iso27001partnersUK certification, costed Get a cost estimate

What ISO 27001 certification costs in the UK

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 11 min read
5 primary sources cited on this page. How we check what is on this site
The part nobody can quote you differently on 5 to 28 audit days

Your certification audit length is set by ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21), a published rule with 22 headcount bands that every accredited certification body works to. It is the whole table, below, and it is the reason half of this question has a precise answer.

Ask what ISO 27001 costs and you will be given a range so wide it tells you nothing — one published UK guide puts implementation anywhere between £500 and £40,000. Part of that spread is honest. But it obscures something useful: the cost splits into four parts, and two of them are set by a published rule and can be stated exactly.

Key points

  • Audit days are not negotiable in the way people assume. The rule allows adjustment of up to 30% either way for complexity and sites, and says audit time is never reduced by more than 30%.
  • Preparation is usually the bigger number, and it is the one with no published rule behind it. That is why everyone answers the cost question with a form.
  • The audit never stops. Surveillance is one third of the initial audit each year and recertification is two thirds in year three, so the three years after you certify cost more audit time than certifying did.
  • How you prepare does not change the audit fee. Toolkit, consultant or platform, the day count is the same, because it is a function of your headcount and complexity and nothing else.
  • Every pound figure on this page is our estimate, built on a day-rate band we name on the methodology page. The day counts are not.

The four parts

Where the money goes on an ISO 27001 certification Three horizontal ranges for a 25-person scope: the certification audit, consultant-led preparation, and the annual surveillance audit, with a combined three-year total underneath. Worked example: 25 people in scope, one site, no adjustments Certification audit 7 days, from the published table £7,700–£10,500 Preparation, consultant-led 10–22 consultant days £6,000–£26,400 Surveillance, per year 2.33 days, one third of the initial audit £2,550–£3,500 First three years, all in £18,800 to £43,900  ·  midpoint about £31,350 Certification audit + preparation + two surveillance years. Day counts exact; money estimated.
The audit is rarely the biggest number. Preparation is, and preparation is the part with no published rule behind it — which is exactly why every site in this market asks you to ring them about it.
The same diagram as a table
Cost parts for 25 people in scope, one site, no adjusting factors
PartLowHighBasis
Certification audit£7,700£10,5007 days, from the published table
Preparation, consultant-led£6,000£26,40010–22 consultant days
Surveillance, per year£2,550£3,5002.33 days, one third of the initial audit
First three years£18,800£43,900 Audit + preparation + two surveillance years

Day counts come from ISO/IEC 27006-1:2024 Table C.1 and are exact. The money is our estimate built on a day-rate band, rendered as a range and never as a single figure.

Part 1 — the certification audit (exact days, estimated rate)

Stage 1 and Stage 2 together. Find your headcount in the table below, apply any adjustment, and multiply by a day rate. We use a band of £1100 to £1500 per day; the midpoint is what the only UK guide publishing a cost table implies.

Part 2 — getting ready (estimated)

Scope, risk assessment, risk treatment, the Statement of Applicability, the documented information, an internal audit and a management review, plus whatever Annex A treatment your risk assessment produced. No rule sets this. It is the whole reason the three delivery routes have different prices, and it is covered in toolkit, consultant or platform.

Part 3 — annual surveillance (exact days, estimated rate)

One third of the initial audit, every year, for as long as you hold the certificate. In year three it becomes recertification at two thirds.

Part 4 — your own people (not priced here, and usually underestimated)

Somebody in your organisation has to make decisions a consultant cannot make for you: what is in scope, what your risk appetite is, who owns each control, and what the management review concludes. On the toolkit route this is the dominant cost and nobody puts a number on it.

The audit-day table, in full

This is ISO/IEC 27006-1:2024 Table C.1, all 22 bands, with our fee band applied. Certification bodies work from this table; it is not a marketing estimate and it is not ours. The surveillance and recertification columns are derived from the initial column at one third and two thirds, and we check that arithmetic against every row on each build rather than trusting it.

ISO/IEC 27006-1:2024 Table C.1, priced. Days are exact; fees are estimates.
People in scopeInitial audit daysSurveillance daysRecertification daysCertification audit feeEach surveillance audit
1–1051.673.33£5,500–£7,500£1,850–£2,500
11–15624£6,600–£9,000£2,200–£3,000
16–2572.334.67£7,700–£10,500£2,550–£3,500
26–458.52.835.67£9,350–£12,750£3,100–£4,250
46–65103.336.67£11,000–£15,000£3,650–£5,000
66–85113.677.33£12,100–£16,500£4,050–£5,500
86–1251248£13,200–£18,000£4,400–£6,000
126–175134.338.67£14,300–£19,500£4,750–£6,500
176–275144.679.33£15,400–£21,000£5,150–£7,000
276–42515510£16,500–£22,500£5,500–£7,500
426–62516.55.511£18,150–£24,750£6,050–£8,250
626–87517.55.8311.67£19,250–£26,250£6,400–£8,750
876–1,17518.56.1712.33£20,350–£27,750£6,800–£9,250
1,176–1,55019.56.513£21,450–£29,250£7,150–£9,750
1,551–2,02521714£23,100–£31,500£7,700–£10,500
2,026–2,675227.3314.67£24,200–£33,000£8,050–£11,000
2,676–3,450237.6715.33£25,300–£34,500£8,450–£11,500
3,451–4,35024816£26,400–£36,000£8,800–£12,000
4,351–5,450258.3316.67£27,500–£37,500£9,150–£12,500
5,451–6,800268.6717.33£28,600–£39,000£9,550–£13,000
6,801–8,50027918£29,700–£40,500£9,900–£13,500
8,501–10,700289.3318.67£30,800–£42,000£10,250–£14,000

Above 10,700 people the published table stops and says the sequence continues; the certification body extends it. Fees assume £1100–£1500 per day and exclude VAT, travel and any application or certificate charge.

Audit days by number of people in scope Bar chart of the published audit-day table. Initial certification audit days rise in steps from 5 days at 1 to 10 people to 16.5 days at 426 to 625 people. A shorter bar in each band shows the annual surveillance audit at one third of the initial figure. 0 3 6 9 12 15 18 days 5 1–10 6 11–15 7 16–25 8.5 26–45 10 46–65 11 66–85 12 86–125 13 126–175 14 176–275 15 276–425 16.5 426–625 people doing work under your control, inside the scope Initial certification audit (Stage 1 + Stage 2)Each annual surveillance audit
The table is a step function, not a line. Taking on one more person can move you a whole band and add half a day of audit; nothing in a quoted price makes that visible, which is why the table is here in full.
The same diagram as a table
ISO/IEC 27006-1:2024 Table C.1, first 11 of 22 bands. Audit days.
People in scopeInitial auditSurveillance Recertification
1–1051.673.33
11–15624
16–2572.334.67
26–458.52.835.67
46–65103.336.67
66–85113.677.33
86–1251248
126–175134.338.67
176–275144.679.33
276–42515510
426–62516.55.511

Surveillance is one third of the initial audit and recertification is two thirds, in every row of the published table. The full 22 bands run to 10,700 people.

What moves you up or down within the band

The table is a starting point, not a final answer. The rule lets a certification body adjust it for how complicated your scope genuinely is — but it caps the adjustment at 30% and states that time is never cut by more than 30%, which is the sentence to remember if a discount sounds too good.

Factors that move the day count, from the same published rule
FactorEffectWhy
Multiple sites in scope↑ more daysEach additional site adds audit time, subject to the square-root sampling rule.
Complex or numerous IT platforms↑ more daysSeveral different platforms, networks and operating systems inside one scope.
Heavy reliance on outsourcing and cloud suppliers↑ more daysThe more of the scope that somebody else runs, the more supplier controls there are to test.
Significant in-house software development↑ more daysSecure development controls have to be audited where development happens.
High-availability and disaster recovery sites↑ more daysAlternate data centres are part of the scope and are audited as such.
A management system that has been running for years↓ fewer daysA mature, evidenced ISMS is quicker to audit than one that was stood up last quarter.
Most staff performing the same activity↓ fewer daysRepetitive, low-variation work can be sampled.
A single site and a simple IT estate↓ fewer daysLess ground to cover.

Multiple sites are handled separately. Where several sites perform the same activity, the certification body samples them rather than visiting all of them, and the sample is the square root of the number of sites, rounded up. Sites doing genuinely different things are not sampled away. That is ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1, and it is why a four-site company is not four times the audit.

Worked examples

Single site, no adjusting factors, consultant-led preparation. The three-year column is the one worth comparing between certification bodies, because it is the one a headline quote leaves out.

Four sizes, end to end. Day counts exact; money estimated.
PeopleBandAudit daysCertification auditPreparation (consultant-led)Surveillance, per yearFirst three years
101–105 days£5,500 to £7,500£3,600 to £16,800£1,850 to £2,500£12,800 to £29,300
2516–257 days£7,700 to £10,500£6,000 to £26,400£2,550 to £3,500£18,800 to £43,900
6046–6510 days£11,000 to £15,000£12,000 to £54,000£3,650 to £5,000£30,300 to £79,000
150126–17513 days£14,300 to £19,500£18,000 to £78,000£4,750 to £6,500£41,800 to £110,500

Run it for your own headcount

Our fee is a fixed amount per enquiry, agreed before anyone sends one. It does not move with the size of your engagement or with which consultancy receives it, which is why this page can tell you that a narrower scope is cheaper, that preparation is where the saving is, and that some readers should buy Cyber Essentials instead.

The five costs that arrive after the quote

1. The internal audit, every year, from somebody else

Clause 9.2 requires internal audits at planned intervals, and you cannot sit Stage 2 without having run one. Your certification body cannot do it for you: BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.6 bars a certification body from providing internal audits to its certified clients, and says doing so locks it out of certifying that management system for 2 years. So this is a separate purchase, or a genuinely independent internal resource, every year for as long as you are certified.

2. Surveillance, which is permanent

The quote you are shown is usually for the initial certification audit. Add one third of it in year one, the same in year two, and two thirds in year three. Taken together, the three years after certification contain more audit time than the certification itself.

3. Fees that are not audit days

Application fees, certificate issue fees and annual registration or licence charges are common and are not day-rate items, so they sit outside any calculation based on the table — including ours. Ask for the full schedule of charges, not the audit quote.

4. The follow-up visit after a major nonconformity

A major nonconformity at Stage 2 has to be closed before a certificate is issued, and closing it often needs the auditor to come back. That visit is chargeable and is not in anyone's original quote. It is the one real financial argument for preparing properly, and it is a probability rather than a certainty.

5. Scope changes

Adding a site, an acquisition or a new product line inside the scope re-runs the day calculation, including the multi-site sampling rule. A scope drawn to flatter a sales cycle is a scope you pay for again later.

Before you spend anything: is it ISO 27001 you need?

If a customer has asked for “security certification” without naming a standard, it is worth establishing which one before committing to the larger of the two. Cyber Essentials is a UK government-backed scheme with published fees and a verified self-assessment against five technical control areas.

Cyber Essentials self-assessment fees, by organisation size (excluding VAT)
SizeEmployeesFee
Micro0–9 employees£320
Small10–49 employees£440
Medium50–249 employees£500
Large250 or more employees£600

Published scheme fees, read 20 September 2026. Cyber Essentials Plus adds a technical audit and is priced separately by the assessment body. These are the certification fees only and exclude any help you buy to get through it.

Cyber Essentials is not a substitute where a contract names ISO 27001, and it is not a management system: it does not ask you to assess risk, set objectives or review anything. But it answers a real question for a fraction of the money, and for a ten-person company being asked for reassurance rather than for a specific certificate, it is frequently the proportionate answer.

Common questions

What is the cheapest ISO 27001 certification can be?

The audit has a floor. The smallest band in the published table is 5 days for 1 to 10 people, and audit time cannot be cut by more than 30% for any reason, so roughly £3,850 of audit is the realistic floor at UK day rates however the discount is presented. Preparation is where the genuine saving is: a documentation toolkit plus your own people's time can be a few hundred pounds of outlay, at the cost of a lot of internal effort. What you cannot do is buy a meaningfully cheaper audit, and an unusually cheap certificate is usually a sign that it is not accredited.

Why do two quotes for the same company differ so much?

Check the day count first. Both quotes should reconcile to the same band in ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21), adjusted within 30% for your sites and complexity. If one quote has materially fewer days than the other for the same scope, either the scopes are not the same or the reduction exceeds what the rule allows. After that, check what is excluded: travel and expenses, application and certificate fees, and any annual registration charge are frequently billed on top of the day rate and left out of a headline number.

Is the surveillance audit included in the price I was quoted?

Usually not, and this is the single most common surprise. The published rule sets each annual surveillance audit at one third of the initial audit and recertification at two thirds. Over the three years after certification that adds up to more audit time than the initial certification audit itself. A three-year figure is the only honest way to compare two certification bodies, and it is worth asking for one in writing.

Does the number of employees mean everybody on the payroll?

No. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1 counts everyone doing work under the organisation's control inside the certified scope. Part-time people count in proportion to the hours they work; contractors and outsourced staff working inside the scope count; people in a business unit genuinely outside the scope do not. This is why scope is a cost decision as well as a commercial one, and why a narrower first certification is often the right call.

Can I reduce the audit cost by being well prepared?

Not much, and this surprises people. The day count comes from your headcount and complexity, not from how tidy your evidence is. Good preparation changes the probability that Stage 2 produces a major nonconformity and a chargeable follow-up visit, and it changes how much of your own staff time the audit consumes. It does not move you down a band. What does move the count is a genuinely narrower scope, a simpler estate, or an ISMS that has been running for years rather than months.

Are toolkit, consultant and platform routes all the same price at audit?

Yes, exactly the same, and that is worth knowing before anyone quotes you. The audit-day count is a function of your headcount, sites and complexity. It is not a function of how you built the management system. So the whole of the price difference between the three routes sits in preparation, which is the part with no published rule behind it.

What about VAT?

Every figure on this page is shown before VAT, because that is how certification bodies and consultancies quote. Add 20% for the cash figure if your organisation cannot recover it.

Should we do Cyber Essentials first?

Often, yes — and this is advice against spending money, which is worth noticing on a site paid for by consultancies. Cyber Essentials is a verified self-assessment with a published fee of £320 to £600 plus VAT depending on size, against five technical control areas. If what your customer actually asked for is evidence of basic security hygiene, it may be the proportionate answer, and it is a reasonable stepping stone. If the requirement names ISO 27001 specifically, or the contract is with a large enterprise or the public sector, it will not substitute.

Sources cited on this page

  1. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
  2. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
  3. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  4. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
  5. IASME, Cyber Essentials certification fees

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Get this costed against your actual scope

Five click-only questions. Consultancies see the headcount and sector before they reply, so the first answer is a real one.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now