BSI ISO 27001 cost: accreditation, audit time and how to get a quote
BSI publishes no rate card and no day rate for ISO 27001, and the tables that determine audit days are sold by ISO rather than published. So this page carries no fee. What it does carry is the part of BSI that is genuinely public and independently checkable: its UKAS schedule of accreditation, what that schedule actually covers, and what will drive the number BSI quotes you.
Updated July 2026
BSI on the UKAS register
Legal entity
BSI Assurance UK Ltd
Accreditation body
UKAS
Accreditation number
0003
ISO/IEC 27001 on the schedule
Confirmed, read from the schedule
Scope line, verbatim
"Information Security Management Systems (ISMS) to ISO/IEC 27001:2022"
Checked July 2026 by downloading the schedule and reading its accredited scope. Schedule of accreditation 0003 | UKAS register
The UK national standards body and the organisation that published BS 7799, the British standard from which ISO/IEC 27001 descends. Its UKAS schedule is one of the broadest in the register, spanning ISMS alongside quality, environmental, health and safety, business continuity and AI management systems.
Accreditation attaches to a legal entity, not to a global brand. BSI Assurance UK Ltd is the entity UKAS accredits, and it is the entity that must appear on your certificate for the accreditation to mean anything. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001: they are separate scheme entries on the schedule, and the register is where you confirm which you are buying.
The breadth of the schedule is the BSI-specific fact
The same schedule also carries ISO/IEC 42001 AI management systems, which matters if you intend to certify both against one integrated programme.
This is worth settling before you request a quote rather than after. If your roadmap is ISO 27001 today and an AI management system or a business continuity certificate within the cycle, then whether one body is accredited for all of them changes how the programme is scheduled and audited. A body accredited only for ISMS can certify your ISMS perfectly well and cannot touch the rest, which means a second body, a second audit programme and a second set of dates.
The register settles that question. Open the schedule, read the scheme list, and confirm each standard you intend to certify appears on it under the entity that would issue your certificate. Then put the scheme list in the brief you send out, because a body quoting a single-scheme ISMS engagement and a body quoting an integrated programme are not quoting the same thing.
Why there is no BSI fee on this page
An audit fee is audit days multiplied by a rate, and both inputs are unpublished.
The rate is commercial. BSI quotes per engagement. No accredited certification body publishes a day rate, and the accreditation registers publish accreditation status only, never anything commercial. There is no rack rate anywhere in this market to quote, to discount from, or to rank bodies against.
The days are behind a paywall. ISMS audit time is determined under ISO/IEC 27006-1:2024. The audit-time provisions are its normative Annex C, with methods for audit time calculations in the informative Annex D. ISO sells that standard and the annex tables are not in the free preview. We have not read them, so we do not reproduce them, and we will not rebuild them from a table written for a different certification scheme.
BSI holds the standard, applies Annex C to your scope, and can tell you the audit days it determined and the basis for them. Ask for that. It is the quantity the standard actually governs, and a body that will state its days is a body you can hold to a scope. More on how audit fees are set.
What actually drives your quote from BSI
These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are drivers, not a formula. Knowing them is what lets you interrogate a quote and change the inputs that are yours to change.
Number of persons doing work under the organisation's control, within the ISMS scope
The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.
ISMS scope
What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.
Complexity and risk of the ISMS
Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.
Sites
Where scoped activities physically happen, and whether multi-site sampling applies.
Delivery mode
How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.
The headcount driver is the one most often got wrong. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation, so a 40-employee company running 25 contractors inside its scope is not a 40-person audit. Fixing that number before you request a quote is the difference between a quote that holds and a quote revised upward after Stage 1.
Price the three-year cycle, not year one
Year one
Two-stage initial audit
Stage 1 tests whether the ISMS is designed and documented well enough to be audited. Stage 2 tests whether it is implemented and effective. BSI determines the total audit time and how it splits across the two stages.
Intervening years
Surveillance audits
Shorter than the initial audit, also determined under ISO/IEC 27006-1:2024, also quoted per engagement. They are not optional and they are part of your cost of certification.
Before expiry
Recertification
The certificate expires and a recertification audit is required to renew it. Ask what happens to the rate across the three years before you sign year one.
A year-one quote is not your cost of certification. A cheaper year one with unstated surveillance is not a cheaper programme. See the three-year cycle page.
How to get a comparable quote from BSI
- Write the scope brief once and send it unchanged to every body. Scope, headcount on the ISO/IEC 27006-1:2024 definition, sites, remote versus on-site appetite, and every scheme you intend to certify. Different briefs produce numbers that cannot be compared.
- Ask BSI to state the audit days it determined. Days are the quantity the standard governs. A price without days is not a quote you can interrogate.
- Confirm accreditation number 0003 covers the scheme you are buying. On the register, under the entity that will issue the certificate, not from marketing material.
- Ask BSI to price the full cycle. Initial audit, surveillance, recertification, and what happens to the rate across three years.
- Get travel and expenses stated separately. They sit outside audit time and are a real line on an on-site audit.
- Confirm audit time is determined under ISO/IEC 27006-1:2024. Both the UKAS and ANAB transition deadlines have passed, so any body quoting today should be applying it.
Verify accreditation yourself: UKAS register | ANAB directory