Skip to content
ExpertSure UK
Current topic ISO Certification
Get Free Quotes
ExpertSure™ Logo
Compare ISO Certification Quotes in 60 Seconds
  • Tell us what you need — it takes under a minute
  • Our system matches you with trusted suppliers
  • 100% free, no pushy sales calls
  • Receive quotes from top providers within 1 hour

You'll be matched with providers like:

Illustration of a glowing light bulb

ISO 27001 Certification UK: How It Works

Clara Wenslow

Written By:

Clara Wenslow

Finance & Business Services Editor

Sarah Mitchell, ExpertSure author

Reviewed By:

Sarah Mitchell

B2B Commerce & Finance Reviewer

Updated August 10, 2026
ExpertSure is reader-supported. When you click through links on our site, we may earn a commission from the providers featured. This never influences our editorial recommendations. How we work

ISO 27001 is the certificate that unlocks enterprise deals for businesses that hold other people’s data. It certifies your information security management system against ISO/IEC 27001:2022, the current edition of the standard. Demand for it rarely comes from inside the business. It arrives in a security questionnaire from a big customer, and it is the most expensive mainstream ISO standard to get.

This guide explains what 27001 certification involves, how it differs from Cyber Essentials, and who genuinely needs it. For the money side, our ISO 27001 cost guide breaks down the published prices and the quote-based market around them.

ISO/IEC 27001:2022
Current edition
Edition 3 of the standard; new certificates are assessed against it
2 stages
Initial audits
Stage 1 readiness review, then the Stage 2 certification audit
3 years
Certificate validity
With annual surveillance audits on the accredited route
£1,295+VAT
Published price floor
Online non-accredited route; £300 above the same card's ISO 9001 price
Key takeaway
  • 27001 certifies a management system, not a firewall - auditors assess how you identify and manage information security risk against ISO/IEC 27001:2022, across people and process as well as technology.
  • It is not Cyber Essentials - the two schemes answer different customer questions, and holding one does not satisfy a contract that names the other.
  • Certification is a 2-stage audit on a 3-year cycle - with annual surveillance visits, and audit days scaled to your headcount under IAF MD 5.
  • It is the priciest mainstream standard - £1,295+VAT even on the budget online route, £300 above ISO 9001 on the same rate card.
  • Scope is your biggest cost lever - certifying one platform or office first cuts audit days, and you can widen scope at a later audit.

FREE QUOTE COMPARISON

Compare ISO Certification Quotes from Trusted Suppliers

100% free • No obligation • Takes under 2 minutes

What Is ISO 27001 Certification?

ISO 27001 certification is independent confirmation that your business runs an information security management system meeting ISO/IEC 27001:2022. An information security management system, or ISMS, is the defined way you identify security risks, decide which controls address them, and prove those controls operate. It spans far more than IT: supplier contracts, joiner and leaver processes, incident response and leadership review all sit inside it. Certification is issued by a certification body after a two-stage audit, and in the UK the bodies themselves are accredited by UKAS, which is what enterprise procurement teams usually expect to see. The 2022 edition is the current one, and businesses still holding certificates against the old 2013 edition have passed the transition deadline. The certificate answers a customer’s core question directly: an external auditor has verified this supplier manages information security systematically, and re-checks it every year.

What the Standard Requires

In practical terms, an auditor will expect to see:

  • A defined ISMS scope – which parts of the business, systems and locations the certificate covers.
  • A risk assessment and treatment plan – your security decisions traced to identified risks, not bought off a shelf.
  • Selected controls with justification – the standard’s Annex A control set applied where your risks demand it, with a statement of applicability explaining what you left out and why.
  • Operating evidence – access reviews, incident records, supplier checks and training logs that show the system running.
  • Internal audit and management review – you test your own system and leadership acts on the results.

ISO 27001 vs Cyber Essentials

ISO 27001 and Cyber Essentials are not competing versions of the same thing, and neither substitutes for the other. Cyber Essentials is a UK government-backed scheme run under the NCSC that checks a fixed set of baseline technical controls, and it is priced at a small fraction of an ISO 27001 project. ISO 27001 certifies an entire management system for information security risk: governance, process and evidence, audited externally on a recurring cycle. A contract that names Cyber Essentials is asking for that specific scheme, and a 27001 certificate does not automatically satisfy it. The reverse is equally true. Many UK businesses hold both, taking Cyber Essentials first for speed and public-sector eligibility, then adding 27001 when enterprise customers start sending security questionnaires. If you are unsure which one your pipeline actually requires, read the contract wording before you buy either.

How Certification Works

The accredited route runs the same way everywhere. You build and operate the ISMS first, alone or with a consultant. The certification body then quotes from your headcount, sites and scope, with audit duration set under IAF MD 5 rules. Stage 1 reviews your documentation and readiness. Stage 2 assesses the system in operation and raises findings you must close before the certificate is issued. The certificate runs for three years, with surveillance audits in years two and three, then recertification. Between visits, the system has to keep producing evidence, because next year’s auditor starts from this year’s records.

Scope before quotes, always

Every part of a 27001 quote scales with scope: audit days, consultancy hours and internal effort. Decide what the certificate must cover to satisfy the customers asking for it, and certify that first. A tightly scoped ISMS that passes is worth more than an everything-scope project that stalls.

What ISO 27001 Costs

The published floor is £1,295 plus VAT for an online, non-UKAS-accredited certificate, limited to organisations of 25 employees or fewer by the provider’s own accreditation statement. Accredited bodies quote individually. Indicatively, small businesses see first-year totals of £5,000 to £10,000 including consultancy, rising into five figures with headcount. The full breakdown lives in our ISO 27001 cost guide, with the cross-standard picture in our ISO certification costs overview.

Who Actually Needs ISO 27001?

Follow the data. Software companies, agencies and outsourced service providers holding client data get asked first, usually the moment they sell to enterprise or regulated customers. If your customers are consumers or small businesses, the demand may never come, and the money is better spent elsewhere until it does. When the questionnaire lands, it usually names 27001 explicitly. Businesses already certified to ISO 9001 have a head start: the management-system machinery of policies, audits and reviews carries across, and bodies price integrated audits below two separate projects. Our guide to the best ISO certification bodies covers who to shortlist once the decision is made.

FREE QUOTE COMPARISON

Compare ISO Certification Quotes from Trusted Suppliers

100% free • No obligation • Takes under 2 minutes

Clara Wenslow

Clara Wenslow

Finance & Business Services Editor

Clara analyses SME finance and procurement markets, covering business loans, invoice finance, payroll, and related B2B services. She ensures each comparison and guide is transparent and data-driven.

Sarah Mitchell

Reviewed by

Sarah Mitchell

B2B Commerce & Finance Reviewer

FAQs

Is ISO 27001 the same as Cyber Essentials?

No. Cyber Essentials is a UK government-backed scheme over a fixed set of technical controls. ISO 27001 certifies a full information security management system. A contract naming one is not satisfied by the other.

Which edition of ISO 27001 do I certify against?

ISO/IEC 27001:2022, the current edition. The transition period from the 2013 edition has passed.

How long is an ISO 27001 certificate valid?

Three years on the accredited route, with annual surveillance audits in years two and three, then a recertification audit.

Free ISO Certification Quotes Compare top UK suppliers