Skip to content

Resources/Cost/5 min read

How much does the ISO 27001 exam cost?

The short answer

There is no company-level ISO 27001 exam. For individuals, an ISO 27001 Lead Auditor or Lead Implementer course with exam costs £1,200 to £3,000 in the UK. Exam-only resits are £150 to £400.

  • Dimitar YotovHead of Compliance

Last updated

It depends which "exam" you mean. If you are a company, there is no exam: your information security management system (ISMS) is audited, not tested, and that costs £4,000 to £12,000 for a small firm's initial cycle (covered in how much ISO 27001 costs in the UK). If you are an individual wanting to become a qualified auditor or implementer, the exam is bundled with a five-day course and costs £1,200 to £3,000, with resits at £150 to £400.

This article covers the personal qualification side, because that is the question being asked.

Lead Implementer and Lead Auditor

ISO 27001 Lead Auditor. This is the qualification certification bodies (CBs) look for when hiring contract auditors. The course runs five days and ends with a written exam, typically two hours. CQI/IRCA-registered providers are the standard in the UK [1], though PECB and Exemplar Global schemes are recognised internationally [2]. Expect £1,500 to £3,000 for the full package. Virtual delivery knocks 20 to 30% off: BSI Training listed its virtual Lead Auditor at around £1,700 in early 2026, against £2,200 for classroom [3]. PECB offers a standalone exam for roughly £600 to £900 if you prefer to self-study, but you will still need verified training hours to register with IRCA.

ISO 27001 Lead Implementer. Same format, similar price range of £1,200 to £2,500. This is the one for people who build ISMSs rather than audit them. More useful if you plan to consult; less useful if you want to sit on the other side of the table during a Stage 2.

A two-day Internal Auditor course (£600 to £1,200) covers enough for someone whose only job is running the clause 9.2 internal audit inside their own organisation. If that is you, save your money.

A one-day Foundation or awareness course (£300 to £600) gives a broad overview and no exam worth mentioning. Fine for onboarding a new team member, not a career credential.

Exam content

The Lead Auditor exam is mostly about auditing technique applied to ISO 27001's clauses 4 to 10 and the 93 Annex A controls. ISO 19011 principles, audit planning, evidence sampling, writing nonconformity statements [4]. Most schemes are open book, which catches people off guard because they assume open book means easy. It does not. You are given a scenario and asked to write a formal nonconformity. "The organisation has not retained documented evidence of management review outputs as required by clause 9.3.3" passes. "Management review seemed a bit thin" does not.

I once sat through an exam debrief where a candidate with fifteen years in InfoSec failed because every nonconformity he wrote cited "Annex A" without a control number. He knew the material cold but hadn't practised the format, and that is what the exam really tests: whether you can write like an auditor, not whether you understand security.

The failure rate in my experience sits around 10 to 15% for people with real security backgrounds. For people who booked the course hoping to change careers with no prior experience, it is higher.

Exam vs experience

This is the part the training companies put in small print. To conduct audits for an accredited certification body you need, under ISO/IEC 27006-1, the exam plus typically five years of work experience (at least two in information security), plus a number of witnessed audit days under a qualified lead auditor [5]. The exam is the cheapest and fastest step; building the experience takes years.

If your goal is to become an ISO 27001 consultant, the Lead Implementer is the more direct route. If your goal is to join a certification body like Calibre as a contract auditor, it is the Lead Auditor plus the field hours.

I cover the full career path, including consultant day rates, separately.

Cost summary

QualificationFormatTypical UK cost (2026)
Lead Auditor (IRCA/PECB/BSI)5 days + exam£1,500 - £3,000
Lead Implementer (IRCA/PECB)5 days + exam£1,200 - £2,500
Internal Auditor2 days + exam£600 - £1,200
Foundation / awareness1 day, no formal exam£300 - £600
Exam resit (PECB/IRCA)Exam only£150 - £400
Annual IRCA registrationMembership£100 - £200

Prices are from published 2026 course listings across BSI, PECB, and IRCA-registered providers. Virtual courses are consistently cheaper than classroom.

The ROI

Demand for qualified auditors is strong. UK auditor day rates have climbed to £1,250 to £1,800 [6], and the ISO Survey 2024 recorded 96,709 valid ISO 27001 certificates worldwide, nearly double the prior year [7]. Every one of those certificates requires annual surveillance audits. A £2,500 course that opens the door to a freelance day rate of £600 to £1,000 pays for itself inside a fortnight, provided you have the experience underneath.

For company founders wondering whether anyone on their team needs these qualifications: no. Clause 9.2 requires competent and impartial internal audits, not a named credential. Plenty of companies use a two-day internal auditor course, or hire an external contractor for internal audits separately from their CB.

FAQ

No. ISO publishes standards but does not train or examine people. Personnel certification schemes like PECB, CQI/IRCA, and Exemplar Global run the exams [1][2].

Yes. Most providers offer remote-proctored exams and virtual classrooms. Check whether the provider is IRCA-approved if you plan to work for a UK certification body, because not all online courses carry that registration [1].

No. Your company's certification depends on an external audit by a CB, not on anyone internally holding a qualification. The requirements for ISO 27001 are about your ISMS, not your staff's exam results.

Both are personnel certification schemes. IRCA (managed by CQI in the UK) is more commonly required by UK and European certification bodies [1]. PECB is widely used internationally, particularly in North America and the Middle East [2]. Either is credible, so pick the one your target employers recognise.

Sources

  1. 1.CQI/IRCA. (2026). "ISO/IEC 27001 Lead Auditor Training Course Criteria". https://www.quality.org/
  2. 2.PECB. (2026). "ISO/IEC 27001 Lead Auditor Certification". https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27001
  3. 3.BSI Training. (2026). "ISO/IEC 27001 Information Security Management Lead Auditor Course". https://www.bsigroup.com/en-GB/training-courses/iso-27001-training-courses/
  4. 4.ISO. (2018). "ISO 19011:2018 Guidelines for auditing management systems". https://www.iso.org/standard/70017.html
  5. 5.ISO/IEC. (2024). "ISO/IEC 27006-1:2024 Requirements for bodies providing audit and certification of information security management systems". https://www.iso.org/standard/82908.html
  6. 6.High Table. (2026). "ISO 27001 Certification Cost Guide". https://hightable.io/iso-27001-certification-cost/
  7. 7.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html

Found this useful? Pass it on.

Certification, without the drag.

A process built for how modern teams actually work, run by tech-first auditors, and honest about what you do and don't need.