Surveillance and recertification: pricing the three-year cycle
ISO 27001 is not a purchase, it is a three-year cycle: a two-stage initial audit, surveillance audits in the intervening years, and recertification before the certificate expires. Every audit in it is quoted per engagement, which is exactly why you price the whole cycle before you choose a body rather than discovering year two when it arrives.
Updated July 2026
The three-year cycle
Year 1
Initial certification
A two-stage audit. Stage 1 establishes whether the ISMS is designed and documented well enough to be audited: scope, risk assessment, Statement of Applicability, management review. Stage 2 tests whether it is implemented and effective, sampling evidence across the scope.
The certification body determines the total audit time and how it splits across the two stages. Both stages sit inside the audit time it quotes.
Years 2 and 3
Surveillance
Shorter audits in the intervening years, sampling the ISMS rather than covering all of it. They confirm the management system is still operating and that improvement, internal audit and management review are genuinely happening.
Determined under the same standard as the initial audit and quoted per engagement. Shorter than the initial audit, by an amount your body determines and does not publish.
Before expiry
Recertification
A full audit of the ISMS before the certificate expires, rather than a sample. It looks at the whole system again, including how it has performed across the cycle, and then the cycle restarts.
Timing matters commercially and operationally: this has to happen before the certificate expires, and a lapsed certificate is a procurement problem rather than an administrative one.
Then it starts again. Certification is a standing commitment rather than a project with an end date, and the budget that treats it as a project is the budget that fails in year two.
Why this page carries no percentage of your audit fee
Surveillance audit time is determined under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C. ISO sells that standard and the tables are not in the free preview, so we have not read them and we do not reproduce them. The day rate is commercial and no accredited body publishes one either.
A surveillance figure expressed as a share of your initial fee would therefore be a guess wearing a percentage sign, and it would be a particularly convincing one because it looks derived. What is true is the structure: surveillance is shorter than the initial audit, recertification looks at the whole ISMS again, and your certification body can tell you all three numbers today.
Price the cycle before you choose a body
This is the whole point of the page. Once you have signed for year one, the body holding your certificate is the body quoting your surveillance, and your negotiating position is worse than it will ever be again. Ask all of this while you are still choosing between bodies:
What are the audit days for the initial audit, surveillance and recertification?
Days are the quantity the standard makes the body determine. A body that will state days for the whole cycle is a body you can hold to a scope.
What is the fee for each audit across the full three years?
A year-one number is not the cost of being certified. The cheapest year one with unstated surveillance is not the cheapest programme, and you will not find out until year two.
What happens to the rate across the three years?
Ask whether it is fixed, indexed, or open. This is the question that turns a three-year quote into a three-year commitment.
How are travel and expenses treated at each visit?
Travel sits outside audit time and recurs at every on-site visit, not just the first. It is also where two apparently comparable quotes stop being comparable.
What happens if our scope or headcount changes mid-cycle?
Both are audit-time inputs. Growth, an acquisition or a contractor bench inside scope can reopen the fee. Find out the mechanism before it happens.
What is your process if a surveillance audit raises a non-conformity?
Timeframes and any follow-up cost are the body's own procedures. Ask while you are still choosing between bodies.
Can we combine this with our other management system audits?
If you hold another certification, ask what a combined audit would look like. Audit time on the other scheme is governed by a different instrument, so this is a question for the body rather than an assumption.
Send the same brief to every body: scope, the number of people doing work under your control inside that scope including contractors, sites, and how much can run remotely. Quotes built on different briefs are not comparable, and a cycle quote built on a headcount you got wrong is not a quote. How to source a defensible quote.
What recurs between the audits
The ISMS itself
- Internal audit. A requirement of the standard, not audit preparation. It recurs whether or not a surveillance visit is due, and it must be independent of the work being audited.
- Management review. Also a requirement in its own right. Top management reviewing ISMS performance is the thing being certified, not a meeting held before the auditor arrives.
- Risk assessment and treatment. Living documents. A risk register that has not changed in two years tells an auditor something.
- Evidence. Continuous collection is easier to defend than a reconstruction in the month before the visit, and considerably cheaper in internal time.
The platform subscription
Where you use a GRC platform, it recurs annually, and this is the one recurring cost with a published price. Lowest published dimension per listing on a 12-month contract, read off the vendor's public AWS Marketplace listing and checked July 2026:
- Vantafrom $6,000
- Drata$7,500
- Secureframe$7,500
- Sprintofrom $2,000
- Scytalefrom $2,100
Separate dimensions, not totals. AWS publishes no combined figure. Above roughly 100 people the published bands run out and every platform moves to a private offer.
What actually moves the cost of the cycle
- Scope. The largest lever you control, and it applies to every audit in the cycle rather than just the first. A scope you narrowed once keeps paying you back for three years.
- The headcount you report. ISO/IEC 27006-1:2024 counts people doing work under your control inside the scope, contractors included. This is an input to surveillance and recertification too, so growth and contractor benches follow you through the cycle.
- Maintaining rather than sprinting. An ISMS kept current between visits presents evidence that already exists. One reconstructed each year costs internal time nobody budgets, every year.
- Delivery mode. How much of each audit runs remotely drives auditor travel, which sits outside audit time and recurs at every visit.
- Doing the internal audit properly. It is a requirement either way. Done well it also surfaces what a surveillance auditor would have found, while you can still fix it quietly.
- Choosing the body on the cycle, not on year one. The initial audit is the only one you have competitive leverage over, so use it to price all three years.