Back to blog
Buyer Guides

How much does ISO 27001 certification really cost?

A breakdown of every cost line in ISO 27001 certification - audit fees, tooling, internal time, remediation and ongoing surveillance - and the factors that move the total up or down.
GRC Copilot Team
How much does ISO 27001 certification really cost?

The certification audit is rarely the biggest cost of ISO 27001. Internal time usually is. Anyone quoting a single figure is guessing, because the total depends on scope, current maturity and whether you use consultants. What is predictable is the shape of the cost - and that is what you can plan against.

The cost lines

1. Certification body fees

Charged by the accredited registrar for the Stage 1 and Stage 2 audits, then annual surveillance, with recertification every three years. Priced on audit days, which are driven by headcount, number of sites and scope complexity. This is the one line with a firm quote before you start - get two or three.

2. Internal effort - usually the largest line

Someone has to write policies, run the risk assessment, implement controls, gather evidence, run the internal audit and manage the auditor. For a first certification this is commonly measured in person-months, not person-days. Cost it at real salary rates and it typically dwarfs the audit fee.

3. Remediation

The gap assessment tells you what is missing. Cost varies enormously: enabling MFA is cheap, introducing centralised logging or segmenting a flat network is not. This is the line that can surprise you, so do the gap assessment before you set the budget.

4. Consultancy (optional)

Ranges from a few days of advisory to a fully outsourced implementation. Outsourcing buys speed but produces an ISMS your team did not build - and the surveillance audits are still yours to pass. A common middle path is advisory for the risk assessment and Statement of Applicability, with implementation in-house.

5. Tooling

A GRC platform to track controls, evidence and audit readiness. Compare against the internal time it removes rather than treating it as pure overhead.

6. Ongoing costs

Certification is not one-off. Budget for annual surveillance audits, recertification in year three, internal audits each year, awareness training, penetration testing where your risk assessment calls for it, and the continuous evidence work.

Cut the largest line item

Internal effort is the biggest cost of certification. GRC Copilot assesses your gaps, maps evidence to controls automatically and keeps you audit-ready - so the work shrinks instead of repeating each year.

What drives the total up

  • Broad scope. Every extra site, product line and legal entity adds audit days and evidence.
  • Low starting maturity. No policies, no risk assessment and no logging means building from zero.
  • Distributed teams and multiple sites. More sampling, sometimes travel.
  • Regulated or high-risk data. Deeper testing and more controls in scope.
  • Legacy estate. Systems that cannot support modern authentication or logging are expensive to bring into line.

What brings it down

  • Tight initial scope. Certify the product and team that customers ask about, then widen at recertification.
  • Existing frameworks. If you already run SOC 2 or the NCA ECC, much of the evidence is reusable.
  • Cloud-native infrastructure. Configuration is easier to evidence automatically.
  • Starting evidence collection early. Reconstructing history late is the most expensive way to do it.
  • Automating the repetitive work - access reviews, evidence mapping, control monitoring.
The most expensive mistake is scoping wide to look impressive. A clean, narrow certificate that you pass beats a broad one that fails - and widening scope later costs far less than a failed Stage 2.

How to build a defensible budget

  1. Define scope precisely, in writing.
  2. Run a gap assessment - you cannot budget remediation you have not identified.
  3. Get two or three registrar quotes based on that scope.
  4. Estimate internal effort honestly and cost it at real salary rates.
  5. Add remediation from the gap list, with the largest items priced individually.
  6. Add a contingency - first certifications reliably uncover something.
  7. Budget across three years, not one, so surveillance and recertification are visible.

Frequently asked questions

Can we get certified without a consultant?

Yes. Many organisations certify entirely in-house, particularly with tooling to structure the work. Consultants buy speed and reduce the risk of misreading the standard - useful when a deal deadline is driving the timeline.

Is the cheapest certification body the right choice?

Not necessarily. Check that the body is properly accredited, has experience in your sector, and that the quote covers the full three-year cycle. An unaccredited certificate can be rejected by the customer you bought it for.

How does the cost compare with SOC 2?

Different shape. ISO front-loads effort into certification with lighter annual surveillance; SOC 2 repeats a full testing cycle each year. Compare total three-year cost rather than the first invoice.

Does tooling actually reduce cost?

It reduces the largest line - internal effort - by removing repeated evidence gathering and manual mapping. Judge it against the person-days it saves each year, not against the audit fee.

Key takeaways

  • Internal effort usually exceeds the audit fee - cost it honestly.
  • Run the gap assessment before setting the budget; remediation is the volatile line.
  • Scope narrowly first, then widen at recertification.
  • Budget over three years so surveillance and recertification are visible.
#iso27001 #cost #budget #certification #planning