Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

ISO 27001 cost UK: UKAS accreditation and what drives your quote

No UKAS-accredited certification body publishes a day rate, so this page prints none. What genuinely matters to a UK buyer is different and more useful: what UKAS accreditation is, how to verify it in a few minutes on a public register, and why your procurement team is asking for it.

Updated July 2026

Why this page carries no UK price table

An audit fee is audit days multiplied by a day rate. In the UK, as everywhere, neither input is published. No accredited certification body publishes its day rate, and the provisions that determine audit days sit in ISO/IEC 27006-1:2024 Annex C, which ISO sells rather than publishes. A table of UK fees would be two invented numbers multiplied together.

The UK does have something specific and genuinely valuable, though, and it is not a price: an independent national accreditation body with a public register you can check before you spend anything. That is the part of this decision you can actually verify, so this page is built on it.

What UKAS is, and what it is not

UKAS accredits the certifier

UKAS is the United Kingdom Accreditation Service, the UK's national accreditation body. It assesses whether a certification body is competent to issue certificates, scheme by scheme, and publishes the result on its own register.

UKAS does not certify your organisation and you do not buy anything from UKAS. Your relationship is with a certification body; UKAS is the reason anyone should believe that body.

Accredited is not the same as certified

Anyone may issue a document that says ISO 27001 on it. An accredited certificate is one issued by a body an accreditation body has assessed as competent for that specific scheme. The difference is invisible on the certificate and decisive in procurement.

This is why the cheapest quote is not always a comparable quote. Establish accreditation first, then compare prices among bodies that pass.

UKAS bodies had to transition to ISO/IEC 27006-1:2024, and the deadline has passed

UKAS: Published 1 March 2024. UKAS-accredited ISMS certification bodies were required to complete transition by 31 July 2025. Technical bulletin

So any UKAS-accredited body quoting you today should be determining your audit time under ISO/IEC 27006-1:2024. Ask them to confirm it, and ask what audit days they determined for your scope. Days are the quantity the standard makes them determine, and a body that will state its days is a body you can hold to a scope.

Check the register, not the brochure

UKAS publishes accreditation status on its own public register, which makes this the one claim in the whole purchase you can verify independently and for free. Four things to confirm:

1

The body is on the register at all

Accreditation is published by the accreditation body, not claimed by the certification body. If it is not on the register, the conversation is over.

2

It is accredited for ISO/IEC 27001 specifically

Accreditation is granted scheme by scheme. A body accredited for ISO 9001 is not accredited for ISMS certification, and this is the trap that catches buyers most often.

3

The scope of accreditation covers you

A schedule of accreditation states what the body may certify. Read it against what you are asking them to certify.

4

It is current, not lapsed or suspended

The register is the live record. A certificate issued under lapsed accreditation is not what your buyer asked for.

The register lives on ukas.com, where accredited organisations and their schedules of accreditation are searchable.

What actually drives a UK quote

These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are the same drivers everywhere: certification is an international scheme, and being in the UK does not change the inputs. Knowing them is what lets you interrogate a quote rather than just receive one.

Number of persons doing work under the organisation's control, within the ISMS scope

The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.

ISMS scope

What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.

Complexity and risk of the ISMS

Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.

Sites

Where scoped activities physically happen, and whether multi-site sampling applies.

Delivery mode

How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.

The headcount driver catches UK buyers with contractor benches. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation, so contractors and freelancers inside the scope count toward the total. Get this right before you request quotes, or your comparison is between numbers that will both change. How audit time is determined.

Reading a UK procurement requirement properly

UK procurement, in both the public sector and enterprise supply chains, frequently asks for accredited certification. What it asks for varies by contract, and the tender document is the only authority on your contract. Before you price a programme against a requirement, establish what the requirement actually says:

  • Does it say accredited? If the buyer means accredited certification, an unaccredited certificate does not satisfy it however cheap it was. If the wording is ambiguous, ask the buyer rather than guessing, before you choose a body.
  • Does it name ISO 27001, or a standard of security? Some requirements name the certificate. Others describe an outcome that several routes satisfy. These are very different budgets, and people routinely price the first when the tender says the second.
  • What scope does it need to cover? A certificate is only worth what its scope statement says. A certificate whose scope excludes the service you are bidding with does not answer the question, and buyers do read the scope line.
  • Is it a condition of award or of contract? Whether you must hold it to bid, or to start delivering, changes your timeline entirely and sometimes changes the answer about whether to certify at all.
  • Would a lighter scheme satisfy it? Some UK requirements are satisfied by a baseline scheme rather than full ISMS certification. Worth establishing before you commit to the larger programme. ISO 27001 and Cyber Essentials Plus compared.

The one layer with published prices

GRC platforms publish list-price dimensions on their public AWS Marketplace listings. A UK buyer can read exactly the same listings as anyone else, which is why this layer is the only part of the budget you can research rather than request. They are published in US dollars, and we report them as published rather than converting them at a rate we picked on a date we chose. Lowest published dimension per listing, 12-month contract, checked July 2026:

Separate dimensions on each listing, not totals. AWS publishes no combined figure, so we present none. Where a listing describes a figure as a starting price it is a floor, and we label it as one. Above roughly 100 people the published bands run out and every platform moves to a private offer.

Frequently asked questions

How much does ISO 27001 cost in the UK?
No UKAS-accredited certification body publishes a rate card or a day rate, so a UK price table would be assembled rather than reported. The audit-time provisions that determine how many days you are quoted sit in ISO/IEC 27006-1:2024 Annex C, and ISO sells that standard rather than publishing it. Both inputs to the fee are unpublished. The one layer that does carry published prices is the GRC platform layer, where several vendors list figures on their public AWS Marketplace listings in US dollars.
What is UKAS and why does it matter?
UKAS is the United Kingdom Accreditation Service, the UK's national accreditation body. It accredits the certification bodies that issue certificates; it does not certify your organisation itself. That distinction is the one that matters commercially, because a certificate from an unaccredited body is frequently refused in procurement. UKAS publishes which schemes each body is accredited for on its own public register, which is where you check rather than on the certification body's marketing pages.
How do I check a UK certification body is genuinely accredited for ISO 27001?
Look it up on the UKAS register rather than taking the body's word for it, and check the scheme rather than just the name. Accreditation is granted scheme by scheme, so a body accredited for ISO 9001 is not thereby accredited for ISO/IEC 27001, and that is a real and common trap. The register states exactly what each body is accredited to do. Confirming this takes a few minutes and is the single highest-value check in the whole procurement.
Does my UK certification body have to use ISO/IEC 27006-1:2024?
Yes, and the transition deadline has passed. UKAS published its transition requirement on 1 March 2024 and UKAS-accredited ISMS certification bodies were required to complete transition by 31 July 2025. Any UKAS-accredited body quoting you today should therefore be determining your audit time under ISO/IEC 27006-1:2024. Asking a body to confirm that, and to state the audit days it has determined for your scope, is a reasonable question and a useful test of who you are dealing with.
Is ISO 27001 required for UK government contracts?
It depends entirely on the contract, and the tender document is the only authority on it. What is consistent is that where certification is required, buyers generally mean accredited certification, and a certificate from an unaccredited body may not satisfy the requirement. Read the exact wording of the security schedule, check whether it names ISO 27001 specifically or accepts alternatives, and confirm your prospective body's accreditation on the UKAS register before you commit to it.
Why are the published platform prices in dollars if I am a UK buyer?
Because that is the surface they are published on. The GRC platforms list their prices on AWS Marketplace in US dollars, and we report figures as they are published rather than converting them. A converted figure would carry an exchange rate we picked and a date we chose, which is our arithmetic rather than the vendor's price. Treat the listed figure as the published one and settle the currency question with the vendor, who will also be the one telling you whether VAT applies.

Updated July 2026