ISO 27001 cost UK: UKAS accreditation and what drives your quote
No UKAS-accredited certification body publishes a day rate, so this page prints none. What genuinely matters to a UK buyer is different and more useful: what UKAS accreditation is, how to verify it in a few minutes on a public register, and why your procurement team is asking for it.
Updated July 2026
Why this page carries no UK price table
An audit fee is audit days multiplied by a day rate. In the UK, as everywhere, neither input is published. No accredited certification body publishes its day rate, and the provisions that determine audit days sit in ISO/IEC 27006-1:2024 Annex C, which ISO sells rather than publishes. A table of UK fees would be two invented numbers multiplied together.
The UK does have something specific and genuinely valuable, though, and it is not a price: an independent national accreditation body with a public register you can check before you spend anything. That is the part of this decision you can actually verify, so this page is built on it.
What UKAS is, and what it is not
UKAS accredits the certifier
UKAS is the United Kingdom Accreditation Service, the UK's national accreditation body. It assesses whether a certification body is competent to issue certificates, scheme by scheme, and publishes the result on its own register.
UKAS does not certify your organisation and you do not buy anything from UKAS. Your relationship is with a certification body; UKAS is the reason anyone should believe that body.
Accredited is not the same as certified
Anyone may issue a document that says ISO 27001 on it. An accredited certificate is one issued by a body an accreditation body has assessed as competent for that specific scheme. The difference is invisible on the certificate and decisive in procurement.
This is why the cheapest quote is not always a comparable quote. Establish accreditation first, then compare prices among bodies that pass.
UKAS bodies had to transition to ISO/IEC 27006-1:2024, and the deadline has passed
UKAS: Published 1 March 2024. UKAS-accredited ISMS certification bodies were required to complete transition by 31 July 2025. Technical bulletin
So any UKAS-accredited body quoting you today should be determining your audit time under ISO/IEC 27006-1:2024. Ask them to confirm it, and ask what audit days they determined for your scope. Days are the quantity the standard makes them determine, and a body that will state its days is a body you can hold to a scope.
Check the register, not the brochure
UKAS publishes accreditation status on its own public register, which makes this the one claim in the whole purchase you can verify independently and for free. Four things to confirm:
The body is on the register at all
Accreditation is published by the accreditation body, not claimed by the certification body. If it is not on the register, the conversation is over.
It is accredited for ISO/IEC 27001 specifically
Accreditation is granted scheme by scheme. A body accredited for ISO 9001 is not accredited for ISMS certification, and this is the trap that catches buyers most often.
The scope of accreditation covers you
A schedule of accreditation states what the body may certify. Read it against what you are asking them to certify.
It is current, not lapsed or suspended
The register is the live record. A certificate issued under lapsed accreditation is not what your buyer asked for.
The register lives on ukas.com, where accredited organisations and their schedules of accreditation are searchable.
What actually drives a UK quote
These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are the same drivers everywhere: certification is an international scheme, and being in the UK does not change the inputs. Knowing them is what lets you interrogate a quote rather than just receive one.
Number of persons doing work under the organisation's control, within the ISMS scope
The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.
ISMS scope
What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.
Complexity and risk of the ISMS
Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.
Sites
Where scoped activities physically happen, and whether multi-site sampling applies.
Delivery mode
How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.
The headcount driver catches UK buyers with contractor benches. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation, so contractors and freelancers inside the scope count toward the total. Get this right before you request quotes, or your comparison is between numbers that will both change. How audit time is determined.
Reading a UK procurement requirement properly
UK procurement, in both the public sector and enterprise supply chains, frequently asks for accredited certification. What it asks for varies by contract, and the tender document is the only authority on your contract. Before you price a programme against a requirement, establish what the requirement actually says:
- Does it say accredited? If the buyer means accredited certification, an unaccredited certificate does not satisfy it however cheap it was. If the wording is ambiguous, ask the buyer rather than guessing, before you choose a body.
- Does it name ISO 27001, or a standard of security? Some requirements name the certificate. Others describe an outcome that several routes satisfy. These are very different budgets, and people routinely price the first when the tender says the second.
- What scope does it need to cover? A certificate is only worth what its scope statement says. A certificate whose scope excludes the service you are bidding with does not answer the question, and buyers do read the scope line.
- Is it a condition of award or of contract? Whether you must hold it to bid, or to start delivering, changes your timeline entirely and sometimes changes the answer about whether to certify at all.
- Would a lighter scheme satisfy it? Some UK requirements are satisfied by a baseline scheme rather than full ISMS certification. Worth establishing before you commit to the larger programme. ISO 27001 and Cyber Essentials Plus compared.
The one layer with published prices
GRC platforms publish list-price dimensions on their public AWS Marketplace listings. A UK buyer can read exactly the same listings as anyone else, which is why this layer is the only part of the budget you can research rather than request. They are published in US dollars, and we report them as published rather than converting them at a rate we picked on a date we chose. Lowest published dimension per listing, 12-month contract, checked July 2026:
Vanta
from $6,000
lowest published dimension
Drata
$7,500
lowest published dimension
Secureframe
$7,500
lowest published dimension
Sprinto
from $2,000
lowest published dimension
Scytale
from $2,100
lowest published dimension
Separate dimensions on each listing, not totals. AWS publishes no combined figure, so we present none. Where a listing describes a figure as a starting price it is a floor, and we label it as one. Above roughly 100 people the published bands run out and every platform moves to a private offer.