ISO 27001 certification cost: the real budget lines explained
How much does ISO 27001 certification cost? The only honest answer: it depends on your scope, and anyone quoting a firm price without examining it is misleading you. What can be pinned down precisely, however, are the budget lines — and understanding them is how you obtain comparable quotes and a realistic budget. Here is the full breakdown.
The certification audit itself
This is the most visible line. Certification bodies (AFNOR Certification, Bureau Veritas, LNE and others) bill by the number of auditor days. That number is not freely negotiable: the accreditation rules that govern ISMS certification bodies frame it according to the headcount in scope, the number of sites and the complexity of activities. That is why two serious quotes on the same scope propose similar day counts — and why an abnormally cheap quote should raise suspicion.
The initial audit runs in two stages (a readiness review, then the implementation audit), both billed. Travel expenses and certificate-management fees may be added according to each body’s price list.
Three levers act directly on this line:
- the scope: fewer sites and activities covered means fewer audit days;
- the headcount concerned: one of the main parameters in the calculation grids;
- competition: request at least three detailed quotes on a strictly identical scope, and compare days as much as totals.
The three-year cycle: surveillance and recertification
The certificate is valid for three years, subject to annual surveillance audits — shorter than the initial audit, but very real in the budget. At the end of the cycle, a fuller recertification audit restarts the three-year period. So think in whole-cycle cost rather than acquisition cost: that is how certification bodies structure their own offers, and it is the only honest basis for comparison. The mechanics are the same as for other management-system standards — our article on ISO 9001 surveillance and renewal walks through the cycle in detail.
Consulting: the most variable line
Many organisations bring in a consultant to structure the ISMS: framing, risk-assessment method, help drafting the statement of applicability, audit preparation. This line varies enormously with the breadth of the engagement — from a few days of targeted coaching to full support over several months.
Two rules to keep it under control. First, never outsource ownership: an ISMS written entirely by a consultant, which your teams do not know, shows at audit from the very first interviews. Second, weigh consulting against the in-house alternative: training your future security officer on the standard often costs less than a long engagement, and the competence stays in the company.
Internal cost: the largest line, and the most forgotten
The biggest budget item of an ISO 27001 project appears on no quote: your teams’ time. Project management, asset inventory, risk assessment, control deployment, documentation, awareness sessions, internal audit, management review — then the permanent operation of the system after certification. Depending on your starting maturity, this time runs to dozens of person-days in the first year.
Academic research confirms that this adoption cost genuinely weighs on the decision: the study by Mirtsch, Kinne and Blind published in 2021 in IEEE Transactions on Engineering Management, based on a large-scale analysis of ISO/IEC 27001-certified organisations, shows that compliance and certification costs rank among the main barriers to adopting the standard, particularly for smaller structures (see the study).
On top of this time come possible technical investments that the risk assessment may reveal as necessary: robust, tested backups, identity management, monitoring, encryption. They are not required “by the standard” in the abstract — they follow from your risks — but they are part of the project’s real cost.
Building a realistic budget
| Line | Nature | Recurrence |
|---|---|---|
| Initial audit (stages 1 and 2) | Auditor days + fees | Once per cycle |
| Surveillance | Auditor days | Annual |
| Recertification | Auditor days | Every 3 years |
| Consulting / training | Depends on engagement | One-off |
| Internal time | Project + ISMS operation | Permanent |
| Technical controls | Depends on risk assessment | Variable |
The winning reflex: settle the scope and headcount first, obtain three quotes from accredited certification bodies on that basis, then cost the internal time before deciding on the level of consulting. A budget built in that order holds no bad surprises. And before putting figures on anything, make sure you can see the whole journey: our guide to getting ISO 27001 certified step by step covers it from scoping to audit.
Take action
The cost of ISO 27001 can be steered: a well-set scope, quotes compared like-for-like, internal time budgeted from day one. Visit the ISO 27001 certification profile to frame the scheme — and download the free ebook there, which details every step of the project.
Frequently asked questions
+Why do ISO 27001 certification quotes vary so much?
Because the number of audit days depends on the headcount in scope, the number of sites and the complexity of activities, and each certification body applies its own daily rates. Even on an identical scope, real differences remain: always request several detailed quotes and compare the number of days proposed, not just the total.
+Can you reduce the cost by narrowing the ISMS scope?
Yes — a narrower scope means fewer audit days and less internal workload. But an artificially limited scope weakens the certificate's commercial value: your clients check what it actually covers. The right setting is to cover the activities your clients are asking you to secure.
+Does the cost stop once the certificate is issued?
No. The certificate is valid for three years with annual surveillance audits, then a fuller recertification audit. You must also budget the permanent internal time needed to run the ISMS: risk monitoring, internal audits, awareness sessions, incident handling.