Schellman ISO 27001 cost: a single-scheme ISMS accreditation
No fee appears on this page, because Schellman does not publish one and no accredited certification body does. What Schellman does have that is public and checkable is a UKAS schedule of accreditation with an unusual shape: ISO/IEC 27001 and nothing else. Here is that schedule, what it means for a buyer, and what will drive the number Schellman quotes.
Updated July 2026
Schellman on the UKAS register
Legal entity
Schellman Compliance, LLC
Accreditation body
UKAS
Accreditation number
8685
ISO/IEC 27001 on the schedule
Confirmed, read from the schedule
Scope line, verbatim
"Information Security Management Systems (ISMS) to ISO/IEC 27001:2022"
Checked July 2026 by downloading the schedule and reading its accredited scope. Schedule of accreditation 8685 | UKAS register
A US-headquartered assurance firm best known in the SOC 2 market, which also holds accreditation for ISMS certification in its own name. Unusually among the bodies here, its UKAS schedule is single-scheme: ISO/IEC 27001 only, with none of the quality or environmental schemes the older groups carry.
Accreditation attaches to a legal entity, not to a global brand. Schellman Compliance, LLC is the entity named on the schedule, and it is the entity that must appear on your certificate for the accreditation to mean anything. Accreditation for one scheme never implies accreditation for another: each scheme is a separate entry on the schedule.
What a single-scheme schedule means for you
If ISO 27001 is the whole job
The schedule covers exactly what you are buying. Nothing about a single-scheme accreditation makes the certificate narrower: an accredited ISO/IEC 27001 certificate is an accredited ISO/IEC 27001 certificate whoever issues it, and the scope line above is the same line the multi-scheme bodies carry.
If your roadmap is wider
A quality, environmental or AI management system certificate is not on this schedule, so it would come from a separate accredited body with a separate audit programme. Decide that before you scope year one, because it changes who you brief and how the cycle is planned.
Relevant if you are buying SOC 2 and ISO 27001 together, since Schellman operates in both markets.
If you are running both, say so in the brief. The scope you certify, the evidence you gather and the timing of the two engagements are all things worth putting on the table with a firm that works in both markets. What we will not do is print a number for the combination, because nobody publishes one. See ISO 27001 and SOC 2 compared.
Why there is no Schellman fee on this page
An audit fee is audit days multiplied by a rate. Neither input is published.
The rate is commercial. Schellman quotes per engagement. No accredited certification body publishes a day rate, and the accreditation registers publish accreditation status only, never anything commercial.
The days are behind a paywall. ISMS audit time is determined under ISO/IEC 27006-1:2024. Its audit-time provisions are the normative Annex C, with methods for audit time calculations in the informative Annex D. ISO sells the standard and the annex tables are not in the free preview. We have not read them, so we do not reproduce them.
Schellman holds the standard and applies Annex C to your scope. The audit days it determined, and the basis for them, are the most useful thing you can ask for. More on how audit fees are set.
What actually drives your quote from Schellman
These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are drivers, not a formula, and they apply identically whichever accredited body you approach.
Number of persons doing work under the organisation's control, within the ISMS scope
The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.
ISMS scope
What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.
Complexity and risk of the ISMS
Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.
Sites
Where scoped activities physically happen, and whether multi-site sampling applies.
Delivery mode
How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.
Headcount is counted on the standard's definition, not on your payroll report. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation, so contractors and freelancers inside the scope count. This one catches SaaS companies with large contractor benches more often than any other input.
Price the three-year cycle, not year one
ISO 27001 certification runs on a three-year cycle: a two-stage initial audit, surveillance audits in the intervening years, and a recertification audit before the certificate expires. This is a different rhythm to an annual SOC 2 examination, which is worth knowing if you are buying both from the same firm.
Surveillance audits are shorter than the initial audit, are also determined under ISO/IEC 27006-1:2024, and are also quoted per engagement. A year-one quote is therefore not your cost of certification. Ask Schellman to price the whole cycle up front and to state what happens to the rate across the three years. See the three-year cycle page.
How to get a comparable quote from Schellman
- Write one scope brief and send it unchanged to every body. Scope, headcount on the ISO/IEC 27006-1:2024 definition, sites, remote versus on-site appetite, and whether SOC 2 is in play alongside ISO 27001.
- Ask Schellman to state the audit days it determined. Days are the quantity the standard governs.
- Confirm schedule 8685 covers the scheme you are buying, under the entity that will issue your certificate.
- Ask for the full cycle. Initial audit, surveillance, recertification, and what happens to the rate across three years.
- Get travel and expenses stated separately. They sit outside audit time.
- Confirm audit time is determined under ISO/IEC 27006-1:2024. UKAS required transition by 31 July 2025 and ANAB required application to all clients by 31 March 2026.
Verify accreditation yourself: UKAS register | ANAB directory