Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

TUV SUD ISO 27001 cost: which entity issues your certificate

No certification body publishes an ISO 27001 rate card, so there is no fee on this page. With TUV SUD there is a second thing worth settling before price ever comes up: accreditation attaches to a legal entity rather than to a group brand, and TUV SUD operates through many national entities. Which entity would issue your certificate is a question with a checkable answer, and this page shows you where to check it.

Updated July 2026

Accreditation attaches to an entity, not to a brand

A German testing and certification group operating through many national entities. Accreditation attaches to each entity separately, so which TUV SUD entity issues your certificate determines which accreditation body stands behind it.

The TUV SUD management systems schedule on the UKAS register, number 0172, belongs to TUV SUD BABT Unlimited and covers ISO 13485 medical devices quality management and UKCA Approved Body work. It does not carry ISO/IEC 27001. We downloaded that schedule and read it in full in July 2026.

We did not confirm an ISO/IEC 27001 accreditation for any TUV SUD entity on a register we could read ourselves. That is a statement about what we checked, not a finding about the group: TUV SUD entities outside the UK are accredited by other national accreditation bodies, each of which publishes its own register.

So if you need a UKAS-accredited ISMS certificate specifically, confirm on the register which entity would issue it before you commit. Ask TUV SUD for the issuing entity by name and the accreditation body that accredits it, then open that register and read the schedule yourself.

Schedule we read

UKAS management systems, number 0172

Entity holding it

TUV SUD BABT Unlimited

What it covers

ISO 13485 medical devices QMS, UKCA Approved Body work

ISO/IEC 27001 on this schedule

Not carried on schedule 0172

Checked July 2026 by downloading the schedule and reading its accredited scope in full. Schedule of accreditation 0172 | UKAS register | ANAB directory

How to run the check yourself, for any group

  1. Ask for the issuing entity by name. Not the group, not the country office: the legal entity that will appear on the certificate.
  2. Ask which accreditation body accredits that entity. Different national accreditation bodies publish different registers.
  3. Open that accreditation body's register and find the schedule. The register is the record. Marketing material is not.
  4. Read the scheme list on the schedule, not the front page. Accreditation for ISO 9001 or ISO 13485 does not imply accreditation for ISO/IEC 27001. Each scheme is its own entry.
  5. Confirm the certificate you receive names that same entity. Accreditation held by one group entity does not transfer to another.

This is a few minutes of work and it is the single highest-value check in the whole procurement, because an unaccredited certificate is often refused later by the buyer who asked for it in the first place. See UKAS accreditation and UK procurement.

Why there is no fee on this page

An audit fee is audit days multiplied by a rate. Neither input is published.

The rate is commercial. TUV SUD quotes per engagement, as every certification body does. None publishes a day rate, and the accreditation registers publish accreditation status only, never anything commercial.

The days are behind a paywall. ISMS audit time is determined under ISO/IEC 27006-1:2024. Its audit-time provisions are the normative Annex C, with methods for audit time calculations in the informative Annex D. ISO sells the standard and the annex tables are not in the free preview. We have not read them, so we do not reproduce them.

The body quoting you holds the standard and applies Annex C to your scope. Ask for the audit days it determined and the basis for them. More on how audit fees are set.

What actually drives your quote

These are the drivers ISO/IEC 27006-1:2024 and the accreditation bodies name. They are drivers, not a formula, and they apply to any accredited body you approach.

Number of persons doing work under the organisation's control, within the ISMS scope

The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.

ISMS scope

What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.

Complexity and risk of the ISMS

Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.

Sites

Where scoped activities physically happen, and whether multi-site sampling applies.

Delivery mode

How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.

Headcount is counted on the standard's definition, not on your payroll report. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope whether or not they are members of the organisation, so contractors and freelancers inside the scope count toward the total.

Price the three-year cycle, not year one

Certification runs on a three-year cycle: a two-stage initial audit, surveillance audits in the intervening years, and a recertification audit before the certificate expires. Surveillance audits are shorter than the initial audit, are also determined under ISO/IEC 27006-1:2024, and are also quoted per engagement.

A year-one quote is not your cost of certification, and a cheaper year one with unstated surveillance is not a cheaper programme. Ask for the whole cycle up front, including what happens to the rate across the three years. See the three-year cycle page.

How to get a comparable quote

  1. Confirm the issuing entity and its accreditation first. With a multi-entity group this comes before price, because it determines what you are actually buying.
  2. Write one scope brief and send it unchanged to every body. Scope, headcount on the ISO/IEC 27006-1:2024 definition, sites, and remote versus on-site appetite.
  3. Ask each body to state the audit days it determined. Days are the quantity the standard governs.
  4. Ask for the full cycle. Initial audit, surveillance, recertification, and the rate across three years.
  5. Get travel and expenses stated separately. They sit outside audit time.
  6. Confirm audit time is determined under ISO/IEC 27006-1:2024. UKAS required transition by 31 July 2025 and ANAB required application to all clients by 31 March 2026.

Frequently asked questions

How much does TUV SUD ISO 27001 certification cost?
TUV SUD publishes no rate card and no day rate for ISO 27001, and neither does any other accredited certification body. An audit fee is audit days multiplied by a rate. The rate is commercial and unpublished. The audit days are determined by the body under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C, and ISO sells that standard rather than publishing it openly. Both inputs are unpublished, so any figure printed here would be invented.
Which TUV SUD entity would issue my ISO 27001 certificate?
That is the question to put to TUV SUD directly, and then to check on the relevant accreditation body's register. TUV SUD is a German testing and certification group that operates through many national entities, and accreditation attaches to each entity separately rather than to the group brand. The entity that issues your certificate determines which accreditation body stands behind it, so ask for the issuing entity by name before you commit.
What does the TUV SUD management systems schedule on the UKAS register cover?
The TUV SUD management systems schedule on the UKAS register, number 0172, belongs to TUV SUD BABT Unlimited and covers ISO 13485 medical devices quality management and UKCA Approved Body work. It does not carry ISO/IEC 27001. We downloaded and read that schedule in full in July 2026. If you need a UKAS-accredited ISMS certificate specifically, confirm on the register which entity would issue it before you commit.
Is a TUV SUD entity accredited for ISO 27001 somewhere else?
We did not confirm that on a register we could read ourselves, and we do not report what we have not read. TUV SUD group entities outside the UK are accredited by other national accreditation bodies, and those bodies publish their own registers. The right move is to ask TUV SUD which entity would issue your certificate and which accreditation body accredits that entity, then open that accreditation body's register and read the schedule yourself. That is the same check worth doing for any certification body in any country.
What drives the audit days a certification body will quote?
The primary input under ISO/IEC 27006-1:2024 is the number of people doing work under the organisation's control within the ISMS scope, counted regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total. Audit time also reflects the ISMS scope itself, the complexity and risk of the ISMS including the criticality of the information handled, the sites involved, and how much of the audit runs remotely rather than on site.
Why does the accredited entity matter to a buyer?
Because an accredited certificate is what most procurement teams are actually asking for, and accreditation is a fact about a legal entity and a specific scheme. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001, and accreditation held by one group entity does not transfer to another. The register is the only place that resolves this, and it takes a couple of minutes to check.

Certification bodies whose ISMS accreditation we read on the register

Updated July 2026