ISO 27001 feels expensive because the audit price is locked to a formula you cannot negotiate, the people qualified to run that audit are in short supply, and the implementation work before the audit is usually two to three times bigger than it needs to be. A small UK tech company should expect to spend £8,000 to £20,000 all-in for the first year [1][2]. Of those three cost drivers, only the last is within your control, and it is the largest number on most budgets.
We audit for a living, so we will take the certification body's side first and then tell you where the fat actually is.
The accreditation chain
Understanding why the price floor exists means understanding how the trust chain works. The International Accreditation Forum (IAF) sets the rules globally. In the UK, the United Kingdom Accreditation Service (UKAS) is the national accreditation body. UKAS assesses and accredits the certification body (CB), the organisation that actually audits you and issues the certificate. That is three layers of oversight before an auditor walks into your office.
Every layer costs money. UKAS charges certification bodies annual fees and runs witness audits where a UKAS assessor sits behind your auditor and watches them work. The certification body carries professional indemnity insurance, employs a technical review team to check audit reports, and maintains its own quality management system under ISO/IEC 17021-1 [3]. All of that is priced into your audit fee, and it is the reason a UKAS certificate is accepted by procurement teams worldwide while a non-accredited one is not.
The audit is priced by rulebook
Every accredited certification body works to IAF MD 5, the IAF's document on audit duration [4]. Feed in your headcount, number of sites and complexity, and it produces a minimum number of auditor days. A body that quotes below that number risks its accreditation, which is the thing that makes its certificate worth having. So when three UKAS bodies quote you 5, 5 and 6 days, that is not a cartel; it is the table.
Then there is the day rate. UK market guides for 2026 put a UKAS-accredited ISO 27001 auditor at £1,250 to £1,800 a day, up roughly 20% on the year before [1][2]. The reasons are a shortage of auditors qualified on the 2022 revision and the bulge of transition work before the 31 October 2025 deadline, after which every 2013 certificate became void. Auditors need five or more years of information security experience plus a lead auditor qualification plus witnessed audits before a body can put them in front of a client. Not many people fit that profile, and the ones who do can earn more consulting.
Multiply 5 days by £1,400 and add a certificate fee and you are at about £7,500 for the initial audit of a small company. That is the part we think is fair value.
Buying the standard
A small but irritating cost: the ISO/IEC 27001:2022 document costs about CHF 129 from iso.org, roughly £115 to £125, and the BSI edition is similar [5]. You cannot legally photocopy it. ISO 27002:2022, the companion guidance for implementing the 93 Annex A controls, is a separate purchase at roughly the same price. Most compliance platforms include the clause and control lists in their tooling, but if you want the actual normative text, you pay. For a standard that governs a global industry, this is an oddity we have never quite got comfortable with.
Implementation costs
A 20-person SaaS company needs, in our experience, about 12 to 15 documents and a risk register with a few dozen rows. What we frequently see arrive at Stage 1 is 60 policies, a 400-line risk register and a Statement of Applicability (SoA) that has been copy-pasted from a template listing controls for a data centre the company does not own. Someone paid a consultant to produce that, and now they will pay us to read it, and then pay someone to maintain it every year.
The three cost multipliers:
- Over-scoping. Clause 4.3 lets you define the scope. Certify the product and the teams that touch customer data. Do not certify the marketing department's laptops unless a customer has asked you to.
- Over-documenting. The standard mandates a short list of documents (see the mandatory documents for ISO 27001). Everything beyond that is a choice, and every extra page is an audit question.
- Buying the wrong help. A consultant who bills by the deliverable is incentivised to produce deliverables. A compliance platform is a fine investment if you will use the integrations; it is a £10,000 folder if you will not.
Recent price increases
Two things have pushed the price higher. The 2022 revision added 11 controls, including threat intelligence (5.7), cloud services (5.23), data leakage prevention (8.12) and monitoring activities (8.16), and each needs a real answer, not a paragraph. And enterprise buyers have got more demanding: the government's Cyber Security Breaches Survey 2025/2026 reports that 43% of UK businesses identified a breach or attack in the year [6], and supply-chain breaches added an average of £241,620 to UK incident costs in IBM's 2025 report [7]. Your customers' security teams are reading your SoA properly now. That pushes companies to build better systems, which costs more than building a paper one.
The ROI
IBM's 2026 Cost of a Data Breach report puts the average UK breach at £3.13 million [7], and even the 2025 figure was £3.29 million; organisations using security AI and automation extensively paid £3.11 million on average versus £3.78 million without [7]. An ISO 27001 programme is not a guarantee against breaches (it is an MOT, not an armoured car), but it forces a risk assessment methodology, access controls, incident response procedures and monitoring that most companies would not build on their own. Set against a seven-figure breach cost, a five-figure certification spend is not expensive — it is the cheapest structured way to find out where your gaps are before a breach does it for you.
Cost reduction
- Scope tightly and write the scope statement before anything else.
- Reuse what you have. Your engineering practices are most of the 93 Annex A controls already; the job is evidence, not reinvention.
- Get three-year quotes from certification bodies and compare the total, not year one. Surveillance audits in years two and three are shorter, but they are not free.
- Pick a body that does not add weeks of committee time. At Calibre the scoping call takes an hour and the certification decision follows Stage 2 in days, which cuts the hidden cost of deals stalled in procurement while you wait.
- Budget the surveillance years. The initial certificate is about half the three-year spend.
For actual figures by company size, see how much ISO 27001 costs in the UK.
FAQ
Not below the IAF MD 5 minimum without documented justification. They can reduce days for low complexity (single site, cloud-only, no in-house development) and will if you give them the information upfront.
Year one is similar. Over three years ISO is usually cheaper because surveillance audits are short, while a SOC 2 Type II is a full re-examination every year. See ISO 27001 vs SOC 2.
Headcount growth, added sites, or the day-rate rise. Ask the body to show you the MD 5 calculation for the new scope so you can see which input changed.
No. Certification body fees cover the audit and certificate. The ISO/IEC 27001:2022 document is roughly £115 to £125 from iso.org or BSI, and you need it (or access to it through a platform) to build your ISMS [5].
Sources
- 1.High Table. (2026). "ISO 27001 Certification Cost [2026 update]". https://hightable.io/iso-27001-certification-cost/
- 2.Iseo Blue. (2026). "ISO 27001 Certification Cost UK 2026". https://iseoblue.com/iso-27001/certification-guides/certification-costs/
- 3.ISO/IEC. (2015). "ISO/IEC 17021-1:2015 Conformity assessment - Requirements for bodies providing audit and certification of management systems". https://www.iso.org/standard/61651.html
- 4.International Accreditation Forum. (2023). "IAF MD 5:2023 Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems". https://iaf.nu/en/iaf-documents/
- 5.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements". https://www.iso.org/standard/27001
- 6.Department for Science, Innovation and Technology. (2026). "Cyber Security Breaches Survey 2025/2026". GOV.UK. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026
- 7.IBM Security and Ponemon Institute. (2025). "Cost of a Data Breach Report 2025". https://www.ibm.com/reports/data-breach

