How we check what is on this site
A direct competitor in an adjacent market describes its figures as “estimates synthesised from public market data using AI research”, with no sample size and no sources. This page exists so that nothing here has to be taken on that basis.
Three labels, applied to every figure
Every value on this site lives in one source module, and every value in it carries a label. The label decides how the figure is allowed to be rendered on a page.
- Primary — read out of the standard, the statutory instrument or the accreditation rule itself, or out of a document that reproduces it verbatim. Published as fact, with the source linked and the edition year attached.
- Secondary — taken from a published price list or a vendor guide. Real, but it is somebody’s commercial position rather than a rule, and it is attributed as such.
- Estimated — our arithmetic on top of the other two. Always rendered as a range, never as a single number, and always labelled on the page where it appears.
| Figure | Basis | Source | Note |
|---|---|---|---|
| Audit days by headcount | Primary | ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21) | All 22 bands, reproduced in full on this site |
| Surveillance and recertification fractions | Primary | ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1 | One third and two thirds of the initial audit; checked against every row |
| The 30% adjustment ceiling | Primary | ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21) | Audit time is never reduced by more than this, for any reason |
| Consultancy bar on certification bodies | Primary | BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text | Clauses 5.2.5 to 5.2.9, quoted verbatim |
| UKAS as national accreditation body | Primary | The Accreditation Regulations 2009 (SI 2009/3155), regulation 3 | Regulation 3, quoted verbatim |
| Annex A control counts, both editions | Primary | ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements | Tagged with the edition year everywhere they appear |
| 2013 to 2022 transition deadline | Primary | IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022 | 31 October 2025 |
| Certificates worldwide | Secondary | The ISO Survey of management system standard certifications 2024 | ISO Survey 2024. The UK country row is deliberately not published here |
| Cyber Essentials fees | Secondary | IASME published fees | Self-assessment fee excluding VAT; the scheme site blocks automated reading |
| Certification body day rate | Estimated | £1100–£1500 per day | Our band. Shown as a range wherever it produces a figure |
| Consultant day rate | Estimated | £600–£1200 per day | Our band |
| Implementation effort | Estimated | 6 to 140 consultant days by size band | Our model of the work clauses 4 to 10 require. Published in full below |
The arithmetic, in full
There are four numbers on this site. Three of them are published rules and one is ours.
- Audit days. Look the headcount up in ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21). Apply the multi-site sampling rule if there is more than one site, then the complexity adjustment, both capped at the 30% the rule allows in either direction. This is exact.
- Surveillance and recertification days. one third and two thirds of the initial audit. Exact, and checked programmatically against every row of the table rather than trusted.
- Certification fee. Audit days multiplied by a day rate of £1100 to £1500. The rate is ours. The midpoint of £1250 is the rate implied by the only UK guide we found that publishes a cost table at all — and its own published costs do not divide evenly by its own published day counts, which is one reason we show the arithmetic rather than a table of finished prices.
- Preparation. A band of consultant-days by size, multiplied by £600 to £1200 per day. The day bands are our model of what clauses 4 to 10 actually require — a scope, a risk assessment, a Statement of Applicability, the documented information, an internal audit and a management review, plus the Annex A treatment the risk assessment produced. They are published here in full so you can disagree with them specifically rather than vaguely.
| People in scope | Consultant days | At our day-rate band |
|---|---|---|
| up to 10 | 6–14 days | £3,600–£16,800 |
| up to 25 | 10–22 days | £6,000–£26,400 |
| up to 45 | 14–30 days | £8,400–£36,000 |
| up to 125 | 20–45 days | £12,000–£54,000 |
| up to 275 | 30–65 days | £18,000–£78,000 |
| up to 625 | 45–95 days | £27,000–£114,000 |
| above 625 | 60–140 days | £36,000–£168,000 |
The platform route is the same day model reduced by roughly a third, because a compliance platform removes evidence-gathering rather than decision-making: it cannot decide your scope, write your risk treatment or hold your management review. The subscription is not in that figure, because no major platform publishes one.
The same number is never written twice
The calculator has to run in your browser, so its arithmetic exists in JavaScript as well as in the source module the pages are built from. That is the one place where a figure could drift out of step with itself — and published guidance in adjacent markets does exactly this, quoting one number in the body text and a different one in its own structured data.
So the two implementations are compared by machine on every build, over five thousand cases covering every band boundary in the table and every combination of the adjustment factors, field by field. The check found a genuine divergence the first time it ran: the two rounded half-way values in opposite directions, putting them £50 apart on a large minority of cases. It was fixed in the source module, not papered over on the page.
What is deliberately missing
We left out the number of ISO 27001 certificates held in the UK. The worldwide totals in the ISO Survey were read from a document reproducing them; the UK country row was not, and a country figure that is out by a thousand is worse than no figure. We also do not publish a price for any compliance-automation platform, because none of them publishes one — we report the absence instead, which is itself the useful fact.
There are no reviews, star ratings, client logos, success rates, case results or superlatives anywhere on this site. Not out of modesty: we hold no data that would substantiate any of them, and neither does anyone else publishing them in this market.
Common questions
Where do the audit-day numbers come from?
ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21). It is the rule that governs how long an ISMS certification audit takes, and it is what accredited certification bodies work to. The standard is not free to read, so we verified the table against a certification body's own published audit-duration procedure, which reproduces all 22 rows. The two agree exactly, including the derived surveillance and recertification columns.
Why is every price on this site a range?
Because a single figure would be a false claim. No UK certification body publishes a day rate and no compliance platform publishes a subscription price. What we can do honestly is take the day count, which is published, multiply it by a rate band we name, and show the result as a range with the arithmetic beside it. A site that gives you one confident number for something nobody publishes has made it up.
How do you decide what counts as a fact and what counts as an estimate?
Every figure in our source module carries one of three labels. Primary means it was read out of the standard, the statutory instrument or the accreditation rule itself, or out of a document that reproduces it verbatim. Secondary means it came from a published price list or vendor guide, which is real but is somebody's commercial position rather than a rule. Estimated means it is our arithmetic on top of the other two, and those are always shown as ranges. This page prints that classification for the whole site.
What did you decide not to publish?
The number of ISO 27001 certificates held in the United Kingdom. The ISO Survey's worldwide totals were read from a document that reproduces them, but the UK country row was not, and a country figure that is out by a thousand is worse than no figure at all. It is left out rather than guessed. The same applies to compliance-platform pricing: we report that none of them publishes a price, and we do not invent one.
Who writes this?
The editorial team behind the site. We are not consultants, auditors or certification body staff, and we do not claim to be: everything here is traceable to a source you can open yourself, which is a stronger basis for trusting a number than a biography would be. Where we quote a clause, we quote it rather than paraphrasing, so you can check that the paraphrase would have been fair.
How do I report an error?
Write to contact@iso27001partners.co.uk with the page and the figure. Corrections that change a number get the figure changed and the review date on the affected pages moved. We would rather be corrected than consistent.
Sources cited on this page
- ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
- ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- The Accreditation Regulations 2009 (SI 2009/3155), regulation 3
- The ISO Survey of management system standard certifications 2024
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Get a costed answer, not a call-back to discuss pricing
Five questions, all of them click-only. Your details are the last step, never the first.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.