Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

ISO 27001 audit cost: how certification body fees are set

An audit fee is audit days multiplied by a day rate. No accredited certification body publishes its day rate, and the tables that determine audit days are sold by ISO rather than published. Both inputs are unpublished, so we do not print a fee. Here is what genuinely sets the number, and how to make a quote defensible.

Updated July 2026

The standard that governs ISMS audit time

ISO/IEC 27006-1:2024

Information security, cybersecurity and privacy protection. Requirements for bodies providing audit and certification of information security management systems. Part 1: General

"This document specifies requirements and provides guidance for bodies providing audit and certification of an information security management system (ISMS), in addition to the requirements contained within ISO/IEC 17021-1."

This is the standard your certification body must satisfy in order to be accredited to issue your certificate at all. Audit time is not a matter of the body's preference: it is a requirement of the standard that accredits them.

AnnexStatusCovers
Annex AnormativeKnowledge and skills for ISMS auditing and certification
Annex BinformativeFurther competence considerations
Annex CnormativeAudit time
Annex DinformativeMethods for audit time calculations
Annex EinformativeGuidance for review of implemented ISO/IEC 27001:2022, Annex A controls

Published March 2024. ISO catalogue entry

Why this page carries no audit-day table

The ISMS audit-time provisions are in Annex C, which is normative. ISO sells ISO/IEC 27006-1:2024; the annex tables are not in the free preview. We have not read them, so we do not reproduce them, and we will not rebuild them out of a table written for a different certification scheme. Your certification body holds the standard, applies Annex C to your scope, and should be able to tell you the audit days it determined and the basis for them. That is a fair question to ask, and a body that cannot answer it is telling you something useful.

Where IAF MD 5 fits, and where it does not

IAF MD 5:2023 is titled "Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems". It states its own application plainly:

"This document is mandatory for the consistent application of the relevant clauses of ISO/IEC 17021-1 for audits of quality, environmental and occupational health and safety management systems."

Information security management systems are outside that scope, and the document carries no ISMS audit-time table. MD 5 matters to an ISO 27001 buyer in exactly one situation: an integrated management system. If you certify ISO 9001 or ISO 14001 alongside ISO 27001, MD 5 governs the audit time on those schemes while ISO/IEC 27006-1:2024 governs the ISMS side, and a combined audit is scheduled against both.

The IAF mandatory documents that do address ISMS are these:

  • IAF MD 13 Knowledge Requirements for Accreditation Body Personnel for Information Security Management Systems (ISO/IEC 27001)
  • IAF MD 26 Transition Requirements for ISO/IEC 27001:2022
  • IAF MD 29 Transition Requirements for ISO/IEC 27006-1:2024

Issue 4, Version 3, issued 14 June 2023. Read IAF MD 5 | IAF document register

What actually drives your audit days

These are the drivers the standard and the accreditation bodies name. They are drivers, not a formula: we do not hold the Annex C tables and we do not reconstruct them. Knowing the drivers is still what lets you interrogate a quote.

Number of persons doing work under the organisation's control, within the ISMS scope

The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.

ISMS scope

What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.

Complexity and risk of the ISMS

Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.

Sites

Where scoped activities physically happen, and whether multi-site sampling applies.

Delivery mode

How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.

The headcount driver is the one most often misunderstood. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation. A 40-employee company running 25 contractors inside its scope is not a 40-person audit. Getting this number right before you request quotes is the difference between a quote that holds and a quote that is revised upward after Stage 1.

Stage 1 and Stage 2

Initial certification is a two-stage audit. The certification body determines the total audit time and how it splits across the stages. We do not publish a split percentage, because the split is set per engagement under the same annex we cannot read.

Stage 1: is the ISMS auditable

  • Reviews ISMS scope, risk assessment, Statement of Applicability, management review
  • Confirms the ISMS is designed and documented well enough to be tested
  • Surfaces readiness gaps while there is still time to close them
  • Often runs partly or wholly remotely

Stage 2: is the ISMS working

  • Tests whether controls are implemented and effective in practice
  • Samples evidence and interviews people across the scope
  • Raises non-conformities that must be closed before certification
  • Certificate issued once outstanding non-conformities are resolved

The cost is a three-year cycle, not a one-off

ISO 27001 certification runs on a three-year cycle: the two-stage initial audit, surveillance audits in the intervening years, and a recertification audit before the certificate expires. Surveillance audits are shorter than the initial audit and are also determined under ISO/IEC 27006-1:2024 and quoted per engagement.

A year-one quote is therefore not your cost of certification. Ask every body to price the full cycle up front, including surveillance and recertification, and to state what happens to the rate across the three years. A cheaper year one with unstated surveillance is not a cheaper programme. See the three-year cycle page.

Check accreditation on the register, not the brochure

Accreditation is the one thing about a certification body that is genuinely public and independently verifiable. Accreditation bodies publish registers stating exactly which schemes each certification body is accredited for. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001, and the register is where you confirm which you are buying.

  • UKAS: Published 1 March 2024. UKAS-accredited ISMS certification bodies were required to complete transition by 31 July 2025. Technical bulletin
  • ANAB: ANAB-accredited and applicant ISMS certification bodies were required to apply ISO/IEC 27006-1:2024 to all clients no later than 31 March 2026. Transition notice

Both deadlines have now passed, so any body quoting you today should be determining your audit time under ISO/IEC 27006-1:2024. Asking a body to confirm that is a reasonable question and a good test of who you are dealing with.

How to source a defensible quote

  1. Fix your scope before you call anyone. Scope is the largest lever you control and the largest source of quote variance. An ambiguous scope invites a defensive estimate.
  2. Count the right people. Everyone doing work under your control inside the ISMS scope, contractors and freelancers included. Undercounting here is the most common cause of a revised quote.
  3. Send every body an identical brief. Scope, headcount on the definition above, sites, and remote versus on-site appetite. Quotes built on different briefs cannot be compared.
  4. Ask for the audit days, not just the price. Days are the determined quantity under ISO/IEC 27006-1:2024. A body that will state its days is a body you can hold to a scope.
  5. Price the whole cycle. Initial audit, surveillance, recertification, and what happens to the rate over three years.
  6. Confirm accreditation for ISO/IEC 27001 on the register. Not for ISO 9001, and not from the brochure.
  7. Get travel and expenses stated separately. These sit outside audit time and are a real line in an on-site audit.

Frequently asked questions

How are ISO 27001 audit fees calculated?
An audit fee is audit days multiplied by the certification body's rate, but neither input is published. Audit days are determined by the body under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C, with methods for audit time calculations in the informative Annex D. ISO sells that standard rather than publishing it openly. The day rate is commercial and no accredited body publishes one. This is why a real quote requires a real conversation about your scope.
Which standard sets ISO 27001 audit duration?
ISO/IEC 27006-1:2024. Its scope clause states that it 'specifies requirements and provides guidance for bodies providing audit and certification of an information security management system (ISMS), in addition to the requirements contained within ISO/IEC 17021-1'. It was published in March 2024. UKAS-accredited bodies were required to complete transition to it by 31 July 2025, and ANAB-accredited bodies were required to apply it to all clients by 31 March 2026.
Does IAF MD 5 apply to ISO 27001?
No. IAF MD 5:2023 is titled 'Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems', and it states that it is mandatory for the consistent application of the relevant clauses of ISO/IEC 17021-1 for audits of quality, environmental and occupational health and safety management systems. Information security management systems sit outside its scope and it contains no ISMS audit-time table. If you certify ISO 9001 and ISO 27001 together, MD 5 governs audit time on the ISO 9001 side and ISO/IEC 27006-1 governs the ISMS side.
What drives the number of audit days?
The primary input under ISO/IEC 27006-1:2024 is the number of people doing work under the organisation's control within the ISMS scope, counted regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total. Audit time also reflects the ISMS scope itself, the complexity and risk of the ISMS including the criticality of the information handled, the sites involved, and how much of the audit runs remotely rather than on site.
What is the difference between Stage 1 and Stage 2?
Certification runs as a two-stage initial audit. Stage 1 reviews whether the ISMS is designed and documented well enough to be audited, covering the scope, the risk assessment, the Statement of Applicability and management review. Stage 2 tests whether the ISMS is actually implemented and effective, sampling evidence across the scope. The certification body determines how the total audit time it has calculated is split between the two stages, and both stages sit inside the audit time it quotes.
How do I get a defensible audit quote?
Approach more than one accredited body with an identical brief: your ISMS scope, the number of people doing work under your control inside that scope including contractors, your sites, and how much of the audit can run remotely. Ask each body to state the audit days it has determined, to confirm its accreditation for ISO/IEC 27001, and to set out surveillance and recertification for the full three-year cycle rather than year one alone. Comparing quotes is only meaningful when the scope brief is identical.
How do I check a certification body is genuinely accredited?
Check the accreditation body's own public register rather than the certification body's marketing material. UKAS publishes schedules of accreditation, and ANAB publishes an accreditation directory. Both state the exact schemes each body is accredited for, and accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001. An unaccredited certificate is often refused in procurement.

Updated July 2026