ZIE MATPROOF OP JOUW STACK — BOEK EEN DEMO VAN 30 MINUTEN

ISO 27001 Certification

What does ISO 27001 really cost?

Transparent cost breakdown for ISO 27001 certification in 2026. Worked examples for organisations of 50, 200, and 500+ staff. Plus the five biggest levers for reducing cost.

2026 figures · based on 100+ certification projects across the UK and EU

TL;DR

ISO 27001 certification cost for a mid-size organisation is typically £22,000 to £130,000 over three years. The cost splits across external audits (£13,000-£35,000), internal effort (£35,000-£70,000 in year one), ISMS tooling (£5,400-£54,000/year), and optional consultancy (£18,000-£90,000). Year 2 and 3 costs drop 30-50% once processes are in place. Modern ISMS software cuts internal effort 50-70%.

Worked examples

Three worked examples.

Figures include external audits, internal effort, tooling, and supporting costs. Advisory optional.

50 staff

Small mid-market

First certification

£38,000 – £62,000

Ongoing (years 2 & 3)

£16,000 – £27,000/yr

  • External audits (Stage 1+2): £9,000-£13,500
  • Internal effort (30-45 days): £18,000-£27,000
  • ISMS software: £5,400-£10,800
  • Policies & training: £3,600-£7,200
  • Advisory buffer: £1,800-£2,700

200 staff

Established mid-market

First certification

£68,000 – £108,000

Ongoing (years 2 & 3)

£27,000 – £50,000/yr

  • External audits (Stage 1+2): £16,000-£25,000
  • Internal effort (60-80 days): £36,000-£54,000
  • ISMS software: £9,000-£22,000
  • Policies & training: £4,500-£9,000
  • Advisory buffer: £2,700-£4,500

500+ staff

Large mid-market / enterprise subsidiary

First certification

£108,000 – £225,000

Ongoing (years 2 & 3)

£50,000 – £90,000/yr

  • External audits (Stage 1+2): £27,000-£45,000
  • Internal effort (80-120 days): £54,000-£108,000
  • ISMS software: £22,000-£54,000
  • Policies & training: £9,000-£18,000
  • Advisory: £9,000-£27,000

Cost reduction

Five levers to cut cost.

Modern ISMS software instead of Excel

Cuts internal effort 50-70%. Typical £18,000-£36,000 saving in year one.

Cross-framework with SOC 2, NIS2, TISAX

One control set feeds multiple certifications. Up to 60% duplication saving on multi-framework programmes.

Tight certification scope

Certify only critical areas. Can halve audit cost.

Get three quotes

Certification bodies vary 30-50% in price. Always benchmark.

Internal audits before Stage 1

Find non-conformities early. Saves expensive remediation after the external audit.

Matproof customers save 30-50% versus classic ISO projects.

Through automated evidence collection, pre-built policy templates, and cross-framework mapping to NIS2, SOC 2 and TISAX, Matproof customers typically reduce internal effort by 50-70%. For a 200-staff organisation that is £27,000-£45,000 saved in year one alone.

Personalised estimate

FAQ

ISO 27001 cost — frequently asked questions

What is the total cost of ISO 27001 certification?+

Total cost of a first-time ISO 27001 certification for a mid-size organisation typically sits between £22,000 and £130,000 over three years. This range covers: external audit fees (£13,000-£35,000 over three years), internal effort for project management, implementation and evidence collection (typically 50-80 person-days), tooling (ISMS software from £450/month up to £4,500/month), optional consultancy (£18,000-£90,000). Internal effort typically drops substantially when modern ISMS software with evidence automation is used.

How much does the external ISO 27001 audit cost?+

External audit cost depends on organisation size, number of sites, scope, and certification body. Typical day rates for accredited auditors: £1,300-£2,200. For a mid-size single-site organisation with ~100 staff: Stage 1 audit (1-2 days, £2,600-£4,400), Stage 2 audit (3-5 days, £6,600-£11,000), annual surveillance audits (1-2 days each), recertification after 3 years. Over the 3-year cycle: approximately £13,000-£26,000 in external audit cost alone.

What internal costs should I budget for?+

The largest costs often hide in internal effort — and are routinely underestimated. Typical line items: project management (20-40 days at £700/day = £14,000-£28,000), information security specialists for implementation (30-60 days), documentation and policies (15-25 days), staff training (0.5 day × headcount), management reviews (4-8 days of leadership time). For a typical mid-size firm this totals £35,000-£70,000 of internal effort in year one.

What tooling costs should I plan for?+

ISMS software is the single biggest lever for reducing cost. Without a tool you lose 50-80% more time on evidence collection, policy maintenance and audit preparation. Typical price ranges: standard ISMS tools (verinice, Fuentis, Antares) £450-£1,800/month, enterprise GRC platforms (ServiceNow GRC, RSA Archer) £2,700-£13,500/month, modern multi-framework platforms like Matproof £900-£4,500/month with significantly higher automation. Annual cost: £5,400-£54,000 depending on ambition.

Do I need to hire an external consultant?+

Not strictly — but a consultant typically shortens certification from 12-18 months to 6-9 months. Consultant costs for first-time certification: fixed-scope advisory £18,000-£35,000, 6-month embedded support £45,000-£70,000, full-project implementation £70,000-£130,000. Alternative: modern ISMS software with built-in templates and expert components (e.g. Matproof's partnership model at £1,800-£3,500/month) can significantly reduce the need for external consultants.

How do I reduce ISO 27001 costs?+

Five levers: (1) Tight scope — certify only critical areas, not the whole organisation. (2) Modern ISMS software with evidence automation reduces internal effort 50-70%. (3) Combine with other certifications (SOC 2, NIS2, TISAX) for cross-framework reuse. (4) Run internal audits before the external Stage 1 — reduces surprises. (5) Get three quotes from certification bodies — prices vary significantly between bodies.

How much does recertification cost after three years?+

Recertification (mandatory every three years) is usually 30-50% cheaper than the first certification: external audit cost £7,000-£16,000, internal effort 15-30 person-days (because processes are established), and with continuous-monitoring software often less, because the system shows current compliance status on demand. Annual surveillance audits (£3,500-£7,000 each) fall between certification cycles — the system must be maintained continuously.

What does 'ISO 27001 accredited' mean?+

An ISO 27001 accredited certification is one issued by a certification body that is itself accredited by a national accreditation authority (UKAS in the UK, DAkkS in Germany, RvA in the Netherlands). Only accredited certifications are recognised by regulators and enterprise buyers. Non-accredited certificates are typically 40-60% cheaper but carry no regulatory weight. Always check UKAS (or local equivalent) accreditation before paying for an audit.

Get started

Your ISO 27001 cost estimate in 15 minutes.

We build a personalised budget projection for your organisation — based on size, scope, existing structure, and desired timeline.