ISO 27001 cost for mid-market: where published pricing runs out
100 to 500 employees is the band where this market stops publishing. Every GRC platform price on AWS Marketplace is drawn against a band that has already ended by the time you get here, and the certification audit was never published at any size. Mid-market is the first stage where you are negotiating both layers privately, with no published reference on either. That is worth knowing plainly, because it changes what a good buyer does next.
Updated July 2026
Every published band has already ended
This table carries no prices, deliberately. It carries the ceiling each vendor publishes on its own AWS Marketplace listing, read off the listing and checked July 2026. At 100 to 500 people, every one of them is behind you.
| Platform | Highest band the listing publishes | What the listing says | At 100-500 people |
|---|---|---|---|
| Vanta | 1-20 employees | The only employee range the listing publishes is for the Essentials package. | Private offer |
| Secureframe | up to 100 employees | The platform dimension states the band explicitly. | Private offer |
| Sprinto | up to 100 employees | The Starter platform dimension states the band explicitly. | Private offer |
| Drata | capacity for a 100 FTE org | The platform fee is published against that capacity. | Private offer |
| Scytale | no employee band published | The listing states a starting price and routes to a quote. | Private offer |
What this means for your budget process
A startup can sanity-check a platform quote against a published band. You cannot. Nothing on this page, and nothing on any honest page anywhere, gives you a published figure to anchor against at your size. So the anchor has to come from structure instead: an identical brief sent to several vendors and several accredited bodies, priced across the full three-year cycle, with the quantities stated rather than only the totals. That is not a consolation prize. Run properly, a comparison of like-for-like quotes is a better anchor than a published band would have been, because it is drawn against your actual scope.
What drives the audit quote
These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are drivers, not a formula: the audit-time provisions sit in the normative Annex C, ISO sells the standard, and we have not read the tables, so we do not reconstruct them. Knowing the drivers is still what lets you interrogate a quote rather than receive one.
Number of persons doing work under the organisation's control, within the ISMS scope
The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.
ISMS scope
What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.
Complexity and risk of the ISMS
Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.
Sites
Where scoped activities physically happen, and whether multi-site sampling applies.
Delivery mode
How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.
Why mid-market is structurally different
Scope stops being a technical decision and becomes an organisational one. A 250-person company usually has more than one business unit, more than one location, often more than one country, and frequently an acquisition somewhere on the spectrum between bought and integrated. Every scope question is therefore also a question about which part of the business goes first and who explains that to their customers. Scope is still the largest lever you hold over audit time, but at this size pulling it requires agreement rather than a decision.
The evidence is distributed. At startup size one person can see the whole estate. At mid-market the access reviews live with IT, the training records with HR, the supplier contracts with legal and procurement, the change management with engineering, and the physical controls with whoever runs the offices. The ISMS does not create that fragmentation, it reveals it. What the programme actually needs is someone with the authority to ask each of those functions for evidence and be answered on a schedule.
And discovery is real. An asset inventory and a supplier register built honestly at this size tend to find things: tools bought on a card, vendors nobody registered, an environment that outlived the project it was built for. Each discovery is then a decision. We publish no figure for this, because it depends entirely on what is in your estate, and a number for your shadow IT from someone who has not looked at your estate is not information.
The scope decisions that are actually contested
The half-integrated acquisition
In scope from day one, deferred to a later cycle, or carved out. Each option has a consequence: bringing it in means raising it to the parent's standard first, deferring means explaining the boundary at every audit, and carving it out means telling that company's customers the certificate does not cover them.
One business unit or all of them
A single-unit scope is a legitimate and common choice, and it is smaller. The question to answer honestly is whether the certificate you end up with covers the thing your buyers are actually asking about. A narrow certificate that misses the point of the ask is the expensive outcome.
The environment that outlived its project
Legacy systems inside the boundary bring their own evidence requirements. Deciding whether a system is genuinely in scope, or whether it can be decommissioned before the audit rather than documented for it, is often the cheaper question to ask first.
Sites and multi-site sampling
Where scoped activity physically happens drives whether multi-site sampling applies, and it drives auditor travel. Travel and expenses sit outside audit time and are usually quoted separately, so ask for them as a separate line.
How to interrogate a private offer
- Fix the scope before you go to market. With no published anchor, the brief is the only thing making quotes comparable. An ambiguous scope invites a defensive estimate, and defensive estimates are expensive.
- Count the right people. Everyone doing work under your control inside the scope, contractors included. This is the definition ISO/IEC 27006-1:2024 uses, and undercounting it is the most common cause of a revised quote.
- Ask each body to state the audit days it determined. Days are the quantity the standard requires them to determine. A quote that states its days is a quote you can hold to a scope; a lump sum is not.
- Ask the platform what your band actually is. You are above every published band, so ask what the offer is drawn against and what happens to it at your next headcount step. That is a fair question and the answer is informative either way.
- Price the full three-year cycle. Initial audit, surveillance in the intervening years, recertification before expiry, and what happens to the rate across all three. A cheaper year one with unstated surveillance is not a cheaper programme.
- Confirm accreditation for ISO/IEC 27001 on the register. On the accreditation body's own register, not the brochure. Accreditation for ISO 9001 does not imply it for ISO/IEC 27001.
- Get travel and expenses stated separately. They sit outside audit time and are a real line at multi-site scale.