What ISO 27001 certification costs in the UK
Your certification audit length is set by ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21), a published rule with 22 headcount bands that every accredited certification body works to. It is the whole table, below, and it is the reason half of this question has a precise answer.
Ask what ISO 27001 costs and you will be given a range so wide it tells you nothing — one published UK guide puts implementation anywhere between £500 and £40,000. Part of that spread is honest. But it obscures something useful: the cost splits into four parts, and two of them are set by a published rule and can be stated exactly.
Key points
- Audit days are not negotiable in the way people assume. The rule allows adjustment of up to 30% either way for complexity and sites, and says audit time is never reduced by more than 30%.
- Preparation is usually the bigger number, and it is the one with no published rule behind it. That is why everyone answers the cost question with a form.
- The audit never stops. Surveillance is one third of the initial audit each year and recertification is two thirds in year three, so the three years after you certify cost more audit time than certifying did.
- How you prepare does not change the audit fee. Toolkit, consultant or platform, the day count is the same, because it is a function of your headcount and complexity and nothing else.
- Every pound figure on this page is our estimate, built on a day-rate band we name on the methodology page. The day counts are not.
The four parts
The same diagram as a table
| Part | Low | High | Basis |
|---|---|---|---|
| Certification audit | £7,700 | £10,500 | 7 days, from the published table |
| Preparation, consultant-led | £6,000 | £26,400 | 10–22 consultant days |
| Surveillance, per year | £2,550 | £3,500 | 2.33 days, one third of the initial audit |
| First three years | £18,800 | £43,900 | Audit + preparation + two surveillance years |
Day counts come from ISO/IEC 27006-1:2024 Table C.1 and are exact. The money is our estimate built on a day-rate band, rendered as a range and never as a single figure.
Part 1 — the certification audit (exact days, estimated rate)
Stage 1 and Stage 2 together. Find your headcount in the table below, apply any adjustment, and multiply by a day rate. We use a band of £1100 to £1500 per day; the midpoint is what the only UK guide publishing a cost table implies.
Part 2 — getting ready (estimated)
Scope, risk assessment, risk treatment, the Statement of Applicability, the documented information, an internal audit and a management review, plus whatever Annex A treatment your risk assessment produced. No rule sets this. It is the whole reason the three delivery routes have different prices, and it is covered in toolkit, consultant or platform.
Part 3 — annual surveillance (exact days, estimated rate)
One third of the initial audit, every year, for as long as you hold the certificate. In year three it becomes recertification at two thirds.
Part 4 — your own people (not priced here, and usually underestimated)
Somebody in your organisation has to make decisions a consultant cannot make for you: what is in scope, what your risk appetite is, who owns each control, and what the management review concludes. On the toolkit route this is the dominant cost and nobody puts a number on it.
The audit-day table, in full
This is ISO/IEC 27006-1:2024 Table C.1, all 22 bands, with our fee band applied. Certification bodies work from this table; it is not a marketing estimate and it is not ours. The surveillance and recertification columns are derived from the initial column at one third and two thirds, and we check that arithmetic against every row on each build rather than trusting it.
| People in scope | Initial audit days | Surveillance days | Recertification days | Certification audit fee | Each surveillance audit |
|---|---|---|---|---|---|
| 1–10 | 5 | 1.67 | 3.33 | £5,500–£7,500 | £1,850–£2,500 |
| 11–15 | 6 | 2 | 4 | £6,600–£9,000 | £2,200–£3,000 |
| 16–25 | 7 | 2.33 | 4.67 | £7,700–£10,500 | £2,550–£3,500 |
| 26–45 | 8.5 | 2.83 | 5.67 | £9,350–£12,750 | £3,100–£4,250 |
| 46–65 | 10 | 3.33 | 6.67 | £11,000–£15,000 | £3,650–£5,000 |
| 66–85 | 11 | 3.67 | 7.33 | £12,100–£16,500 | £4,050–£5,500 |
| 86–125 | 12 | 4 | 8 | £13,200–£18,000 | £4,400–£6,000 |
| 126–175 | 13 | 4.33 | 8.67 | £14,300–£19,500 | £4,750–£6,500 |
| 176–275 | 14 | 4.67 | 9.33 | £15,400–£21,000 | £5,150–£7,000 |
| 276–425 | 15 | 5 | 10 | £16,500–£22,500 | £5,500–£7,500 |
| 426–625 | 16.5 | 5.5 | 11 | £18,150–£24,750 | £6,050–£8,250 |
| 626–875 | 17.5 | 5.83 | 11.67 | £19,250–£26,250 | £6,400–£8,750 |
| 876–1,175 | 18.5 | 6.17 | 12.33 | £20,350–£27,750 | £6,800–£9,250 |
| 1,176–1,550 | 19.5 | 6.5 | 13 | £21,450–£29,250 | £7,150–£9,750 |
| 1,551–2,025 | 21 | 7 | 14 | £23,100–£31,500 | £7,700–£10,500 |
| 2,026–2,675 | 22 | 7.33 | 14.67 | £24,200–£33,000 | £8,050–£11,000 |
| 2,676–3,450 | 23 | 7.67 | 15.33 | £25,300–£34,500 | £8,450–£11,500 |
| 3,451–4,350 | 24 | 8 | 16 | £26,400–£36,000 | £8,800–£12,000 |
| 4,351–5,450 | 25 | 8.33 | 16.67 | £27,500–£37,500 | £9,150–£12,500 |
| 5,451–6,800 | 26 | 8.67 | 17.33 | £28,600–£39,000 | £9,550–£13,000 |
| 6,801–8,500 | 27 | 9 | 18 | £29,700–£40,500 | £9,900–£13,500 |
| 8,501–10,700 | 28 | 9.33 | 18.67 | £30,800–£42,000 | £10,250–£14,000 |
Above 10,700 people the published table stops and says the sequence continues; the certification body extends it. Fees assume £1100–£1500 per day and exclude VAT, travel and any application or certificate charge.
The same diagram as a table
| People in scope | Initial audit | Surveillance | Recertification |
|---|---|---|---|
| 1–10 | 5 | 1.67 | 3.33 |
| 11–15 | 6 | 2 | 4 |
| 16–25 | 7 | 2.33 | 4.67 |
| 26–45 | 8.5 | 2.83 | 5.67 |
| 46–65 | 10 | 3.33 | 6.67 |
| 66–85 | 11 | 3.67 | 7.33 |
| 86–125 | 12 | 4 | 8 |
| 126–175 | 13 | 4.33 | 8.67 |
| 176–275 | 14 | 4.67 | 9.33 |
| 276–425 | 15 | 5 | 10 |
| 426–625 | 16.5 | 5.5 | 11 |
Surveillance is one third of the initial audit and recertification is two thirds, in every row of the published table. The full 22 bands run to 10,700 people.
What moves you up or down within the band
The table is a starting point, not a final answer. The rule lets a certification body adjust it for how complicated your scope genuinely is — but it caps the adjustment at 30% and states that time is never cut by more than 30%, which is the sentence to remember if a discount sounds too good.
| Factor | Effect | Why |
|---|---|---|
| Multiple sites in scope | ↑ more days | Each additional site adds audit time, subject to the square-root sampling rule. |
| Complex or numerous IT platforms | ↑ more days | Several different platforms, networks and operating systems inside one scope. |
| Heavy reliance on outsourcing and cloud suppliers | ↑ more days | The more of the scope that somebody else runs, the more supplier controls there are to test. |
| Significant in-house software development | ↑ more days | Secure development controls have to be audited where development happens. |
| High-availability and disaster recovery sites | ↑ more days | Alternate data centres are part of the scope and are audited as such. |
| A management system that has been running for years | ↓ fewer days | A mature, evidenced ISMS is quicker to audit than one that was stood up last quarter. |
| Most staff performing the same activity | ↓ fewer days | Repetitive, low-variation work can be sampled. |
| A single site and a simple IT estate | ↓ fewer days | Less ground to cover. |
Multiple sites are handled separately. Where several sites perform the same activity, the certification body samples them rather than visiting all of them, and the sample is the square root of the number of sites, rounded up. Sites doing genuinely different things are not sampled away. That is ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1, and it is why a four-site company is not four times the audit.
Worked examples
Single site, no adjusting factors, consultant-led preparation. The three-year column is the one worth comparing between certification bodies, because it is the one a headline quote leaves out.
| People | Band | Audit days | Certification audit | Preparation (consultant-led) | Surveillance, per year | First three years |
|---|---|---|---|---|---|---|
| 10 | 1–10 | 5 days | £5,500 to £7,500 | £3,600 to £16,800 | £1,850 to £2,500 | £12,800 to £29,300 |
| 25 | 16–25 | 7 days | £7,700 to £10,500 | £6,000 to £26,400 | £2,550 to £3,500 | £18,800 to £43,900 |
| 60 | 46–65 | 10 days | £11,000 to £15,000 | £12,000 to £54,000 | £3,650 to £5,000 | £30,300 to £79,000 |
| 150 | 126–175 | 13 days | £14,300 to £19,500 | £18,000 to £78,000 | £4,750 to £6,500 | £41,800 to £110,500 |
Our fee is a fixed amount per enquiry, agreed before anyone sends one. It does not move with the size of your engagement or with which consultancy receives it, which is why this page can tell you that a narrower scope is cheaper, that preparation is where the saving is, and that some readers should buy Cyber Essentials instead.
The five costs that arrive after the quote
1. The internal audit, every year, from somebody else
Clause 9.2 requires internal audits at planned intervals, and you cannot sit Stage 2 without having run one. Your certification body cannot do it for you: BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.6 bars a certification body from providing internal audits to its certified clients, and says doing so locks it out of certifying that management system for 2 years. So this is a separate purchase, or a genuinely independent internal resource, every year for as long as you are certified.
2. Surveillance, which is permanent
The quote you are shown is usually for the initial certification audit. Add one third of it in year one, the same in year two, and two thirds in year three. Taken together, the three years after certification contain more audit time than the certification itself.
3. Fees that are not audit days
Application fees, certificate issue fees and annual registration or licence charges are common and are not day-rate items, so they sit outside any calculation based on the table — including ours. Ask for the full schedule of charges, not the audit quote.
4. The follow-up visit after a major nonconformity
A major nonconformity at Stage 2 has to be closed before a certificate is issued, and closing it often needs the auditor to come back. That visit is chargeable and is not in anyone's original quote. It is the one real financial argument for preparing properly, and it is a probability rather than a certainty.
5. Scope changes
Adding a site, an acquisition or a new product line inside the scope re-runs the day calculation, including the multi-site sampling rule. A scope drawn to flatter a sales cycle is a scope you pay for again later.
Before you spend anything: is it ISO 27001 you need?
If a customer has asked for “security certification” without naming a standard, it is worth establishing which one before committing to the larger of the two. Cyber Essentials is a UK government-backed scheme with published fees and a verified self-assessment against five technical control areas.
| Size | Employees | Fee |
|---|---|---|
| Micro | 0–9 employees | £320 |
| Small | 10–49 employees | £440 |
| Medium | 50–249 employees | £500 |
| Large | 250 or more employees | £600 |
Published scheme fees, read 20 September 2026. Cyber Essentials Plus adds a technical audit and is priced separately by the assessment body. These are the certification fees only and exclude any help you buy to get through it.
Cyber Essentials is not a substitute where a contract names ISO 27001, and it is not a management system: it does not ask you to assess risk, set objectives or review anything. But it answers a real question for a fraction of the money, and for a ten-person company being asked for reassurance rather than for a specific certificate, it is frequently the proportionate answer.
Common questions
What is the cheapest ISO 27001 certification can be?
The audit has a floor. The smallest band in the published table is 5 days for 1 to 10 people, and audit time cannot be cut by more than 30% for any reason, so roughly £3,850 of audit is the realistic floor at UK day rates however the discount is presented. Preparation is where the genuine saving is: a documentation toolkit plus your own people's time can be a few hundred pounds of outlay, at the cost of a lot of internal effort. What you cannot do is buy a meaningfully cheaper audit, and an unusually cheap certificate is usually a sign that it is not accredited.
Why do two quotes for the same company differ so much?
Check the day count first. Both quotes should reconcile to the same band in ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21), adjusted within 30% for your sites and complexity. If one quote has materially fewer days than the other for the same scope, either the scopes are not the same or the reduction exceeds what the rule allows. After that, check what is excluded: travel and expenses, application and certificate fees, and any annual registration charge are frequently billed on top of the day rate and left out of a headline number.
Is the surveillance audit included in the price I was quoted?
Usually not, and this is the single most common surprise. The published rule sets each annual surveillance audit at one third of the initial audit and recertification at two thirds. Over the three years after certification that adds up to more audit time than the initial certification audit itself. A three-year figure is the only honest way to compare two certification bodies, and it is worth asking for one in writing.
Does the number of employees mean everybody on the payroll?
No. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1 counts everyone doing work under the organisation's control inside the certified scope. Part-time people count in proportion to the hours they work; contractors and outsourced staff working inside the scope count; people in a business unit genuinely outside the scope do not. This is why scope is a cost decision as well as a commercial one, and why a narrower first certification is often the right call.
Can I reduce the audit cost by being well prepared?
Not much, and this surprises people. The day count comes from your headcount and complexity, not from how tidy your evidence is. Good preparation changes the probability that Stage 2 produces a major nonconformity and a chargeable follow-up visit, and it changes how much of your own staff time the audit consumes. It does not move you down a band. What does move the count is a genuinely narrower scope, a simpler estate, or an ISMS that has been running for years rather than months.
Are toolkit, consultant and platform routes all the same price at audit?
Yes, exactly the same, and that is worth knowing before anyone quotes you. The audit-day count is a function of your headcount, sites and complexity. It is not a function of how you built the management system. So the whole of the price difference between the three routes sits in preparation, which is the part with no published rule behind it.
What about VAT?
Every figure on this page is shown before VAT, because that is how certification bodies and consultancies quote. Add 20% for the cash figure if your organisation cannot recover it.
Should we do Cyber Essentials first?
Often, yes — and this is advice against spending money, which is worth noticing on a site paid for by consultancies. Cyber Essentials is a verified self-assessment with a published fee of £320 to £600 plus VAT depending on size, against five technical control areas. If what your customer actually asked for is evidence of basic security hygiene, it may be the proportionate answer, and it is a reasonable stepping stone. If the requirement names ISO 27001 specifically, or the contract is with a large enterprise or the public sector, it will not substitute.
Sources cited on this page
- ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
- ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- IASME, Cyber Essentials certification fees
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Get this costed against your actual scope
Five click-only questions. Consultancies see the headcount and sector before they reply, so the first answer is a real one.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.