DNV ISO 27001 cost: accreditation, audit time and sourcing a quote
This page carries no DNV fee, because DNV does not publish one and no accredited certification body does. The audit-day tables are sold by ISO. What is public is DNV's schedule of accreditation on the UKAS register, and what is useful is knowing exactly which inputs will move the number when DNV quotes your scope.
Updated July 2026
DNV on the UKAS register
Legal entity
DNV Business Assurance UK Limited
Accreditation body
UKAS
Accreditation number
0013
ISO/IEC 27001 on the schedule
Confirmed, read from the schedule
Scope line, verbatim
"Information Security Management Systems (ISMS) to ISO/IEC 27001:2022"
Checked July 2026 by downloading the schedule and reading its accredited scope. Schedule of accreditation 0013 | UKAS register
The assurance arm of the Norwegian classification society, with deep roots in maritime, energy and industrial assurance. The UK entity holds the UKAS ISMS accreditation.
Accreditation attaches to a legal entity, not to a global brand, and it attaches per scheme. DNV Business Assurance UK Limited is the entity UKAS accredits, and the ISMS line above is the entry that matters for an ISO 27001 buyer. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001, whatever else appears on a schedule.
Why there is no DNV fee on this page
An audit fee is audit days multiplied by a rate. Neither input is published.
The rate is commercial. DNV quotes per engagement. No accredited certification body publishes a day rate, and the accreditation registers publish accreditation status only, never anything commercial. There is no rack rate in this market to quote or to discount from.
The days are behind a paywall. ISMS audit time is determined under ISO/IEC 27006-1:2024. Its audit-time provisions are the normative Annex C, with methods for audit time calculations in the informative Annex D. ISO sells the standard and the annex tables are not in the free preview. We have not read them, so we do not reproduce them.
DNV holds the standard and applies Annex C to your scope. Ask for the audit days it determined and the basis for them. That is the quantity the standard actually governs. More on how audit fees are set.
What actually drives your quote from DNV
These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are drivers, not a formula: we do not hold the Annex C tables and we do not reconstruct them.
Number of persons doing work under the organisation's control, within the ISMS scope
The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.
ISMS scope
What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.
Complexity and risk of the ISMS
Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.
Sites
Where scoped activities physically happen, and whether multi-site sampling applies.
Delivery mode
How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.
Headcount is counted on the standard's definition, not on your payroll report. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation, so contractors and freelancers inside the scope count toward the total. Fixing that number before you request quotes is the difference between a quote that holds and a quote revised upward after Stage 1.
What DNV is actually doing across the two stages
Stage 1: is the ISMS auditable
- Reviews ISMS scope, risk assessment, Statement of Applicability, management review
- Confirms the ISMS is designed and documented well enough to be tested
- Surfaces readiness gaps while there is still time to close them
- Often runs partly or wholly remotely
Stage 2: is the ISMS working
- Tests whether controls are implemented and effective in practice
- Samples evidence and interviews people across the scope
- Raises non-conformities that must be closed before certification
- Certificate issued once outstanding non-conformities are resolved
DNV determines the total audit time and how it splits across the two stages. We publish no split, because the split is set per engagement under the same annex we cannot read. Both stages sit inside the audit time quoted.
Price the three-year cycle, not year one
Certification runs on a three-year cycle: the two-stage initial audit above, surveillance audits in the intervening years, and a recertification audit before the certificate expires. Surveillance audits are shorter than the initial audit, are also determined under ISO/IEC 27006-1:2024, and are also quoted per engagement.
A year-one quote is not your cost of certification, and a cheaper year one with unstated surveillance is not a cheaper programme. Ask DNV to price the whole cycle up front and to state what happens to the rate across the three years. See the three-year cycle page.
How to get a comparable quote from DNV
- Write one scope brief and send it unchanged to every body. Scope, headcount on the ISO/IEC 27006-1:2024 definition, sites, remote versus on-site appetite, and every scheme you intend to certify.
- Ask DNV to state the audit days it determined. Days are the quantity the standard governs.
- Confirm schedule 0013 covers the scheme you are buying, under the entity that will issue your certificate.
- Ask for the full cycle. Initial audit, surveillance, recertification, and the rate across three years.
- Get travel and expenses stated separately. They sit outside audit time and are a real line on an on-site audit.
- Confirm audit time is determined under ISO/IEC 27006-1:2024. UKAS required transition by 31 July 2025 and ANAB required application to all clients by 31 March 2026.
Verify accreditation yourself: UKAS register | ANAB directory