Independent cost guide. Not affiliated with any certification body or compliance platform. Estimates based on published rates and practitioner experience. Always obtain a formal quote.

LRQA ISO 27001 Certification Cost: Lloyd's Register Spinoff Read

LRQA first-year ISO 27001 audit fees range from $6,500 for a micro-organisation up to $40,000 for a large enterprise. Day rates of $1,800 to $2,300 in the US, GBP 1,100 to 1,500 in the UK. LRQA sits at the lower end of the premium-tier band, with two distinguishing dimensions: the Lloyd's Register heritage that carries weight in maritime and energy procurement contexts, and the integrated ISO 27001 plus ISO 22301 (business continuity) audit bundle that the BCM-experienced auditor pool delivers more cost-efficiently than most generalist bodies. Here is the honest read on when LRQA earns the engagement.

Updated May 2026

Who LRQA is, post-spinoff

LRQA was the management-systems certification arm of Lloyd's Register, the British classification society founded in 1760 to assess the seaworthiness of merchant vessels for insurance underwriting. The Lloyd's Register name carried 260+ years of maritime trust infrastructure and that heritage shaped LRQA's reputation in maritime, oil-and-gas, energy, and heavy-industry management-system certification. In 2021 Lloyd's Register sold the LRQA business to Goldman Sachs Asset Management Private Equity, and the certification body has operated as a standalone entity under the LRQA brand since.

The implication for buyers: the Lloyd's Register name is licensed for legacy reference (some marketing materials still reference the heritage explicitly) but the operational entity is private-equity-owned and run with a growth mandate. The investment thesis post-spinoff has been capacity expansion in information security, sustainability assurance (ISO 14001, GHG verification), and emerging schemes (ESG, supply-chain integrity). The auditor pool for ISO 27001 specifically has grown materially over 2022 to 2026 as a result of this investment, narrowing the historical gap with BSI in tech and SaaS auditor depth.

LRQA is accredited by UKAS in the UK, ANAB in the US, JAS-ANZ in Australia and New Zealand, and equivalent national accreditation bodies across 120+ operating geographies. The international accreditation footprint is competitive with Bureau Veritas and SGS. Service detail is published at lrqa.com/iso-27001.

How LRQA prices

LRQA uses the IAF MD 5 audit-day calculation as the base. The day-rate band sits at the lower end of the premium tier: $1,800 to $2,300 per day in the US, GBP 1,100 to 1,500 per day in the UK, and EUR 1,200 to 1,700 per day in mainland Europe. The day-rate band is slightly tighter than BSI's, with less geographic dispersion. The realistic posture for a buyer is that the rack-rate quote will discount 5 to 12 percent on a three-year programme commitment and a further 5 to 10 percent on a multi-framework bundle, particularly when ISO 22301 or ISO 14001 is added to the bundle.

The integrated audit pricing is the distinctive editorial pivot for LRQA. The Lloyd's Register heritage gave the certification body deep business-continuity-management expertise; an integrated ISO 27001 plus ISO 22301 audit through LRQA typically prices at 70 to 78 percent of the sum of two standalone audits, saving 22 to 30 percent. The integrated audit also tightens the implementation work because the ISO 27001 controls related to business continuity (Annex A.5.29 information security during disruption, A.5.30 ICT readiness for business continuity) get assessed once rather than twice with overlapping evidence demands.

Retainer engagements are uncommon for ISO 27001 at LRQA, as at the other premium-tier bodies. The standard engagement is a quoted-fee Stage 1 + Stage 2 audit in year one, surveillance audits at 30 to 33 percent of the initial audit fee in years two and three, and a full recertification audit in year four at approximately the initial fee level.

LRQA audit-day count by size

EmployeesAudit daysLRQA US feeLRQA UK feeSurveillance/yr
1-104-5$7,200-$11,500GBP 4,400-7,500$2,400-$3,800
11-255-7$9,000-$16,100GBP 5,500-10,500$3,000-$5,300
26-657-10$12,600-$23,000GBP 7,700-15,000$4,200-$7,600
66-1259-13$16,200-$29,900GBP 9,900-19,500$5,400-$9,900
126-27513-18$23,400-$41,400GBP 14,300-27,000$7,800-$13,700
276-62518-23$32,400-$52,900GBP 19,800-34,500$10,800-$17,500
626-1,17523-28$41,400-$64,400GBP 25,300-42,000$13,800-$21,300
1,176+28+$50,400+GBP 30,800+$16,800+

Three LRQA scenarios

Energy SaaS

40-person energy-vertical SaaS, UK

  • 7 days total
  • GBP 1,250/day mid-band UK
  • GBP 8,750 Stage 1 + 2

~GBP 8,750 first year

Vertical fit: energy buyers recognise the LR heritage even post-spinoff.

Bundled ISO 27001 + 22301

150-person fintech, integrated audit

  • 14 days total (vs 18-20 separate)
  • $2,100/day US blend
  • $29,400 Stage 1 + 2 combined

~$29,400 first year

Integrated audit saves ~25 percent vs running 27001 and 22301 separately.

Manufacturing IT

400-person manufacturer, 3 sites

  • 19 days total (multi-site sampling, 2 of 3 sites)
  • EUR 1,500/day EU blend
  • EUR 28,500 Stage 1 + 2

~EUR 28,500 first year

Manufacturing fit: pre-existing LRQA ISO 9001 relationship made the bundle attractive.

Where LRQA wins

LRQA wins on three dimensions. First, integrated ISO 27001 plus ISO 22301 (business continuity management) audits: the historical Lloyd's Register expertise in BCM translates into an auditor pool that handles the integrated audit more efficiently than generalist bodies, with cost savings of 22 to 30 percent vs running the two schemes separately. Second, maritime, energy, oil-and-gas, and heavy-industry procurement: the Lloyd's Register heritage continues to carry weight in these sectors and the LRQA brand earns the engagement when the buyer recognises the lineage. Third, sustainability-assurance bundling: LRQA has invested heavily in ESG, GHG verification, and ISO 14001 capacity post-spinoff, making integrated information-security plus sustainability programmes more efficient.

Where LRQA might not be the right fit

For pure SaaS organisations whose buyers are US enterprise procurement teams, the LRQA brand carries less SaaS-specific resonance than Schellman ISO practice or A-LIGN ISO practice. Both Schellman and A-LIGN are recognised through their SOC 2 audit franchises in the US procurement workflow; LRQA is not, despite the equivalent accreditation chain and competitive pricing. For SaaS-only US engagements, the SaaS-specialist mid-tier bodies often deliver better procurement signal at lower cost.

For single-site organisations with no business-continuity-management programme, the LRQA differentiator (integrated audit, BCM expertise) is irrelevant, and the price will be comparable to BSI without the equivalent brand recognition. A single-site 50-person SaaS without BCM ambitions would typically be better served by NQA (SME tier, identical accredited certificate, 25 to 35 percent cheaper) or by BSI (premium brand recognition in enterprise procurement).

Negotiation tips specific to LRQA

First, raise the integrated audit opportunity early. If you have any business-continuity-management requirement on the roadmap (regulatory, customer-driven, or internal-resilience-led), bundling ISO 22301 with ISO 27001 in a single LRQA audit programme is materially cheaper than two separate programmes and the LRQA auditor pool handles it well.

Second, ask about the sustainability-assurance bundle. LRQA's post-spinoff investment in ESG and GHG verification means they have packages that combine ISO 27001 with ISO 14001 or with GHG Protocol assurance at integrated-audit pricing. For organisations under pressure on both sustainability and information-security reporting, this is a more cost-efficient route than separate engagements.

Third, leverage the heritage where it matters. If your buyer recognises the Lloyd's Register lineage (maritime, energy, oil-and-gas, classic engineering procurement), the LRQA certificate carries trust-signal value that justifies the premium-tier price. If the buyer is pure SaaS procurement, the heritage is a marketing flourish without trust-signal value, and you should consider whether the price is justified.

Fourth, ask for the three-year programme quote with a frozen day rate against inflation. The Goldman Sachs ownership has put commercial pressure on annual rate increases; locking the rate for the certification cycle protects the year-two and year-three budgets from the 4 to 8 percent annual increase pattern observed across the premium tier in 2024-2026.

Frequently asked questions

How much does LRQA ISO 27001 certification cost?
LRQA ISO 27001 first-year audit fees range from $6,500 for a micro-organisation up to $40,000 for a large enterprise. Day rates are $1,800 to $2,300 in the US and GBP 1,100 to 1,500 in the UK, placing LRQA at the lower end of the premium-tier band, typically 5 to 15 percent below BSI on rack-rate quotes.
Is LRQA the same as Lloyd's Register?
Not anymore. LRQA was the management-systems certification arm of Lloyd's Register, the 264-year-old British classification society for shipping. In 2021 Lloyd's Register sold the LRQA business to Goldman Sachs Asset Management and the entity now operates as a standalone certification body under the LRQA brand. The Lloyd's Register name and heritage remain referenced; the corporate ownership is now private equity, not the maritime classification society.
What is LRQA best known for?
LRQA is best known for management-system certification in maritime, energy, oil-and-gas, automotive, and increasingly technology and SaaS sectors. The Lloyd's Register heritage carries particular weight in maritime and energy procurement contexts. For ISO 27001 specifically, the tech-practice growth over the past five years has built a credible SaaS auditor pool, though the deepest auditor expertise remains in industrial sectors.
Is LRQA accredited in the US?
Yes. LRQA holds ANAB accreditation in the US, UKAS accreditation in the UK, and equivalent national accreditations across its operating geographies. The accreditation chain is identical to BSI and Bureau Veritas; certificate weight in supplier-risk-management workflows is the same.
Does LRQA offer combined ISO 27001 plus ISO 22301 audits?
Yes, and this is a common LRQA bundle. ISO 22301 (business continuity management) overlaps significantly with ISO 27001 Annex A.5.29 / A.5.30 (information security during disruption) and A.5.24-A.5.28 (incident management). An integrated audit through LRQA typically saves 25 to 35 percent vs running the two schemes separately, and LRQA's maritime / energy heritage gives the auditors strong BCM experience.
How long does LRQA audit scheduling take?
LRQA fresh-client scheduling for Stage 1 and Stage 2 audits in 2026 typically runs 8 to 12 weeks from contract signature, comparable to Bureau Veritas and faster than BSI. The Goldman Sachs ownership has invested in capacity expansion since 2021 which has reduced backlogs vs the pre-spinoff era.

Compare with other certification bodies

Updated May 2026