ISO 27001 cost calculator
One number decides most of this: how many people do work under your control inside the scope. Enter it and the audit days come straight out of the published rule. Everything else on this page adjusts around that.
1. The certification audit days are exact
- Table band for — people: — → — days
- Sites: —
- Complexity adjustment: —
2. Getting ready estimated
Roughly — consultant days of work at this size. The audit fee above is the same on all three routes — the day count does not care how you prepared.
| Route | Cost of getting ready | What is not in that figure |
|---|---|---|
| Documentation toolkit | — | Your own people’s time, which on this route is the largest cost |
| Consultant-led | — midpoint about — |
Your time in workshops and the decisions only you can make |
| Platform + support | — | The subscription. No major platform publishes a price |
3. Every year after that days are exact
In year three it is recertification instead: — days, two thirds of the initial audit. Add an internal audit each year as well — clause 9.2 requires one and your certification body is barred from doing it.
First three years, consultant-led
Your answers are carried into the enquiry below, so a consultancy sees the headcount, the sites and the day count before it replies.
Send this to consultanciesHow to read the output
- The day counts are exact. They are ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21), adjusted within the 30% the rule permits. Check a real quote against them.
- Every pound figure is an estimate and is shown as a range. The day rates behind them are named on the methodology page.
- The audit fee is identical on all three routes. The whole price difference between toolkit, consultant and platform is in getting ready.
- The platform figure excludes the subscription because no major platform publishes one. Over three years that missing line is often the largest.
Why the headcount matters more than anything else you could tell us
Most cost estimators in this market ask for a budget, a timeline and a sector, none of which changes the answer. The published rule does not mention any of them. It has one input — the number of people doing work under your control inside the scope — and a short list of complexity factors on top.
Everyone doing work under the organisation’s control within the scope, not everyone on the payroll. Part-time people count in proportion to the hours they work. Contractors and outsourced staff inside the scope count. People in a business unit that is genuinely outside the scope do not.
Which makes scope a cost decision as much as a commercial one. Certifying one product team of eighteen rather than the whole ninety-person company is not a trick; it is a legitimate, common scope, it costs materially less to audit, and it can be widened later. What it must not do is exclude something a customer assumes is covered, because the schedule on the certificate says exactly what was audited and procurement teams read it.
The same diagram as a table
| People in scope | Initial audit | Surveillance | Recertification |
|---|---|---|---|
| 1–10 | 5 | 1.67 | 3.33 |
| 11–15 | 6 | 2 | 4 |
| 16–25 | 7 | 2.33 | 4.67 |
| 26–45 | 8.5 | 2.83 | 5.67 |
| 46–65 | 10 | 3.33 | 6.67 |
| 66–85 | 11 | 3.67 | 7.33 |
| 86–125 | 12 | 4 | 8 |
| 126–175 | 13 | 4.33 | 8.67 |
| 176–275 | 14 | 4.67 | 9.33 |
| 276–425 | 15 | 5 | 10 |
| 426–625 | 16.5 | 5.5 | 11 |
Surveillance is one third of the initial audit and recertification is two thirds, in every row of the published table. The full 22 bands run to 10,700 people.
What the calculator does, step by step
- Look up the band. Your headcount finds one of the 22 rows in the published table, which gives the initial certification audit days.
- Apply the sites rule. Where several sites perform the same activity, the certification body samples them rather than visiting all of them, and the sample is the square root of the number of sites, rounded up. Sites doing genuinely different things are not sampled away.
- Apply the complexity adjustment. Five percentage points per factor, capped at 30% in either direction. The rule itself sets that ceiling and states that audit time is never cut by more than 30%.
- Derive the ongoing days. One third for each surveillance audit, two thirds for recertification.
- Apply a day-rate band to produce the money. This is the only estimated step in the audit column, and it is the reason the output is a range.
The five percentage points per factor is deliberately coarse. Published certification body scoring sheets work in steps of that size, and pretending to finer resolution than the people actually doing the pricing would be false precision.
We are paid a fixed fee per enquiry, set in advance. It does not change with the size of the number this calculator produces, with which route you choose, or with whether you go ahead. That is why the result appears before the form rather than behind it.
Three routes, at your size
The same diagram as a table
| Route | Low | High | What is in it |
|---|---|---|---|
| Toolkit | £95 | £1,500 | Your own people do the work |
| Consultant-led | £6,000 | £26,400 | 10–22 days bought in |
| Platform + help | £3,600 | £18,500 | Services only — no subscription |
All three then pay the same certification audit fee, because audit days are set by ISO/IEC 27006-1:2024 Table C.1 and not by how the management system was built.
The comparison is worth making carefully, because the two obvious places to look for it are both selling something. A toolkit vendor's comparison finds for the toolkit; a platform vendor's finds for the platform. The full comparison sets out what each route genuinely does well and what each one hides.
Checking a quote you already have
If you have been quoted, this page is most useful in reverse:
- Find the day count in the quote. If it is not stated, ask. It is the basis of the price and there is no reason for it to be confidential.
- Compare it to the table. It should sit within 30% of your band. Materially below that, and either the scope is not what you think it is or the reduction exceeds what the rule allows.
- Divide the fee by the days. That is the real day rate you are being charged, and it is a far better comparison between two certification bodies than the headline total.
- Ask for years two and three. Surveillance and recertification are rarely in the first quote and, taken together, exceed it.
Common questions
Where does the audit-day figure come from?
ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21), the rule that governs how long an ISMS certification audit takes. It has 22 headcount bands running from 1 person to 10,700, and accredited certification bodies work to it. This calculator looks your headcount up in that table, applies the multi-site sampling rule if you have more than one site, then applies the complexity adjustment, capped at the 30% the rule allows in either direction. That part of the output is exact. The money is not.
Why does it give me a range instead of a price?
Because a single number would be a false claim. No UK certification body publishes a day rate and no compliance platform publishes a subscription price, so the honest move is to take the day count, which is published, multiply by a rate band we name, and show the spread. If you have a real quote, you can divide it by the day count this page gives you and see what rate you are actually being charged — which is a more useful thing to know than our range.
Is this what a certification body will quote me?
The days, most likely yes, within the adjustment the rule allows. The money, not necessarily: rates vary, and application fees, certificate fees, annual registration charges and travel are commonly billed on top and are not day-rate items. Treat the day count as the thing to check a quote against, and the fee as an order of magnitude.
What counts as a person in scope?
Everyone doing work under the organisation’s control within the scope, not everyone on the payroll. Part-time people count in proportion to the hours they work. Contractors and outsourced staff inside the scope count. People in a business unit that is genuinely outside the scope do not. That is ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1. It is worth getting right before you ask for quotes, because it is the single input that moves the answer most.
Does the preparation figure include my own staff time?
No, and nothing you will be quoted does either. It is the consultant-day estimate only. On the toolkit route your own people's time is the dominant cost and it is genuinely difficult to price, so we do not pretend to. Treat the toolkit figure as an outlay, not as a total.
Why is the platform route cheaper here than a consultant, but with a warning?
Because the figure shown is the services only. A compliance platform removes evidence gathering, so the consultant time falls by roughly a third in our model — but it cannot decide your scope, write your risk treatment or hold your management review. The subscription is on top and no major platform publishes a price, so we cannot include a number we do not have. Over three years the subscription is frequently the largest single line, which is why it matters that it is missing.
Does using a cheaper consultant reduce the audit fee?
No. The audit-day count is a function of your headcount, sites and complexity. It is not a function of who prepared you or how much you paid them. Everyone pays the same for the audit, which is why the comparison between routes is only ever about preparation.
Sources cited on this page
- ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
- ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Send this estimate to consultancies
Your headcount, sites and day count travel with the enquiry, so the first reply is a real answer rather than a request for a call.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.