Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

ISO 27001 cost for mid-market: where published pricing runs out

100 to 500 employees is the band where this market stops publishing. Every GRC platform price on AWS Marketplace is drawn against a band that has already ended by the time you get here, and the certification audit was never published at any size. Mid-market is the first stage where you are negotiating both layers privately, with no published reference on either. That is worth knowing plainly, because it changes what a good buyer does next.

Updated July 2026

Every published band has already ended

This table carries no prices, deliberately. It carries the ceiling each vendor publishes on its own AWS Marketplace listing, read off the listing and checked July 2026. At 100 to 500 people, every one of them is behind you.

PlatformHighest band the listing publishesWhat the listing saysAt 100-500 people
Vanta1-20 employeesThe only employee range the listing publishes is for the Essentials package.Private offer
Secureframeup to 100 employeesThe platform dimension states the band explicitly.Private offer
Sprintoup to 100 employeesThe Starter platform dimension states the band explicitly.Private offer
Dratacapacity for a 100 FTE orgThe platform fee is published against that capacity.Private offer
Scytaleno employee band publishedThe listing states a starting price and routes to a quote.Private offer

What this means for your budget process

A startup can sanity-check a platform quote against a published band. You cannot. Nothing on this page, and nothing on any honest page anywhere, gives you a published figure to anchor against at your size. So the anchor has to come from structure instead: an identical brief sent to several vendors and several accredited bodies, priced across the full three-year cycle, with the quantities stated rather than only the totals. That is not a consolation prize. Run properly, a comparison of like-for-like quotes is a better anchor than a published band would have been, because it is drawn against your actual scope.

What drives the audit quote

These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are drivers, not a formula: the audit-time provisions sit in the normative Annex C, ISO sells the standard, and we have not read the tables, so we do not reconstruct them. Knowing the drivers is still what lets you interrogate a quote rather than receive one.

Number of persons doing work under the organisation's control, within the ISMS scope

The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.

ISMS scope

What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.

Complexity and risk of the ISMS

Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.

Sites

Where scoped activities physically happen, and whether multi-site sampling applies.

Delivery mode

How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.

Why mid-market is structurally different

Scope stops being a technical decision and becomes an organisational one. A 250-person company usually has more than one business unit, more than one location, often more than one country, and frequently an acquisition somewhere on the spectrum between bought and integrated. Every scope question is therefore also a question about which part of the business goes first and who explains that to their customers. Scope is still the largest lever you hold over audit time, but at this size pulling it requires agreement rather than a decision.

The evidence is distributed. At startup size one person can see the whole estate. At mid-market the access reviews live with IT, the training records with HR, the supplier contracts with legal and procurement, the change management with engineering, and the physical controls with whoever runs the offices. The ISMS does not create that fragmentation, it reveals it. What the programme actually needs is someone with the authority to ask each of those functions for evidence and be answered on a schedule.

And discovery is real. An asset inventory and a supplier register built honestly at this size tend to find things: tools bought on a card, vendors nobody registered, an environment that outlived the project it was built for. Each discovery is then a decision. We publish no figure for this, because it depends entirely on what is in your estate, and a number for your shadow IT from someone who has not looked at your estate is not information.

The scope decisions that are actually contested

The half-integrated acquisition

In scope from day one, deferred to a later cycle, or carved out. Each option has a consequence: bringing it in means raising it to the parent's standard first, deferring means explaining the boundary at every audit, and carving it out means telling that company's customers the certificate does not cover them.

One business unit or all of them

A single-unit scope is a legitimate and common choice, and it is smaller. The question to answer honestly is whether the certificate you end up with covers the thing your buyers are actually asking about. A narrow certificate that misses the point of the ask is the expensive outcome.

The environment that outlived its project

Legacy systems inside the boundary bring their own evidence requirements. Deciding whether a system is genuinely in scope, or whether it can be decommissioned before the audit rather than documented for it, is often the cheaper question to ask first.

Sites and multi-site sampling

Where scoped activity physically happens drives whether multi-site sampling applies, and it drives auditor travel. Travel and expenses sit outside audit time and are usually quoted separately, so ask for them as a separate line.

How to interrogate a private offer

  1. Fix the scope before you go to market. With no published anchor, the brief is the only thing making quotes comparable. An ambiguous scope invites a defensive estimate, and defensive estimates are expensive.
  2. Count the right people. Everyone doing work under your control inside the scope, contractors included. This is the definition ISO/IEC 27006-1:2024 uses, and undercounting it is the most common cause of a revised quote.
  3. Ask each body to state the audit days it determined. Days are the quantity the standard requires them to determine. A quote that states its days is a quote you can hold to a scope; a lump sum is not.
  4. Ask the platform what your band actually is. You are above every published band, so ask what the offer is drawn against and what happens to it at your next headcount step. That is a fair question and the answer is informative either way.
  5. Price the full three-year cycle. Initial audit, surveillance in the intervening years, recertification before expiry, and what happens to the rate across all three. A cheaper year one with unstated surveillance is not a cheaper programme.
  6. Confirm accreditation for ISO/IEC 27001 on the register. On the accreditation body's own register, not the brochure. Accreditation for ISO 9001 does not imply it for ISO/IEC 27001.
  7. Get travel and expenses stated separately. They sit outside audit time and are a real line at multi-site scale.

Frequently asked questions

How much does ISO 27001 cost for a 250-employee company?
There is no published figure, and that is the finding rather than an evasion. Every GRC platform band published on AWS Marketplace has already run out by 250 people: Secureframe and Sprinto publish platform dimensions up to 100 employees, Drata publishes its platform fee as capacity for a 100 FTE organisation, and Vanta's only published employee range is 1-20. Above those lines each vendor moves to a private offer. The certification audit was never published at any size, because accredited bodies quote per engagement and the audit-time tables sit in ISO/IEC 27006-1:2024 Annex C, which ISO sells. At mid-market both layers are private, so the only way to learn your number is to run a structured quote process.
Why does published pricing stop at around 100 employees?
Because that is where the listings stop. It is a commercial choice by the vendors: below roughly 100 people the product is standardised enough to list a price against a band, and above it the deals are shaped per customer. The consequence for a buyer is specific. Crossing 100 people means crossing out of published pricing on the platform layer, while the audit layer was already private. Mid-market is the first stage where a company is negotiating both layers with no published reference point on either.
What actually drives a mid-market audit quote?
The drivers named by ISO/IEC 27006-1:2024 and the accreditation bodies: the number of people doing work under the organisation's control within the ISMS scope, counted regardless of whether they are members of the organisation, so contractors count; the ISMS scope itself; the complexity and risk of the ISMS including the criticality of the information handled; the sites involved and whether multi-site sampling applies; and how much of the audit runs remotely rather than on site. These are drivers, not a formula. We do not hold the Annex C tables and we do not reconstruct them.
Does mid-market need a dedicated ISO 27001 lead?
In practice the work needs an owner with authority, which is the real constraint rather than a headcount number. At this size the implementation is cross-functional by nature: engineering, IT, HR, legal, procurement and facilities all hold evidence, and someone has to be able to ask each of them for it and be answered. Where organisations get into trouble is adding the work to an existing manager's responsibilities without the authority or the time to match, which shows up as a timeline that keeps moving rather than as a line in a budget.
What is the biggest mid-market surprise?
Discovery. The ISMS requires an asset inventory and a supplier register, and building them honestly at this size tends to surface tools and vendors that no central register knew about. Each one then needs a decision: assess it, contract it properly, or replace it. The work is real and it lands mid-implementation, after the budget was set. We do not publish a figure for it because it depends entirely on what you find, and anyone quoting you a number for your shadow IT has not looked at your estate.
Should mid-market choose a premium brand certification body?
The test is whether your buyers ask for a named body or for ISO 27001. Accreditation is what makes a certificate recognised, and it is verifiable on the accreditation body's own public register, which states the exact schemes each body is accredited for. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001. Since no body publishes a rate card, any claim about what one body charges relative to another is not something we can source, so we do not make one. Approach several accredited bodies with an identical brief and let the quotes answer the question.

Related reading

Updated July 2026