Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

SGS ISO 27001 cost: accreditation, entity and what sets the quote

SGS publishes no rate card and no day rate for ISO 27001, and the tables that determine audit days are sold by ISO. So there is no fee here. There is the schedule of accreditation on the UKAS register, the entity that holds it, and the inputs that will actually move the number when SGS quotes your scope.

Updated July 2026

SGS on the UKAS register

Legal entity

SGS United Kingdom Limited

Accreditation body

UKAS

Accreditation number

0005

ISO/IEC 27001 on the schedule

Confirmed, read from the schedule

Scope line, verbatim

"Information Security Management Systems (ISMS) to ISO/IEC 27001:2022"

Checked July 2026 by downloading the schedule and reading its accredited scope. Schedule of accreditation 0005 | UKAS register

A Swiss-headquartered inspection and certification group with one of the largest global footprints. The UK entity holds the UKAS ISMS accreditation.

A global footprint is not a global accreditation

This is the fact most worth carrying away from an SGS conversation, and it is not a criticism of SGS: it is how accreditation works everywhere. Accreditation attaches to a legal entity and to a specific scheme. A group operating in many countries operates through many entities, and those entities are accredited separately by their own national accreditation bodies. The reach of the brand tells you nothing about which of those accreditations backs your certificate.

The resolution is two questions and one lookup. Which entity will issue my certificate, and which accreditation body accredits it? Then open that register and read the schedule. Where your requirement is UKAS specifically, the entity above is the one holding the UKAS ISMS accreditation, and schedule 0005 is the document to read.

The same logic applies scheme by scheme. On a broad schedule, the presence of the ISMS line is the thing to confirm. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001, however many other schemes sit alongside it.

Why there is no SGS fee on this page

An audit fee is audit days multiplied by a rate. Neither input is published.

The rate is commercial. SGS quotes per engagement. No accredited certification body publishes a day rate, and the accreditation registers publish accreditation status only, never anything commercial.

The days are behind a paywall. ISMS audit time is determined under ISO/IEC 27006-1:2024. Its audit-time provisions are the normative Annex C, with methods for audit time calculations in the informative Annex D. ISO sells the standard and the annex tables are not in the free preview. We have not read them, so we do not reproduce them.

SGS holds the standard and applies Annex C to your scope. Ask for the audit days it determined and the basis for them. More on how audit fees are set.

What actually drives your quote from SGS

These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are drivers, not a formula. If you are distributed across sites, the last two are where your quote is decided.

Number of persons doing work under the organisation's control, within the ISMS scope

The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.

ISMS scope

What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.

Complexity and risk of the ISMS

Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.

Sites

Where scoped activities physically happen, and whether multi-site sampling applies.

Delivery mode

How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.

Headcount is counted on the standard's definition, not on your payroll report. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation, so contractors and freelancers inside the scope count toward the total.

Price the three-year cycle, not year one

Year one

Two-stage initial audit

Stage 1 tests whether the ISMS is designed and documented well enough to be audited. Stage 2 tests whether it is implemented and effective. SGS determines the total audit time and how it splits across the stages.

Intervening years

Surveillance audits

Shorter than the initial audit, also determined under ISO/IEC 27006-1:2024, also quoted per engagement, and part of your cost of certification rather than an extra.

Before expiry

Recertification

The certificate expires and recertification is required to renew it. Ask what happens to the rate across the three years before you sign year one.

A year-one quote is not your cost of certification. See the three-year cycle page.

How to get a comparable quote from SGS

  1. Write one scope brief and send it unchanged to every body. Scope, headcount on the ISO/IEC 27006-1:2024 definition, sites, remote versus on-site appetite, and every scheme you intend to certify.
  2. Ask SGS to state the audit days it determined. Days are the quantity the standard governs.
  3. Confirm the issuing entity and that its schedule covers ISO/IEC 27001. For a UKAS requirement, that is schedule 0005.
  4. Ask for the full cycle. Initial audit, surveillance, recertification, and the rate across three years.
  5. Get travel and expenses stated separately. They sit outside audit time and matter most when you are spread across sites.
  6. Confirm audit time is determined under ISO/IEC 27006-1:2024. UKAS required transition by 31 July 2025 and ANAB required application to all clients by 31 March 2026.

Verify accreditation yourself: UKAS register | ANAB directory

Frequently asked questions

How much does SGS ISO 27001 certification cost?
SGS publishes no rate card and no day rate for ISO 27001, and neither does any other accredited certification body. An audit fee is audit days multiplied by a rate. The rate is commercial and unpublished. The audit days are determined by the body under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C, and ISO sells that standard rather than publishing it openly. Both inputs are unpublished, so any figure printed here would be invented. SGS quotes against your actual scope.
Is SGS accredited for ISO 27001?
Yes. SGS's management systems schedule of accreditation on the UKAS register, number 0005, is held by SGS United Kingdom Limited and carries "Information Security Management Systems (ISMS) to ISO/IEC 27001:2022". We downloaded and read that schedule in July 2026. Accreditation attaches to a legal entity rather than to a brand, so confirm the entity named on your certificate against the register.
Does SGS's global footprint mean the certificate is accredited everywhere?
No. Accreditation is a fact about a legal entity and a specific scheme, and a large international group operates through many entities accredited by different national accreditation bodies. The UKAS accreditation above is held by the UK entity. If your buyer requires accreditation by a particular accreditation body, ask which SGS entity would issue your certificate and check that entity on the relevant register rather than relying on the group's footprint.
What drives the audit days SGS will quote?
The primary input under ISO/IEC 27006-1:2024 is the number of people doing work under the organisation's control within the ISMS scope, counted regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total. Audit time also reflects the ISMS scope itself, the complexity and risk of the ISMS including the criticality of the information handled, the sites involved, and how much of the audit runs remotely rather than on site.
How are multiple sites handled in an SGS ISO 27001 quote?
Sites are one of the drivers of audit time under ISO/IEC 27006-1:2024: where scoped activities physically happen, and whether multi-site sampling applies, feeds into the audit time the body determines. Delivery mode matters alongside it, because how much of the audit runs remotely versus on site drives auditor travel and expenses, which are usually quoted separately from audit time. State your sites and your remote appetite in the brief so every body prices the same assumption.
How do I brief SGS so the quote is comparable to another body's?
Send SGS and every other body an identical brief: your ISMS scope, the number of people doing work under your control inside that scope including contractors, your sites, and how much of the audit can run remotely. Ask each body to state the audit days it has determined, to confirm its ISO/IEC 27001 accreditation on the accreditation body's register, to price surveillance and recertification across the full three-year cycle, and to state travel and expenses separately. Quotes built on different briefs cannot be compared.

Other certification bodies on the register

Updated July 2026