
If your organisation is considering ISO 27001 certification, one of the first questions is likely to be: how much will it cost?
There is no single price that applies to every organisation. The cost of ISO 27001 certification depends on factors such as the size and complexity of the organisation, the scope of the Information Security Management System (ISMS), the number of sites involved and the audit time required.
Certification fees are typically calculated according to the number of audit days required. The audit time is influenced by factors including the number of employees and the scope of the ISMS.
Understanding these factors can help you plan your budget and provide the right information when requesting a quotation.
The number of people within the organisation is an important consideration when determining audit time.
However, ISO 27001 audit time is not simply a matter of applying a fixed price to the number of employees. The relevant personnel and activities within the scope of the ISMS need to be considered, alongside the characteristics of the organisation and its management system. ISO/IEC 27006-1:2024 identifies the people doing work under the organisation's control as a starting point for determining audit time.
This means two organisations with similar headcounts could still receive different certification quotations if their ISMS scopes, structures or operational arrangements differ.
The scope of your Information Security Management System is another major consideration.
A narrowly defined ISMS covering a specific service, business unit or location may require less audit effort than a scope covering multiple business functions, services, locations or information-processing activities.
The scope should therefore be clearly defined before seeking a quotation. It should reflect what your organisation needs to protect and what you want the certification to cover.
A clear scope can also make the certification process easier to understand internally and externally.
Multiple locations can affect the way audit time is determined.
For multi-site organisations, ISO/IEC 27006-1:2024 contains specific requirements for determining audit time. The total audit time generally considers the people doing work under the organisation's control irrespective of their location, while alternative approaches may apply where there are justified and documented reasons.
As a result, simply multiplying the cost of a single-site audit by the number of locations is not an appropriate way to estimate certification costs.
The complexity of the organisation and its information security arrangements can also influence audit effort.
Factors may include the nature of the services provided, the information and systems being protected, organisational structure, operational processes and the way information security responsibilities are managed.
The more complex the environment being assessed, the more carefully the certification body needs to determine the appropriate audit time.
Audit time is central to understanding certification fees.
ISO/IEC 27006-1:2024 sets additional requirements for bodies that audit and certify ISMS against ISO/IEC 27001. It complements ISO/IEC 17021-1 and is intended to support consistent, competent and impartial certification.
The standard also includes requirements relevant to determining audit time. UKAS highlights updated audit-time calculation requirements as one of the changes introduced by ISO/IEC 27006-1:2024.
The practical implication for businesses is straightforward: audit time should be determined from the characteristics of the organisation and its ISMS rather than assumed from a generic online price guide.
This is why a reputable certification body should ask for relevant information about your organisation, scope and operations before providing a quotation.
Understanding the certification cycle also helps put the cost into context.
The certification process consists of the following stages.
The Stage 1 audit reviews the design and documentation of your ISMS. This includes areas such as policies, risk assessments and security procedures.
The purpose is to establish whether the management system is sufficiently developed for the Stage 2 audit.
The Stage 2 audit examines how the ISMS has been implemented and whether it is operating effectively.
Auditors assess the organisation against the requirements of ISO/IEC 27001 and examine evidence that the management system and relevant controls are operating in practice.
If the requirements are met, the certification process proceeds to the certification decision.
ISO 27001 certification is maintained through ongoing surveillance.
Annual surveillance audits are conducted during Years 2 and 3 to check that the ISMS continues to meet the requirements of the standard and remains effective.
Surveillance audits are generally less extensive than the initial certification audit. They typically require significantly less time than the initial audit, with around one third of the initial audit duration given as a typical indication. This should be treated as an indication rather than a universal rule.
ISO 27001 certification operates on a three-year cycle, subject to successful surveillance audits.
At the end of the cycle, a recertification audit is carried out to assess whether the ISMS continues to meet the certification requirements.
The certification body's fee is only one part of the overall cost of achieving and maintaining ISO 27001.
Your organisation may also need to allocate internal resources to activities such as:
There may also be costs associated with technology, security controls, systems or other measures identified through your information security risk assessment.
Some organisations choose to engage an external consultant for assistance with the implementation of their ISMS. If you would benefit from expert support, TÜV UK can connect you with trusted consultants from our Partner Programme. Complete our consultant referral form today and we’ll help you find the right partner for your implementation needs.
These costs will vary considerably between organisations. They should not be confused with the certification body's fee.
ISO itself does not carry out certification or issue certificates. Certification is performed by independent certification bodies.
The objective should not be to minimise audit time at the expense of an effective certification process. Instead, organisations can focus on making the certification scope and management system clear and proportionate to their needs.
Useful steps include:
Good preparation can make the audit process more efficient while helping ensure that the ISMS is genuinely embedded within the organisation.
The most reliable way to establish the cost is to request a quotation from an accredited certification body based on your organisation's actual circumstances.
Be prepared to provide information such as:
This allows the certification body to determine the appropriate audit requirements and provide a quotation based on your specific circumstances.
Avoid relying solely on generic online price ranges. A figure that may be appropriate for one organisation could be misleading for another.
There is no meaningful single figure that applies to every UK organisation.
Instead, think about the cost in two parts:
These are the fees associated with the independent certification process, including the required audits and certification activities.
These are the resources your organisation invests in developing, operating and continually improving its ISMS.
Keeping these two categories separate gives decision-makers a much clearer view of the overall investment involved.
For a reliable estimate of certification costs, provide your certification body with accurate information about your organisation, proposed scope and operating arrangements.
TÜV UK provides independent, UKAS-accredited third-party certification for ISO/IEC 27001. If you are considering ISO 27001 certification, contact us today to discuss your requirements and request a tailored quotation.
TÜV UK Ltd
AMP House
Suites 27 - 29, Fifth Floor, Dingwall Road
Croydon, CR0 2LX
Tel.: +44 20 8680-7711
Enquiries.UK@tuv-nord.com