Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

ISO 27001 cost by company size: what actually scales

One layer of this cost genuinely scales with headcount and is genuinely published: the GRC platform bands. Above roughly 100 people they run out and everything becomes a private offer. Headcount also drives audit time, but under a definition that is wider than your payroll. Everything else about size is less decisive than you have been told.

Updated July 2026

The bands that are actually published

These vendors band a dimension by headcount on their public AWS Marketplace listings, and this is the only place in an ISO 27001 budget where company size meets a published price. Each is a separate dimension on a 12-month contract, read off the listing and checked July 2026. AWS publishes no combined total, so none is shown.

PlatformDimensionBand as stated on the listingListed
Vantastarting priceEssentials Package1-20 employees, per 12-month contractfrom $14,000
Vantastarting pricePlus Package1-20 employees, per 12-month contractfrom $21,500
Vantastarting priceProfessional Package1-20 employees, per 12-month contractfrom $23,000
Vantastarting priceTrust Center1-20 employees, per 12-month contractfrom $6,000
DrataPlatform Feecapacity for a 100 FTE org, per 12-month contract$25,000
SecureframeAccess the Secureframe Platformup to 100 employees, per 12-month contract$7,500
Sprintostarting priceStarter Platformup to 100 employees, per 12-month contractfrom $7,500

Read these as line items, not as programme prices. Most listings also carry a separate framework dimension, and where a listing describes a figure as a starting price it is a floor rather than a price. Per-platform detail: Vanta, Drata, Secureframe, Sprinto, Scytale.

At roughly 100 people, the published bands stop

This is the most useful fact on the page. Secureframe and Sprinto both band platform access up to 100 employees. Drata prices its platform fee at capacity for a 100 FTE organisation. Vanta's Essentials package is banded at 1-20 employees, and its listing states that pricing is tiered based on company size and program complexity.

Above that line, there is no public figure. Every platform moves to a private offer, and any site presenting a mid-market or enterprise platform price is presenting a number no vendor published. The honest statement is that the published information ends here, and what replaces it is a negotiation.

Practically: below roughly 100 people you can research a real part of your budget before you speak to anyone. Above it, you cannot, and the work shifts to running a proper procurement with more than one vendor and an identical brief. Where published pricing runs out.

Your company size is not your headcount for this purpose

Headcount is the primary input to audit time under ISO/IEC 27006-1:2024, which is why every cost-by-size page starts with employee bands. But the standard does not count employees. It counts people doing work under the organisation's control within the ISMS scope, regardless of whether they are members of the organisation.

Two things follow, and both are worth money. Contractors and freelancers inside your scope count toward the number that drives your audit, so a 40-employee company running 25 contractors in scope is not a 40-person audit. And people outside the ISMS scope do not count, which means scope decisions change your effective size.

Work out this number properly before you request quotes. It is the most common cause of a quote being revised upward after Stage 1, and it makes every comparison you ran on the old number worthless. How audit time is determined.

What size decides, and what it does not

Number of people in scope

Scales with headcount

The primary audit-time input under ISO/IEC 27006-1:2024, and it counts contractors doing work under your control inside the scope, not just employees.

Published platform band

Scales with headcount

The one cost layer that is both published and banded by headcount. It scales in steps rather than smoothly, and the steps stop at roughly 100 people.

Coordination overhead

Scales with headcount

More people means more teams to interview, more evidence owners to chase, and more of the internal time that never appears on an invoice.

ISMS scope

Independent of headcount

Entirely your decision. A large company can certify a narrow scope and a small one can certify everything. This is the biggest lever you control and it is independent of headcount.

Complexity and risk

Independent of headcount

Two organisations with identical headcount can attract different audit time based on the criticality of the information handled and the risk associated with the ISMS.

Sites

Independent of headcount

Where scoped activities physically happen, and whether multi-site sampling applies. A distributed 50-person company can have more sites in scope than a 300-person one in a single building.

Existing maturity

Independent of headcount

How much of your ISMS already exists decides how much you have to build. This tracks history and discipline, not size, and it is often the largest single difference between two similar companies.

Four of the seven do not move with your size. That is why a cost-by-size table with a single total per band cannot be right: it would have to assume away the scope decision, which is the largest lever in the whole programme and the one thing you fully control.

What to do at your size

Inside the published bands

Up to roughly 20

  • Vanta's Essentials package is banded here and you can read the figure yourself
  • Count contractors in scope before you ask anyone for an audit quote
  • Scope narrowly and deliberately; at this size it is easy and it stays easy
  • Check the demand first: certification is cheap to research and expensive to regret

Startups: where the bands fit

Inside the published bands

Roughly 20 to 100

  • Several platform dimensions are banded up to 100 employees and are readable today
  • You are approaching the edge of the published band, so ask what happens when you cross it
  • Contractor headcount matters most here, where benches are often largest relative to payroll
  • Get audit quotes from more than one accredited body on an identical brief

SaaS by stage

Past the published bands

Above roughly 100

  • No published platform price exists for you. Nobody can research this number, including us
  • Run a real procurement: same brief to every vendor, and compare offers rather than rate cards
  • Scope is now the dominant variable and deserves a decision, not a default
  • Price the full three-year cycle up front, not year one

Mid-market: where pricing runs out

Related guides

Frequently asked questions

How much does ISO 27001 cost for a small business?
The part anyone can tell you is the platform layer, because it is the only part that is published. Vanta lists a $14,000 Essentials package for a 1-20 employee band on AWS Marketplace, Secureframe lists $7,500 for platform access up to 100 employees, and Sprinto lists $7,500 for its Starter platform up to 100 employees, all checked July 2026. The certification audit is quote-only: no accredited body publishes a rate card, and the audit-time provisions sit in ISO/IEC 27006-1:2024 Annex C, which ISO sells. So a total for a small business is not something we can honestly print, and neither can anyone else.
What is the cost per employee for ISO 27001?
There is no published cost-per-employee figure, and building one would require a total that nobody publishes. The idea is also misleading in a specific way: headcount drives audit time, but scope drives what is being audited, and a large company certifying one product can be a smaller engagement than a smaller company certifying everything it does. Cost per employee implies a linear relationship that the actual mechanics do not have.
Does headcount really drive the audit?
Yes. Headcount is the primary input to audit time under ISO/IEC 27006-1:2024, but the definition is wider than payroll: the standard counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation. Contractors and freelancers inside the scope count. A 40-employee company running 25 contractors inside its scope is not a 40-person audit, and getting this wrong before requesting quotes is the most common reason a quote is revised upward.
Why do published prices stop at around 100 employees?
Because that is where the vendors stop publishing. Secureframe and Sprinto both band their platform dimension up to 100 employees, and Drata prices its platform fee at capacity for a 100 FTE organisation. Above that, every platform moves to a private offer, and there is no public figure to report at all. This is the single most useful thing to know about ISO 27001 pricing at scale: the transition from a published band to a negotiation is real, and it happens at roughly 100 people.
Is ISO 27001 too expensive for startups?
The published band is narrowest and clearest at that size, which makes a startup one of the few cases where you can research a meaningful part of your budget before speaking to anyone. Vanta's Essentials package is listed for a 1-20 employee band, and both Secureframe and Sprinto publish platform access up to 100 employees. The audit still has to be quoted. Whether it is worth it is a question about your pipeline rather than your size, and it is answerable from your own CRM.
Why can a bigger company get a smaller audit?
Because scope and headcount are separate drivers. Audit time reflects the number of people inside the ISMS scope, but also the scope itself, the complexity and risk of the ISMS, the sites involved and how much of the audit runs remotely. A 500-person business certifying one product line with one environment can present less to audit than a 120-person business certifying every system it operates. Scope is the lever you control, and it does not move with your headcount.

Updated July 2026