Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How much does ISO 27001 cost?
Last verifiedISO/IEC 27001 cost is certification-body fees plus internal effort, optional consultants, tooling, and remediation. Figures here are typical and illustrative, not quotes. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
Budget guide, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. IAF MD 5 and ISO/IEC 27006 influence audit-day counts. There is no cheapest or guaranteed price. Only an IAF-MLA accredited body issues a recognised certificate.
What this page is, and what it is not
Audience: a budget owner who has been given only an “audit fee” and knows that cannot be the whole number.
This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file. Last verified 10 September 2026.
Do not use these rows as a bid. Ask accredited bodies for proposals that show how they applied IAF MD 5.
Cost components and illustrative ranges
Worked example framing: a small single-site software company (tens of people in scope) often sees certification-body initial fees in the low-to-mid five figures in USD, with internal time larger than the invoice. Larger or multi-site scopes scale with audit days. Last verified 10 September 2026. Not legal advice.
| Cost component | Typical/illustrative range | Driver | Kind of text |
|---|---|---|---|
| Certification-body Stage 1 and Stage 2 fees | Often low-to-mid five figures USD for a small single-site software ISMS; higher when IAF MD 5 adds days | Effective personnel, complexity, number of sites, standard (ISO/IEC 27006) additions | Illustrative commercial range — not a quote. |
| Surveillance audits (usually years 1 and 2) | Typically a fraction of the initial audit-day count, invoiced each surveillance year | Partial sample; scope change increases days | Illustrative. 17021-1 surveillance practice. |
| Recertification (year 3) | Typically closer to a full audit than to a surveillance visit | Full ISMS reassessment before expiry | Illustrative. |
| Internal effort (staff time) | Often the largest component — months of part-time owners across security, engineering, and leadership | Whether Clauses 4–10 already exist; evidence quality | Illustrative programme cost, not a salary survey. |
| Consultants (optional) | From a short readiness review to a full implementation engagement — wide band, ask for a written scope | How much documented information you still lack | Optional commercial choice. Not a mandatory clause. |
| Tooling (optional) | Subscription cost of whatever you already use or newly buy to hold evidence and policies | Whether you replace screenshots with system exports | Optional. This product does not quote a price here. |
| Remediation | Highly variable — from a policy rewrite to multi-month engineering work | Gaps found in readiness or Stage 1 | Illustrative. Not a penalty schedule. |
Legal requirement, regulatory guidance, best practice, or our recommendation
Price is not a kind of legal authority. Last verified 10 September 2026. Not legal advice.
| Statement | Which kind of authority | What it does not mean |
|---|---|---|
| You only need to pay a certification body if you choose accredited certification (or a contract requires it). | Certification standard / contractual demand — ISO 27001 is not a law. | Does not say you must get certified. |
| IAF MD 5 determines accredited audit duration. | IAF mandatory document. | Does not set a global price list. |
| ISO/IEC 17021-1 and ISO/IEC 27006 constrain the body, including impartiality. | CB accreditation standards. | Does not make an unaccredited cheap offer equivalent. |
| Get at least two accredited proposals and compare days, not slogans. | Industry best practice. | Does not rank bodies and does not name a cheapest winner. |
| Budget internal time and remediation separately from the CB invoice. | ShipReady Metrics recommendation. | Does not guarantee savings. |
Worked example (illustrative only)
Example A — small SaaS, one site, existing SOC 2: plan a CB initial fee in the low-to-mid five figures USD, two surveillance invoices across the cycle, a recertification invoice near the end of year 3, plus a larger internal-time number. Example B — no prior ISMS: keep the CB band similar for the same headcount, and raise internal and consultant lines. These are teaching examples, not quotes. Last verified 10 September 2026. Not legal advice.
Checklist
This is the checklist artifact for a budget pack. Last verified 10 September 2026. Not legal advice.
- Does every figure on our slide say typical/illustrative or quote, never guaranteed?
- Have we included surveillance and recertification, not only Stage 1/2?
- Have we included internal time and remediation?
- Did every bidder show IAF-MLA accreditation and an IAF MD 5 day count?
- Have we refused unaccredited “certificates” sold as cheaper?
- Have we compared ISO 27001 cost with SOC 2 only as two different artefacts, not as “better”?
What to do now
These steps do not file and do not start a clock.
- Build a six-line budget: Stage 1/2, surveillance, recert, internal, optional consultant, remediation.
- Read how long certification takes so the years match the invoices.
- Read how to choose a certification body — criteria, not a ranked winner.
- Read SOC 2 vs ISO 27001 if the board is comparing artefacts.
- Re-verify sources; last verified 10 September 2026.
Where this shows up in ShipReady Metrics
Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.
If you already have a session: signed-in app → Compliance evidence collection can reduce some internal hunting. That is a capability statement, not a savings guarantee. ISO 27001 is in the 24-framework library with an Annex A crosswalk to about 72 canonical controls and a density honesty layer — coverage, not a pass.
CB fees remain a contract between you and an accredited certification body.
Primary sources (last verified 10 September 2026)
IAF MD 5; ISO/IEC 27006; IAF CertSearch to verify the body you are paying. ISO/IEC 27001:2022 does not publish a price. Not legal advice.