Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

ISO 27001 implementation: the phases and the decisions in each

Certification is a sequence of decisions, not a sequence of purchases. Here is what happens at each phase, who does it, what it produces, and the decision inside it that actually moves your cost. Where a figure is published we give it. Where it is not, we say so rather than estimating.

Updated July 2026

What is published, and what is not

Published

The platform layer

Lowest published dimension per vendor listing, 12-month contract, read off the public AWS Marketplace listing and checked July 2026.

Separate dimensions, not totals. AWS publishes no combined figure.

Quote-only

Audit and consulting

No accredited certification body publishes a rate card or a day rate, and the audit-time provisions sit in ISO/IEC 27006-1:2024 Annex C, which ISO sells rather than publishes. Consultants publish no rates either.

Both are sourced by asking more than one, on an identical brief.

Yours to estimate

Internal time

Usually the largest cost and the only one nobody invoices you for, which is why it never makes the budget. It depends on how much of your ISMS already exists.

Name the tasks, ask the people who will do them, price it at your own loaded rates. Where it goes.

The phases

The order matters more than the labels. Each phase produces something the next one needs, and the two most consequential decisions in the whole programme are made in the first two.

1

Scoping

Decide what the ISMS covers: which services, systems, teams and locations sit inside the boundary. Everything downstream is priced off this, and it is the one lever you fully control.

The decision

How wide to draw the boundary. Wider means more audit time, more controls in play and more internal time, for a certificate that says more. Draw it against what your buyers actually ask for, not against your org chart.

Who: You, ideally with adviceProduces: A written scope statement, and the headcount on the right definition
2

Gap analysis

Assess where you are against what certification requires. This converts the budget from a guess into an estimate, which is why it sits before the budget rather than inside it.

The decision

Go, adjust or wait. A gap analysis that could only ever have said go was a formality.

Who: Consultant, platform, or an honest internal assessmentProduces: What is missing, what it takes to close, and a scope recommendation

More on this phase

3

Risk assessment and treatment

Identify the risks to information in scope and decide what to do about each. A consultant can supply the method and challenge your thinking, but the risk decisions are the organisation's own and auditors can tell the difference.

The decision

What you accept versus what you treat. Accepting a risk is a legitimate, documented decision, not a failure. Pretending to treat everything is the expensive path and it is transparent to an auditor.

Who: You. This one cannot be outsourcedProduces: A risk methodology, a risk register, and treatment decisions
4

The Statement of Applicability

Which controls apply, which do not, and why. This is the document your auditor reads first, because it is where you state what you have decided the ISMS actually is.

The decision

Each exclusion has to be justifiable to someone who is not you. Excluding something because it is inconvenient is the finding that gets written up.

Who: You, usually with helpProduces: Every Annex A control, with a decision and a justification

More on this phase

5

Closing the gaps

The variable phase, and usually the largest. For some organisations this is documenting what already happens. For others it is building processes that do not exist. The gap analysis told you which one you are.

The decision

Where to stop. Over-engineering a control that was already adequate costs real money and buys nothing, and it is a common way to spend a budget without improving the outcome.

Who: Your teamsProduces: Controls that operate, and evidence that they do
6

Internal audit

A requirement of the standard in its own right, not audit preparation. It must be independent of the work being audited, which constrains who can run it, including which consultant if they built your ISMS.

The decision

Whether to treat it as a formality or as your last cheap chance to find what a certification auditor would find. The second is the entire point.

Who: Someone independent of the work being auditedProduces: An audit report and non-conformities you found yourself
7

Management review

Top management reviewing ISMS performance, audit results, risks and improvement. This is the part that cannot be bought or delegated, and it is where auditors probe whether the ISMS is real.

The decision

Whether leadership actually engages. An ISMS that only exists below the leadership line is visible to an auditor within an hour of arriving.

Who: Top management, genuinelyProduces: Documented review, decisions and actions
8

Stage 1

The body reviews whether the ISMS is designed and documented well enough to be audited: scope, risk assessment, Statement of Applicability, management review. Often runs partly or wholly remotely.

The decision

Already made. By now you have chosen a body and agreed a scope, which is precisely why doing a gap analysis on your own timetable was worth it.

Who: Your certification bodyProduces: A view on whether you are ready for Stage 2
9

Stage 2

The body tests whether controls are implemented and effective, sampling evidence and interviewing people across the scope. Non-conformities must be resolved before the certificate is issued.

The decision

Theirs, and independently. No consultant controls this outcome, which is why anyone guaranteeing it is telling you something about themselves.

Who: Your certification bodyProduces: The certification decision

The cost is decided long before the auditor arrives

The two phases that set your cost are the two cheapest ones. Scoping decides what is being audited, and the gap analysis tells you what closing it takes. Everything after that is execution against decisions already made.

This is why organisations that skip to the audit quote get numbers that move. A quote against an unfixed scope and a headcount counted on the wrong definition is provisional, whatever it says on the paper. Fix both first and the rest of the programme becomes a project rather than a discovery.

What drives implementation up or down

Increases it

  • A broad scope, or one nobody has agreed
  • Contractors inside scope who were not counted
  • No existing policies, asset inventory or risk register
  • Processes that exist only in people's heads
  • Multiple sites and multiple environments in scope
  • No named owner with authority to decide
  • Leadership treating it as a compliance errand

Reduces it

  • A tight scope, decided deliberately and written down
  • An existing framework with overlapping evidence
  • Cloud-native architecture with clear boundaries
  • Evidence already collected rather than reconstructed
  • A named owner with the authority to make decisions
  • Documented processes, even imperfect ones
  • Honest self-assessment early, rather than optimism until Stage 1

Scope leads both lists. It drives audit time under ISO/IEC 27006-1:2024, the number of controls in play, and the internal hours, all at once. It is also the only item on either list that you can change this afternoon.

And then it recurs

Implementation ends at the certificate. The programme does not. Certification runs on a three-year cycle: the two-stage initial audit, surveillance audits in the intervening years, and recertification before the certificate expires. The internal audit and management review are standing requirements rather than one-off tasks. Budget the cycle, not the project. Pricing the three-year cycle.

Frequently asked questions

How much does ISO 27001 implementation cost?
The programme divides into one published layer and one quote-only layer, and no honest total spans both. The GRC platform layer is published: several vendors list prices on their public AWS Marketplace listings. The certification audit is quote-only, because no accredited body publishes a rate card and the audit-time provisions sit in ISO/IEC 27006-1:2024 Annex C, which ISO sells. Consulting is also quoted per engagement. Internal time, usually the largest cost, is yours to estimate against your own rates.
What is the most expensive phase of ISO 27001 implementation?
Usually the one where you close the gaps, but the honest answer is that it depends entirely on how many gaps you have, which is what the gap analysis exists to find out. For an organisation whose controls largely exist, the work is documenting and evidencing what already happens. For one starting from nothing, it is building processes that do not exist yet. Those are different programmes, and no published figure describes both, which is why the gap analysis comes before the budget.
Can you phase the implementation to spread costs?
Yes, by scoping narrowly first and expanding later, and it is a common and sensible approach. The trade is real: scope drives audit time under ISO/IEC 27006-1:2024, so a narrow initial scope means a smaller first audit, but expanding the scope later is a change your certification body has to handle rather than something you do quietly. Decide it deliberately with your body's input, and ask them what a later scope extension involves before you commit to the narrow start.
What is the difference between Stage 1 and Stage 2?
Stage 1 reviews whether the ISMS is designed and documented well enough to be audited: the scope, the risk assessment, the Statement of Applicability, the management review. Stage 2 tests whether it is actually implemented and effective, sampling evidence across the scope and interviewing people. The certification body determines the total audit time under ISO/IEC 27006-1:2024 and how it splits between the stages, and both sit inside the audit time it quotes.
How long does ISO 27001 implementation take?
It depends on the same thing the cost depends on: how much of the ISMS already exists, how broad the scope is, and how much attention your people can actually give it. The last of those is the one that slips, because certification competes with delivery for the same senior engineers and the same management time. The programmes that run long are usually not the ones with the most gaps, they are the ones where nobody owned it.
Do I need to buy tools to implement ISO 27001?
Only the ones your gap analysis shows you are missing. Tooling is not a fixed cost of certification; it is the difference between the controls you have decided are applicable and the ones you can currently evidence, and that is different for every organisation. Organisations on modern SaaS stacks often find much of the difference is configuration and documentation rather than procurement. Establish what your auditor expects as evidence before you buy anything.

Updated July 2026