ISO 27001 certification costs more than any other mainstream ISO standard. The cheapest published UK route is £1,295 plus VAT for an online, non-accredited certificate, and UKAS-accredited certification is quote-based, with small businesses typically quoted in the low-to-mid four figures for year one and larger SMEs into five figures. This guide breaks down where that money goes, why 27001 carries a premium over ISO 9001, and how to keep an accredited quote honest.
Sourcing note: only one provider in the UK set we checked in August 2026 publishes fixed 27001 pricing. The accredited bodies, BSI, NQA, Amtivo, QMS International and ISOQAR, all quote individually. Fixed prices below come from the provider’s own pricing page; ranges are indicative market figures and labelled as such.
- £1,295+VAT is the published floor - the online, non-accredited route; UKAS-accredited certification is quote-only and starts materially higher.
- 27001 is priced above every other mainstream standard - a £300 premium over ISO 9001 even at the budget end, driven by a broader evidence base and specialist auditors.
- Headcount drives the accredited quote - audit days are set from employee count under IAF MD 5, so a 5-person and a 50-person business get very different numbers.
- Budget for 3 years, not 1 - accredited certificates run a 3-year cycle with annual surveillance audits billed each year.
- Check the accreditation line before you buy - many enterprise customers and tenders specify UKAS-accredited certification, which the £1,295 route is not.
FREE QUOTE COMPARISON
Compare ISO Certification Quotes from Trusted Suppliers
100% free • No obligation • Takes under 2 minutes
How Much Does ISO 27001 Certification Cost?
UK ISO 27001 certification pricing splits into two routes. The online route has a published price: £1,295 plus VAT from ISO Accelerator, renewing at £295 plus VAT a year, with the provider’s own accreditation limited to organisations of 25 employees or fewer and not UKAS-accredited. The accredited route has no published prices at all. UKAS-accredited certification bodies quote from your employee headcount, the scope of your information security management system and your site count, with audit duration set under IAF MD 5 rules. Indicatively, small UK businesses pursuing accredited 27001 certification see first-year totals in the £5,000 to £10,000 band once consultancy support is included, and quotes rise into five figures as headcount grows. Certification is assessed against ISO/IEC 27001:2022, the current edition of the standard.
If you are weighing 27001 against other standards, or unsure whether you need it at all, start with our overview of ISO certification costs across all four major standards before committing to the most expensive one.
Why ISO 27001 Costs More Than ISO 9001
ISO 27001 certification costs more than ISO 9001 for three structural reasons. First, the evidence base is broader: an information security management system covers risk assessment, technical controls, supplier security and incident response, so auditors review more material for the same size of company. Second, the auditor pool is more specialist, which shows up in day rates and scheduling. Third, preparation is heavier: most businesses buy more consultancy hours for 27001 than for a quality management system, because the gap between current practice and the standard is usually wider. The pattern is visible even at the budget end of the market, where the same online provider prices 27001 at £1,295 plus VAT against £995 for 9001, a £300 premium before an accredited auditor ever gets involved.
The scope of your ISMS is the one cost lever fully in your control. Certifying a single product platform or one office first, rather than the whole company, reduces audit days and consultancy hours, and you can widen the scope at a later surveillance or recertification audit.
What an Accredited 27001 Quote Is Built From
Every accredited quote is assembled from the same parts. Knowing them makes a quote comparable and negotiable:
| Cost component | When it hits | What moves it |
|---|---|---|
| Stage 1 audit | Year 1 | Documentation and readiness review; scope and headcount |
| Stage 2 audit | Year 1 | The full certification assessment; audit days per IAF MD 5 |
| Consultancy / gap analysis | Before Stage 1 | How far current practice is from the standard; optional but common |
| Surveillance audits | Years 2 and 3 | Annual visits at the body’s day rate |
| Recertification audit | Year 4 | Starts the next 3-year cycle |
| Internal time | Continuous | Running the ISMS, evidence upkeep, closing findings |
Accredited bodies calculate audit duration from your headcount and scope under IAF MD 5, so that part of the quote should look similar between bodies. Day rates and consultancy bundles vary freely. If two accredited quotes differ sharply, the difference is usually rate and bundling, which is exactly the part you can negotiate or shop around.
Cost by Company Size
Headcount is the first question on every 27001 enquiry form because audit time scales with it. As a planning frame:
- 1 to 4 employees – minimum audit durations apply; the online route is also technically available at this size, if your customers accept non-accredited certification.
- 5 to 10 employees – the leanest accredited quotes; a tightly-scoped ISMS matters more than headcount here.
- 11 to 49 employees – audit days step up and supplier-security evidence multiplies; most first-time accredited buyers sit in this band.
- 50 to 100 employees – multi-day Stage 2 audits, and internal time becomes the largest hidden cost line.
- Over 100 employees – treat certification as a formal project with an owner; five-figure first-year totals are the norm.
ISO 27001 or Cyber Essentials First?
They answer different questions and are not substitutes. Cyber Essentials is a UK government-backed baseline covering a fixed set of technical controls, priced at a small fraction of 27001. ISO 27001 certifies a whole management system for information security risk. If a customer contract names Cyber Essentials, 27001 does not automatically satisfy it, and the reverse is also true. Many UK businesses hold both, starting with Cyber Essentials for speed and adding 27001 when enterprise deals demand it. The distinction is covered properly in our ISO 27001 certification guide.
How to Keep 27001 Costs Down
- Scope the ISMS tightly – one platform or office first; extend scope at a later audit rather than certifying everything on day one.
- Get at least two accredited quotes – the rule-based audit-day count should match; where the totals differ, you are comparing day rates and consultancy, the negotiable parts.
- Separate consultancy from certification – the body auditing you should not build your ISMS; keeping the roles apart is cleaner for accreditation and keeps both prices visible.
- Reuse what you already run – existing access controls, onboarding checklists and incident logs count as evidence; a gap analysis that starts from what exists costs less than a system built from scratch.
- Decide accredited vs online honestly – if no customer or tender requires UKAS-accredited certification yet, the online route buys a credential while you grow into the accredited one; if one does, skip the detour.
27001 demand usually arrives from customers handling sensitive data. If that is your situation, the same procurement push often asks about your wider operations too. Our guides to CRM software costs and business phone systems cover two systems that commonly fall inside a first ISMS scope.
FREE QUOTE COMPARISON
Compare ISO Certification Quotes from Trusted Suppliers
100% free • No obligation • Takes under 2 minutes









