Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How much does ISO 27001 cost?

Last verified

ISO/IEC 27001 cost is certification-body fees plus internal effort, optional consultants, tooling, and remediation. Figures here are typical and illustrative, not quotes. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.

Budget guide, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. IAF MD 5 and ISO/IEC 27006 influence audit-day counts. There is no cheapest or guaranteed price. Only an IAF-MLA accredited body issues a recognised certificate.

What this page is, and what it is not

Audience: a budget owner who has been given only an “audit fee” and knows that cannot be the whole number.

This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file. Last verified 10 September 2026.

Do not use these rows as a bid. Ask accredited bodies for proposals that show how they applied IAF MD 5.

Cost components and illustrative ranges

Worked example framing: a small single-site software company (tens of people in scope) often sees certification-body initial fees in the low-to-mid five figures in USD, with internal time larger than the invoice. Larger or multi-site scopes scale with audit days. Last verified 10 September 2026. Not legal advice.

ISO 27001 cost components — typical/illustrative, not quotes (not legal advice; last verified 10 September 2026)
Cost componentTypical/illustrative rangeDriverKind of text
Certification-body Stage 1 and Stage 2 feesOften low-to-mid five figures USD for a small single-site software ISMS; higher when IAF MD 5 adds daysEffective personnel, complexity, number of sites, standard (ISO/IEC 27006) additionsIllustrative commercial range — not a quote.
Surveillance audits (usually years 1 and 2)Typically a fraction of the initial audit-day count, invoiced each surveillance yearPartial sample; scope change increases daysIllustrative. 17021-1 surveillance practice.
Recertification (year 3)Typically closer to a full audit than to a surveillance visitFull ISMS reassessment before expiryIllustrative.
Internal effort (staff time)Often the largest component — months of part-time owners across security, engineering, and leadershipWhether Clauses 4–10 already exist; evidence qualityIllustrative programme cost, not a salary survey.
Consultants (optional)From a short readiness review to a full implementation engagement — wide band, ask for a written scopeHow much documented information you still lackOptional commercial choice. Not a mandatory clause.
Tooling (optional)Subscription cost of whatever you already use or newly buy to hold evidence and policiesWhether you replace screenshots with system exportsOptional. This product does not quote a price here.
RemediationHighly variable — from a policy rewrite to multi-month engineering workGaps found in readiness or Stage 1Illustrative. Not a penalty schedule.

Worked example (illustrative only)

Example A — small SaaS, one site, existing SOC 2: plan a CB initial fee in the low-to-mid five figures USD, two surveillance invoices across the cycle, a recertification invoice near the end of year 3, plus a larger internal-time number. Example B — no prior ISMS: keep the CB band similar for the same headcount, and raise internal and consultant lines. These are teaching examples, not quotes. Last verified 10 September 2026. Not legal advice.

Checklist

This is the checklist artifact for a budget pack. Last verified 10 September 2026. Not legal advice.

  • Does every figure on our slide say typical/illustrative or quote, never guaranteed?
  • Have we included surveillance and recertification, not only Stage 1/2?
  • Have we included internal time and remediation?
  • Did every bidder show IAF-MLA accreditation and an IAF MD 5 day count?
  • Have we refused unaccredited “certificates” sold as cheaper?
  • Have we compared ISO 27001 cost with SOC 2 only as two different artefacts, not as “better”?

What to do now

These steps do not file and do not start a clock.

  • Build a six-line budget: Stage 1/2, surveillance, recert, internal, optional consultant, remediation.
  • Read how long certification takes so the years match the invoices.
  • Read how to choose a certification body — criteria, not a ranked winner.
  • Read SOC 2 vs ISO 27001 if the board is comparing artefacts.
  • Re-verify sources; last verified 10 September 2026.

Where this shows up in ShipReady Metrics

Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.

If you already have a session: signed-in app → Compliance evidence collection can reduce some internal hunting. That is a capability statement, not a savings guarantee. ISO 27001 is in the 24-framework library with an Annex A crosswalk to about 72 canonical controls and a density honesty layer — coverage, not a pass.

CB fees remain a contract between you and an accredited certification body.

Primary sources (last verified 10 September 2026)

IAF MD 5; ISO/IEC 27006; IAF CertSearch to verify the body you are paying. ISO/IEC 27001:2022 does not publish a price. Not legal advice.

Frequently asked questions