ISO 27001 Certification
What does ISO 27001 really cost?
Transparent cost breakdown for ISO 27001 certification in 2026. Worked examples for organisations of 50, 200, and 500+ staff. Plus the five biggest levers for reducing cost.
2026 figures · based on 100+ certification projects across the UK and EU
TL;DR
ISO 27001 certification cost for a mid-size organisation is typically £22,000 to £130,000 over three years. The cost splits across external audits (£13,000-£35,000), internal effort (£35,000-£70,000 in year one), ISMS tooling (£5,400-£54,000/year), and optional consultancy (£18,000-£90,000). Year 2 and 3 costs drop 30-50% once processes are in place. Modern ISMS software cuts internal effort 50-70%.
Worked examples
Three worked examples.
Figures include external audits, internal effort, tooling, and supporting costs. Advisory optional.
50 staff
Small mid-market
First certification
£38,000 – £62,000
Ongoing (years 2 & 3)
£16,000 – £27,000/yr
- External audits (Stage 1+2): £9,000-£13,500
- Internal effort (30-45 days): £18,000-£27,000
- ISMS software: £5,400-£10,800
- Policies & training: £3,600-£7,200
- Advisory buffer: £1,800-£2,700
200 staff
Established mid-market
First certification
£68,000 – £108,000
Ongoing (years 2 & 3)
£27,000 – £50,000/yr
- External audits (Stage 1+2): £16,000-£25,000
- Internal effort (60-80 days): £36,000-£54,000
- ISMS software: £9,000-£22,000
- Policies & training: £4,500-£9,000
- Advisory buffer: £2,700-£4,500
500+ staff
Large mid-market / enterprise subsidiary
First certification
£108,000 – £225,000
Ongoing (years 2 & 3)
£50,000 – £90,000/yr
- External audits (Stage 1+2): £27,000-£45,000
- Internal effort (80-120 days): £54,000-£108,000
- ISMS software: £22,000-£54,000
- Policies & training: £9,000-£18,000
- Advisory: £9,000-£27,000
Cost reduction
Five levers to cut cost.
Modern ISMS software instead of Excel
Cuts internal effort 50-70%. Typical £18,000-£36,000 saving in year one.
Cross-framework with SOC 2, NIS2, TISAX
One control set feeds multiple certifications. Up to 60% duplication saving on multi-framework programmes.
Tight certification scope
Certify only critical areas. Can halve audit cost.
Get three quotes
Certification bodies vary 30-50% in price. Always benchmark.
Internal audits before Stage 1
Find non-conformities early. Saves expensive remediation after the external audit.
Matproof customers save 30-50% versus classic ISO projects.
Through automated evidence collection, pre-built policy templates, and cross-framework mapping to NIS2, SOC 2 and TISAX, Matproof customers typically reduce internal effort by 50-70%. For a 200-staff organisation that is £27,000-£45,000 saved in year one alone.
Personalised estimateFAQ
ISO 27001 cost — frequently asked questions
What is the total cost of ISO 27001 certification?+
Total cost of a first-time ISO 27001 certification for a mid-size organisation typically sits between £22,000 and £130,000 over three years. This range covers: external audit fees (£13,000-£35,000 over three years), internal effort for project management, implementation and evidence collection (typically 50-80 person-days), tooling (ISMS software from £450/month up to £4,500/month), optional consultancy (£18,000-£90,000). Internal effort drops 40-70% when modern ISMS software is used.
How much does the external ISO 27001 audit cost?+
External audit cost depends on organisation size, number of sites, scope, and certification body. Typical day rates for accredited auditors: £1,300-£2,200. For a mid-size single-site organisation with ~100 staff: Stage 1 audit (1-2 days, £2,600-£4,400), Stage 2 audit (3-5 days, £6,600-£11,000), annual surveillance audits (1-2 days each), recertification after 3 years. Over the 3-year cycle: approximately £13,000-£26,000 in external audit cost alone.
What internal costs should I budget for?+
The largest costs often hide in internal effort — and are routinely underestimated. Typical line items: project management (20-40 days at £700/day = £14,000-£28,000), information security specialists for implementation (30-60 days), documentation and policies (15-25 days), staff training (0.5 day × headcount), management reviews (4-8 days of leadership time). For a typical mid-size firm this totals £35,000-£70,000 of internal effort in year one.
What tooling costs should I plan for?+
ISMS software is the single biggest lever for reducing cost. Without a tool you lose 50-80% more time on evidence collection, policy maintenance and audit preparation. Typical price ranges: standard ISMS tools (verinice, Fuentis, Antares) £450-£1,800/month, enterprise GRC platforms (ServiceNow GRC, RSA Archer) £2,700-£13,500/month, modern multi-framework platforms like Matproof £900-£4,500/month with significantly higher automation. Annual cost: £5,400-£54,000 depending on ambition.
Do I need to hire an external consultant?+
Not strictly — but a consultant typically shortens certification from 12-18 months to 6-9 months. Consultant costs for first-time certification: fixed-scope advisory £18,000-£35,000, 6-month embedded support £45,000-£70,000, full-project implementation £70,000-£130,000. Alternative: modern ISMS software with built-in templates and expert components (e.g. Matproof's partnership model at £1,800-£3,500/month) reduces consultant need by 60-80%.
How do I reduce ISO 27001 costs?+
Five levers: (1) Tight scope — certify only critical areas, not the whole organisation. (2) Modern ISMS software with evidence automation reduces internal effort 50-70%. (3) Combine with other certifications (SOC 2, NIS2, TISAX) for cross-framework reuse. (4) Run internal audits before the external Stage 1 — reduces surprises. (5) Get three quotes from certification bodies — prices vary 30-50%. Matproof customers typically report 30-50% cost reduction versus classic ISO projects.
How much does recertification cost after three years?+
Recertification (mandatory every three years) is usually 30-50% cheaper than the first certification: external audit cost £7,000-£16,000, internal effort 15-30 person-days (because processes are established), and for Matproof customers often minimal because the system shows current compliance status on demand. Annual surveillance audits (£3,500-£7,000 each) fall between certification cycles — the system must be maintained continuously.
What does 'ISO 27001 accredited' mean?+
An ISO 27001 accredited certification is one issued by a certification body that is itself accredited by a national accreditation authority (UKAS in the UK, DAkkS in Germany, RvA in the Netherlands). Only accredited certifications are recognised by regulators and enterprise buyers. Non-accredited certificates are typically 40-60% cheaper but carry no regulatory weight. Always check UKAS (or local equivalent) accreditation before paying for an audit.
Get started
Your ISO 27001 cost estimate in 15 minutes.
We build a personalised budget projection for your organisation — based on size, scope, existing structure, and desired timeline.