For a small UK company (up to 50 people), getting ISO 27001 certified costs £8,000 to £40,000 in the first year. About a third of that is the certification body's fee. The rest is the work you do before anyone audits you: building the information security management system (ISMS), fixing whatever your risk assessment uncovers, and proving the whole thing has been running long enough to have real evidence.
I'll walk through the cost at each phase, in the order you actually spend the money.
Phase 1: gap analysis (months 0 to 1)
Before you write a single policy, you need to know what you already have and what is missing. A gap analysis compares your current security posture against the requirements of Clauses 4 to 10 and the 93 Annex A controls.
If you do it yourself, the cost is time: 20 to 40 hours for someone who reads the standard carefully and maps it against your existing tooling. That is roughly £1,200 to £2,400 in loaded salary for a senior engineer at £60 an hour.
If you hire a consultant, a gap analysis is typically a 2- to 5-day engagement. UK consultant day rates in 2026 sit at £500 to £1,200 [1], so expect £1,000 to £6,000. Some compliance platforms include automated gap scans against the Annex A control set, which gets you part of the way for the platform subscription price (more on that below).
You will also need the standard itself. ISO/IEC 27001:2022 costs about CHF 130 (roughly £120) from iso.org [2]. ISO 27002:2022, the implementation guidance companion, is a similar price and more useful day to day. Budget £240 for both.
Phase 2: implementation (months 1 to 4)
This is where most of the money goes, and where most of it is invisible because it is your own people's time.
You need to build: a defined scope (Clause 4.3), an interested-parties register (4.2), a risk assessment methodology and risk treatment plan (6.1.2, 6.1.3), a Statement of Applicability listing which of the 93 controls you apply and why, somewhere between 10 and 20 policies and procedures, and the operational evidence that all of it actually runs.
Internal effort for a 20-person company runs 150 to 300 hours — roughly one to two days a week from a senior person for about a quarter. If you already run SSO, device management, code review and a ticketing system, you are at the low end because the controls exist and only the paperwork is missing.
Three ways to accelerate:
- A consultant for implementation support: 10 to 25 days for a small firm, so £6,000 to £25,000 [1]. A good consultant writes nothing for you (that would create an impartiality problem if they later act as your internal auditor) but tells you exactly what to write and reviews each draft.
- A compliance platform (Vanta, Drata, Sprinto, or similar): £5,000 to £20,000 a year. Automates evidence collection, provides policy templates, and maps controls to cloud configurations. Worth it if you are a cloud-native company where most of the evidence lives in APIs.
- Neither, and a founder who reads ISO 27002 over a weekend. I have certified companies that took this path. It works if the person is disciplined and the company is simple.
One cost people miss: fixing what the risk assessment finds. If it says your backups are untested, you now have to test them. If it says you have no incident response process, you need one. This is the point of the exercise, but budget for the remediation work.
Phase 3: internal audit and management review (month 4)
Before a certification body will schedule your Stage 2, you must have completed at least one internal audit (Clause 9.2) and one management review (Clause 9.3). These are mandatory documents under the standard.
If your consultant does the internal audit, that is 1 to 3 days (£500 to £3,600). If you do it in-house, the auditor cannot audit their own work, so you need someone other than the person who built the ISMS. The management review is a meeting with top management; the cost is their time, typically half a day.
Phase 4: the certification audit (months 4 to 6)
An accredited certification body (CB) runs two audits: Stage 1 is a documentation and readiness review (usually one day, often remote), and Stage 2 is the implementation audit where the auditor interviews staff, samples records and tests that controls operate as described — two to four days for a small company.
Auditor-day counts come from IAF MD 5 [3], the accreditation rule that all UKAS-accredited bodies must apply, so quotes from accredited CBs should be within a day or so of each other for the same scope and headcount.
Day rates in 2026 sit around £1,250 to £1,800 [4][5]. For a 20-person cloud company, that is 4 to 6 auditor days, so roughly £5,000 to £9,000 for the initial certification cycle (Stage 1 plus Stage 2).
At Calibre, we scope in hours, run Stage 1 remotely, and aim for a certification decision within days of Stage 2 closing, because the cost that hurts startups most is the eight weeks of waiting while a deal sits in procurement.
Phase 5: surveillance and recertification (years 2 and 3)
The certificate is valid for three years, but it is not a case of passing the MOT and forgetting about the car until next time. You sit a surveillance audit in year one and year two (each roughly a third of the initial audit duration), and a full recertification audit in year three.
For the 20-person company above, that means roughly 2 auditor days per surveillance visit (£2,500 to £3,600 a year), and recertification at year three is slightly shorter than the original Stage 1 plus Stage 2 but broadly the same cost — with platform and tooling renewals continuing annually on top.
Phase-by-phase cost summary (25-person B2B SaaS, one UK office, AWS)
| Phase | Timeline | Cost range |
|---|---|---|
| Gap analysis (internal or consultant) | Month 0-1 | £1,200 - £6,000 |
| Copy of the standard and ISO 27002 | Month 0 | £240 |
| Implementation (internal time, 200 hrs at £60/hr) | Months 1-4 | £12,000 |
| Compliance platform, year one | Months 1-12 | £5,000 - £20,000 |
| Consultant support (optional, 6 days) | Months 1-4 | £0 - £7,200 |
| Penetration test | Month 3-4 | £3,000 - £10,000 |
| Internal audit (consultant, 2 days) | Month 4 | £1,000 - £2,400 |
| Certification body, Stage 1 + Stage 2 (5 days) | Months 4-6 | £5,000 - £9,000 |
| Year-one total | £27,440 - £66,840 | |
| Year-two surveillance + platform renewal | Year 2 | £7,500 - £23,600 |
| Year-three surveillance + platform renewal | Year 3 | £7,500 - £23,600 |
Strip the consultant and platform, lean on the engineer and use free tooling, and the same company gets certified for about £20,000 in year one. Add a second office and a data centre and it climbs past £60,000.
The ROI
The government's Cyber Security Breaches Survey 2025/2026 puts breaches or attacks at 43% of UK businesses in a single year [6]. IBM's UK average breach cost was £3.29 million in the 2025 report [7]. Neither number means a certificate makes you immune, but ISO 27001 forces the risk assessment that makes you fix the obvious things. Worldwide, there were 96,709 valid certificates at end-2024, up from 48,671 the year before [8], which tells you a lot of organisations have done the maths and decided it pays.
Most founders I work with recoup the cost on the first enterprise contract that required it.
For the broader UK cost picture by company size, see how much ISO 27001 costs in the UK. If you are wondering whether you can skip the spend entirely, read is ISO 27001 certification free?. And if the total feels steep, why ISO 27001 is so expensive breaks down where the money actually goes.
FAQ
Three to six months for a small company starting from reasonable engineering hygiene. The audits themselves take about a week; the long pole is building three months of operating evidence before Stage 2.
No. The standard does not require one, and a certification body cannot legally require you to use a specific consultancy. A consultant helps most when nobody internal has time or when your first draft of the ISMS is bloated. Note that a CB auditing its own consultancy work is an impartiality breach under ISO/IEC 17021-1 [9], so never use the same firm for both.
Yes, and most companies do. Year one is the heaviest. Years two and three are surveillance audits, platform renewals, and the ongoing internal effort to keep the ISMS running. Budget roughly 30% to 40% of year one for each subsequent year.
You do not fail in the exam sense. The auditor raises nonconformities. Minor ones you fix with a corrective action plan within an agreed timeframe. Major ones need to be closed, usually with a short follow-up audit, before the certificate is issued. Certification bodies charge their day rate for follow-up time.
Sources
- 1.ISO Adviser. (2026). "ISO Certification Costs: Complete UK Pricing Guide". https://isoadviser.com/iso-certification-costs-complete-guide/
- 2.ISO. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection". https://www.iso.org/standard/27001
- 3.International Accreditation Forum. (2023). "IAF MD 5:2023 Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems". https://iaf.nu/en/iaf-documents/
- 4.High Table. (2026). "ISO 27001 Certification Cost [2026 update]". https://hightable.io/iso-27001-certification-cost/
- 5.Iseo Blue. (2026). "ISO 27001 Certification Cost UK 2026". https://iseoblue.com/iso-27001/certification-guides/certification-costs/
- 6.Department for Science, Innovation and Technology. (2026). "Cyber Security Breaches Survey 2025/2026". GOV.UK. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026
- 7.IBM Security and Ponemon Institute. (2025). "Cost of a Data Breach Report 2025". https://www.ibm.com/reports/data-breach
- 8.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html
- 9.ISO/IEC. (2015). "ISO/IEC 17021-1:2015 Conformity assessment - Requirements for bodies providing audit and certification of management systems". https://www.iso.org/standard/61651.html

