Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

LRQA ISO 27001 cost: the accreditation, and what sets the quote

There is no LRQA fee on this page, because LRQA does not publish one and neither does any other accredited certification body. The audit-day tables are sold by ISO. What is public, and what this page is built on, is LRQA's schedule of accreditation on the UKAS register and the drivers the standard names for determining your audit time.

Updated July 2026

LRQA on the UKAS register

Legal entity

LRQA Limited

Accreditation body

UKAS

Accreditation number

0001

ISO/IEC 27001 on the schedule

Confirmed, read from the schedule

Scope line, verbatim

"Information Security Management Systems (ISMS) to ISO/IEC 27001:2022"

Checked July 2026 by downloading the schedule and reading its accredited scope. Schedule of accreditation 0001 | UKAS register

Formerly Lloyd's Register Quality Assurance, now an independent group. Holds UKAS accreditation number 0001. Its schedule carries ISMS alongside food safety, business continuity and supply chain security management systems.

Accreditation attaches to a legal entity, not to a global brand. LRQA Limited is the entity UKAS accredits, and it is the entity that must appear on your certificate for the accreditation to mean anything. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001: those are separate scheme entries on the schedule.

What number 0001 does and does not tell you

What it tells you

  • Which schedule to open on the UKAS register
  • Which legal entity the accreditation is held by
  • The exact list of schemes that entity is accredited for, including ISMS
  • That the accreditation is current, because UKAS maintains the register

What it does not tell you

  • Anything about price, because the register carries nothing commercial
  • Anything about audit quality or standing, because it identifies rather than rates
  • How many audit days your scope would attract
  • Which auditor you would get, or when

The useful thing is not the number but the schedule it points to, which is why every accreditation claim on this page links to the schedule rather than to a brand page.

Why there is no LRQA fee on this page

An audit fee is audit days multiplied by a rate. Neither input is published.

The rate is commercial. LRQA quotes per engagement. No accredited certification body publishes a day rate, and the accreditation registers publish accreditation status only. There is no rack rate in this market to quote or to discount from.

The days are behind a paywall. ISMS audit time is determined under ISO/IEC 27006-1:2024. Its audit-time provisions are the normative Annex C, with methods for audit time calculations in the informative Annex D. ISO sells the standard and the annex tables are not in the free preview. We have not read them, so we do not reproduce them.

LRQA holds the standard and applies Annex C to your scope. The audit days it determined, and the basis for them, are a fair thing to ask for and the most useful number in the whole conversation. More on how audit fees are set.

What actually drives your quote from LRQA

These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are drivers, not a formula, and the first two are largely yours to set before you ask anyone for a number.

Number of persons doing work under the organisation's control, within the ISMS scope

The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.

ISMS scope

What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.

Complexity and risk of the ISMS

Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.

Sites

Where scoped activities physically happen, and whether multi-site sampling applies.

Delivery mode

How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.

Headcount is counted on the standard's definition, not on your payroll report. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation, so contractors and freelancers inside the scope count. Getting that number right before you request quotes is the difference between a quote that holds and a quote revised upward after Stage 1.

Price the three-year cycle, not year one

Certification runs on a three-year cycle: a two-stage initial audit, surveillance audits in the intervening years, and a recertification audit before the certificate expires. Surveillance audits are shorter than the initial audit, are also determined under ISO/IEC 27006-1:2024, and are also quoted per engagement.

So a year-one quote is not your cost of certification, and a cheaper year one with unstated surveillance is not a cheaper programme. Ask LRQA to price the whole cycle up front and to state what happens to the rate across the three years. See the three-year cycle page.

How to get a comparable quote from LRQA

  1. Fix the scope brief first, then send it unchanged to every body. Scope, headcount on the ISO/IEC 27006-1:2024 definition, sites, remote versus on-site appetite, and every scheme you intend to certify.
  2. Ask LRQA to state the audit days it determined. Days are the quantity the standard governs.
  3. Confirm schedule 0001 covers the scheme you are buying, under the entity that will issue your certificate.
  4. Ask for the full cycle. Initial audit, surveillance, recertification, and what happens to the rate across three years.
  5. Get travel and expenses stated separately. They sit outside audit time and are a real line on an on-site audit.
  6. Confirm audit time is determined under ISO/IEC 27006-1:2024. UKAS required transition by 31 July 2025 and ANAB required application to all clients by 31 March 2026, so both deadlines have passed.

Verify accreditation yourself: UKAS register | ANAB directory

Frequently asked questions

How much does LRQA ISO 27001 certification cost?
LRQA publishes no rate card and no day rate for ISO 27001, and neither does any other accredited certification body. An audit fee is audit days multiplied by a rate. The rate is commercial and unpublished. The audit days are determined by the body under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C, and ISO sells that standard rather than publishing it openly. With both inputs unpublished, any figure printed here would be invented. LRQA quotes against your actual scope.
Is LRQA accredited for ISO 27001?
Yes. LRQA's management systems schedule of accreditation on the UKAS register, number 0001, is held by LRQA Limited and carries "Information Security Management Systems (ISMS) to ISO/IEC 27001:2022". We downloaded and read that schedule in July 2026. Accreditation attaches to a legal entity rather than to a brand, so confirm the entity named on your certificate against the register.
What does UKAS accreditation number 0001 mean?
It is an identifier for the accreditation, not a ranking or a rating. UKAS issues a number to each accreditation it grants, and the number itself carries no information about audit quality, price or standing. What carries information is the schedule the number points to: the legal entity that holds it and the exact list of schemes that entity is accredited for. Read the schedule rather than the number.
What else is on LRQA's UKAS schedule alongside ISO 27001?
LRQA's schedule carries ISMS alongside food safety, business continuity and supply chain security management systems. That combination matters only if it maps to your roadmap. A body accredited for a scheme can certify it, and a body not accredited for a scheme cannot whatever else it audits, so check every standard you intend to certify against the schedule before you scope the engagement.
What drives the audit days LRQA will quote?
The primary input under ISO/IEC 27006-1:2024 is the number of people doing work under the organisation's control within the ISMS scope, counted regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total. Audit time also reflects the ISMS scope itself, the complexity and risk of the ISMS including the criticality of the information handled, the sites involved, and how much of the audit runs remotely rather than on site.
How do I brief LRQA so the quote is comparable to another body's?
Send LRQA and every other body an identical brief: your ISMS scope, the number of people doing work under your control inside that scope including contractors, your sites, and how much of the audit can run remotely. Ask each body to state the audit days it has determined, to confirm its ISO/IEC 27001 accreditation on the accreditation body's register, to price surveillance and recertification across the full three-year cycle, and to state travel and expenses separately. Quotes built on different briefs cannot be compared.

Other certification bodies on the register

Updated July 2026