Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

The hidden costs of ISO 27001 certification

The costs that break an ISO 27001 budget are rarely the ones on an invoice. They are the time nobody books, a headcount definition that is wider than your payroll, a scope that grows after the quote is agreed, and a cycle that recurs for three years. None of them has a published price. All of them are predictable.

Updated July 2026

Why this page has no total

A hidden-cost total would be an invention. These costs depend on what your organisation already has, and the whole point of the gap analysis is that nobody, including you, knows that number before it is done. What we can give you is the complete list of where budgets get surprised, the mechanism behind each one, and the point in the programme where it bites. Price them against your own organisation, and you will have a number that is worth something.

Where budgets get surprised

Internal time

Bites: Throughout, heaviest before Stage 2High impact

The largest cost of most programmes and the only one that never arrives as an invoice, which is exactly why it never makes the budget. It is drawn from engineering, IT, HR, legal and senior management, and it competes for the same attention as the work that generates revenue. Nobody can publish your number, because it depends on how much of your ISMS already exists. You can estimate it: name the tasks, ask the people who will do them, price it at your own loaded rates, and put it in the budget as a line rather than as an assumption.

The headcount definition

Bites: At quotation, and again after Stage 1 if you got it wrongHigh impact

ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation. Contractors and freelancers inside your scope count toward the number that drives audit time. A company that answers the headcount question with its payroll number, while running a substantial contractor bench inside scope, has understated the input that matters most. This is the most common cause of a quote being revised upward, and it costs nothing to avoid.

Scope creep

Bites: After the quote is agreedHigh impact

Scope is the largest lever you control over cost, which makes it the largest way to lose control of cost. Scope grows quietly: a system that turns out to process in-scope data, a team that turns out to touch the service, an acquisition, a second environment. Every addition changes the audit-time inputs and can reopen a fee that was agreed against a smaller boundary. Fix the scope in writing before you request quotes, and treat any change to it as a change to the budget.

Auditor travel and expenses

Bites: Each on-site audit, every year of the cycle

Travel sits outside audit time. It is a real line on an on-site audit and it is usually quoted separately from the fee, which means a quote can be compared favourably against another quote that simply presented the same costs differently. Ask for travel and expenses to be stated explicitly, ask how much of the audit can run remotely, and remember this recurs at every surveillance visit rather than once.

The recurring cycle

Bites: Years two and three, then againHigh impact

Certification is a three-year cycle: the two-stage initial audit, surveillance audits in the intervening years, and recertification before the certificate expires. Surveillance is shorter than the initial audit, and like the initial audit it is determined under the standard and quoted per engagement rather than published. A year-one budget is not the cost of being certified. Ask every body to price the full cycle up front, and to state what happens to the rate across it.

Gap-dependent tooling

Bites: After gap analysis, before Stage 2

Tooling is not a fixed cost of certification. It is the difference between the controls you have decided are applicable and the ones you can currently evidence, which is a different number for every organisation and is unknowable before the gap analysis. This is why the gap analysis belongs before the budget rather than after it. An organisation on a modern SaaS stack frequently finds the gap is documentation and configuration rather than procurement.

The standards themselves

Bites: Day one

ISO sells its standards. ISO 27001 and ISO 27002 are copyrighted documents you buy from ISO or your national standards body, and they cannot be freely redistributed inside your organisation, which matters if you plan to hand copies to a project team. Current prices are on the ISO catalogue and on your national body's site. Budget for the purchase and check the licence terms for the number of users you need.

Evidence you have to create rather than collect

Bites: ISMS build

Some requirements are satisfied by writing down what you already do. Others require you to start doing something you do not currently do at all, and those are the expensive ones. The internal audit and the management review are requirements of the standard in their own right, not audit preparation, and an organisation that has never run either is building a new process rather than documenting an existing one. Supplier assessment is often the same story.

Remediation between the stages

Bites: Between Stage 1 and Stage 2

Stage 1 exists to establish whether the ISMS is ready to be tested at Stage 2. When it surfaces gaps, closing them takes time and often money, and it can move your Stage 2 date. Non-conformities raised at Stage 2 must be resolved before the certificate is issued, on a timeframe the certification body sets. Budget for the possibility rather than assuming a clean run, and treat a candid Stage 1 as the cheap outcome it is.

Delay

Bites: Every month the certificate is not in hand

If certification is gating deals, the cost of the programme running long is the revenue those deals represent, and it usually dwarfs the fee arguments people spend their time on. This cuts both ways: it is an argument for starting early and resourcing properly, not an argument for rushing a programme that will fail Stage 2. You can price this line yourself from your own pipeline.

The one to get right before you ask for a quote

Headcount is the primary input to audit time, and ISO/IEC 27006-1:2024 defines it more widely than most buyers assume: people doing work under the organisation's control within the ISMS scope, whether or not they are members of the organisation. A 40-employee company running 25 contractors inside its scope is not a 40-person audit.

Every other item on this page costs you money. This one costs you credibility as well, because it surfaces after the quote is signed and it makes every comparison you ran meaningless. Count it properly first. How audit time is determined.

Ask these before you sign anything

Most of the costs on this page are hidden only because nobody asked. These questions surface them while you still have leverage, which is before you have chosen a body.

  • What audit days have you determined for our scope, and what were the inputs?
  • How many people did you count, and did that include contractors doing work under our control inside the scope?
  • What are the surveillance and recertification fees for the full three-year cycle?
  • What happens to the rate across the three years?
  • How much of the audit can run remotely, and how are travel and expenses quoted?
  • What evidence do you expect for the Annex A controls we have marked applicable?
  • What happens, commercially, if Stage 1 finds we are not ready for Stage 2?

Frequently asked questions

What are the most commonly overlooked ISO 27001 costs?
Internal time is the big one, because it is the only major cost that never arrives as an invoice and therefore never appears in a budget line. After that: the headcount definition, which counts contractors and can make your audit larger than your employee count suggests; scope creep, which raises cost after the quote is agreed; auditor travel and expenses, which sit outside audit time and are quoted separately; and the fact that certification is a recurring three-year cycle rather than a one-off purchase.
How much internal time does ISO 27001 require?
There is no honest published figure, because the answer depends on how much of your ISMS already exists. An organisation with current policies, an asset inventory and evidence it already collects is doing a fraction of the work of one starting from nothing. What is predictable is where the hours land: scoping and risk assessment, writing the policies you do not have, collecting evidence, the mandatory internal audit and management review, and preparing people for interview. Estimate it by naming those tasks and asking the people who will do them.
Do contractors count toward my ISO 27001 audit size?
Yes, if they do work under your control inside the ISMS scope. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation. That means contractors and freelancers inside the scope count toward the number that drives your audit time. This is the most common reason a quote is revised upward, and it is entirely avoidable by counting correctly before you request quotes.
Do I need penetration testing for ISO 27001?
The standard does not name penetration testing as a required activity. Annex A control 8.8 covers management of technical vulnerabilities, and you have to show your certification body that you manage them. Testing is a common way to evidence that, but what your auditor will accept is a question for your auditor rather than for a cost page. Ask the certification body what evidence it expects for 8.8 against your scope before you buy anything, because the answer changes what you need to buy.
What tools do I need to buy for ISO 27001?
Only the ones your gap analysis shows you are missing. Tooling is not a fixed cost of certification, it is the difference between the controls you have decided are applicable and the ones you can currently evidence. An organisation on a modern SaaS stack often finds most of that difference is configuration and documentation rather than procurement. This is precisely why the gap analysis comes before the budget, not after it.
Why does the cost keep going after certification?
Because certification is a three-year cycle, not a purchase. After the two-stage initial audit there are surveillance audits in the intervening years and a recertification audit before the certificate expires, each determined under ISO/IEC 27006-1:2024 and quoted per engagement. The ISMS also has to keep running between audits: the internal audit and management review are requirements of the standard, not one-off tasks. A budget built on year one is a budget that runs out in year two.

Updated July 2026