Skip to main content
RiskZeroCertifiers

Pricing

Fixed fees, calculated in the open

ISO 27001 audit time is regulated, not invented. We calculate yours from the rules every accredited body must follow, show the working in the proposal, and fix the daily rate for the whole three-year cycle.

How to get a quote

  1. 1 Tell us your scope, headcount, and sites.
  2. 2 We confirm the auditor and calculate audit time.
  3. 3 You receive a fixed-fee proposal within two business days.
Request a quote

What moves the number

Six factors that determine audit time

  • People in scope

    The largest factor. Counted as effective personnel: full-time equivalents doing work covered by the ISMS, including contractors, adjusted for shifts and repetitive roles.

  • Sites

    Each site with people or infrastructure in scope may need visiting at least once in the cycle. Multi-site organizations with consistent processes can use sampling, which reduces time.

  • Technical complexity

    In-house development, own data centers, many critical systems, and complex networks increase time. Heavy use of cloud platforms with clear shared responsibility often reduces it.

  • Information sensitivity and regulation

    Health data, financial data, and government information add regulatory requirements the auditor must cover, which increases the sample.

  • Other standards

    Adding ISO 27701 or ISO 22301 to an integrated audit adds time, but less than auditing them separately.

  • Maturity and history

    For recertifications, a clean audit history and a stable scope can reduce the time required.

What the fee includes

  • Stage 1 and Stage 2 audit days, on site or remote as agreed
  • Two surveillance audits, one in each of years one and two
  • Independent certification decision and certificate issue
  • Certificate verification for your customers, for the life of the certificate
  • Certification mark artwork and usage guidelines
  • Audit planning, reporting, and review of corrective action plans

What is quoted separately

  • Travel and accommodation for on-site days, charged at cost and agreed in advance
  • Follow-up audits required to verify closure of a major nonconformity
  • Additional audit time for scope extensions, new sites, or significant headcount growth
  • The recertification audit, which is quoted at the same fixed rates before the end of the cycle

Questions

Questions about pricing

Why do you not publish a price list?
Because the audit time, and therefore the price, is calculated from your specific scope, and publishing a single number would be misleading in both directions. What we do publish is the calculation method, the factors that move it, and a commitment to fixed daily rates for the cycle. A quote takes two business days.
Can we reduce the audit time?
Within limits. The minimums are set by IAF MD 5 and ISO/IEC 27006-1 and we cannot go below them. Within the permitted range, a well-organized evidence set, a single clearly defined scope, consistent processes across sites, and remote-friendly working all help the auditor cover more in less time.
Are your rates fixed for the whole cycle?
Yes. The daily rate in your proposal applies to Stage 1, Stage 2, both surveillance audits, and the recertification audit. The only things that change the total are changes to your scope, sites, or headcount, and we tell you in advance.
How does this compare with other certification bodies?
Accredited bodies must apply the same audit-time rules, so quotes for the same scope should land in a similar range of days. Large differences usually indicate a different understanding of the scope, items missing from the quote, or a body that is not applying the rules. Our article on what drives certification cost explains how to compare quotes.

Get a quote

Tell us about your scope

Five questions is enough for us to calculate audit time and confirm an auditor. We reply within two business days with a fixed-fee proposal and available dates.

We reply within two business days with a fixed-fee quote. Read our privacy policy.