Skip to main content
Precursor Security
UK ISO 27001 Pricing, 2026 Guide

How Much Does
ISO 27001 Cost?

Total ISO 27001 cost has three parts: implementation and consultancy (Precursor from £8,000 for under-50 employee organisations, £12,000 to £25,000 for larger scopes), the separate audit fees charged by an independent UKAS-accredited certification body, and internal staff time. The certificate itself is always issued by the certification body, never by the consultant.

ISO 27001 cost is made up of three separate pieces: consultancy, the certification body's audit fees, and your own internal time. Precursor consultancy starts from £8,000. Here is the full breakdown, so nothing arrives as a surprise once you are scoped.

From £8,000
Fixed-price consultancy
Certification body fees separate
No day rates
Scroll
3,000+ Assessments DeliveredTriple-CREST Accredited24/7 UK SOC in NewcastleReports Accepted by Insurers & RegulatorsEst. 2018
The Short Answer

ISO 27001 consultancy costs from £8,000.

That figure covers consultancy and implementation only. Certification body audit fees are billed separately by an independent UKAS-accredited body, and internal staff time runs alongside both. The certificate is issued by the certification body, never by your consultant.

£8k
Consultancy from
£3-8k
Cert body fees
£14-23k
SME year 1 total
ISO 27001 Certified Consultants
UK-Based, Leeds / London / Newcastle / Edinburgh
Fixed-Price Guarantee
Stage 2 Audit Attendance

First ISO 27001 project?

Start with a free scoping call. We confirm your organisation size, scope, and existing maturity, then return a fixed-price consultancy quote within 48 hours, separate from certification body fees you will confirm directly with your chosen body. See the full ISO 27001 consultancy service for what is included.

Get a Fixed-Price Quote
Free scoping call
Three Cost Buckets

What "ISO 27001 cost" actually covers

Quotes that only mention one figure are usually only describing one of three costs. Splitting them out is the fastest way to compare providers on a like-for-like basis.

Bucket 1

Consultancy & Implementation

From £8,000

Precursor fixed-price fee for gap analysis, ISMS design, risk assessment, documentation, internal audit support, and certification body liaison through Stage 1 and Stage 2.

Paid to your consultant

Bucket 2

Certification Body Audit Fees

Separate, get a quote

Stage 1 and Stage 2 audit fees, plus annual surveillance audits, set independently by your chosen UKAS-accredited certification body. These are never included in a consultancy fee.

Paid to the certification body

Bucket 3

Internal Time

Variable, unbilled

Staff hours for evidence gathering, policy review, control implementation, and staff awareness training, running alongside the consultancy engagement.

Your team, not billed

Consultancy Pricing

Consultancy cost by organisation size

Fixed-price consultancy after a free scoping call, no day rates. This covers implementation only, certification body audit fees sit on top.

Under 50 employees
Simple scope, single site, limited IT
From £8,000
3-4 months
50-150 employees
Standard scope
£12,000-£15,000
4-6 months
150-500 employees
Multi-site or complex IT
£18,000-£25,000
5-8 months
500+ employees
Enterprise scope
POA after scoping
6-12 months

Timelines and prices are indicative. A free scoping call confirms your exact figure based on organisation size, scope, and existing maturity.

What affects the price

Three factors set where your consultancy quote lands. We confirm all three on a free scoping call before quoting.

Organisation size
Headcount and number of sites are the biggest single driver of consultancy price, moving you between the tiers below.
Scope complexity
A single-site, single-system scope is cheaper to certify than a multi-site estate with complex or legacy IT.
Existing maturity
Organisations with an existing ISMS, even a partial one, or established security policies typically need less consultancy time to reach certification.
Independent of Your Consultant

Certification body fees, explained

A UKAS-accredited certification body, such as BSI, NQA, Alcumus ISOQAR, or Bureau Veritas, audits your ISMS and issues the ISO 27001 certificate. This is a separate organisation from your consultant, with its own fees, and it is the only body that can actually certify you.

Audit stageTypical fee
Stage 1 + Stage 2 (initial certification)£3,000-£8,000
Annual surveillance audit (years 1 and 2)£1,500-£3,000/year
Recertification audit (year 3)Broadly similar to initial audit

These figures are typical ranges, not quotes from any specific body. Fees vary by certification body and by the size and complexity of your ISMS scope, so budget for them separately and get a direct quote from your chosen body once you have decided who to certify with. Precursor's consultancy fee covers Stage 1 and Stage 2 liaison and attendance alongside your team, not the certification body's own audit fee.

DIY vs consultancy cost

Implementing ISO 27001 without a consultant is possible. Whether it is cheaper depends on what you value: a lower headline cost, or a shorter timeline with a lower first-pass audit failure risk.

FactorDIYPrecursor consultancy
Typical timeline12-18 months3-6 months
DocumentationTemplate-based, self-interpretedCustom ISMS documentation
Audit outcomeHigher first-pass failure rateStage 1 & 2 audit attendance
Certification body relationshipsNoneBSI / NQA / ISOQAR liaison

DIY implementation avoids the consultancy fee but typically takes 12 to 18 months against 3 to 6 months with consultancy, and carries a higher risk of nonconformities at Stage 1 or Stage 2 that extend the timeline further. Certification body audit fees apply either way, since only the certification body can issue the certificate.

Buyer Guidance

Questions worth asking before you sign

Since ISO 27001 cost is genuinely split across two organisations, confirm what each figure covers before comparing quotes.

Is the quote for consultancy only, or does it include certification body fees?
Which UKAS-accredited certification body will audit us, and have you worked with them?
Is the consultancy fee fixed-price, or open-ended day rates?
Does the fee include Stage 1 and Stage 2 attendance?
What happens to the price if the scope changes during the project?
How is internal staff time estimated for gap analysis and training?

A free scoping call confirms your fixed consultancy figure in writing, typically within 48 hours. For the full scope of what consultancy includes, see the ISO 27001 consultancy service.

Compare across the closed loop

Annex A controls 8.15 and 8.16 require active monitoring after certification. Most clients pair ISO 27001 consultancy with a penetration test and managed detection, see the closed-loop security model and related pricing.

Get your fixed-price ISO 27001 quote

A free scoping call confirms your organisation size, scope, and existing maturity. You get a fixed-price consultancy quote, no day rates, with certification body fees kept clearly separate.

Get a Fixed-Price Quote
ISO 27001 Cost FAQ

ISO 27001 pricing questions

ISO 27001 cost has three parts. Consultancy and implementation is £8,000 to £25,000 depending on organisation size and scope, with Precursor pricing from £8,000 for under-50 employee organisations. Certification body audit fees are billed separately by an independent UKAS-accredited body and typically run £3,000 to £8,000 for Stage 1 and Stage 2, plus £1,500 to £3,000 a year for surveillance audits. Internal staff time for evidence gathering and training sits alongside both. A typical UK SME budgets £14,000 to £23,000 in total for the first year.

Consultancy fees pay for the implementation work: gap analysis, ISMS design, risk assessment, documentation, internal audit support, and attendance at your certification audits. The certificate itself is issued by an independent UKAS-accredited certification body, such as BSI, NQA, Alcumus ISOQAR, or Bureau Veritas, once their auditors confirm your ISMS meets ISO 27001:2022 during Stage 1 and Stage 2. A consultant cannot issue the certificate; only the certification body can.

No. Certification body audit fees are separate from consultancy fees and are set independently by whichever UKAS-accredited body you choose, not by your consultant. Budget for them separately and get a direct quote from the certification body, since fees vary by body and by the scope of your ISMS. Precursor supports Stage 1 and Stage 2 liaison as part of the consultancy fee, but the audit fee itself is paid to the certification body.

For most UK SMEs, the process from gap analysis to certification takes 3 to 6 months depending on starting maturity, organisation size, and scope. Larger or more complex organisations typically take 6 to 12 months. Organisations with existing security policies and processes often move faster through the gap analysis and ISMS build stages.

For organisations facing a client, procurement, or supply chain requirement, yes: the certification is often the difference between winning and losing the contract, and fixed-price consultancy compresses a 12 to 18 month DIY timeline down to 3 to 6 months with lower first-pass audit failure risk. For organisations with no external driver, the value depends on whether the governance and risk management the standard forces you to build is worth the investment on its own. A gap analysis is the cheapest way to test that before committing to full implementation.