Ask three suppliers what ISO 27001 certification cost you should be budgeting for and you will get three numbers that cannot be compared. A certification body quotes audit days. A consultant quotes a project fee. A compliance platform quotes an annual subscription. None of them is being dishonest, and none of them is quoting the whole thing — which is why so many UK companies approve a security budget in January and are back in front of the board in June asking for more.

The realistic ISO 27001 certification cost for a UK SME sits somewhere between roughly £5,000 and £45,000 in the first year. Where you land inside that range depends far more on your scope, your headcount and your starting maturity than on which auditor you pick. And the ISO 27001 certification cost that actually matters is the three-year figure, because certification is a cycle you re-enter every twelve months, not a purchase you make once.

This guide breaks the number into the parts you can genuinely get quotes for, benchmarks each part by company size, sets out a realistic timeline from kick-off to certificate, and lists the levers that reduce spend without putting the audit outcome at risk. It is written for UK businesses between two and 250 employees — the ones that need the certificate to win contracts but cannot absorb enterprise-scale compliance overhead.

If you already outsource, read it alongside our overview of managed IT services and the supplier questions in vendor management, because your provider will carry a large share of the evidence you are about to be audited on.

What the ISO 27001 Certification Cost Actually Covers

iso 27001 certification cost uk smes b stacked cost columns on circular platform

The single biggest cause of budget overrun is treating one supplier’s quote as the whole project. It never is.

The four budgets hiding inside one number

Every ISO 27001 certification cost breaks into four separate lines: the certification body’s audit fee, external help to build the management system, tooling and subscriptions, and internal staff time. The audit fee is the only one with a firm published basis. The other three are where SMEs either save thousands or lose them.

What the certificate itself actually buys

Certification confirms that an accredited auditor examined your Information Security Management System — your ISMS — against the requirements of ISO/IEC 27001:2022 and found it working. It does not certify that you are secure, that you use particular products, or that you have never had an incident. It certifies that you run a documented, risk-driven, continuously reviewed process. Understanding that distinction is what stops the ISO 27001 certification cost being confused with a security spend — the audit fee buys assurance about your process, not the controls themselves.

The standard document is a separate purchase

The standard itself is copyrighted. A single-user PDF of ISO/IEC 27001:2022 runs to roughly £150–£200 from the ISO store or BSI, and most teams also want ISO/IEC 27002 for the control guidance, at a similar price. It is a rounding error against the total ISO 27001 certification cost, but it catches people out because no supplier includes it.

Why “certification from £2,995” is technically true

Those headline offers usually quote the audit fee for a very small, single-site, low-complexity scope — and nothing else. The number is real. It is also about a third of what that business will actually spend. Read every quote for what it excludes, not what it includes.

Accredited or not — the fork in the road

A UKAS-accredited certificate carries the national accreditation mark and is what procurement teams check for. Non-accredited certificates are cheaper and faster, and a growing number of buyers now reject them outright. You can verify a certification body’s accreditation directly on the UKAS register. Trimming the ISO 27001 certification cost by dropping accreditation is a false economy: buying the cheap version and re-certifying properly two years later is the most expensive route of all.

ISO 27001 Certification Cost Benchmarks for UK SMEs

iso 27001 certification cost uk smes c clipboard checklist beside magnifier

Numbers are more useful than principles here, so these are indicative first-year ISO 27001 certification cost ranges for UK SMEs certifying a normal office-based or SaaS scope with a UKAS-accredited body. Treat them as a planning envelope, not a quote.

Indicative first-year budget by headcount

The table below splits the ISO 27001 certification cost into the three lines you can obtain quotes for. Internal staff time sits outside it and is covered separately further down.

People in scope Certification body fee External support Tooling Typical first-year total
1–10 £3,000–£5,500 £3,000–£8,000 £0–£4,000 £6,000–£15,000
11–50 £5,000–£9,000 £6,000–£15,000 £3,000–£9,000 £14,000–£30,000
51–150 £8,000–£14,000 £10,000–£25,000 £5,000–£14,000 £23,000–£48,000
151–250 £12,000–£20,000 £15,000–£35,000 £8,000–£20,000 £35,000–£70,000

Micro businesses: 1–10 people

A ten-person consultancy or early-stage SaaS company with one office and a cloud-only stack is the cheapest realistic case. The ISO 27001 certification cost here is dominated by external help, because there is nobody internal with spare capacity. Expect £6,000–£15,000 in year one, and be sceptical of anything under £5,000 that promises a UKAS certificate.

Small businesses: 11–50 people

This is the most common UK SME band and the widest spread of ISO 27001 certification cost outcomes. The same headcount can produce a £14,000 project or a £30,000 one depending purely on how much documentation, access control and supplier assurance already exists. A business with Cyber Essentials Plus, decent Microsoft 365 hygiene and a real asset register lands at the bottom of that range.

Medium businesses: 51–250 people

Above fifty people the audit days climb, multiple departments come into scope, and the internal coordination burden becomes the dominant cost. The ISO 27001 certification cost for this band routinely exceeds £30,000 in year one, and most such businesses appoint a part-time internal owner rather than relying entirely on a consultant.

The four factors that move you up a band

Headcount is the headline driver, but four things push the ISO 27001 certification cost upward regardless of size: multiple physical sites, regulated or highly sensitive data, in-house software development, and a scope drawn wider than the business actually needs. Only the last one is fully within your control — and it is the one most often got wrong.

Certification Body Audit Fees Explained

iso 27001 certification cost uk smes d circular arrow loop around three stepped tiers

The audit fee is the most predictable part of the budget because it is not really negotiable on volume — it is calculated.

How audit days are worked out

Certification bodies do not invent the duration. Audit days are derived from a mandatory international table published by the International Accreditation Forum, based on the number of “effective personnel” in scope, then adjusted up or down for complexity, risk, site count and how much of the work can be done remotely. Two auditors quoting the same scope should land within a day of each other.

Stage 1 and Stage 2

Initial certification is a two-stage audit. Stage 1 is a readiness review: the auditor checks that your ISMS documentation, scope, risk assessment and Statement of Applicability exist and hang together. Stage 2, usually four to eight weeks later, tests whether you are actually doing what you documented. Stage 1 is short — often one day. Stage 2 carries most of the days and most of the fee.

Typical UK day rates

UK certification bodies commonly charge somewhere between £900 and £1,500 per auditor-day, with the larger international names sitting at the top of that band. A small business needing three to five total days for initial certification is therefore looking at roughly £3,000–£7,000 of audit fee before travel and the annual certificate maintenance charge. Multiply days by rate and you have the only part of the ISO 27001 certification cost you can predict to the pound.

Travel, expenses and remote auditing

Remote auditing is now widely accepted for a large share of ISMS work, which has quietly reduced the ISO 27001 certification cost for distributed businesses. Ask explicitly what proportion can be done remotely and whether travel is charged at cost or as a fixed uplift — a two-auditor site visit to a regional office can add several hundred pounds nobody budgeted.

What is genuinely negotiable

The day count barely is. The day rate sometimes is. What is very negotiable is the scope you present, the number of sites the auditor must visit, and whether you commit to a three-year agreement up front in exchange for fixed pricing. Getting three quotes on an identical, tightly written scope statement is the single most effective procurement move available.

The Three-Year Cycle Behind Every ISO 27001 Certification Cost

iso 27001 certification cost uk smes e iceberg block above and below grid plane

A certificate is valid for three years, but you are audited every year. Budgeting only for year one is the most common planning error in this whole process.

Year one: initial certification

Everything front-loads here — Stage 1, Stage 2, the build work, the tooling you buy, and the internal time you will never see on an invoice. This is the year that produces the alarming number.

Years two and three: surveillance audits

Each surveillance audit is a partial re-examination, typically around a third of the initial audit days. In cash terms, expect roughly 30–40% of the year-one audit fee annually, plus whatever tooling renews. The ISO 27001 certification cost in a surveillance year for a thirty-person business commonly lands between £3,000 and £8,000 all-in.

Year three: recertification

At the end of the cycle the whole ISMS is re-audited. Recertification usually takes around two-thirds of the original audit days, so it costs more than a surveillance year but less than initial certification. Then the cycle restarts.

The honest three-year total

For a thirty-person UK business, a realistic three-year ISO 27001 certification cost is roughly £30,000–£55,000 rather than the £20,000 the year-one quote implies. Presenting the three-year figure to your board first is uncomfortable once and comfortable thereafter.

Why year two is cheaper than people fear

The build effort does not repeat. Once the risk register, policies, internal audit programme and supplier reviews exist, maintaining them is genuinely lighter work. Businesses that treat the ISMS as a live process rather than a certification sprint see their ongoing ISO 27001 certification cost fall year on year. Businesses that let it lapse and rebuild before each audit pay the build cost repeatedly.

Hidden Costs That Wreck an SME Budget

iso 27001 certification cost uk smes f milestone track with connected node pins

The invoices are the visible part of the ISO 27001 certification cost. Below the waterline sits the spending that turns a £15,000 project into a £28,000 one.

Internal staff time — always the biggest line

Nobody invoices you for it, so nobody budgets it, and it is routinely the largest single component of the true ISO 27001 certification cost. A first certification typically consumes somewhere between 150 and 400 hours of internal effort across the leadership team, IT, HR and operations. At a blended £40 per hour that is £6,000–£16,000 of real organisational capacity, and it is the reason certification projects stall in busy quarters rather than for want of money.

Remediation you cannot price until you look

The gap analysis tells you what is missing. It might be a policy set and some MFA enforcement. It might be a backup platform, a mobile device management rollout and a logging solution. Remediation is genuinely unknowable in advance, which is precisely why the gap analysis should come before you commit the rest of the budget.

Penetration testing and vulnerability scanning

ISO 27001 does not mandate a penetration test by name, but risk assessments for software and cloud businesses almost always conclude that one is required, and auditors expect to see technical assurance. A CREST-registered external and internal test for a typical SME runs £3,000–£8,000, repeated annually — often the largest recurring item in the ISO 27001 certification cost after the audit itself.

Compliance tooling and GRC platforms

Platforms such as ISMS.online, Vanta, Drata, Hicomply or Scytale automate evidence collection and policy management. SME tiers commonly run £4,000–£12,000 per year. They genuinely reduce consultant days and internal hours — but only if bought after you understand your scope, not before.

Training and awareness

Security awareness training for all staff, plus lead implementer or internal auditor training for one or two people, adds £1,000–£4,000. Auditors check that competence is evidenced, not asserted.

Scope creep after the quote

If you tell the auditor “just the London office and the SaaS product” and then add a second site or a new product line mid-project, the audit days are recalculated and the ISO 27001 certification cost moves with them. Lock the scope statement before you sign.

The certificate maintenance fee

Many certification bodies charge a separate annual licence or certificate maintenance fee of £400–£1,200, distinct from audit days. It is easy to miss in a quote that leads with a day rate.

How Long ISO 27001 Certification Really Takes

Time is the constraint people underestimate most, usually because a contract deadline arrived before the project did.

The honest headline: six to twelve months

A UK SME starting from a normal, uncertified baseline should plan for six to twelve months. Three to four months is achievable for a very small, cloud-native business with strong existing practice and a dedicated owner. Anything promising a certificate in four weeks is either non-accredited or describing the audit alone — and compressed timelines usually raise the ISO 27001 certification cost rather than lowering it, because rushed work gets redone.

Months 1–2: scoping and gap analysis

Define what the ISMS covers, run a gap analysis against the 2022 standard, and build the project plan. This phase costs relatively little and determines almost everything downstream — including the ISO 27001 certification cost itself, because scope drives audit days.

Months 2–5: building the ISMS

Risk assessment and treatment plan, the Statement of Applicability covering all 93 Annex A controls, the policy set, asset and supplier registers, and the technical remediation the risk assessment demanded. This is the heaviest phase for internal time.

Months 5–8: operating it and gathering evidence

This is the step that cannot be compressed. Auditors need to see the ISMS running — access reviews performed, incidents logged, changes approved, suppliers assessed. Most certification bodies want roughly three months of operating evidence before Stage 2.

Months 7–9: internal audit and management review

Both are mandatory clauses and both must be complete before Stage 2. A full internal audit cycle and a documented management review with leadership attendance are non-negotiable, and they are the two things rushed projects most often skip.

Months 9–12: Stage 1, Stage 2 and the certificate

Stage 1, a four-to-eight-week gap to close findings, then Stage 2. Certificates are typically issued two to six weeks after Stage 2 once any nonconformities are resolved.

What happens if the auditor raises findings

A minor nonconformity generally does not block certification; you submit a corrective action plan and evidence closure, often at the next surveillance audit. A major nonconformity does block it and must be closed — usually within 90 days — before the certificate is issued, which can push your timeline by a quarter.

Three Delivery Routes, Three Very Different Budgets

How you resource the project changes the total more than any negotiation with the auditor will.

Route one: full-service consultancy

A consultant builds the ISMS, writes the documentation and holds your hand through both audit stages. UK day rates run £700–£1,200, and fixed-price SME packages commonly land between £8,000 and £20,000. This is the highest ISO 27001 certification cost per certificate but the lowest demand on your own people — fastest and lowest-risk — and it carries a real hazard: a system built entirely by someone else tends to decay the moment they leave.

Route two: platform plus light consultancy

A compliance platform supplies the framework, policy templates and evidence automation; a consultant is retained for a fixed number of days at the difficult moments. For most 20–100 person UK businesses this is the best value route, typically landing the first-year ISO 27001 certification cost around £15,000–£25,000 while keeping ownership in-house.

Route three: fully in-house

Cheapest in cash, most expensive in time. Viable when you have someone with genuine ISMS experience and the capacity to spend a day or two a week on it for six months. Without both, this route does not lower the real ISO 27001 certification cost — it just moves the overspend into a delayed timeline and a failed Stage 2.

Matching the route to the business

Under ten people with no internal expertise: fixed-price consultancy. Twenty to a hundred people with a capable IT lead: platform plus advisory days. Over a hundred people: appoint an internal owner and buy specialist support around them. Businesses that already run structured IT outsourcing arrangements often find their provider can supply a large share of the technical evidence directly.

Nine Proven Ways to Reduce Your ISO 27001 Certification Cost

These are the levers that work. Note what is absent: cutting corners on the audit itself never appears, because it converts a cost problem into a certificate problem.

1. Get the scope right before anything else

Scope is the highest-leverage decision in the entire project. Certifying one product line and the team that runs it, rather than the whole company, can halve the ISO 27001 certification cost. Scope must be defensible and honest — but it does not have to be maximal.

2. Run the gap analysis first, buy second

Commission a gap analysis before committing to a platform or a consultancy package. It typically costs £1,000–£3,000 and routinely takes ten times that off the eventual ISO 27001 certification cost by preventing you from buying capability you already have.

3. Reuse your Cyber Essentials work

If you hold Cyber Essentials or Cyber Essentials Plus, a meaningful slice of the technical control evidence is already assembled. The NCSC’s Cyber Essentials scheme is a genuinely cost-effective on-ramp, and starting there before ISO 27001 lowers the eventual bill rather than duplicating it.

4. Get three quotes on one written scope

Send an identical scope statement to three UKAS-accredited bodies. Quoted ISO 27001 certification cost figures for the same scope routinely differ by 30% or more, and the exercise also exposes which auditor understands your sector.

5. Challenge the audit-day calculation

If the proposed day count looks high for your headcount, ask which complexity factors were applied and why. Auditors size conservatively when a scope is described vaguely; a precise scope description frequently removes a day.

6. Certify multiple standards together

If ISO 9001 or ISO 27701 is also on the roadmap, an integrated management system audited in one visit costs substantially less than two separate cycles. Combined audits typically save 20–30% against sequential certification.

7. Split the spend across financial years

Gap analysis and remediation in one financial year, build and audit in the next, spreads the ISO 27001 certification cost across two budgets without extending the calendar timeline much.

8. Build the system your business will actually use

A 300-page policy library nobody reads generates nonconformities at every surveillance audit and consultant days to fix them. A lean, genuinely operated ISMS is cheaper to run and cheaper to audit. This is where sensible cost optimization thinking pays off for years.

9. Fix the basics before the auditor finds them

MFA everywhere, leavers removed promptly, backups tested, an accurate asset register. These are cheap to do in advance and expensive to remediate under a 90-day major nonconformity clock.

Is the ISO 27001 Certification Cost Worth It for a UK SME?

Certification is a commercial decision, not a moral one. It is worth doing when it unlocks revenue or removes a real risk, and not otherwise.

When it clearly pays for itself

If enterprise or public sector buyers are asking for it in tenders, the maths is simple: compare the three-year ISO 27001 certification cost against the value of the contracts currently out of reach. Businesses routinely recover the entire spend on a single deal, and many report shorter sales cycles because security questionnaires shrink from weeks to a certificate reference.

The regulatory direction of travel

UK cyber regulation is tightening. The forthcoming Cyber Security and Resilience Bill brings managed service providers and data centres into scope for the first time, and their customers will feel the contractual consequences. Businesses that already run a certified ISMS are absorbing that shift rather than reacting to it.

Insurance and supply chain leverage

Cyber insurers increasingly price on demonstrable controls, and some offer measurably better terms to certified organisations. Certification also changes your position as a supplier — you answer one questionnaire a year instead of thirty.

When it is genuinely not worth it

If no customer has asked, you have under ten staff, and you handle no sensitive data, the ISO 27001 certification cost is difficult to justify today. Cyber Essentials Plus at a fraction of the price covers the practical risk. Certify when there is a buyer on the other side of the decision.

The SOC 2 question

US-headquartered buyers often ask for SOC 2 instead. If your market is primarily North American, SOC 2 may serve you better; if it is UK, European or public sector, ISO 27001 is the stronger card. Running both is possible and roughly 60–70% of the evidence overlaps, but it is not an SME-scale project in year one.

ISO 27001 Certification Cost FAQs for UK SMEs

What is the cheapest realistic ISO 27001 certification cost?

For a genuinely tiny, single-site, cloud-only business doing much of the work in-house, around £6,000 in year one including a UKAS-accredited audit. Below that, something material is being excluded.

Can we get certified in three months?

Occasionally, if you are under fifteen people, already well run, and dedicate someone to it full-time. The binding constraint is not the auditor’s diary — it is the requirement to show the ISMS has actually been operating, plus a completed internal audit and management review.

Does the certification body fee include the consultant?

No, and any supplier offering both should be questioned closely. Impartiality rules prevent a certification body from consulting on the ISMS it audits. Genuinely independent auditing is what makes the certificate worth buying.

How much does it cost each year after certification?

Budget 30–40% of the year-one audit fee for each surveillance year, plus tooling renewals and internal maintenance time. For most SMEs the ongoing ISO 27001 certification cost is £4,000–£12,000 annually.

Do we need a full-time information security manager?

Almost never below 250 people. The requirement is defined responsibility and demonstrable competence, not a dedicated headcount. A named owner spending one to two days a week during the build, dropping to a few days a month afterwards, satisfies it.

What happens if we fail Stage 2?

Outright failure is rare. Auditors normally raise nonconformities rather than refusing certification. Majors must be closed before the certificate is issued, typically within 90 days, and closure usually requires a short follow-up visit that adds to the ISO 27001 certification cost.

Is a non-accredited certificate ever acceptable?

Only if your buyers accept it — and check before you buy, not after. Procurement teams increasingly verify accreditation on the UKAS register, and discovering the gap mid-tender is worse than never having certified.

Does using a managed IT provider reduce the cost?

Usually yes, provided the provider can produce evidence rather than just assurances. Ask whether they hold their own certification, whether their scope covers the services you buy, and whether they will supply audit evidence on request. A capable provider can remove a meaningful share of the technical workload.

Where to Start Without Wasting Money

The order of operations matters more than the size of the budget.

Do these three things first

Write a one-paragraph scope statement covering which products, sites and teams are in. Commission a gap analysis against ISO/IEC 27001:2022. Send that scope to three UKAS-accredited certification bodies for quotes. Total spend at this point is £1,000–£3,000, and it converts a guess into a plan.

Then decide the route, not the budget

With a gap report and three quotes, the delivery route usually chooses itself. The businesses that overspend are the ones that pick a consultant or a platform before they know what they are missing — and the ISO 27001 certification cost they end up paying reflects that ordering error more than any market rate.

Build the case around a deadline that exists

Certification projects that succeed are anchored to a real commercial event: a tender, a renewal, an investor requirement. Projects without one drift, and drifting projects cost more because the build work gets repeated. Set the target date from the contract, then work backwards through the nine to twelve month timeline above.

The one-sentence summary

Budget £6,000–£15,000 for a micro business, £14,000–£30,000 for a typical small business and £23,000–£48,000 above fifty people in year one, add roughly a third of the audit fee annually thereafter, scope tightly, gap-analyse before you buy anything, and treat the ISO 27001 certification cost as a three-year commercial investment rather than a one-off compliance purchase.