How Much Does
ISO 27001 Cost?
Total ISO 27001 cost has three parts: implementation and consultancy (Precursor from £8,000 for under-50 employee organisations, £12,000 to £25,000 for larger scopes), the separate audit fees charged by an independent UKAS-accredited certification body, and internal staff time. The certificate itself is always issued by the certification body, never by the consultant.
ISO 27001 cost is made up of three separate pieces: consultancy, the certification body's audit fees, and your own internal time. Precursor consultancy starts from £8,000. Here is the full breakdown, so nothing arrives as a surprise once you are scoped.
ISO 27001 consultancy costs from £8,000.
That figure covers consultancy and implementation only. Certification body audit fees are billed separately by an independent UKAS-accredited body, and internal staff time runs alongside both. The certificate is issued by the certification body, never by your consultant.
First ISO 27001 project?
Start with a free scoping call. We confirm your organisation size, scope, and existing maturity, then return a fixed-price consultancy quote within 48 hours, separate from certification body fees you will confirm directly with your chosen body. See the full ISO 27001 consultancy service for what is included.
What "ISO 27001 cost" actually covers
Quotes that only mention one figure are usually only describing one of three costs. Splitting them out is the fastest way to compare providers on a like-for-like basis.
Consultancy & Implementation
Precursor fixed-price fee for gap analysis, ISMS design, risk assessment, documentation, internal audit support, and certification body liaison through Stage 1 and Stage 2.
Paid to your consultant
Certification Body Audit Fees
Stage 1 and Stage 2 audit fees, plus annual surveillance audits, set independently by your chosen UKAS-accredited certification body. These are never included in a consultancy fee.
Paid to the certification body
Internal Time
Staff hours for evidence gathering, policy review, control implementation, and staff awareness training, running alongside the consultancy engagement.
Your team, not billed
Consultancy cost by organisation size
Fixed-price consultancy after a free scoping call, no day rates. This covers implementation only, certification body audit fees sit on top.
Timelines and prices are indicative. A free scoping call confirms your exact figure based on organisation size, scope, and existing maturity.
What affects the price
Three factors set where your consultancy quote lands. We confirm all three on a free scoping call before quoting.
Certification body fees, explained
A UKAS-accredited certification body, such as BSI, NQA, Alcumus ISOQAR, or Bureau Veritas, audits your ISMS and issues the ISO 27001 certificate. This is a separate organisation from your consultant, with its own fees, and it is the only body that can actually certify you.
| Audit stage | Typical fee |
|---|---|
| Stage 1 + Stage 2 (initial certification) | £3,000-£8,000 |
| Annual surveillance audit (years 1 and 2) | £1,500-£3,000/year |
| Recertification audit (year 3) | Broadly similar to initial audit |
These figures are typical ranges, not quotes from any specific body. Fees vary by certification body and by the size and complexity of your ISMS scope, so budget for them separately and get a direct quote from your chosen body once you have decided who to certify with. Precursor's consultancy fee covers Stage 1 and Stage 2 liaison and attendance alongside your team, not the certification body's own audit fee.
DIY vs consultancy cost
Implementing ISO 27001 without a consultant is possible. Whether it is cheaper depends on what you value: a lower headline cost, or a shorter timeline with a lower first-pass audit failure risk.
| Factor | DIY | Precursor consultancy |
|---|---|---|
| Typical timeline | 12-18 months | 3-6 months |
| Documentation | Template-based, self-interpreted | Custom ISMS documentation |
| Audit outcome | Higher first-pass failure rate | Stage 1 & 2 audit attendance |
| Certification body relationships | None | BSI / NQA / ISOQAR liaison |
DIY implementation avoids the consultancy fee but typically takes 12 to 18 months against 3 to 6 months with consultancy, and carries a higher risk of nonconformities at Stage 1 or Stage 2 that extend the timeline further. Certification body audit fees apply either way, since only the certification body can issue the certificate.
Questions worth asking before you sign
Since ISO 27001 cost is genuinely split across two organisations, confirm what each figure covers before comparing quotes.
A free scoping call confirms your fixed consultancy figure in writing, typically within 48 hours. For the full scope of what consultancy includes, see the ISO 27001 consultancy service.
Compare across the closed loop
Annex A controls 8.15 and 8.16 require active monitoring after certification. Most clients pair ISO 27001 consultancy with a penetration test and managed detection, see the closed-loop security model and related pricing.
Get your fixed-price ISO 27001 quote
A free scoping call confirms your organisation size, scope, and existing maturity. You get a fixed-price consultancy quote, no day rates, with certification body fees kept clearly separate.
Get a Fixed-Price QuoteISO 27001 pricing questions
ISO 27001 cost has three parts. Consultancy and implementation is £8,000 to £25,000 depending on organisation size and scope, with Precursor pricing from £8,000 for under-50 employee organisations. Certification body audit fees are billed separately by an independent UKAS-accredited body and typically run £3,000 to £8,000 for Stage 1 and Stage 2, plus £1,500 to £3,000 a year for surveillance audits. Internal staff time for evidence gathering and training sits alongside both. A typical UK SME budgets £14,000 to £23,000 in total for the first year.
Consultancy fees pay for the implementation work: gap analysis, ISMS design, risk assessment, documentation, internal audit support, and attendance at your certification audits. The certificate itself is issued by an independent UKAS-accredited certification body, such as BSI, NQA, Alcumus ISOQAR, or Bureau Veritas, once their auditors confirm your ISMS meets ISO 27001:2022 during Stage 1 and Stage 2. A consultant cannot issue the certificate; only the certification body can.
No. Certification body audit fees are separate from consultancy fees and are set independently by whichever UKAS-accredited body you choose, not by your consultant. Budget for them separately and get a direct quote from the certification body, since fees vary by body and by the scope of your ISMS. Precursor supports Stage 1 and Stage 2 liaison as part of the consultancy fee, but the audit fee itself is paid to the certification body.
For most UK SMEs, the process from gap analysis to certification takes 3 to 6 months depending on starting maturity, organisation size, and scope. Larger or more complex organisations typically take 6 to 12 months. Organisations with existing security policies and processes often move faster through the gap analysis and ISMS build stages.
For organisations facing a client, procurement, or supply chain requirement, yes: the certification is often the difference between winning and losing the contract, and fixed-price consultancy compresses a 12 to 18 month DIY timeline down to 3 to 6 months with lower first-pass audit failure risk. For organisations with no external driver, the value depends on whether the governance and risk management the standard forces you to build is worth the investment on its own. A gap analysis is the cheapest way to test that before committing to full implementation.



