iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 cost calculator

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 6 min read
4 primary sources cited on this page. How we check what is on this site

One number decides most of this: how many people do work under your control inside the scope. Enter it and the audit days come straight out of the published rule. Everything else on this page adjusts around that.

Not your whole payroll. Part-time people count in proportion to hours worked; contractors inside the scope count. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1.
Where sites do the same thing they are sampled, not all visited: the sample is the square root of the number of sites, rounded up. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1.
Anything that makes your scope harder or easier to audit Each one moves the day count by five percentage points. The rule caps the total adjustment at 30% in either direction and says audit time is never reduced by more than 30%, so the calculator will not go past that however many boxes you tick.

How to read the output

  • The day counts are exact. They are ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21), adjusted within the 30% the rule permits. Check a real quote against them.
  • Every pound figure is an estimate and is shown as a range. The day rates behind them are named on the methodology page.
  • The audit fee is identical on all three routes. The whole price difference between toolkit, consultant and platform is in getting ready.
  • The platform figure excludes the subscription because no major platform publishes one. Over three years that missing line is often the largest.

Why the headcount matters more than anything else you could tell us

Most cost estimators in this market ask for a budget, a timeline and a sector, none of which changes the answer. The published rule does not mention any of them. It has one input — the number of people doing work under your control inside the scope — and a short list of complexity factors on top.

Everyone doing work under the organisation’s control within the scope, not everyone on the payroll. Part-time people count in proportion to the hours they work. Contractors and outsourced staff inside the scope count. People in a business unit that is genuinely outside the scope do not.

Which makes scope a cost decision as much as a commercial one. Certifying one product team of eighteen rather than the whole ninety-person company is not a trick; it is a legitimate, common scope, it costs materially less to audit, and it can be widened later. What it must not do is exclude something a customer assumes is covered, because the schedule on the certificate says exactly what was audited and procurement teams read it.

Audit days by number of people in scope Bar chart of the published audit-day table. Initial certification audit days rise in steps from 5 days at 1 to 10 people to 16.5 days at 426 to 625 people. A shorter bar in each band shows the annual surveillance audit at one third of the initial figure. 0 3 6 9 12 15 18 days 5 1–10 6 11–15 7 16–25 8.5 26–45 10 46–65 11 66–85 12 86–125 13 126–175 14 176–275 15 276–425 16.5 426–625 people doing work under your control, inside the scope Initial certification audit (Stage 1 + Stage 2)Each annual surveillance audit
The table is a step function, not a line. Taking on one more person can move you a whole band and add half a day of audit; nothing in a quoted price makes that visible, which is why the table is here in full.
The same diagram as a table
ISO/IEC 27006-1:2024 Table C.1, first 11 of 22 bands. Audit days.
People in scopeInitial auditSurveillance Recertification
1–1051.673.33
11–15624
16–2572.334.67
26–458.52.835.67
46–65103.336.67
66–85113.677.33
86–1251248
126–175134.338.67
176–275144.679.33
276–42515510
426–62516.55.511

Surveillance is one third of the initial audit and recertification is two thirds, in every row of the published table. The full 22 bands run to 10,700 people.

What the calculator does, step by step

  1. Look up the band. Your headcount finds one of the 22 rows in the published table, which gives the initial certification audit days.
  2. Apply the sites rule. Where several sites perform the same activity, the certification body samples them rather than visiting all of them, and the sample is the square root of the number of sites, rounded up. Sites doing genuinely different things are not sampled away.
  3. Apply the complexity adjustment. Five percentage points per factor, capped at 30% in either direction. The rule itself sets that ceiling and states that audit time is never cut by more than 30%.
  4. Derive the ongoing days. One third for each surveillance audit, two thirds for recertification.
  5. Apply a day-rate band to produce the money. This is the only estimated step in the audit column, and it is the reason the output is a range.

The five percentage points per factor is deliberately coarse. Published certification body scoring sheets work in steps of that size, and pretending to finer resolution than the people actually doing the pricing would be false precision.

We are paid a fixed fee per enquiry, set in advance. It does not change with the size of the number this calculator produces, with which route you choose, or with whether you go ahead. That is why the result appears before the form rather than behind it.

Three routes, at your size

Three ways to prepare for ISO 27001, priced side by side Three horizontal cost ranges: a documentation toolkit, a consultant-led engagement, and a compliance platform with support services. A note records that the toolkit route hides your own staff time and the platform route hides an unpublished subscription. Getting ready: three routes, 25 people in scope The certification audit itself is the same price on all three routes — £7,700 to £10,500 — because the day count is set by the table, not by how you prepared. Toolkit Your own people do the work £95–£1,500 Consultant-led 10–22 days bought in £6,000–£26,400 Platform + help Services only — no subscription £3,600–£18,500 What the bars do not show Toolkit: your own people’s time, which is the largest cost on that route and the one nobody prices. Platform: the subscription. No major compliance platform publishes a price, so this figure is the services only.
Whichever route you take, the certification audit costs the same. The day count comes from the published table and no amount of preparation changes it.
The same diagram as a table
Preparation cost by route, 25 people in scope. Estimates.
RouteLowHighWhat is in it
Toolkit£95£1,500Your own people do the work
Consultant-led£6,000£26,40010–22 days bought in
Platform + help£3,600£18,500Services only — no subscription

All three then pay the same certification audit fee, because audit days are set by ISO/IEC 27006-1:2024 Table C.1 and not by how the management system was built.

The comparison is worth making carefully, because the two obvious places to look for it are both selling something. A toolkit vendor's comparison finds for the toolkit; a platform vendor's finds for the platform. The full comparison sets out what each route genuinely does well and what each one hides.

Checking a quote you already have

If you have been quoted, this page is most useful in reverse:

  1. Find the day count in the quote. If it is not stated, ask. It is the basis of the price and there is no reason for it to be confidential.
  2. Compare it to the table. It should sit within 30% of your band. Materially below that, and either the scope is not what you think it is or the reduction exceeds what the rule allows.
  3. Divide the fee by the days. That is the real day rate you are being charged, and it is a far better comparison between two certification bodies than the headline total.
  4. Ask for years two and three. Surveillance and recertification are rarely in the first quote and, taken together, exceed it.

Common questions

Where does the audit-day figure come from?

ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21), the rule that governs how long an ISMS certification audit takes. It has 22 headcount bands running from 1 person to 10,700, and accredited certification bodies work to it. This calculator looks your headcount up in that table, applies the multi-site sampling rule if you have more than one site, then applies the complexity adjustment, capped at the 30% the rule allows in either direction. That part of the output is exact. The money is not.

Why does it give me a range instead of a price?

Because a single number would be a false claim. No UK certification body publishes a day rate and no compliance platform publishes a subscription price, so the honest move is to take the day count, which is published, multiply by a rate band we name, and show the spread. If you have a real quote, you can divide it by the day count this page gives you and see what rate you are actually being charged — which is a more useful thing to know than our range.

Is this what a certification body will quote me?

The days, most likely yes, within the adjustment the rule allows. The money, not necessarily: rates vary, and application fees, certificate fees, annual registration charges and travel are commonly billed on top and are not day-rate items. Treat the day count as the thing to check a quote against, and the fee as an order of magnitude.

What counts as a person in scope?

Everyone doing work under the organisation’s control within the scope, not everyone on the payroll. Part-time people count in proportion to the hours they work. Contractors and outsourced staff inside the scope count. People in a business unit that is genuinely outside the scope do not. That is ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1. It is worth getting right before you ask for quotes, because it is the single input that moves the answer most.

Does the preparation figure include my own staff time?

No, and nothing you will be quoted does either. It is the consultant-day estimate only. On the toolkit route your own people's time is the dominant cost and it is genuinely difficult to price, so we do not pretend to. Treat the toolkit figure as an outlay, not as a total.

Why is the platform route cheaper here than a consultant, but with a warning?

Because the figure shown is the services only. A compliance platform removes evidence gathering, so the consultant time falls by roughly a third in our model — but it cannot decide your scope, write your risk treatment or hold your management review. The subscription is on top and no major platform publishes a price, so we cannot include a number we do not have. Over three years the subscription is frequently the largest single line, which is why it matters that it is missing.

Does using a cheaper consultant reduce the audit fee?

No. The audit-day count is a function of your headcount, sites and complexity. It is not a function of who prepared you or how much you paid them. Everyone pays the same for the audit, which is why the comparison between routes is only ever about preparation.

Sources cited on this page

  1. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
  2. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
  3. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  4. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Send this estimate to consultancies

Your headcount, sites and day count travel with the enquiry, so the first reply is a real answer rather than a request for a call.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now