The Short Answer
ISO 27001 certification cost runs from about $17,000 for a company under 25 people to $80,000 for a company of 250, in year one, all in. The certification body's audit fee is only 31 to 40 percent of that. The rest is readiness work, tooling, and remediation.
Holding a quote from a certification body right now? Multiply it by roughly 2.5 to 3 and you have a realistic budget. Jump to cost by company size.
This page assumes you already know what ISO 27001 is and how the Stage 1 and Stage 2 audits work. If not, start with the complete ISO 27001 guide.
How Much Is ISO 27001 Certification, by Company Size
Headcount is the strongest single predictor, because certification body fees are calculated in auditor days, and auditor days scale with the number of people, processes and sites in scope. These are year-one, all-in ranges for a single-site organisation.
| Company size | Certification body fee | Tooling | Readiness & consulting | Year-one total |
|---|---|---|---|---|
| Under 25 | $6,000 – $10,000 | $3,000 – $6,000 | $8,000 – $15,000 | $17,000 – $31,000 |
| 25 – 50 | $8,000 – $14,000 | $5,000 – $10,000 | $10,000 – $20,000 | $23,000 – $44,000 |
| 50 – 100 | $10,000 – $18,000 | $5,000 – $15,000 | $10,000 – $25,000 | $25,000 – $58,000 |
| 100 – 250 | $15,000 – $25,000 | $8,000 – $20,000 | $18,000 – $35,000 | $41,000 – $80,000 |
The certification body fee lands at 31 to 40 percent of the total in every band. Worth noting: that is a smaller share than SOC 2, where the CPA fee runs 36 to 41 percent. ISO 27001 front-loads more effort into building and documenting the management system before an auditor is ever involved, which is why the audit invoice understates the project more severely here than it does for SOC 2.
What each column covers
- Certification body fee — the Stage 1 documentation review and Stage 2 implementation audit, priced in auditor days. Paid to an independent, accredited body.
- Tooling — annual subscriptions for whatever your risk assessment says you need: logging and monitoring, endpoint management, vulnerability scanning, policy and evidence platforms.
- Readiness & consulting — gap analysis, risk assessment, Statement of Applicability, policy set, internal audit, management review, and remediating whatever the gap analysis finds. The most variable line by a wide margin.
Internal time: excluded from every figure above
None of those numbers include your own team's hours, and that is consistently the largest omission in an ISO 27001 budget. Expect 200 to 350 hours under 50 people, and 400 to 800 hours between 50 and 250. At a loaded $80 per hour, that is $16,000 to $64,000 of diverted capacity.
ISO 27001 is more internal-time-hungry than SOC 2 because the standard requires artefacts only your organisation can produce: a risk assessment reflecting your actual business, a Statement of Applicability justifying every control decision, a genuine internal audit, and a documented management review.
Get a figure for your actual scope
Headcount is one input. Sites, existing maturity, and the controls your risk assessment justifies move the number substantially.
Calculate my ISO 27001 costThe Three Cost Components
1. The certification body fee
Paid to an accredited certification body, and the only genuinely fixed line. It is calculated from auditor days, which are guided by IAF mandatory documents based on your headcount, scope complexity, number of sites, and the nature of your business. Two bodies quoting the same organisation will usually land within 20 to 30 percent of each other, because the day count is externally guided rather than freely invented.
This also means a quote dramatically below market is a signal worth investigating — it usually indicates fewer auditor days than the guidance suggests, or an unaccredited certificate.
2. Readiness and consulting
The largest and most variable component. Where you land depends almost entirely on your starting point. An organisation already running access reviews, change management and incident response is documenting what exists. An organisation starting from nothing is building a management system, then documenting it.
This is also where the site's published ranges have historically varied, and the reason is scope: $8,000 to $15,000 is realistic for a small single-site company, while $18,000 to $35,000 is realistic at 100 to 250 people, and complex multi-site programmes run higher still.
3. Tooling
Unlike SOC 2, ISO 27001 does not assume a compliance automation platform. What it requires is evidence that the controls in your Statement of Applicability are operating. Some organisations satisfy that with existing infrastructure and a document repository. Others need genuine investment in logging, endpoint management or vulnerability scanning — not because ISO demands those products, but because their own risk assessment identified the gap.
A Worked Example: 60-Person Software Company
A 60-person company, single office, cloud-hosted product, selling into UK and EU enterprise accounts. They have SSO, MFA and a ticketing system, but no formal ISMS, no risk register, and no internal audit function.
Their certification body quotes $13,000 for Stage 1 and Stage 2. That is the number that reaches the board. Here is the actual year:
- Certification body fee — $13,000. The quoted figure.
- Readiness and consulting — $17,000. Gap analysis, risk assessment, Statement of Applicability, a 20-document policy set, internal audit, management review, and remediation.
- Tooling — $9,000. Centralised logging and endpoint management, identified as gaps by the risk assessment.
Year-one cash total: $39,000 — inside the $25,000 to $58,000 band for their size, and three times the quote they began with. The certification body fee lands at 33 percent of the total, exactly where the heuristic predicts.
Add roughly 350 internal hours at $80, another $28,000, and the true all-in figure is around $67,000.
Their three-year picture: $39,000 in year one, then about $14,500 in each of years two and three (a $5,500 surveillance audit plus continuing tooling), for a three-year total near $68,000. Then year four arrives.
The Full Certification Cycle — and the Year-Four Surprise
An ISO 27001 certificate is valid for three years, with a surveillance audit each year to confirm the system is still operating. This is the structural advantage over SOC 2, which requires a full audit annually with no cheaper years.
But the cycle does not run indefinitely. At the end of year three the certificate expires and the whole thing restarts with a recertification audit.
| Year | Activity | Cost (50 – 100 staff) |
|---|---|---|
| 1 | Initial certification (Stage 1 + Stage 2) | $25,000 – $58,000 |
| 2 | Surveillance audit | $9,000 – $22,000 |
| 3 | Surveillance audit | $9,000 – $22,000 |
| 3-year total | — | $43,000 – $102,000 |
| 4 | Recertification — cycle restarts | $15,000 – $35,000 |
Recertification is cheaper than initial certification because the management system already exists and the certification body knows you. It is nonetheless two to three times a surveillance year, and it is the single most commonly missed line in an ISO 27001 budget. Companies model three years, get certified, and are then surprised by a bill they had no plan for.
Budget it from day one. Over six years you will pay for two full cycles, not one.
Accredited vs Non-Accredited: Why the Cheap Certificate Costs More
Search for ISO 27001 certification and you will find offers at $3,000, sometimes less, promising a certificate in weeks. These are real certificates. They are also, in most enterprise contexts, worthless.
The distinction is accreditation. A legitimate certification body is itself audited by a national accreditation body — UKAS in the UK, ANAB in the US, and equivalents elsewhere — which are mutually recognised under the IAF multilateral agreement. That oversight is what makes the certificate mean something, and it costs money, which is reflected in the fee.
An unaccredited body has no such supervision. Nothing stops it issuing a certificate after a cursory review.
The commercial problem is straightforward: enterprise procurement and security teams check. They look for the accreditation mark and verify the body against the accreditation register. A certificate without one is routinely rejected, at which point you pay a second time for the real thing, having lost months. If the certificate exists to satisfy enterprise buyers, an unaccredited one does not do the job it was bought for.
Multi-Site and Multi-Location Scaling
The table above assumes a single site. Additional locations are one of the largest cost multipliers, and one of the most negotiable.
Because fees are driven by auditor days, each additional in-scope location typically adds 15 to 30 percent to the certification body fee, plus travel where the auditor must attend in person.
The lever is multi-site sampling. Where locations run genuinely identical processes under central management, ISO permits the auditor to sample a representative subset rather than visiting all of them, commonly the square root of the total number of sites. A twenty-five-site organisation might see five sites audited per cycle rather than twenty-five.
Qualifying requires real central control: one management system, one set of policies, centrally run internal audit. Organisations where each office does its own thing do not qualify, and pay accordingly. If you are multi-site, this single question is worth more to your budget than every other negotiation combined.
What Drives Your Number Up or Down
- Scope statement. Which parts of the business, which systems, which locations. The biggest lever you fully control, and the one most often set too wide out of caution.
- Annex A applicability. ISO 27001:2022 lists 93 controls across four themes. They are not all mandatory — you implement what your risk assessment justifies and document exclusions in the Statement of Applicability. Most organisational and people controls are process work with no licence cost. The expensive ones are technological: logging and monitoring, endpoint management, data loss prevention, backup and continuity.
- Starting maturity. The gap between current practice and what the standard expects. This is exactly what a gap analysis measures, and why quotes given without one are estimates.
- Number of sites and whether you qualify for sampling.
- Headcount, which drives the auditor-day calculation directly.
- Certification body selection. Fees vary, though less than people expect, because day counts are externally guided.
ISO 27001 vs SOC 2 on Cost
Year one, ISO 27001 is generally the cheaper of the two. Over three years the gap widens considerably, because ISO's surveillance years cost a fraction of a full audit while SOC 2 requires a complete audit every year.
For a 50 to 100 person company: ISO 27001 runs roughly $43,000 to $102,000 across three years, against roughly $155,000 to $300,000 for SOC 2 Type 2 over the same period.
That is not an argument for choosing ISO 27001. The frameworks serve different markets — North American enterprise buyers overwhelmingly ask for SOC 2, while ISO 27001 carries more weight in the UK, EU and APAC. Choose on where you sell, then budget accordingly. Our ISO 27001 vs SOC 2 comparison covers the strategic decision, and the SOC 2 certification cost breakdown covers the other side of these figures.
If you need both — increasingly common for companies selling on both sides of the Atlantic — run them as one programme. The control overlap is substantial and doing them together typically saves 30 to 40 percent against sequential projects.
Seven Ways to Reduce ISO 27001 Cost
- Write a tight scope statement. Certify the part of the business that customers ask about, not the whole legal entity.
- Use Annex A properly. Justify exclusions in the Statement of Applicability rather than implementing all 93 controls reflexively.
- Qualify for multi-site sampling if you have more than one location. The highest-value single action available to a distributed organisation.
- Do a gap analysis first. Finding problems before Stage 2 is far cheaper than a major nonconformity that requires a follow-up audit.
- Get quotes from three accredited bodies — but compare auditor days, not headline price. A cheaper quote with fewer days may simply be a smaller audit.
- Combine with SOC 2 if you need both, rather than running them sequentially.
- Budget year four from day one. Not a saving as such, but it prevents the most common and most avoidable budget failure in ISO 27001.
Want a scoped number rather than a range?
Scope, sites and current maturity move this figure more than headcount does. We have guided 3,000+ organisations across 40+ markets to certification.
Get a free scoped quoteFrequently asked questions about ISO 27001 cost
How much is ISO 27001 certification for a small company?
For a company under 25 people on a single site, expect roughly $17,000 to $31,000 in year one: $6,000 to $10,000 for the certification body audit, $3,000 to $6,000 for tooling, and $8,000 to $15,000 for readiness and consulting. Internal staff time sits on top of that. Get a scoped estimate.
What share of ISO 27001 cost is the certification body's fee?
Typically 31 to 40 percent of year-one spend. That is a smaller share than SOC 2, where the CPA fee runs 36 to 41 percent, because ISO 27001 front-loads more effort into building and documenting the management system before the auditor is involved. Budgeting from the certification body quote alone understates the real figure by roughly two and a half to three times.
How much do ISO 27001 surveillance audits cost in years two and three?
The surveillance audit itself typically costs $4,000 to $7,000 per year, roughly a third to a half of the initial Stage 1 and Stage 2 fee. Adding continuing tooling subscriptions, most companies budget $9,000 to $22,000 per year in years two and three for a 50 to 100 person organisation.
What does ISO 27001 recertification cost in year four?
An ISO 27001 certificate is valid for three years, after which the cycle restarts with a full recertification audit. For a 50 to 100 person company, budget $15,000 to $35,000 in year four. It is cheaper than initial certification because the management system already exists, but substantially more than a surveillance year, and it is the cost companies most often forget to plan for.
Why does an accredited ISO 27001 certificate cost more, and is it worth it?
An accredited certificate is issued by a certification body that is itself audited by a national accreditation body such as UKAS or ANAB under the IAF multilateral agreement. That oversight costs money and is reflected in the fee. Unaccredited certificates can be bought for a few thousand dollars, but enterprise procurement and security teams routinely check the accreditation mark and reject certificates without one, which means paying twice.
How much does each additional site or location add to ISO 27001 cost?
Certification body fees are driven by auditor days, and additional sites add days. As a rough guide each additional in-scope location adds 15 to 30 percent to the audit fee, plus travel. Multi-site sampling can reduce this substantially: where sites run genuinely identical processes under central control, an auditor may sample a subset rather than visiting every location.
Do all 93 Annex A controls cost money to implement?
No. Annex A of ISO 27001:2022 lists 93 controls, but they are not all mandatory: you apply the ones your risk assessment justifies and document the rest as excluded in your Statement of Applicability. Most organisational and people controls are policy and process work with no licence cost. The expensive ones are technological, typically logging and monitoring, endpoint management, data loss prevention, and backup or continuity infrastructure.
Can we reduce cost by combining ISO 27001 with SOC 2 in one project?
Yes, meaningfully. The two frameworks share a large proportion of underlying controls covering access management, change management, risk assessment, vendor management and incident response. Running them as one programme with a single evidence set typically saves 30 to 40 percent against doing them sequentially, though the audits remain separate engagements with separate fees since they are issued by different bodies.
About Avantcert. Avantcert is an ISO and compliance certification consultancy that has guided 3,000+ organisations across 40+ markets to certification, with gap analysis, implementation and accredited audit readiness. See our ISO 27001 consulting service or request a free quote.