TUV SUD ISO 27001 cost: which entity issues your certificate
No certification body publishes an ISO 27001 rate card, so there is no fee on this page. With TUV SUD there is a second thing worth settling before price ever comes up: accreditation attaches to a legal entity rather than to a group brand, and TUV SUD operates through many national entities. Which entity would issue your certificate is a question with a checkable answer, and this page shows you where to check it.
Updated July 2026
Accreditation attaches to an entity, not to a brand
A German testing and certification group operating through many national entities. Accreditation attaches to each entity separately, so which TUV SUD entity issues your certificate determines which accreditation body stands behind it.
The TUV SUD management systems schedule on the UKAS register, number 0172, belongs to TUV SUD BABT Unlimited and covers ISO 13485 medical devices quality management and UKCA Approved Body work. It does not carry ISO/IEC 27001. We downloaded that schedule and read it in full in July 2026.
We did not confirm an ISO/IEC 27001 accreditation for any TUV SUD entity on a register we could read ourselves. That is a statement about what we checked, not a finding about the group: TUV SUD entities outside the UK are accredited by other national accreditation bodies, each of which publishes its own register.
So if you need a UKAS-accredited ISMS certificate specifically, confirm on the register which entity would issue it before you commit. Ask TUV SUD for the issuing entity by name and the accreditation body that accredits it, then open that register and read the schedule yourself.
Schedule we read
UKAS management systems, number 0172
Entity holding it
TUV SUD BABT Unlimited
What it covers
ISO 13485 medical devices QMS, UKCA Approved Body work
ISO/IEC 27001 on this schedule
Not carried on schedule 0172
Checked July 2026 by downloading the schedule and reading its accredited scope in full. Schedule of accreditation 0172 | UKAS register | ANAB directory
How to run the check yourself, for any group
- Ask for the issuing entity by name. Not the group, not the country office: the legal entity that will appear on the certificate.
- Ask which accreditation body accredits that entity. Different national accreditation bodies publish different registers.
- Open that accreditation body's register and find the schedule. The register is the record. Marketing material is not.
- Read the scheme list on the schedule, not the front page. Accreditation for ISO 9001 or ISO 13485 does not imply accreditation for ISO/IEC 27001. Each scheme is its own entry.
- Confirm the certificate you receive names that same entity. Accreditation held by one group entity does not transfer to another.
This is a few minutes of work and it is the single highest-value check in the whole procurement, because an unaccredited certificate is often refused later by the buyer who asked for it in the first place. See UKAS accreditation and UK procurement.
Why there is no fee on this page
An audit fee is audit days multiplied by a rate. Neither input is published.
The rate is commercial. TUV SUD quotes per engagement, as every certification body does. None publishes a day rate, and the accreditation registers publish accreditation status only, never anything commercial.
The days are behind a paywall. ISMS audit time is determined under ISO/IEC 27006-1:2024. Its audit-time provisions are the normative Annex C, with methods for audit time calculations in the informative Annex D. ISO sells the standard and the annex tables are not in the free preview. We have not read them, so we do not reproduce them.
The body quoting you holds the standard and applies Annex C to your scope. Ask for the audit days it determined and the basis for them. More on how audit fees are set.
What actually drives your quote
These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are drivers, not a formula, and they apply to any accredited body you approach.
Number of persons doing work under the organisation's control, within the ISMS scope
The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.
ISMS scope
What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.
Complexity and risk of the ISMS
Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.
Sites
Where scoped activities physically happen, and whether multi-site sampling applies.
Delivery mode
How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.
Headcount is counted on the standard's definition, not on your payroll report. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation, so contractors and freelancers inside the scope count toward the total.
Price the three-year cycle, not year one
Certification runs on a three-year cycle: a two-stage initial audit, surveillance audits in the intervening years, and a recertification audit before the certificate expires. Surveillance audits are shorter than the initial audit, are also determined under ISO/IEC 27006-1:2024, and are also quoted per engagement.
A year-one quote is not your cost of certification, and a cheaper year one with unstated surveillance is not a cheaper programme. Ask for the whole cycle up front, including what happens to the rate across the three years. See the three-year cycle page.
How to get a comparable quote
- Confirm the issuing entity and its accreditation first. With a multi-entity group this comes before price, because it determines what you are actually buying.
- Write one scope brief and send it unchanged to every body. Scope, headcount on the ISO/IEC 27006-1:2024 definition, sites, and remote versus on-site appetite.
- Ask each body to state the audit days it determined. Days are the quantity the standard governs.
- Ask for the full cycle. Initial audit, surveillance, recertification, and the rate across three years.
- Get travel and expenses stated separately. They sit outside audit time.
- Confirm audit time is determined under ISO/IEC 27006-1:2024. UKAS required transition by 31 July 2025 and ANAB required application to all clients by 31 March 2026.