Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

BSI ISO 27001 cost: accreditation, audit time and how to get a quote

BSI publishes no rate card and no day rate for ISO 27001, and the tables that determine audit days are sold by ISO rather than published. So this page carries no fee. What it does carry is the part of BSI that is genuinely public and independently checkable: its UKAS schedule of accreditation, what that schedule actually covers, and what will drive the number BSI quotes you.

Updated July 2026

BSI on the UKAS register

Legal entity

BSI Assurance UK Ltd

Accreditation body

UKAS

Accreditation number

0003

ISO/IEC 27001 on the schedule

Confirmed, read from the schedule

Scope line, verbatim

"Information Security Management Systems (ISMS) to ISO/IEC 27001:2022"

Checked July 2026 by downloading the schedule and reading its accredited scope. Schedule of accreditation 0003 | UKAS register

The UK national standards body and the organisation that published BS 7799, the British standard from which ISO/IEC 27001 descends. Its UKAS schedule is one of the broadest in the register, spanning ISMS alongside quality, environmental, health and safety, business continuity and AI management systems.

Accreditation attaches to a legal entity, not to a global brand. BSI Assurance UK Ltd is the entity UKAS accredits, and it is the entity that must appear on your certificate for the accreditation to mean anything. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001: they are separate scheme entries on the schedule, and the register is where you confirm which you are buying.

The breadth of the schedule is the BSI-specific fact

The same schedule also carries ISO/IEC 42001 AI management systems, which matters if you intend to certify both against one integrated programme.

This is worth settling before you request a quote rather than after. If your roadmap is ISO 27001 today and an AI management system or a business continuity certificate within the cycle, then whether one body is accredited for all of them changes how the programme is scheduled and audited. A body accredited only for ISMS can certify your ISMS perfectly well and cannot touch the rest, which means a second body, a second audit programme and a second set of dates.

The register settles that question. Open the schedule, read the scheme list, and confirm each standard you intend to certify appears on it under the entity that would issue your certificate. Then put the scheme list in the brief you send out, because a body quoting a single-scheme ISMS engagement and a body quoting an integrated programme are not quoting the same thing.

Why there is no BSI fee on this page

An audit fee is audit days multiplied by a rate, and both inputs are unpublished.

The rate is commercial. BSI quotes per engagement. No accredited certification body publishes a day rate, and the accreditation registers publish accreditation status only, never anything commercial. There is no rack rate anywhere in this market to quote, to discount from, or to rank bodies against.

The days are behind a paywall. ISMS audit time is determined under ISO/IEC 27006-1:2024. The audit-time provisions are its normative Annex C, with methods for audit time calculations in the informative Annex D. ISO sells that standard and the annex tables are not in the free preview. We have not read them, so we do not reproduce them, and we will not rebuild them from a table written for a different certification scheme.

BSI holds the standard, applies Annex C to your scope, and can tell you the audit days it determined and the basis for them. Ask for that. It is the quantity the standard actually governs, and a body that will state its days is a body you can hold to a scope. More on how audit fees are set.

What actually drives your quote from BSI

These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are drivers, not a formula. Knowing them is what lets you interrogate a quote and change the inputs that are yours to change.

Number of persons doing work under the organisation's control, within the ISMS scope

The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.

ISMS scope

What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.

Complexity and risk of the ISMS

Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.

Sites

Where scoped activities physically happen, and whether multi-site sampling applies.

Delivery mode

How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.

The headcount driver is the one most often got wrong. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation, so a 40-employee company running 25 contractors inside its scope is not a 40-person audit. Fixing that number before you request a quote is the difference between a quote that holds and a quote revised upward after Stage 1.

Price the three-year cycle, not year one

Year one

Two-stage initial audit

Stage 1 tests whether the ISMS is designed and documented well enough to be audited. Stage 2 tests whether it is implemented and effective. BSI determines the total audit time and how it splits across the two stages.

Intervening years

Surveillance audits

Shorter than the initial audit, also determined under ISO/IEC 27006-1:2024, also quoted per engagement. They are not optional and they are part of your cost of certification.

Before expiry

Recertification

The certificate expires and a recertification audit is required to renew it. Ask what happens to the rate across the three years before you sign year one.

A year-one quote is not your cost of certification. A cheaper year one with unstated surveillance is not a cheaper programme. See the three-year cycle page.

How to get a comparable quote from BSI

  1. Write the scope brief once and send it unchanged to every body. Scope, headcount on the ISO/IEC 27006-1:2024 definition, sites, remote versus on-site appetite, and every scheme you intend to certify. Different briefs produce numbers that cannot be compared.
  2. Ask BSI to state the audit days it determined. Days are the quantity the standard governs. A price without days is not a quote you can interrogate.
  3. Confirm accreditation number 0003 covers the scheme you are buying. On the register, under the entity that will issue the certificate, not from marketing material.
  4. Ask BSI to price the full cycle. Initial audit, surveillance, recertification, and what happens to the rate across three years.
  5. Get travel and expenses stated separately. They sit outside audit time and are a real line on an on-site audit.
  6. Confirm audit time is determined under ISO/IEC 27006-1:2024. Both the UKAS and ANAB transition deadlines have passed, so any body quoting today should be applying it.

Verify accreditation yourself: UKAS register | ANAB directory

Frequently asked questions

How much does BSI ISO 27001 certification cost?
BSI does not publish a rate card or a day rate for ISO 27001 certification, and neither does any other accredited certification body. An audit fee is audit days multiplied by a rate. The rate is commercial and unpublished. The audit days are determined by the body under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C, and ISO sells that standard rather than publishing it openly. Both inputs are unpublished, so no honest figure can be printed here. A real number comes from BSI quoting your actual scope.
Is BSI accredited for ISO 27001?
Yes. BSI's management systems schedule of accreditation on the UKAS register, number 0003, is held by BSI Assurance UK Ltd and carries "Information Security Management Systems (ISMS) to ISO/IEC 27001:2022". We downloaded and read that schedule in July 2026. Accreditation attaches to a legal entity rather than to a brand, so the entity named on your certificate is the thing to confirm on the register.
What else is on BSI's UKAS schedule alongside ISO 27001?
BSI's schedule is one of the broadest in the UKAS register. It spans ISMS alongside quality, environmental, health and safety, business continuity and AI management systems, including ISO/IEC 42001 for AI management systems. That breadth matters if you intend to certify more than one scheme against a single integrated programme, because a body accredited for every scheme you need can audit them together rather than sending you to a second body with a second audit programme.
What drives the audit days BSI will quote?
The primary input under ISO/IEC 27006-1:2024 is the number of people doing work under the organisation's control within the ISMS scope, counted regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total. Audit time also reflects the ISMS scope itself, the complexity and risk of the ISMS including the criticality of the information handled, the sites involved, and how much of the audit runs remotely rather than on site.
Does IAF MD 5 set BSI's ISO 27001 audit days?
No. IAF MD 5:2023 is titled 'Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems' and it applies to those schemes. Information security management systems sit outside its scope and it contains no ISMS audit-time table. ISMS audit time is determined under ISO/IEC 27006-1:2024. If you certify ISO 9001 alongside ISO 27001 through BSI, MD 5 governs audit time on the quality side while ISO/IEC 27006-1 governs the ISMS side.
How do I brief BSI so the quote is comparable to another body's?
Send BSI and every other body you approach an identical brief: your ISMS scope, the number of people doing work under your control inside that scope including contractors, your sites, and how much of the audit can run remotely. Ask each body to state the audit days it has determined, to confirm its ISO/IEC 27001 accreditation on the accreditation body's register, to price surveillance and recertification across the full three-year cycle, and to state travel and expenses separately from audit time. Quotes built on different briefs cannot be compared.

Other certification bodies on the register

Updated July 2026