ISO 27001 Certification Cost: The Full Breakdown

A 20 to 200 person company should plan for $35,000 to $120,000 to reach ISO 27001 certification and get through the first three-year cycle. The certification body audit itself, Stage 1 plus Stage 2, runs $6,000 to $30,000 depending on headcount and scope. Implementation is the larger and more variable line: $15,000 to $60,000 with consultant support, or six to twelve months of internal effort without it. The mandatory internal audit adds $5,000 to $15,000 if outsourced. Surveillance audits cost $4,000 to $12,000 in each of the two years after certification, and recertification lands near the initial audit fee. One boundary worth setting early: BD Emerson is not a certification body. We implement and we audit internally; an accredited registrar issues the certificate.
How certification bodies price the audit
Accredited certification bodies price on auditor-days, and auditor-days are set by tables the accreditation rules require them to follow (IAF MD 5), driven by the number of people doing work in scope, the number of sites, and technical complexity. Day rates run $1,200 to $2,000. That makes fees fairly predictable once you know your scope:
- Under 25 people in scope: roughly 4 to 6 auditor-days initial, $6,000 to $12,000
- 25 to 100 people: 6 to 10 days, $9,000 to $18,000
- 100 to 500 people: 10 to 18 days, $15,000 to $35,000
- Larger or multi-site, multi-country scopes: $35,000 to $75,000 and climbing with site sampling
Stage 1 is a documentation and readiness review, often remote, one or two days. Stage 2 is the full audit of whether the ISMS actually operates. Both are included in the ranges above. Two cautions. First, scope is a design decision: certifying the product engineering organization rather than the entire company is often legitimate and materially cheaper, provided the scope statement still covers what your customers are buying. Second, only accredited certificates count. A certificate from an unaccredited body, and there are mills selling them, fails the first customer due-diligence check that looks the registrar up in the ANAB or UKAS directory.
What moves you inside those ranges
Site count matters more than headcount past a point, because each additional location pulls sampling days. Complexity of the technology estate matters too: a cloud-native software company audits faster than a firm running its own data centers and OT networks. Certification body brand carries a real spread, with the largest international registrars pricing 20 to 40 percent above smaller accredited bodies for the same accredited outcome. Combining audits pays: bodies discount when ISO 27001 runs alongside ISO 27701, ISO 22301, or ISO 42001 in an integrated audit, since shared management-system clauses get audited once. None of this changes the biggest lever, which is scoping the ISMS to the part of the business that actually needs the certificate.
Implementation: the bigger number
The audit verifies an ISMS; someone still has to build one. That means a risk assessment and treatment plan, a Statement of Applicability across the 93 Annex A controls, policies people actually follow, supplier review, internal metrics, management review, and the evidence trail proving all of it runs. Starting from a reasonable security baseline, expect six to twelve months elapsed.
Done purely internally, the cash cost is zero and the real cost is 300 to 600 hours of someone senior, plus the risk of building it wrong and discovering that at Stage 2. Consultant-supported implementation runs $15,000 to $60,000, with the range driven by starting maturity, headcount, and whether the consultant writes with you or merely reviews what you wrote. Companies already holding SOC 2 sit at the low end because the control overlap is large, an overlap covered in achieving SOC 2 and ISO 27001 simultaneously. Companies starting from no formal program, or folding in a second business unit, sit at the top.
Two things consistently blow implementation budgets: scope creep, where the ISMS quietly grows to cover departments no customer asked about, and policy libraries imported wholesale from templates that describe a company you are not. Certification auditors read borrowed policies as exactly that, and the rework lands in the worst weeks, right before Stage 2.
The internal audit you cannot skip
Clause 9.2 requires an internal audit of the ISMS before certification and on a program thereafter, performed by someone independent of the thing they are auditing. In a 1,000-person company that can be an internal audit function. In an 80-person company there is usually nobody who is both competent to audit an ISMS and independent of having built it, which is why this is the most commonly outsourced piece of the whole program. Expect $5,000 to $15,000 for a credible external internal audit, scaled by scope. It is also the cheapest place to find your Stage 2 problems while they are still yours to fix quietly. The certification body cannot do this work for you; auditing the ISMS and then certifying it would put them on both sides of their own opinion.
The three-year cycle
Certification is not an event with a renewal, it is a cycle. Year one: Stage 1 and Stage 2, certificate issued, valid for three years. Years two and three: surveillance audits, smaller in scope, typically a third to half the initial auditor-days, so $4,000 to $12,000 each for most mid-sized scopes. End of year three: recertification, close to the initial fee. Your internal audit and management review run every year regardless. Miss a surveillance audit and the certificate is suspended, which surfaces in customer procurement checks at the worst possible moment. Budget the cycle, not the certificate.
A worked example
Take a 100-person SaaS company, single site, certifying its whole operation with consultant support and a compliance platform. Implementation lands at $30,000 to $40,000 over roughly eight months. The internal audit, outsourced, costs $8,000. Stage 1 and Stage 2 with a mid-tier accredited body come in around $14,000 to $18,000. Tooling runs $15,000 for the year, and training two staff members adds $5,000. Year one total: roughly $75,000, plus a few hundred internal hours. Years two and three each carry a $6,000 to $8,000 surveillance audit, the annual internal audit, and the tooling renewal, call it $30,000 a year. Full first cycle: around $135,000, of which the certification body collected less than a quarter. That ratio is the point. The registrar's invoice is the visible cost, not the main one.
The costs that do not appear on quotes
Tooling: a compliance automation platform helps here exactly as it does for SOC 2, at $8,000 to $25,000 per year depending on headcount, plus risk-register or GRC tooling if you outgrow spreadsheets. Training: Clause 7.2 expects demonstrated competence, and lead implementer or internal auditor training runs $1,500 to $3,500 a seat. Evidence time: 150 to 400 internal hours in year one spread across engineering, IT, and people operations, which is payroll spent on compliance rather than product. Penetration testing if your Statement of Applicability says you do it: $8,000 to $25,000. None of this is optional in the sense that matters, because the Stage 2 auditor will ask to see all of it. Timing matters as much as totals: implementation spend starts in month one, tooling bills at signature, and the internal audit plus both certification stages all land in a two or three month window at the end, so finance teams expecting a smooth curve meet a spike instead.
Who does what, and the line we do not cross
Three distinct roles keep the system credible. An implementer builds the ISMS with you. An internal auditor checks it independently. A certification body, accredited by ANAB, UKAS, or a peer, audits it and issues the certificate. The roles are separated for a reason: a firm that builds your ISMS and also hands you the certificate is grading its own work, and accredited certification bodies are barred from consulting for the clients they certify. BD Emerson is not a certification body and does not issue certificates. We do the implementation work and we perform Clause 9.2 internal audits, keeping the two independent when both are in play, and we help you select and manage the registrar relationship from your side of the table. If a vendor offers you implementation and a certificate in one contract, the certificate will not survive scrutiny.
Where BD Emerson fits
Our ISO 27001 consulting practice runs implementation end to end: scoping decisions that keep auditor-days down, the risk assessment, the Statement of Applicability, policies, and the evidence cadence that makes Stage 2 uneventful. Separately, our ISO 27001 internal audit service covers the Clause 9.2 requirement with auditors who have sat through enough Stage 2s to know where certification bodies push. Every number above narrows once scope is real, and scoping is the first conversation worth having.
