Skip to main content
RiskZeroCertifiers

Buying advice

ISO 27001 certification cost: what actually drives the audit quote

How accredited certification bodies calculate ISO 27001 audit fees, what IAF MD 5 audit time means for your quote, hidden costs to watch for, and how to compare quotes.

By RiskZero Certifiers4 min read

Certification body quotes can look arbitrary. One body quotes six audit days, another quotes nine, and a third will not give a number without a call. In fact the calculation is more constrained than it looks, and understanding it will help you compare quotes and avoid surprises in year two.

Audit time is regulated

Accredited certification bodies do not get to choose how long an ISO 27001 audit takes. The International Accreditation Forum publishes a mandatory document, IAF MD 5, which sets the minimum audit time based on the number of people in scope, adjusted for complexity. ISO/IEC 27006-1 adds ISMS-specific rules. Accreditation bodies check that certification bodies apply them.

This means two accredited bodies quoting the same scope should arrive at similar audit durations. If one is dramatically lower, either they have understood your scope differently or they are not applying the rules, and the latter will eventually be a problem for you.

What drives the audit time

Effective number of people

The starting point is the number of people who do work within the scope, adjusted for part-time staff, shift patterns, and people doing repetitive tasks. Contractors who work under your ISMS count. A 150-person company with a 40-person engineering scope is priced on the 40, plus the supporting functions.

Complexity

IAF MD 5 and ISO/IEC 27006-1 allow the time to be increased or decreased based on factors such as:

  • Number and type of sites and whether they need visiting
  • Complexity of IT, including in-house development and the number of critical systems
  • Sensitivity and volume of information handled, and regulatory context
  • Degree of outsourcing and reliance on suppliers
  • Maturity of the ISMS and the results of previous audits

A fully remote SaaS company with heavy outsourcing to cloud providers will often sit at the lower end of the range. A company with in-house data centers, several offices, and regulated data sits higher.

The cycle

Initial certification includes Stage 1 and Stage 2. Each surveillance audit is around a third of the initial audit time. Recertification is around two thirds. The total over three years is roughly twice the initial audit time.

What a quote should include

A useful quote lists:

  • Stage 1 and Stage 2 durations and whether they are on site or remote
  • Surveillance audit durations for years one and two
  • The recertification audit duration and rate, even if invoiced later
  • Daily rates and whether they are fixed for the cycle
  • Travel and expenses policy
  • Fees for the certification decision, certificate issue, and registry listing
  • What happens to the price if headcount or sites change

If any of these are missing, ask. The most common unpleasant surprise is a surveillance audit priced much higher than the initial quote implied.

Hidden and adjacent costs

  • Follow-up audits. If a major nonconformity requires a verification visit, that is additional audit time.
  • Scope extensions. Adding a site or product mid-cycle adds audit time.
  • Consultancy and tooling. Not part of the certification fee but usually the larger cost. Implementation help, a compliance platform, penetration testing, and staff time all belong in the budget.
  • Your own time. Plan for the ISMS owner to spend substantial time during audits and for process owners to give one to two hours each.

Comparing quotes fairly

  1. Check that both bodies are accredited and that their accreditation covers ISO/IEC 27001. Unaccredited certificates are cheaper and frequently worthless in procurement.
  2. Compare audit days, not just prices. If one quote has fewer days for the same scope, ask how they arrived at the number.
  3. Ask for the three-year total, including recertification.
  4. Ask about auditor allocation. Who will actually turn up, and what is their background?
  5. Ask about lead times for dates. A cheap quote with a four-month wait can cost you a contract.

How RiskZero prices

We calculate audit time from IAF MD 5 and ISO/IEC 27006-1, show the working in the proposal, and fix the daily rate for the full cycle. Our pricing page explains the factors that determine audit time, and a quote takes two business days.

  • cost
  • pricing
  • audit time
  • IAF MD 5

Read next

Ready to scope your audit?

Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.