UK businesses, about 612,000 of them, identified a breach or attack in the previous 12 months [6]. A £20,000 certificate that also makes you close the gaps those numbers come from is cheap insurance, before you even count the enterprise deals it unblocks.

There is also the market. The ISO Survey 2024 counted 96,709 valid ISO 27001 certificates worldwide, nearly double the 48,671 from a year earlier, with 4,455 of them in the UK [7]. Your competitors are getting it. Procurement teams increasingly assume you have it.

Common overspends

The three mistakes we see on the invoices:

  1. Buying a consultant's full template library and then paying the consultant again to explain it. Your ISMS should be as small as your company. Most 20-person firms need about 12 to 15 documents, not 60.
  2. Over-scoping. Certifying "the whole company" when customers only care about the production platform adds auditor days for nothing. Scope is your decision under clause 4.3.
  3. Choosing a CB on year-one price alone. Check the three-year number and check whether they are UKAS-accredited. An unaccredited certificate is worth roughly nothing to a UK enterprise buyer, which means you paid for it twice: once to get it, once to get a real one.

FAQ

No. Accredited certification bodies calculate audit days from IAF MD 5 using your headcount, sites and complexity, then multiply by a day rate. Two companies with the same headcount can get different quotes if one has more locations or a more complex technical estate.

A micro company with clean infrastructure, no consultant and a founder willing to write the documents can get certified for £5,000 to £8,000 in CB fees plus their own time. It has been done. It is not the norm.

Usually not in the headline figure. Ask for the full three-year cycle: initial certification, two annual surveillance audits, and recertification at year three.

Only if nobody who matters will ever check. UK enterprise procurement, government frameworks and most insurers look for UKAS accreditation on the certificate. Save the money and do it once.

Sources

  1. 1.High Table. (2026). "ISO 27001 Certification Cost [2026 update]". https://hightable.io/iso-27001-certification-cost/
  2. 2.Iseo Blue. (2026). "ISO 27001 Certification Cost UK 2026". https://iseoblue.com/iso-27001/certification-guides/certification-costs/
  3. 3.ISO Adviser. (2026). "ISO Certification Costs: Complete UK Pricing Guide". https://isoadviser.com/iso-certification-costs-complete-guide/
  4. 4.ISO27001Cost.com. (2026). "ISO 27001 Cost UK 2026". https://iso27001cost.com/cost-uk
  5. 5.IBM Security and Ponemon Institute. (2025). "Cost of a Data Breach Report 2025". https://www.ibm.com/reports/data-breach
  6. 6.Department for Science, Innovation and Technology. (2026). "Cyber Security Breaches Survey 2025/2026". GOV.UK. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026
  7. 7.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html
  8. 8.International Accreditation Forum. (2023). "IAF MD 5:2023 Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems". https://iaf.nu/en/iaf-documents/
  9. 9.CQI/IRCA. (2026). "ISO 27001 Lead Auditor Training Courses". https://www.quality.org/find-a-course
  10. 10.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements". https://www.iso.org/standard/27001

Found this useful? Pass it on.

Certification, without the drag.

A process built for how modern teams actually work, run by tech-first auditors, and honest about what you do and don't need.