HDS certification cost: the real budget lines to plan for
How much does French HDS certification cost? Fair question, honest answer: there is no regulated price and no public scale, and any figure quoted without studying your perimeter is guesswork. What can be budgeted very precisely, however, are the cost lines — they are known, stable, and you can price them through quotes. Here is the full structure of an HDS budget, and the levers that bring it down.
Why there is no “price of HDS certification”
Certification is issued by accredited bodies (accredited by COFRAC, the French accreditation committee, or an equivalent European accreditor), which set their fees freely. The quote depends mechanically on the perimeter: the “physical infrastructure host” certificate (physical sites and hardware infrastructure activities), the “managed-services host” certificate (virtual infrastructure, application platform, administration and operation, backup), or both; the number of sites; the size and complexity of the information system. Two candidates can receive very different quotes for the same list of activities simply because their architectures have nothing in common.
Practical consequence: always compare several certifiers on a strictly identical perimeter — same list of activities, same sites, same system description. That is the only comparison that means anything.
Line 1 — Audits, across the full three-year cycle
The HDS certificate is valid for three years. Audit costs therefore go beyond the initial audit:
| Moment | Service | Frequency |
|---|---|---|
| Year 1 | Certification audit (documentation + on-site) | Once |
| Years 2 and 3 | Surveillance audits | Annual |
| At the 3-year mark | Renewal audit | Every cycle |
Budget the full cycle, not the first year: quotes only compare meaningfully over three years. Also plan for the unfavourable scenario: non-conformities left uncorrected past the three-month window force a repeat of the on-site audit, at your expense. A well-run mock audit always costs less than a repeated one.
Line 2 — Compliance work: the real dominant cost
In most projects, the bulk of the budget is not with the certifier: it sits in the internal programme. The framework, published by the ANS (the French digital-health agency), combines an ISO 27001 base — a complete information-security management system — with health-specific requirements. Depending on your starting point, that covers:
- building or upgrading the ISMS: risk analysis, policies, procedures, continuity planning;
- technical investment: access control, encryption, logging, monitoring, physical security where relevant;
- contract rework: the framework imposes specific clauses in your client contracts — a legal workstream that is regularly underestimated;
- team time, the invisible but very real line: the ISMS mobilises management, IT, legal and sales;
- external support where needed (consulting, mock audit), useful if you lack in-house security-management skills.
The academic literature on ISO 27001 confirms this cost structure: the systematic review by Culot and co-authors, published in 2021 in The TQM Journal, finds that the implementation effort — internal resources, expertise, upkeep over time — is the main investment, well ahead of certification fees themselves (see the study). The same reasoning applies to the HDS framework, which incorporates that base. We detail the budget mechanics of the base in our article on the cost of ISO 27001 certification.
Line 3 — Upkeep over time
The certificate is not a one-off purchase: it is a subscription to a level of rigour. Between audits, the system must keep running — management reviews, internal audits, incident handling, monitoring of the framework itself (revised in 2024, with new EEA-localisation and transparency requirements: see what the 2024 framework changes). Build this recurring cost into your pricing: certified hosts structurally price this level of rigour into their business model.
The levers that genuinely cut the bill
- Capitalise on an existing ISO 27001 certification. The most powerful lever: with a shared base, a valid certification on the right perimeter concentrates the residual effort on health-specific requirements.
- Tighten the perimeter. Certify only the activities you actually perform; delegate the rest to already-certified subcontractors. Every added activity and site is paid for at audit — but beware of excluding an activity you do operate in-house, which would leave you unlawful on it (who must be certified, activity by activity).
- Put certifiers in competition. Several accredited bodies operate on this market: quotes on an identical perimeter reveal real gaps, on price and on lead times.
- Invest in a mock audit. Securing the passage avoids the most galling extra cost: repeating the on-site audit for want of correcting non-conformities within three months.
Think in terms of return on investment
The right frame is not “what does the certificate cost” but “what is market access worth”. Hosting health data on behalf of third parties is closed to the uncertified: without the certificate there is no lawful offer, and your prospects — themselves required to choose certified hosts — will check your presence on the ANS public list. The HDS budget should be weighed against the revenue of the market it opens, and against the far higher cost of a security incident involving health data.
Take action
Set your perimeter, gather comparable quotes and price the internal programme before committing: compliance work, not the audit, will make your budget. The HDS certification page gives you the full picture of the scheme, and the free ebook that comes with it includes the complete method, from framing to renewal.
Frequently asked questions
+Is there an official price for HDS certification?
No. Accredited certification bodies set their prices freely, based on the perimeter to audit: certificate types (physical infrastructure, managed services), number of activities, number of sites, system complexity. The only reliable method is to request several quotes on a strictly identical perimeter.
+Is the audit the main expense?
Rarely. In most projects the dominant line is compliance work: building or upgrading the information-security management system, technical measures, reworking client contracts, team time. The audit and annual surveillance matter, but weigh less than the internal programme.
+Can costs be reduced if you already hold ISO 27001?
Yes, and it is the most effective lever: the HDS framework builds on the ISO 27001 base, and a valid certification on a relevant perimeter can be taken into account by the certifier. The residual effort then concentrates on the requirements specific to health-data hosting.