SGS ISO 27001 cost: accreditation, entity and what sets the quote
SGS publishes no rate card and no day rate for ISO 27001, and the tables that determine audit days are sold by ISO. So there is no fee here. There is the schedule of accreditation on the UKAS register, the entity that holds it, and the inputs that will actually move the number when SGS quotes your scope.
Updated July 2026
SGS on the UKAS register
Legal entity
SGS United Kingdom Limited
Accreditation body
UKAS
Accreditation number
0005
ISO/IEC 27001 on the schedule
Confirmed, read from the schedule
Scope line, verbatim
"Information Security Management Systems (ISMS) to ISO/IEC 27001:2022"
Checked July 2026 by downloading the schedule and reading its accredited scope. Schedule of accreditation 0005 | UKAS register
A Swiss-headquartered inspection and certification group with one of the largest global footprints. The UK entity holds the UKAS ISMS accreditation.
A global footprint is not a global accreditation
This is the fact most worth carrying away from an SGS conversation, and it is not a criticism of SGS: it is how accreditation works everywhere. Accreditation attaches to a legal entity and to a specific scheme. A group operating in many countries operates through many entities, and those entities are accredited separately by their own national accreditation bodies. The reach of the brand tells you nothing about which of those accreditations backs your certificate.
The resolution is two questions and one lookup. Which entity will issue my certificate, and which accreditation body accredits it? Then open that register and read the schedule. Where your requirement is UKAS specifically, the entity above is the one holding the UKAS ISMS accreditation, and schedule 0005 is the document to read.
The same logic applies scheme by scheme. On a broad schedule, the presence of the ISMS line is the thing to confirm. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001, however many other schemes sit alongside it.
Why there is no SGS fee on this page
An audit fee is audit days multiplied by a rate. Neither input is published.
The rate is commercial. SGS quotes per engagement. No accredited certification body publishes a day rate, and the accreditation registers publish accreditation status only, never anything commercial.
The days are behind a paywall. ISMS audit time is determined under ISO/IEC 27006-1:2024. Its audit-time provisions are the normative Annex C, with methods for audit time calculations in the informative Annex D. ISO sells the standard and the annex tables are not in the free preview. We have not read them, so we do not reproduce them.
SGS holds the standard and applies Annex C to your scope. Ask for the audit days it determined and the basis for them. More on how audit fees are set.
What actually drives your quote from SGS
These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are drivers, not a formula. If you are distributed across sites, the last two are where your quote is decided.
Number of persons doing work under the organisation's control, within the ISMS scope
The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.
ISMS scope
What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.
Complexity and risk of the ISMS
Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.
Sites
Where scoped activities physically happen, and whether multi-site sampling applies.
Delivery mode
How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.
Headcount is counted on the standard's definition, not on your payroll report. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation, so contractors and freelancers inside the scope count toward the total.
Price the three-year cycle, not year one
Year one
Two-stage initial audit
Stage 1 tests whether the ISMS is designed and documented well enough to be audited. Stage 2 tests whether it is implemented and effective. SGS determines the total audit time and how it splits across the stages.
Intervening years
Surveillance audits
Shorter than the initial audit, also determined under ISO/IEC 27006-1:2024, also quoted per engagement, and part of your cost of certification rather than an extra.
Before expiry
Recertification
The certificate expires and recertification is required to renew it. Ask what happens to the rate across the three years before you sign year one.
A year-one quote is not your cost of certification. See the three-year cycle page.
How to get a comparable quote from SGS
- Write one scope brief and send it unchanged to every body. Scope, headcount on the ISO/IEC 27006-1:2024 definition, sites, remote versus on-site appetite, and every scheme you intend to certify.
- Ask SGS to state the audit days it determined. Days are the quantity the standard governs.
- Confirm the issuing entity and that its schedule covers ISO/IEC 27001. For a UKAS requirement, that is schedule 0005.
- Ask for the full cycle. Initial audit, surveillance, recertification, and the rate across three years.
- Get travel and expenses stated separately. They sit outside audit time and matter most when you are spread across sites.
- Confirm audit time is determined under ISO/IEC 27006-1:2024. UKAS required transition by 31 July 2025 and ANAB required application to all clients by 31 March 2026.
Verify accreditation yourself: UKAS register | ANAB directory