ISO 27001 Certification

What does ISO 27001 really cost?

Transparent cost breakdown for ISO 27001 certification in 2026. Worked examples for organisations of 50, 200, and 500+ staff. Plus the five biggest levers for reducing cost.

Get a cost estimateFree readiness check

2026 figures · based on 100+ certification projects across the UK and EU

TL;DR

ISO 27001 certification cost for a mid-size organisation is typically £22,000 to £130,000 over three years. The cost splits across external audits (£13,000-£35,000), internal effort (£35,000-£70,000 in year one), ISMS tooling (£5,400-£54,000/year), and optional consultancy (£18,000-£90,000). Year 2 and 3 costs drop 30-50% once processes are in place. Modern ISMS software cuts internal effort 50-70%.

Worked examples

Three worked examples.

Figures include external audits, internal effort, tooling, and supporting costs. Advisory optional.

50 staff

Small mid-market

First certification

£38,000 – £62,000

Ongoing (years 2 & 3)

£16,000 – £27,000/yr

  • External audits (Stage 1+2): £9,000-£13,500
  • Internal effort (30-45 days): £18,000-£27,000
  • ISMS software: £5,400-£10,800
  • Policies & training: £3,600-£7,200
  • Advisory buffer: £1,800-£2,700

200 staff

Established mid-market

First certification

£68,000 – £108,000

Ongoing (years 2 & 3)

£27,000 – £50,000/yr

  • External audits (Stage 1+2): £16,000-£25,000
  • Internal effort (60-80 days): £36,000-£54,000
  • ISMS software: £9,000-£22,000
  • Policies & training: £4,500-£9,000
  • Advisory buffer: £2,700-£4,500

500+ staff

Large mid-market / enterprise subsidiary

First certification

£108,000 – £225,000

Ongoing (years 2 & 3)

£50,000 – £90,000/yr

  • External audits (Stage 1+2): £27,000-£45,000
  • Internal effort (80-120 days): £54,000-£108,000
  • ISMS software: £22,000-£54,000
  • Policies & training: £9,000-£18,000
  • Advisory: £9,000-£27,000

Cost reduction

Five levers to cut cost.

Modern ISMS software instead of Excel

Cuts internal effort 50-70%. Typical £18,000-£36,000 saving in year one.

Cross-framework with SOC 2, NIS2, TISAX

One control set feeds multiple certifications. Up to 60% duplication saving on multi-framework programmes.

Tight certification scope

Certify only critical areas. Can halve audit cost.

Get three quotes

Certification bodies vary 30-50% in price. Always benchmark.

Internal audits before Stage 1

Find non-conformities early. Saves expensive remediation after the external audit.

Matproof customers save 30-50% versus classic ISO projects.

Through automated evidence collection, pre-built policy templates, and cross-framework mapping to NIS2, SOC 2 and TISAX, Matproof customers typically reduce internal effort by 50-70%. For a 200-staff organisation that is £27,000-£45,000 saved in year one alone.

Personalised estimate

FAQ

ISO 27001 cost — frequently asked questions

What is the total cost of ISO 27001 certification?+

Total cost of a first-time ISO 27001 certification for a mid-size organisation typically sits between £22,000 and £130,000 over three years. This range covers: external audit fees (£13,000-£35,000 over three years), internal effort for project management, implementation and evidence collection (typically 50-80 person-days), tooling (ISMS software from £450/month up to £4,500/month), optional consultancy (£18,000-£90,000). Internal effort drops 40-70% when modern ISMS software is used.

How much does the external ISO 27001 audit cost?+

External audit cost depends on organisation size, number of sites, scope, and certification body. Typical day rates for accredited auditors: £1,300-£2,200. For a mid-size single-site organisation with ~100 staff: Stage 1 audit (1-2 days, £2,600-£4,400), Stage 2 audit (3-5 days, £6,600-£11,000), annual surveillance audits (1-2 days each), recertification after 3 years. Over the 3-year cycle: approximately £13,000-£26,000 in external audit cost alone.

What internal costs should I budget for?+

The largest costs often hide in internal effort — and are routinely underestimated. Typical line items: project management (20-40 days at £700/day = £14,000-£28,000), information security specialists for implementation (30-60 days), documentation and policies (15-25 days), staff training (0.5 day × headcount), management reviews (4-8 days of leadership time). For a typical mid-size firm this totals £35,000-£70,000 of internal effort in year one.

What tooling costs should I plan for?+

ISMS software is the single biggest lever for reducing cost. Without a tool you lose 50-80% more time on evidence collection, policy maintenance and audit preparation. Typical price ranges: standard ISMS tools (verinice, Fuentis, Antares) £450-£1,800/month, enterprise GRC platforms (ServiceNow GRC, RSA Archer) £2,700-£13,500/month, modern multi-framework platforms like Matproof £900-£4,500/month with significantly higher automation. Annual cost: £5,400-£54,000 depending on ambition.

Do I need to hire an external consultant?+

Not strictly — but a consultant typically shortens certification from 12-18 months to 6-9 months. Consultant costs for first-time certification: fixed-scope advisory £18,000-£35,000, 6-month embedded support £45,000-£70,000, full-project implementation £70,000-£130,000. Alternative: modern ISMS software with built-in templates and expert components (e.g. Matproof's partnership model at £1,800-£3,500/month) reduces consultant need by 60-80%.

How do I reduce ISO 27001 costs?+

Five levers: (1) Tight scope — certify only critical areas, not the whole organisation. (2) Modern ISMS software with evidence automation reduces internal effort 50-70%. (3) Combine with other certifications (SOC 2, NIS2, TISAX) for cross-framework reuse. (4) Run internal audits before the external Stage 1 — reduces surprises. (5) Get three quotes from certification bodies — prices vary 30-50%. Matproof customers typically report 30-50% cost reduction versus classic ISO projects.

How much does recertification cost after three years?+

Recertification (mandatory every three years) is usually 30-50% cheaper than the first certification: external audit cost £7,000-£16,000, internal effort 15-30 person-days (because processes are established), and for Matproof customers often minimal because the system shows current compliance status on demand. Annual surveillance audits (£3,500-£7,000 each) fall between certification cycles — the system must be maintained continuously.

What does 'ISO 27001 accredited' mean?+

An ISO 27001 accredited certification is one issued by a certification body that is itself accredited by a national accreditation authority (UKAS in the UK, DAkkS in Germany, RvA in the Netherlands). Only accredited certifications are recognised by regulators and enterprise buyers. Non-accredited certificates are typically 40-60% cheaper but carry no regulatory weight. Always check UKAS (or local equivalent) accreditation before paying for an audit.

Get started

Your ISO 27001 cost estimate in 15 minutes.

We build a personalised budget projection for your organisation — based on size, scope, existing structure, and desired timeline.

Request cost estimateSee ISO 27001 software →