← All posts

ISO 27001 certification cost: UK budget guide 2026

For most UK organisations, first-year ISO 27001 certification cost varies significantly depending on organisation size and complexity, and the three-year cycle adds surveillance and recertification on top. The principal drivers are organisation size, number of sites in scope, and your existing ISMS maturity — not, as many assume, the certification body's audit fee alone. UKAS-accredited registrars such as BSI, NQA, and LRQA calculate audit days using IAF MD 5 guidelines, and their day rates are generally within a typical market range. Shieldiqcyber's GRC platform sits alongside those registrars as a practical way to cut internal labour, which is consistently the largest cost item in any ISO 27001 project.

Cybersecurity analyst typing at cluttered desk

One figure to fix in your mind before reading further: annual surveillance audits typically cost a proportion of the initial audit fee, and you will face two of them before recertification in year three. Budget for the full cycle from day one.

Top cost drivers at a glance:

  • Organisation size and employee count in scope
  • Number of physical or cloud sites included
  • Current ISMS maturity (starting from scratch costs more)
Cost component Typical UK range One-off or recurring
Gap analysis / preparation varies depending on organisation size and approach One-off
Consultant / implementation cost varies widely depending on scope and engagement type One-off (or phased)
Certification body audit (Stage 1 + 2) cost depends on audit days and registrar rates One-off, then recurring
Tooling and technical controls costs vary by selected tools and scope Recurring (annual)
Internal staff time (opportunity cost) often exceeds the combined consultant and audit fees and is typically the largest single cost in most projects Recurring
Surveillance audits (years 2 and 3) cost is a fraction of the initial audit fee Recurring annually

Table of Contents

What does ISO 27001 certification actually cost you?

The five cost buckets below cover everything you will realistically pay. Understanding which are one-off and which recur is what separates an accurate budget from a nasty surprise at year two.

Gap analysis and preparation covers the initial assessment of where your controls, policies, and processes stand against the ISO/IEC 27001 standard. A consultant-led gap analysis typically runs £1,500–£6,000 for an SME; a self-directed approach using a structured tool can bring that closer to £500–£1,500 in cash, though internal hours rise accordingly. Shieldiqcyber's self-assessment guidance offers a practical starting point if you want to run this stage without a consultant.

Consultant and implementation fees are the most variable line item. Fixed-price projects for SMEs typically range from £8,000 to £25,000; day-rate engagements run £800–£1,500 per day in the UK market. What you get varies significantly: some consultants deliver documentation only, others manage the entire ISMS build and internal audit programme.

Consultants discussing ISO 27001 fees around table

Certification body audit fees are mandatory and non-negotiable. Stage 1 (documentation review) and Stage 2 (on-site or remote implementation audit) together typically cost £3,000–£8,000 for a micro business and £8,000–£20,000 for a mid-market organisation. These figures reflect UK auditor day rates vary by registrar and market conditions multiplied by the audit days IAF MD 5 assigns to your employee count and scope.

Tooling and technical controls include your GRC platform or documentation toolkit, vulnerability scanning, and potentially a penetration test. Pen testing alone can range from a few thousand to tens of thousands of pounds depending on scope. GRC platform subscription costs vary depending on features and vendor.

Infographic showing ISO 27001 cost components

Internal staff time is the item most budgets undercount. Hours spent preparing evidence, managing remediation, running internal audits, and attending the Stage 2 audit convert to a real cash cost when multiplied by loaded salary rates. For a 50-person company, this can easily exceed £20,000 in year one.

Component What it covers Typical UK range Type
Gap analysis Current-state assessment vs ISO 27001 £1,500–£6,000 One-off
Consultant / implementation ISMS build, policies, risk register One-off
Certification audit (Stage 1 + 2) Registrar audit days £3,000–£20,000 One-off
Penetration testing Technical vulnerability assessment £3,000–£20,000+ Periodic
GRC platform / tooling Evidence management, policy templates Recurring
Internal staff time Evidence prep, remediation, audits Recurring
Surveillance audits Annual ongoing compliance check 30–40% of initial audit Recurring

Mandatory spend is the certification body audit. Everything else is a choice about how you distribute effort between consultants, platforms, and your own team.

Which variables push your ISO 27001 cost up or down?

Six factors determine whether your project lands at the low or high end of any published range. Knowing which apply to you is the fastest way to sense-check a quote.

  • Employee count in scope. IAF MD 5 ties audit day allocations directly to headcount. A 10-person company might need two audit days; a 200-person company could need six or more. More days means a higher audit fee, and it also means more evidence to prepare.
  • Number of sites. Each additional physical location typically adds audit days. A second UK office or a cloud data centre hosted in a separate environment can push the audit day count up and increase travel costs if the registrar audits on-site.
  • Technologies and cloud services in scope. Including AWS, Azure, or a complex SaaS stack adds controls to evidence and can require specialist auditor knowledge, which some registrars price separately.
  • Existing ISMS maturity. Organisations that already operate Cyber Essentials Plus or have documented security policies will spend less on remediation and documentation. Starting from scratch adds months and cost.
  • Inclusion of additional standards. Combining ISO 27001 with ISO 27701 (privacy) or SOC 2 increases scope but can also create efficiencies if controls overlap. The net effect on cost depends on how much overlap exists.
  • Geography and auditor availability. UK auditor shortages have pushed day rates upward, and remote auditing (now widely accepted post-pandemic) can reduce travel costs by several hundred pounds per audit day.

Pro Tip: Before requesting quotes, map your scope precisely using the IAF MD 5 framework. Audit day allocations are calculated from employee count, sites, and scope complexity. Providing incomplete scope information leads to re-quoting later — often at a higher figure than the original estimate. Give every registrar the same detailed scope document so quotes are genuinely comparable.

Always declare the full scope to the certification body upfront. Under-reporting employee count or omitting a site to reduce the quote is a short-term saving that creates a longer-term cost when the registrar recalculates on audit day.

How the certification stages work and what each one costs

ISO 27001 certification follows a two-stage audit process, and understanding what each stage involves helps you budget auditor time accurately.

Stage 1: Documentation review. The auditor reviews your ISMS documentation — scope statement, risk assessment, Statement of Applicability, and key policies — to confirm you are ready for Stage 2. This is typically conducted remotely and takes one to two days for an SME. The output is a list of observations and any areas requiring attention before Stage 2 proceeds.

Stage 2: Implementation audit. The auditor verifies that your documented controls are actually operating in practice. They will interview staff, review evidence logs, and test that your ISMS is functioning as described. This is the substantive audit and takes the majority of the total audit days allocated.

Audit fees are calculated as: auditor day rate × total audit days. The IAF MD 5 guidelines set the minimum audit day allocations based on employee count and scope. Registrars may add days for complexity, multiple sites, or specialist technology.

Representative audit day counts and fees:

Organisation profile Employees in scope Estimated audit days Estimated audit fee (—/day)
Micro 1–10 2–3
SME 10–50 3–5
Mid-market 50–250 5–6
Enterprise (multi-site) 250+ 6–8

What to expect on an audit invoice:

  • Auditor day rate (Stage 1 and Stage 2 billed separately or combined)
  • Travel and accommodation if on-site (can add £200–£600 per day)
  • Application or registration fee (some registrars charge £300–£800 upfront)
  • Certificate issuance fee (typically £200–£500)
  • Remote audit discount (some registrars reduce day rates by 10–15% for fully remote audits)

Always ask registrars for a day estimate based on your specific employee count, sites, and scope before accepting a quote. A quote that omits these details is not reliable.

Consultant fees, internal staff time, and tooling: the bigger line items

The audit fee is the most visible cost. The consultant and internal labour costs are usually larger.

Consultant pricing models

UK ISO 27001 consultants typically offer two structures. A fixed-price project covers a defined scope: gap analysis, ISMS documentation, risk assessment, internal audit support, and Stage 2 preparation. For an SME, expect £8,000–£20,000 for a well-scoped fixed-price engagement. A day-rate arrangement runs £800–£1,500 per day in the current UK market and suits organisations that want to retain control but need expert input at specific points.

Common consultant deliverables include: scope statement and ISMS framework, risk assessment and treatment plan, Statement of Applicability, policy suite, internal audit programme, and management review support.

Internal staff time: the cost most budgets miss

Internal staff time consistently exceeds the certification body audit fee and is often the largest single cost item in most ISO 27001 projects, especially when factoring in preparation, remediation, and internal audit activities for even a moderately sized organisation.

Three implementation approaches compared

There are three common routes to certification, each with a different cost and effort profile:

  1. DIY with a documentation toolkit. Lowest cash outlay; highest internal time commitment. Suitable for organisations with an experienced security lead and time to spare. Risk: slower progress and higher chance of Stage 1 observations if documentation is incomplete.
  2. Consultant-led project. Higher cash cost but faster delivery and lower internal burden. Suitable when speed matters or internal expertise is limited. Risk: scope creep and day-rate overruns if the engagement is not tightly defined.
  3. Platform-assisted hybrid (GRC platform + targeted consulting). Sits between the two on cost and speed. A GRC platform handles evidence management, policy templates, and audit reporting; a consultant provides strategic input at key milestones. This approach reduces both internal hours and consultant days.

Decision checklist — which approach fits your situation?

  1. Do you have a dedicated security or compliance resource with 20+ hours per week available? If yes, DIY or hybrid is viable.
  2. Is your timeline under six months? Consultant-led or hybrid is more reliable.
  3. Is your budget under £15,000 cash? Hybrid or DIY with a toolkit is the realistic path.
  4. Do you need to certify multiple frameworks (e.g. ISO 27001 plus SOC 2)? A GRC platform pays back fastest in this scenario.
  5. Is your ISMS starting from scratch? Factor in at least 30% more internal hours than you initially estimate.

Worked UK examples: sample budgets by organisation size

The figures below are modelled estimates based on market benchmarks and published audit-day guidance. They assume a single UK site, no existing ISMS, and a consultant-assisted approach. Adjust upward for additional sites, lower ISMS maturity, or a fully consultant-led engagement.

Profile Employees Gap analysis Consultant Audit (Stage 1+2) Tooling Internal time Year 1 total Annual maintenance
Micro 1–10 £1,500 £3,000
SME 10–50 £3,000 £15,000 ~£8,000
Mid-market 50–250 £6,000 £25,000 ~£15,000
Enterprise (multi-site) 250+ £16,000 £8,000 £40,000 ~£109,000 ~£25,000

Annual maintenance includes surveillance audit fees (30–40% of the initial audit fee), GRC platform subscription, and ongoing internal audit and management review time. Year three adds a recertification audit, which is broadly comparable in cost to the initial certification audit.

A few UK-specific points worth noting. VAT applies to consultant and registrar fees at the standard rate, so add 20% to cash figures if your organisation is not VAT-registered. UKAS-accredited registrars — BSI, NQA, and LRQA among them — are the only bodies whose certificates carry UKAS accreditation, which many procurement frameworks and government contracts require. Non-UKAS-accredited certificates exist but may not satisfy customer or tender requirements.

Practical ways to reduce your ISO 27001 cost

Cost reduction in ISO 27001 is almost always about reducing audit days, consultant hours, or internal labour. The tactics below are legitimate and auditor-friendly.

  • Tighten your scope. Limiting certification to a specific product line, service, or business unit reduces employee count in scope, which directly reduces audit days and consultant effort. A narrower scope also means fewer policies to write and less evidence to collect.
  • Phase certification. Certify a core scope first, then expand in subsequent cycles. This spreads cost over time and lets your team build ISMS competence before tackling a larger scope.
  • Use editable documentation toolkits. Pre-built, ISO 27001-aligned policy templates reduce documentation time from weeks to days. Verify that any toolkit you buy covers all Annex A controls and is updated for ISO/IEC 27001:2022.
  • Automate evidence capture. Manual evidence collection is one of the most time-consuming activities in any ISO 27001 project. A GRC platform that pulls evidence automatically from your existing tools (cloud logs, HR systems, ticketing tools) can cut evidence-preparation hours significantly.
  • Run internal audits in-house. Training one or two staff members as internal auditors costs less than outsourcing every internal audit cycle. Internal auditors also build institutional knowledge that reduces consultant dependency over time.
  • Schedule penetration testing early. Pen tests commissioned late in the project can delay Stage 2 if findings require remediation. Scheduling them at the start of the remediation phase avoids timeline slippage and the associated cost of extending consultant engagements.
  • Choose remote audits where accepted. Most UKAS-accredited registrars now offer remote Stage 1 and, in some cases, remote Stage 2 audits. This removes travel costs and can reduce the overall audit day count slightly.

Pro Tip: Structure your scope by product line rather than by department. Auditors assess controls relative to the scope boundary, not the org chart. A product-line scope lets you exclude support functions that add audit days without adding meaningful risk coverage. Confirm this approach with your chosen registrar before finalising the scope statement.

Pro Tip: Batch your evidence runs. Rather than collecting evidence continuously, schedule two or three structured evidence-collection sprints aligned to your audit calendar. This reduces the total internal hours spent on evidence management and makes it easier to demonstrate a consistent pattern of control operation to the auditor.

Governance automation tools such as Tekkr's governance platform can also reduce repetitive evidence work, particularly for organisations managing multiple compliance frameworks simultaneously.

What timeline should you plan for, and how does it affect cost?

Certification timelines typically run 3–12 months, with small, well-prepared organisations reaching Stage 2 in three to four months and larger or less mature organisations taking six to twelve months or more. The timeline matters for cost because a longer project means more consultant days, more internal hours, and more months of GRC platform subscription.

Typical milestones and durations:

  • Scoping and gap analysis: 2–4 weeks (micro/SME); 4–8 weeks (mid-market/enterprise)
  • Documentation and ISMS build: 4–8 weeks (micro/SME); 8–16 weeks (mid-market/enterprise)
  • Operate ISMS to generate evidence: minimum 4–8 weeks of live operation before Stage 2
  • Internal audit and management review: 1–2 weeks
  • Stage 1 audit: 1–2 days; typically 2–4 weeks after internal audit
  • Remediation of Stage 1 observations: 2–4 weeks
  • Stage 2 audit: 2–5 days depending on scope
  • Certificate issuance: 1–3 weeks post-Stage 2

The evidence-generation period is the most common cause of timeline extension. Auditors need to see that controls have been operating consistently, not just that they exist on paper. Rushing this phase by shortening the operation period is a common mistake that leads to Stage 2 observations and additional remediation cost.

Remote audits save travel time and cost but rarely shorten the overall project timeline. The evidence-generation period is fixed regardless of whether the audit is conducted on-site or remotely.

The single largest cost driver: what the research actually shows

The most consistent finding across 2026 market guides is that internal staff time and tooling often exceed the certification body audit fee and are frequently the largest single cost item in an ISO 27001 project. This contradicts the common assumption that the registrar's invoice is the primary budget concern.

A practical example: a 40-person SME assigns a security manager (£65,000 salary, £33/hour loaded) and a part-time IT manager (£55,000 salary, £28/hour loaded) to the project. The security manager spends 250 hours; the IT manager spends 120 hours. That is £8,250 plus £3,360, totalling £11,610 in internal labour cost — before a single consultant invoice or audit fee is paid.

The methodology behind the cost estimates in this guide draws on published audit-day rules (IAF MD 5), market quotes from UKAS-accredited registrars, and 2026 benchmark guides from compliance-focused publishers. Where ranges are wide, the lower end assumes good ISMS maturity and a narrow scope; the upper end assumes a starting-from-scratch position with multiple sites.

Three practical implications:

  • Budget internal time as a cash cost, not a free resource. Use loaded salary rates.
  • Reducing internal hours through automation or a GRC platform has a direct, calculable return.
  • Automating evidence management with a GRC platform shortens time-to-audit and reduces ongoing labour cost, providing a cost-effective middle ground between full consultancy and DIY.

Key takeaways

ISO 27001 certification in the UK is a three-year financial commitment, and internal staff time is frequently the largest cost item — not the registrar's audit fee.

Point Details
UK first-year ISO 27001 certification costs vary greatly by organisation size and complexity.
Largest hidden cost Internal staff time, when converted to loaded salary rates, is frequently the largest single cost item and often exceeds combined consultant and audit fees.
Audit day mechanics Fees are calculated as auditor day rate (£1,000–£1,800) × IAF MD 5 audit days; always supply full scope details to get a reliable quote.
Budget for the full cycle Surveillance audits cost a portion of the initial audit fee annually; recertification in year three is broadly comparable to the initial audit.
Shieldiqcyber reduces labour cost Shieldiqcyber's GRC platform automates evidence capture, policy generation, and gap analysis, cutting the internal hours that drive the largest cost line.

Why the audit fee is the wrong number to fixate on

Most budget conversations about ISO 27001 start with "how much does the registrar charge?" That is the wrong question to lead with. The audit fee is fixed by IAF MD 5 and your scope; you cannot negotiate it down without changing the scope. What you can control is everything else: how many consultant days you need, how many internal hours you spend, and how efficiently you collect and manage evidence.

The organisations that consistently come in under budget are not the ones that found the cheapest registrar. They are the ones that invested early in good documentation, ran a disciplined gap analysis, and used tooling to reduce manual evidence work. The registrar's invoice is the smallest lever in the room.

There is also a longer-term point worth making. ISO 27001 is not a project with a finish line; it is an ongoing management system. The three-year certification cycle means surveillance audits, continuous control operation, and a recertification audit. Organisations that treat it as a one-off project tend to let controls drift between audits, which creates remediation cost and audit risk in year two and three. Building the ISMS to run with minimal manual intervention from the start is the most cost-effective long-term decision you can make.

Shieldiqcyber cuts the cost of getting to ISO 27001

The biggest saving available to most UK SMEs is not a cheaper registrar. It is fewer internal hours spent on evidence collection, policy writing, and audit preparation. Shieldiqcyber's AI-powered GRC platform is built specifically to reduce that labour cost, giving compliance leads and IT managers their time back while keeping the ISMS audit-ready year-round.

Shieldiqcyber

Four platform capabilities map directly to the cost drivers covered in this guide:

  • Automated evidence capture pulls control evidence from your existing tools continuously, eliminating manual collection sprints before each audit.
  • AI policy generator produces ISO 27001-aligned policies in minutes, not weeks, cutting documentation time from the consultant or internal resource budget.
  • Gap analysis module gives you a structured, auditor-ready view of where your controls stand against ISO/IEC 27001:2022 — without paying a consultant to run the assessment.
  • Audit-ready reporting generates the evidence packs and control summaries your registrar needs for Stage 1 and Stage 2, reducing the back-and-forth that extends audit timelines.

For organisations that want expert support alongside the platform, Shieldiqcyber's consulting services cover virtual CISO, audit preparation, and security awareness training — targeted engagements that complement the platform rather than replace it. Book a readiness assessment or request a demo at shieldiqcyber.com to see how the platform fits your scope and budget.

Useful UK sources and next steps

The estimates in this guide are derived from published IAF MD 5 audit-day rules, market quotes from UKAS-accredited registrars, and 2026 benchmark guides. For your own project, the following steps and sources are the most practical starting points.

Where to go next:

  • Buy the standard. ISO/IEC 27001:2022 is available directly from ISO and from BSI. The standard itself is the authoritative reference for scope and control requirements.
  • Confirm accreditation. Only UKAS-accredited certification bodies issue certificates that carry UKAS recognition. Check the UKAS register at gov.uk before engaging a registrar.
  • Request quotes from UKAS-accredited registrars. BSI, NQA, and LRQA are among the most widely used in the UK. When requesting a quote, supply: employee count in scope, number of sites, a brief description of in-scope technologies, and your target certification date. Quotes that omit these details are not comparable.
  • Run a gap analysis first. Before approaching a registrar, understand your current control posture. Shieldiqcyber's ISO 27001 compliance page explains how the platform supports this step for SMEs.
  • Schedule penetration testing early. If your scope includes internet-facing systems, commission a pen test at the start of the remediation phase, not the end.
  • Budget for the full three-year cycle. Surveillance audits, ongoing GRC platform costs, and internal audit time are recurring. Build them into your annual security budget from year one.

Key UK institutions and standards bodies:

  • UKAS (United Kingdom Accreditation Service): accreditation body for certification bodies
  • BSI (British Standards Institution): UKAS-accredited ISO 27001 registrar and standards publisher
  • NQA: UKAS-accredited registrar with a strong UK SME client base
  • LRQA (Lloyd's Register): UKAS-accredited registrar operating across UK and international markets
  • ISO: publisher of ISO/IEC 27001:2022 and the ISO Survey of certifications

Recommended