Bureau Veritas ISO 27001 cost: accreditation and quote drivers
Bureau Veritas publishes no rate card and no day rate for ISO 27001, and the tables that determine audit days are sold by ISO. So there is no fee here. What there is: the exact schedule of accreditation on the UKAS register, the legal entity that holds it, and the drivers that will decide the number you are quoted.
Updated July 2026
Bureau Veritas on the UKAS register
Legal entity
Bureau Veritas Certification Holding SAS - UK Branch
Accreditation body
UKAS
Accreditation number
0008
ISO/IEC 27001 on the schedule
Confirmed, read from the schedule
Scope line, verbatim
"Information Security Management Systems (ISMS) to ISO/IEC 27001:2022"
Checked July 2026 by downloading the schedule and reading its accredited scope. Schedule of accreditation 0008 | UKAS register
A global testing, inspection and certification group. The UKAS accreditation sits with the UK branch of the French certification entity, and the schedule spans a wide spread of sector schemes alongside ISMS.
The entity on the schedule is the entity that matters
The UKAS accreditation above is held by Bureau Veritas Certification Holding SAS - UK Branch, which is a UK branch of the French certification entity rather than the group as a whole. That is worth reading twice, because it is the general rule in this market rather than a quirk: accreditation attaches to a legal entity, and a global group can operate through many entities accredited by many different national accreditation bodies.
For a buyer this collapses to two concrete questions. Which entity will issue my certificate, and which accreditation body accredits that entity? Once you have those two answers you can open the right register, find the right schedule, and read the scheme list yourself. If your procurement requirement names UKAS specifically, that is the register to check and the entity above is the one to look for.
The second half of the rule is just as important. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001. On a broad schedule spanning many sector schemes, the presence of the ISMS line is the thing to confirm, not the length of the list around it.
Why there is no Bureau Veritas fee on this page
An audit fee is audit days multiplied by a rate. Neither input is published.
The rate is commercial. Bureau Veritas quotes per engagement. No accredited certification body publishes a day rate, and the accreditation registers publish accreditation status only, never anything commercial. There is no rack rate in this market to quote or to discount from.
The days are behind a paywall. ISMS audit time is determined under ISO/IEC 27006-1:2024. Its audit-time provisions are the normative Annex C, with methods for audit time calculations in the informative Annex D. ISO sells the standard and the annex tables are not in the free preview. We have not read them, so we do not reproduce them, and we will not rebuild them from a table written for a different scheme.
Bureau Veritas holds the standard and applies Annex C to your scope. Ask for the audit days it determined and the basis for them. More on how audit fees are set.
What actually drives your quote from Bureau Veritas
These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are drivers, not a formula. Scope and headcount are the two you control before anyone quotes you.
Number of persons doing work under the organisation's control, within the ISMS scope
The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.
ISMS scope
What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.
Complexity and risk of the ISMS
Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.
Sites
Where scoped activities physically happen, and whether multi-site sampling applies.
Delivery mode
How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.
Headcount is counted on the standard's definition, not on your payroll report. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation, so contractors and freelancers inside the scope count. Getting that number right before you request quotes is the difference between a quote that holds and a quote revised upward after Stage 1.
Price the three-year cycle, not year one
Certification runs on a three-year cycle: a two-stage initial audit, surveillance audits in the intervening years, and a recertification audit before the certificate expires. Surveillance audits are shorter than the initial audit, are also determined under ISO/IEC 27006-1:2024, and are also quoted per engagement.
A year-one quote is not your cost of certification, and a cheaper year one with unstated surveillance is not a cheaper programme. Ask Bureau Veritas to price the whole cycle up front and to state what happens to the rate across the three years. See the three-year cycle page.
How to get a comparable quote from Bureau Veritas
- Write one scope brief and send it unchanged to every body. Scope, headcount on the ISO/IEC 27006-1:2024 definition, sites, remote versus on-site appetite, and every scheme you intend to certify.
- Ask Bureau Veritas to state the audit days it determined. Days are the quantity the standard governs.
- Confirm schedule 0008 covers the scheme you are buying, under the entity that will issue your certificate.
- Ask for the full cycle. Initial audit, surveillance, recertification, and the rate across three years.
- Get travel and expenses stated separately. They sit outside audit time and are a real line on an on-site audit.
- Confirm audit time is determined under ISO/IEC 27006-1:2024. UKAS required transition by 31 July 2025 and ANAB required application to all clients by 31 March 2026.
Verify accreditation yourself: UKAS register | ANAB directory