Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

Surveillance and recertification: pricing the three-year cycle

ISO 27001 is not a purchase, it is a three-year cycle: a two-stage initial audit, surveillance audits in the intervening years, and recertification before the certificate expires. Every audit in it is quoted per engagement, which is exactly why you price the whole cycle before you choose a body rather than discovering year two when it arrives.

Updated July 2026

The three-year cycle

Year 1

Initial certification

A two-stage audit. Stage 1 establishes whether the ISMS is designed and documented well enough to be audited: scope, risk assessment, Statement of Applicability, management review. Stage 2 tests whether it is implemented and effective, sampling evidence across the scope.

The certification body determines the total audit time and how it splits across the two stages. Both stages sit inside the audit time it quotes.

Years 2 and 3

Surveillance

Shorter audits in the intervening years, sampling the ISMS rather than covering all of it. They confirm the management system is still operating and that improvement, internal audit and management review are genuinely happening.

Determined under the same standard as the initial audit and quoted per engagement. Shorter than the initial audit, by an amount your body determines and does not publish.

Before expiry

Recertification

A full audit of the ISMS before the certificate expires, rather than a sample. It looks at the whole system again, including how it has performed across the cycle, and then the cycle restarts.

Timing matters commercially and operationally: this has to happen before the certificate expires, and a lapsed certificate is a procurement problem rather than an administrative one.

Then it starts again. Certification is a standing commitment rather than a project with an end date, and the budget that treats it as a project is the budget that fails in year two.

Why this page carries no percentage of your audit fee

Surveillance audit time is determined under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C. ISO sells that standard and the tables are not in the free preview, so we have not read them and we do not reproduce them. The day rate is commercial and no accredited body publishes one either.

A surveillance figure expressed as a share of your initial fee would therefore be a guess wearing a percentage sign, and it would be a particularly convincing one because it looks derived. What is true is the structure: surveillance is shorter than the initial audit, recertification looks at the whole ISMS again, and your certification body can tell you all three numbers today.

Price the cycle before you choose a body

This is the whole point of the page. Once you have signed for year one, the body holding your certificate is the body quoting your surveillance, and your negotiating position is worse than it will ever be again. Ask all of this while you are still choosing between bodies:

What are the audit days for the initial audit, surveillance and recertification?

Days are the quantity the standard makes the body determine. A body that will state days for the whole cycle is a body you can hold to a scope.

What is the fee for each audit across the full three years?

A year-one number is not the cost of being certified. The cheapest year one with unstated surveillance is not the cheapest programme, and you will not find out until year two.

What happens to the rate across the three years?

Ask whether it is fixed, indexed, or open. This is the question that turns a three-year quote into a three-year commitment.

How are travel and expenses treated at each visit?

Travel sits outside audit time and recurs at every on-site visit, not just the first. It is also where two apparently comparable quotes stop being comparable.

What happens if our scope or headcount changes mid-cycle?

Both are audit-time inputs. Growth, an acquisition or a contractor bench inside scope can reopen the fee. Find out the mechanism before it happens.

What is your process if a surveillance audit raises a non-conformity?

Timeframes and any follow-up cost are the body's own procedures. Ask while you are still choosing between bodies.

Can we combine this with our other management system audits?

If you hold another certification, ask what a combined audit would look like. Audit time on the other scheme is governed by a different instrument, so this is a question for the body rather than an assumption.

Send the same brief to every body: scope, the number of people doing work under your control inside that scope including contractors, sites, and how much can run remotely. Quotes built on different briefs are not comparable, and a cycle quote built on a headcount you got wrong is not a quote. How to source a defensible quote.

What recurs between the audits

The ISMS itself

  • Internal audit. A requirement of the standard, not audit preparation. It recurs whether or not a surveillance visit is due, and it must be independent of the work being audited.
  • Management review. Also a requirement in its own right. Top management reviewing ISMS performance is the thing being certified, not a meeting held before the auditor arrives.
  • Risk assessment and treatment. Living documents. A risk register that has not changed in two years tells an auditor something.
  • Evidence. Continuous collection is easier to defend than a reconstruction in the month before the visit, and considerably cheaper in internal time.

The platform subscription

Where you use a GRC platform, it recurs annually, and this is the one recurring cost with a published price. Lowest published dimension per listing on a 12-month contract, read off the vendor's public AWS Marketplace listing and checked July 2026:

Separate dimensions, not totals. AWS publishes no combined figure. Above roughly 100 people the published bands run out and every platform moves to a private offer.

What actually moves the cost of the cycle

  • Scope. The largest lever you control, and it applies to every audit in the cycle rather than just the first. A scope you narrowed once keeps paying you back for three years.
  • The headcount you report. ISO/IEC 27006-1:2024 counts people doing work under your control inside the scope, contractors included. This is an input to surveillance and recertification too, so growth and contractor benches follow you through the cycle.
  • Maintaining rather than sprinting. An ISMS kept current between visits presents evidence that already exists. One reconstructed each year costs internal time nobody budgets, every year.
  • Delivery mode. How much of each audit runs remotely drives auditor travel, which sits outside audit time and recurs at every visit.
  • Doing the internal audit properly. It is a requirement either way. Done well it also surfaces what a surveillance auditor would have found, while you can still fix it quietly.
  • Choosing the body on the cycle, not on year one. The initial audit is the only one you have competitive leverage over, so use it to price all three years.

Frequently asked questions

How much does an ISO 27001 surveillance audit cost?
It is quoted per engagement, and no accredited certification body publishes a rate card or a day rate. Surveillance audit time is determined under ISO/IEC 27006-1:2024 like the initial audit, and those provisions sit in the normative Annex C, which ISO sells rather than publishes. So there is no published figure and no honest percentage of your initial fee either. The number exists, your certification body can tell you it, and the time to ask is before you choose them rather than in year two.
What is the ISO 27001 three-year cycle?
Certification runs on a three-year cycle. It starts with a two-stage initial audit: Stage 1 establishes whether the ISMS is designed and documented well enough to be audited, and Stage 2 tests whether it is actually implemented and effective. Surveillance audits follow in the intervening years, and a recertification audit takes place before the certificate expires, after which the cycle begins again. Each of those audits is determined under ISO/IEC 27006-1:2024 and quoted per engagement.
Is a surveillance audit smaller than the initial audit?
Yes. Surveillance audits are shorter than the initial audit because they sample rather than cover the whole ISMS. How much shorter is determined by your certification body under ISO/IEC 27006-1:2024 against your scope, and we do not publish a ratio because the annex that governs it is paywalled and we have not read it. Anyone quoting you a fixed percentage of your initial fee has assembled it. Ask your body for the surveillance days alongside the initial ones.
Is recertification cheaper than initial certification?
The audit itself is a full audit of the ISMS rather than a sample, so it is a larger exercise than a surveillance visit. What is usually different is everything around it: you are not building an ISMS from nothing, writing a policy set or standing up evidence collection for the first time. The audit fee is determined per engagement under the same standard as every other audit in the cycle. Ask for it at the start, in the same conversation as the initial quote, when you still have leverage.
What happens if a surveillance audit finds problems?
Your certification body raises non-conformities and sets a timeframe to close them, and what happens next depends on their severity and on whether you close them. A body can ultimately suspend or withdraw a certificate. The details are the body's own procedures rather than a published universal rule, which makes this a question to ask when you are choosing a body rather than after a finding. Ask what their process is, what timeframes apply, and what any follow-up work would cost.
What recurs between audits?
The ISMS does. The internal audit and the management review are requirements of the standard in their own right rather than audit preparation, so they recur whether or not an auditor is due. Any platform subscription recurs annually at the vendor's list price, and that layer is genuinely published: several GRC vendors list prices on their public AWS Marketplace listings. Internal time also recurs, and organisations that let the ISMS lapse between visits generally pay for it in the run-up to the next one.

Updated July 2026