How we source ISO 27001 cost figures
Every externally attributed figure on this site is read off a primary surface we opened ourselves, and carries the date we checked it. If we could not read it, it is not here. That rule decides most of what follows, including the fact that this site publishes no certification-body day rate and no audit-day table, and it is the reason those absences are findings rather than gaps.
The sourcing standard
- Primary surfaces only. A figure enters this site from the surface that publishes it: the vendor's own listing, the standards body's own document, the scheme operator's own site, the accreditation body's own register. Not from a summary of one.
- We must have read it. A document we could not open is not a source we quote figures from. We may describe what it governs. We may not reproduce numbers we never saw.
- Attribution is to the surface, not the company. We write that a vendor lists a figure on AWS Marketplace, checked on a date. We do not write that the vendor costs that figure. Those are different claims and only one of them is ours to make.
- A starting price is a floor. Where a listing describes a figure as a starting price, we label it as a floor and quote the listing's own hedge alongside it.
- We never sum published dimensions into a headline. AWS Marketplace publishes platform and framework fees as separate dimensions and publishes no combined figure. Where we add two together it is our arithmetic, it is labelled as ours, and it never appears in a heading, a page title or a stat tile.
- Every figure carries a check date. Published prices move. A figure without a date is a claim about the present that nobody verified.
Every externally attributed figure on this site resolves to a single source file, so a number cannot be typed into a page by hand. If it is not in that file with a URL and a check date, it does not render.
What is genuinely published
One layer of the ISO 27001 budget has real, public, verifiable list prices: the GRC platform layer. Several vendors publish pricing dimensions on public AWS Marketplace listings, on 12-month contracts. We read those listings, record each dimension with the band the listing states, and report them with the check date. Those are the figures this site carries.
- Vanta. AWS Marketplace listing Figures on this listing are a floor, and we label them as one.
- Drata. AWS Marketplace listing
- Secureframe. AWS Marketplace listing
- Sprinto. AWS Marketplace listing Figures on this listing are a floor, and we label them as one.
- Scytale. AWS Marketplace listing Figures on this listing are a floor, and we label them as one.
The published bands have ceilings, and we say so on every page where it matters. Above roughly 100 employees these listings run out and every platform moves to a private offer. That boundary is one of the more useful things on this site, and it only exists because we report what the listings actually say rather than extrapolating past them.
Cyber Essentials: the other published price
The UK Cyber Essentials scheme publishes real certification pricing banded by organisation size, and we report it. It comes from IASME Consortium, which operates the scheme, and the UK National Cyber Security Centre (NCSC) independently states the same floor. Both surfaces read on 17 July 2026.
The scheme also illustrates our rule working in both directions. Cyber Essentials Plus, from the same operator, publishes no price: IASME states that the assessment has to be quoted for individually and that cost depends on the size and complexity of the network. So we publish the basic bands and no Plus figure, from the same source, on the same page.
IASME Cyber Essentials FAQ | NCSC Cyber Essentials overview
Audit time: what governs it, and what we publish
ISO/IEC 27006-1:2024 is the instrument that governs how accredited bodies determine ISMS certification audit time. Its audit-time provisions sit in Annex C, which is normative, with methods for audit time calculations in the informative Annex D.
ISO sells that standard. The annex tables are not in the free preview, we have not read them, and so we publish no audit-day table and no audit-day figure anywhere on this site. We also do not reconstruct them from a document written for a different certification scheme. Your certification body holds the standard, applies Annex C to your scope, and can tell you the audit days it determined and the basis for them.
What we do publish is the drivers the standard and the accreditation bodies name, because knowing them is what lets a buyer interrogate a quote: the number of people doing work under the organisation's control within the ISMS scope, the scope itself, the complexity and risk of the ISMS, the sites, and the delivery mode.
IAF MD 5:2023 is a different instrument and does not govern ISMS audit time. It is titled "Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems" and states that it is mandatory for audits of quality, environmental and occupational health and safety management systems. We read the full document. It matters to an ISO 27001 buyer only where an integrated management system means ISO 9001 or ISO 14001 is being certified alongside the ISMS.
ISO catalogue entry for ISO/IEC 27006-1:2024 | IAF MD 5:2023 | IAF MD 26:2023 | IAF document register
Why this site carries no day rates
No accredited certification body publishes a rate card or a day rate. Neither do ISO 27001 consultancies. We looked; there is nothing to report. So an audit fee, which is audit days multiplied by a day rate, has both of its inputs unpublished, and this site prints no audit fee, no consultant day rate, and nothing derived from either.
This is the point on which we differ most from other pages on this question, so it is worth being plain about the reasoning. A precise-looking fee built from an assumed day count and an assumed day rate is not an estimate, it is a number with the shape of a fact and none of the substance, and it is worse than no number because it anchors a budget conversation on nothing. What we publish instead is the structure: what determines your quote, what to ask for, and how to make competing quotes comparable. See the audit cost page.
What we verify on registers
Accreditation is the one thing about a certification body that is genuinely public and independently verifiable, and it is published by the accreditation bodies themselves. That is what our certification-body pages carry: accreditation status read off the accreditation body's own register, never off the certification body's marketing material. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001, and the register is where that distinction is settled.
What we do not cite
- Aggregators and review platforms. Crowd-sourced contract values and review-site pricing panels are not primary surfaces. They report what somebody said they paid, unverifiably, at an unknown date and scope.
- Our own sites. Digital Signet operates other reference sites. None of them is a source for a figure here. Citing ourselves would be circular, and a number does not become verified by being republished.
- Paywalled documents we could not read. Naming a standard is not the same as having read it. We name what governs what, and quote only what we opened.
- Vendor marketing as a price source. A published listing is a surface. A brochure claim is not.
Structured data
Pages on this site emit Article, Breadcrumb and FAQPage structured data only. We deliberately emit no Offer, AggregateOffer or priceRange markup. Offer markup asserts that a seller offers something at a price, and we are not the seller of any third party's product. Publishing a third party's price as machine-readable Offer data under our name would be a claim we have no standing to make, whatever the figure.
Update cadence
Figures update when the surface that publishes them changes. Triggers:
- A vendor changes a published AWS Marketplace pricing dimension or band
- The Cyber Essentials scheme changes its published bands
- A revision to ISO/IEC 27001 or to ISO/IEC 27006-1:2024
- An IAF mandatory document or accreditation-body transition requirement that changes the mechanics
- A surface that published nothing starts publishing, or stops
We re-read the surfaces on a scheduled pass and record the check date whether or not the figure moved. Cosmetic date bumps are not made.
Editorial position
This site is operated by Digital Signet, an independent AI-development studio. Digital Signet does not sell ISO 27001 certification, does not act as a certification body, does not run a GRC platform, and does not accept paid placements from any vendor in the compliance space. No vendor named on this site has any influence over what it says about them. See /about for the operator.
Editorial direction is set by Digital Signet's editor. Drafts are produced via Digital Signet's autonomous AI development methodology and reviewed against the sourcing standard above before publication.
Corrections
If a figure here disagrees with the surface it cites, we want to know and we will fix it. That includes vendors: if your listing says something different from what we report, tell us and we will re-read it. [email protected].