There is no authoritative flat price for ISO/IEC 27001 certification. The defensible budget is the sum of internal implementation effort, remediation and tooling, optional advisory support, an independent certification body's audit fees, and the ongoing cost of operating and auditing the ISMS. Obtain written quotes against a defined scope instead of relying on generic online ranges.
ISO/IEC 27001:2022 is the published requirements standard, with Amendment 1:2024. ISO develops standards but does not audit organisations or issue certificates; external certification bodies perform certification. Accreditation is independent recognition of a certification body's competence, and ISO advises buyers to evaluate several bodies and check accreditation where relevant.
The five budget components
1. Internal programme effort
Include the time of the ISMS lead, system and process owners, executive sponsor, HR, legal or privacy, procurement, engineering, IT operations, internal audit and participants in risk and management reviews. This is often the least visible cost.
Estimate by deliverable and role:
| Workstream | Internal inputs to budget |
|---|---|
| Scope and context | Entities, sites, products, processes, technology, interfaces |
| Risk management | Workshops, asset knowledge, treatment decisions, approval |
| Control operation | Owners, procedures, evidence, exception handling |
| Assurance | Metrics, internal audit, corrective action, management review |
| Certification support | Audit preparation, interviews, evidence and corrections |
2. Remediation and technology
Do not label every security purchase an ISO cost. Budget only the people, process, physical or technology changes justified by risk treatment and organisational objectives. Existing controls may be adequate; new tools still require operation, integration and evidence.
Typical remediation can involve identity governance, logging, backup testing, vulnerability management, supplier oversight, secure development, training or physical protection. Price each approved treatment rather than assuming a standard tool bundle.
3. Advisory support
Advisory scope can range from coaching to programme management, risk workshops, document development, internal-audit support and remediation design. Compare proposals by deliverables, assumptions, responsibility split and knowledge transfer. The adviser should not promise a guaranteed certificate and should not compromise required independence in audit roles.
4. Certification-body fees
Ask certification bodies to quote the same information:
- exact ISMS and certificate scope;
- headcount and effective personnel in scope;
- sites, shifts, remote functions and countries;
- business and technology complexity;
- existing management systems and integrated-audit assumptions;
- stage 1 and stage 2 audit activities;
- travel, expenses, application and certificate charges;
- surveillance and recertification assumptions; and
- rates for additional work or follow-up on nonconformities.
Do not describe a consultant's readiness review as certification. Confirm the certification body, accreditation status, standard edition and certificate scope.
5. Ongoing ISMS operation
Certification is not the end of the programme. Budget for risk review, awareness, control operation, metrics, internal audit, management review, corrective actions, supplier monitoring, change assessment, surveillance activity and eventual recertification.
Main cost drivers
Cost generally changes with scope and complexity, not the number of documents. Important drivers include multiple legal entities or sites, varied products, legacy or operational technology, regulated data, extensive suppliers, incomplete asset knowledge, immature controls, aggressive timing and weak internal availability.
Reduce cost responsibly by narrowing scope only where boundaries are real and defensible, reusing effective controls, assigning available owners, resolving evidence gaps early and comparing like-for-like certification quotes. An artificially narrow scope can produce a certificate that does not answer customer or risk needs.
Budget worksheet
- Define the intended certificate scope and business reason.
- Run a gap and evidence assessment.
- Estimate named internal roles by workstream.
- Price approved remediation separately from advisory work.
- Obtain comparable certification-body quotes.
- Include surveillance, recertification and ongoing control ownership.
- Add a documented contingency for confirmed uncertainty.
- Track forecast versus actual cost and explain scope changes.
Claims that certification “pays for itself”, guarantees contracts, cuts insurance premiums by a fixed percentage or automatically satisfies NIS2 are not dependable budgeting evidence. Measure expected value against your own customer, risk and regulatory objectives.
For scope and implementation support, see our cybersecurity services.
Sources and review
This guide was substantively reviewed on 8 August 2026. Unsupported market prices, savings, certification-volume claims and guaranteed-return claims were removed.
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.