ISO 27001 implementation: the phases and the decisions in each
Certification is a sequence of decisions, not a sequence of purchases. Here is what happens at each phase, who does it, what it produces, and the decision inside it that actually moves your cost. Where a figure is published we give it. Where it is not, we say so rather than estimating.
Updated July 2026
What is published, and what is not
Published
The platform layer
Lowest published dimension per vendor listing, 12-month contract, read off the public AWS Marketplace listing and checked July 2026.
- Vantafrom $6,000
- Drata$7,500
- Secureframe$7,500
- Sprintofrom $2,000
- Scytalefrom $2,100
Separate dimensions, not totals. AWS publishes no combined figure.
Quote-only
Audit and consulting
No accredited certification body publishes a rate card or a day rate, and the audit-time provisions sit in ISO/IEC 27006-1:2024 Annex C, which ISO sells rather than publishes. Consultants publish no rates either.
Both are sourced by asking more than one, on an identical brief.
Yours to estimate
Internal time
Usually the largest cost and the only one nobody invoices you for, which is why it never makes the budget. It depends on how much of your ISMS already exists.
Name the tasks, ask the people who will do them, price it at your own loaded rates. Where it goes.
The phases
The order matters more than the labels. Each phase produces something the next one needs, and the two most consequential decisions in the whole programme are made in the first two.
Scoping
Decide what the ISMS covers: which services, systems, teams and locations sit inside the boundary. Everything downstream is priced off this, and it is the one lever you fully control.
The decision
How wide to draw the boundary. Wider means more audit time, more controls in play and more internal time, for a certificate that says more. Draw it against what your buyers actually ask for, not against your org chart.
Gap analysis
Assess where you are against what certification requires. This converts the budget from a guess into an estimate, which is why it sits before the budget rather than inside it.
The decision
Go, adjust or wait. A gap analysis that could only ever have said go was a formality.
Risk assessment and treatment
Identify the risks to information in scope and decide what to do about each. A consultant can supply the method and challenge your thinking, but the risk decisions are the organisation's own and auditors can tell the difference.
The decision
What you accept versus what you treat. Accepting a risk is a legitimate, documented decision, not a failure. Pretending to treat everything is the expensive path and it is transparent to an auditor.
The Statement of Applicability
Which controls apply, which do not, and why. This is the document your auditor reads first, because it is where you state what you have decided the ISMS actually is.
The decision
Each exclusion has to be justifiable to someone who is not you. Excluding something because it is inconvenient is the finding that gets written up.
Closing the gaps
The variable phase, and usually the largest. For some organisations this is documenting what already happens. For others it is building processes that do not exist. The gap analysis told you which one you are.
The decision
Where to stop. Over-engineering a control that was already adequate costs real money and buys nothing, and it is a common way to spend a budget without improving the outcome.
Internal audit
A requirement of the standard in its own right, not audit preparation. It must be independent of the work being audited, which constrains who can run it, including which consultant if they built your ISMS.
The decision
Whether to treat it as a formality or as your last cheap chance to find what a certification auditor would find. The second is the entire point.
Management review
Top management reviewing ISMS performance, audit results, risks and improvement. This is the part that cannot be bought or delegated, and it is where auditors probe whether the ISMS is real.
The decision
Whether leadership actually engages. An ISMS that only exists below the leadership line is visible to an auditor within an hour of arriving.
Stage 1
The body reviews whether the ISMS is designed and documented well enough to be audited: scope, risk assessment, Statement of Applicability, management review. Often runs partly or wholly remotely.
The decision
Already made. By now you have chosen a body and agreed a scope, which is precisely why doing a gap analysis on your own timetable was worth it.
Stage 2
The body tests whether controls are implemented and effective, sampling evidence and interviewing people across the scope. Non-conformities must be resolved before the certificate is issued.
The decision
Theirs, and independently. No consultant controls this outcome, which is why anyone guaranteeing it is telling you something about themselves.
The cost is decided long before the auditor arrives
The two phases that set your cost are the two cheapest ones. Scoping decides what is being audited, and the gap analysis tells you what closing it takes. Everything after that is execution against decisions already made.
This is why organisations that skip to the audit quote get numbers that move. A quote against an unfixed scope and a headcount counted on the wrong definition is provisional, whatever it says on the paper. Fix both first and the rest of the programme becomes a project rather than a discovery.
What drives implementation up or down
Increases it
- A broad scope, or one nobody has agreed
- Contractors inside scope who were not counted
- No existing policies, asset inventory or risk register
- Processes that exist only in people's heads
- Multiple sites and multiple environments in scope
- No named owner with authority to decide
- Leadership treating it as a compliance errand
Reduces it
- A tight scope, decided deliberately and written down
- An existing framework with overlapping evidence
- Cloud-native architecture with clear boundaries
- Evidence already collected rather than reconstructed
- A named owner with the authority to make decisions
- Documented processes, even imperfect ones
- Honest self-assessment early, rather than optimism until Stage 1
Scope leads both lists. It drives audit time under ISO/IEC 27006-1:2024, the number of controls in play, and the internal hours, all at once. It is also the only item on either list that you can change this afternoon.
And then it recurs
Implementation ends at the certificate. The programme does not. Certification runs on a three-year cycle: the two-stage initial audit, surveillance audits in the intervening years, and recertification before the certificate expires. The internal audit and management review are standing requirements rather than one-off tasks. Budget the cycle, not the project. Pricing the three-year cycle.