Skip to content

Resources/Cost/5 min read

Is ISO 27001 certification free?

The short answer

No. ISO 27001 certification requires an audit by an independent certification body, which costs at least £3,500 to £6,000 for the smallest company. The standard document itself costs about £120. You can implement the standard for free using your own time, but you cannot self-certify.

  • Gautham SenthilnathanCEO & Co-Founder

Last updated

No. There is no free ISO 27001 certificate, and anyone offering one is either selling a self-assessment badge that no procurement team will accept, or using "free" to mean "free trial of our software". The cheapest legitimate route is a micro company paying an accredited certification body £3,500 to £6,000 for the initial audit and doing all the implementation work in-house. Even the standard document isn't free: ISO/IEC 27001:2022 costs about CHF 130, roughly £120, from iso.org.

I get asked this a lot, usually by founders who have just been told by a prospect that they need "the ISO thing". So here is what is free, what isn't, and why.

Self-certification is not a thing

ISO 27001 certification means an independent, accredited body has audited your information security management system (ISMS) against the standard and issued a certificate saying it conforms. The independence is the whole point. A certificate you award yourself is a policy document with a logo on it. Under ISO/IEC 17021-1 [3], the rules certification bodies must follow, the body cannot even have helped you build the system it audits, because that would compromise impartiality. So there is a hard floor of at least one external party being paid.

You can, entirely legitimately, implement ISO 27001 without certifying. Plenty of companies do, and say "aligned with ISO 27001" on their security page. It is honest and it costs only your time. It just isn't certification, and enterprise buyers know the difference. For what the standard actually requires, see the requirements for ISO 27001.

Minimum spend

  • The audit. Accredited certification bodies (CBs) calculate audit days from IAF MD 5 [4]. For the smallest scope, that is roughly a one-day Stage 1 and a two-day Stage 2. At 2026 UK day rates of £1,250 to £1,800 [1], call it £3,500 to £6,000 for the initial certification, then a shorter surveillance audit each year.
  • The standard. £120 or so if you want the source text [5]. You can get by without buying it, because the clause and control lists are reproduced in every compliance platform and most CBs will walk you through them, but I'd buy it. It is 30 pages.

The free parts

  • Your own labour. The ISMS can be written by a founder over a few weekends. I have audited these and some were better than consultant-built ones, because they were short and the people understood them.
  • Policy templates. Plenty of decent free ones exist, and they make a reasonable starting point if you cut them down to what your company actually does.
  • Most of the technical controls, for a cloud-native company. SSO, MFA, device encryption, code review, logging: you likely have these already, and the 93 Annex A controls are largely asking you to prove it.
  • Free tiers of compliance platforms, for a while. Read the pricing page before you rely on one.

The leanest possible budget

ItemCost
Standard (ISO/IEC 27001:2022)~£120
ImplementationFounder time, 100-200 hours
Certification body, Stage 1 + Stage 2£3,500-£6,000
Year-one cash outlay~£3,600-£6,100

That is the floor. For the full range by company size, see how much ISO 27001 costs in the UK.

A free certificate would be worthless

The value of the certificate to the person asking you for it comes entirely from the fact that a stranger checked. The ISO Survey 2024 counted 96,709 valid certificates worldwide [2], every one issued after an accredited audit, with the UK alone holding 4,455 at end-2024 to rank fourth globally [2]. That shared trust is why a procurement officer in Frankfurt will accept a certificate from a body in Manchester without further questions; remove the audit and you remove the thing they are buying.

With 43% of UK businesses identifying a cyber breach or attack in the last twelve months [6], the question is less whether certification has a cost and more whether not having it does. The average UK data breach costs £3.13 million [7]. Against that, even the £6,000 ceiling for a micro company looks like a rounding error.

At Calibre the audit is what we do; we don't sell implementation and we don't sell templates, so there is no bundle to upsell you into. If you have built the ISMS yourself and want someone to check it in days rather than months, that is the conversation to have.

FAQ

Not legally. ISO and national bodies such as BSI sell the standard under copyright. Free PDFs online are unauthorised copies, often of the withdrawn 2013 version.

Occasionally, through regional growth hubs or innovation vouchers, but nothing national and nothing guaranteed. Cyber Essentials, a separate and much lighter scheme, has had funded support at times. Check your local growth hub.

Cyber Essentials costs £320 to £600 for the self-assessed version and is a good first step, but it covers five technical controls and is not a management system standard. It won't satisfy a customer asking for ISO 27001.

Sources

  1. 1.High Table. (2026). "ISO 27001 Certification Cost [2026 update]". https://hightable.io/iso-27001-certification-cost/
  2. 2.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html
  3. 3.ISO/IEC. (2015). "ISO/IEC 17021-1:2015 Conformity assessment - Requirements for bodies providing audit and certification of management systems". https://www.iso.org/standard/61651.html
  4. 4.International Accreditation Forum. (2023). "IAF MD 5:2023 Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems". https://iaf.nu/en/iaf-documents/
  5. 5.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements". https://www.iso.org/standard/27001
  6. 6.Department for Science, Innovation and Technology. (2026). "Cyber Security Breaches Survey 2025/2026". GOV.UK. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026
  7. 7.IBM Security and Ponemon Institute. (2026). "Cost of a Data Breach Report 2026". https://www.ibm.com/reports/data-breach

Found this useful? Pass it on.

Certification, without the drag.

A process built for how modern teams actually work, run by tech-first auditors, and honest about what you do and don't need.