iso27001partnersUK certification, costed Get a cost estimate

How we check what is on this site

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 7 min read
6 primary sources cited on this page. How we check what is on this site

A direct competitor in an adjacent market describes its figures as “estimates synthesised from public market data using AI research”, with no sample size and no sources. This page exists so that nothing here has to be taken on that basis.

Three labels, applied to every figure

Every value on this site lives in one source module, and every value in it carries a label. The label decides how the figure is allowed to be rendered on a page.

  • Primary — read out of the standard, the statutory instrument or the accreditation rule itself, or out of a document that reproduces it verbatim. Published as fact, with the source linked and the edition year attached.
  • Secondary — taken from a published price list or a vendor guide. Real, but it is somebody’s commercial position rather than a rule, and it is attributed as such.
  • Estimated — our arithmetic on top of the other two. Always rendered as a range, never as a single number, and always labelled on the page where it appears.
Every class of figure on this site, and its basis
FigureBasisSourceNote
Audit days by headcountPrimaryISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)All 22 bands, reproduced in full on this site
Surveillance and recertification fractionsPrimaryISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1One third and two thirds of the initial audit; checked against every row
The 30% adjustment ceilingPrimaryISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)Audit time is never reduced by more than this, for any reason
Consultancy bar on certification bodiesPrimaryBS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full textClauses 5.2.5 to 5.2.9, quoted verbatim
UKAS as national accreditation bodyPrimaryThe Accreditation Regulations 2009 (SI 2009/3155), regulation 3Regulation 3, quoted verbatim
Annex A control counts, both editionsPrimaryISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — RequirementsTagged with the edition year everywhere they appear
2013 to 2022 transition deadlinePrimaryIAF MD 26:2023, Transition requirements for ISO/IEC 27001:202231 October 2025
Certificates worldwideSecondaryThe ISO Survey of management system standard certifications 2024ISO Survey 2024. The UK country row is deliberately not published here
Cyber Essentials feesSecondaryIASME published feesSelf-assessment fee excluding VAT; the scheme site blocks automated reading
Certification body day rateEstimated£1100–£1500 per dayOur band. Shown as a range wherever it produces a figure
Consultant day rateEstimated£600–£1200 per dayOur band
Implementation effortEstimated6 to 140 consultant days by size bandOur model of the work clauses 4 to 10 require. Published in full below

The arithmetic, in full

There are four numbers on this site. Three of them are published rules and one is ours.

  1. Audit days. Look the headcount up in ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21). Apply the multi-site sampling rule if there is more than one site, then the complexity adjustment, both capped at the 30% the rule allows in either direction. This is exact.
  2. Surveillance and recertification days. one third and two thirds of the initial audit. Exact, and checked programmatically against every row of the table rather than trusted.
  3. Certification fee. Audit days multiplied by a day rate of £1100 to £1500. The rate is ours. The midpoint of £1250 is the rate implied by the only UK guide we found that publishes a cost table at all — and its own published costs do not divide evenly by its own published day counts, which is one reason we show the arithmetic rather than a table of finished prices.
  4. Preparation. A band of consultant-days by size, multiplied by £600 to £1200 per day. The day bands are our model of what clauses 4 to 10 actually require — a scope, a risk assessment, a Statement of Applicability, the documented information, an internal audit and a management review, plus the Annex A treatment the risk assessment produced. They are published here in full so you can disagree with them specifically rather than vaguely.
The implementation-effort model, published so it can be argued with
People in scopeConsultant daysAt our day-rate band
up to 106–14 days£3,600–£16,800
up to 2510–22 days£6,000–£26,400
up to 4514–30 days£8,400–£36,000
up to 12520–45 days£12,000–£54,000
up to 27530–65 days£18,000–£78,000
up to 62545–95 days£27,000–£114,000
above 62560–140 days£36,000–£168,000

The platform route is the same day model reduced by roughly a third, because a compliance platform removes evidence-gathering rather than decision-making: it cannot decide your scope, write your risk treatment or hold your management review. The subscription is not in that figure, because no major platform publishes one.

The same number is never written twice

The calculator has to run in your browser, so its arithmetic exists in JavaScript as well as in the source module the pages are built from. That is the one place where a figure could drift out of step with itself — and published guidance in adjacent markets does exactly this, quoting one number in the body text and a different one in its own structured data.

So the two implementations are compared by machine on every build, over five thousand cases covering every band boundary in the table and every combination of the adjustment factors, field by field. The check found a genuine divergence the first time it ran: the two rounded half-way values in opposite directions, putting them £50 apart on a large minority of cases. It was fixed in the source module, not papered over on the page.

What is deliberately missing

We left out the number of ISO 27001 certificates held in the UK. The worldwide totals in the ISO Survey were read from a document reproducing them; the UK country row was not, and a country figure that is out by a thousand is worse than no figure. We also do not publish a price for any compliance-automation platform, because none of them publishes one — we report the absence instead, which is itself the useful fact.

There are no reviews, star ratings, client logos, success rates, case results or superlatives anywhere on this site. Not out of modesty: we hold no data that would substantiate any of them, and neither does anyone else publishing them in this market.

Common questions

Where do the audit-day numbers come from?

ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21). It is the rule that governs how long an ISMS certification audit takes, and it is what accredited certification bodies work to. The standard is not free to read, so we verified the table against a certification body's own published audit-duration procedure, which reproduces all 22 rows. The two agree exactly, including the derived surveillance and recertification columns.

Why is every price on this site a range?

Because a single figure would be a false claim. No UK certification body publishes a day rate and no compliance platform publishes a subscription price. What we can do honestly is take the day count, which is published, multiply it by a rate band we name, and show the result as a range with the arithmetic beside it. A site that gives you one confident number for something nobody publishes has made it up.

How do you decide what counts as a fact and what counts as an estimate?

Every figure in our source module carries one of three labels. Primary means it was read out of the standard, the statutory instrument or the accreditation rule itself, or out of a document that reproduces it verbatim. Secondary means it came from a published price list or vendor guide, which is real but is somebody's commercial position rather than a rule. Estimated means it is our arithmetic on top of the other two, and those are always shown as ranges. This page prints that classification for the whole site.

What did you decide not to publish?

The number of ISO 27001 certificates held in the United Kingdom. The ISO Survey's worldwide totals were read from a document that reproduces them, but the UK country row was not, and a country figure that is out by a thousand is worse than no figure at all. It is left out rather than guessed. The same applies to compliance-platform pricing: we report that none of them publishes a price, and we do not invent one.

Who writes this?

The editorial team behind the site. We are not consultants, auditors or certification body staff, and we do not claim to be: everything here is traceable to a source you can open yourself, which is a stronger basis for trusting a number than a biography would be. Where we quote a clause, we quote it rather than paraphrasing, so you can check that the paraphrase would have been fair.

How do I report an error?

Write to contact@iso27001partners.co.uk with the page and the figure. Corrections that change a number get the figure changed and the review date on the affected pages moved. We would rather be corrected than consistent.

Sources cited on this page

  1. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
  2. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
  3. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  4. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
  5. The Accreditation Regulations 2009 (SI 2009/3155), regulation 3
  6. The ISO Survey of management system standard certifications 2024

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Get a costed answer, not a call-back to discuss pricing

Five questions, all of them click-only. Your details are the last step, never the first.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now