Back to Blog
Compliance
4 min read

ISO 27001 Certification Cost: A Line-by-Line Breakdown

Stage 1, Stage 2, surveillance audits and recertification — plus the internal audit and management review that the standard requires and nobody prices.

GuardsArm Team

Security Experts

September 25, 2026

ISO 27001 certification cost breakdown

ISO 27001 costs more than SOC 2 in year one for most organisations, and less over five years. The reason is structural: ISO certifies a management system, so you are building something that runs continuously, then having it audited on a three-year cycle rather than re-audited annually from scratch.

A cycle, not an audit
Three years, with surveillance in between
Scope is the lever
Certify a product, not the whole company
Cheaper than SOC 2 over five years
More expensive in year one

The certification cycle

The ISO 27001 certification cycleThe ISO 27001 certification cycle1Gap analysisMonth 0Position against the standard and Annex A controls.2ISMS implementationMonths 1-6Scope, risk methodology, Statement of Applicability, policies, processes.3Internal audit and management reviewMonth 6-8Both mandatory. Internal audit must be independent of the area audited.4Stage 1 certification auditMonth 8Documentation review. Findings here are cheaper than findings at Stage 2.5Stage 2 certification auditMonth 9-10Effectiveness. The certificate follows.6Surveillance, then recertificationYears 1, 2, then 3Annual surveillance audits, full recertification at year three.
Budget the whole cycle. Year one is not the steady-state cost.

The three-year cycle is the thing to understand before budgeting. You are not buying an audit; you are entering a cycle with a fixed rhythm of surveillance and a recertification at the end.


The cost lines

Gap analysis. Where you stand against the standard and Annex A. One-off, and it determines everything downstream.

ISMS implementation. The bulk of year one. Scope definition, risk assessment methodology, Statement of Applicability, policy set, and the operational processes the standard requires. This is where organisations either build something real or build a binder.

Risk assessment. ISO is explicitly risk-based. You need a documented, repeatable methodology and evidence you applied it — not a spreadsheet produced once for the auditor.

Internal audit. Mandatory. Must be independent of the area audited, which usually means an external party for a smaller organisation. Recurring annually.

Management review. Mandatory, at planned intervals, with defined inputs and outputs. Cheap in money, real in executive calendar time, and a common non-conformity when skipped.

Certification body fees. Stage 1 and Stage 2, priced on organisation size, scope and complexity. Then surveillance annually and recertification at year three.

Internal effort. As with SOC 2, systematically underestimated.

Internal audit and management review are not optional
Both are explicit requirements of the standard, and both are routinely skipped by organisations focused on the Annex A control list. They are among the most common non-conformities raised at Stage 2, and they cost almost nothing to do properly if planned from the start.

What makes it cheaper or more expensive

FactorEffect on cost
Scope breadthThe single biggest lever — certify a product, not the company
Number of sitesMulti-site adds sampling and travel
HeadcountCertification body fees scale with it
Existing management systemsISO 9001 already in place makes this much easier
Existing certificationsSOC 2 work transfers substantially
Choice of certification bodyAccredited bodies vary; the cheapest may not be recognised by your buyers

Scope is the lever. Certifying "the information security management system supporting the X platform and its supporting functions" is a fraction of the cost of certifying an entire company, and is usually what a customer asked for anyway. Check the scope statement on any certificate you are asked to match — buyers rarely read them, but a narrow scope is entirely legitimate.


Against SOC 2

Both are commonly requested; they answer different questions. SOC 2 is a report on controls over a period, prevalent in North America. ISO 27001 is a certification of a management system, recognised internationally, and generally the stronger signal outside North America.

If you are asked for both, sequence them: the control work overlaps substantially, and doing them together costs far less than two separate programmes. See SOC 2 versus ISO 27001.


Choosing a certification body

This decision is made casually and matters more than expected.

  • Accreditation. A certificate from a body accredited by a recognised national accreditation body carries weight. One from an unaccredited certifier may be rejected by the customer who asked for it, which wastes the entire programme.
  • Sector familiarity. An auditor who understands your industry spends less time on orientation and raises more useful findings.
  • Auditor continuity across the three-year cycle reduces repeated explanation.
  • Cost across the cycle, not the Stage 2 fee alone. Surveillance and recertification are where the difference accumulates.

Ask any prospective customer whether they require a specific accreditation before you select.


The ongoing cost nobody plans for

Certification is not the end of spending. Each year you need internal audits covering the scope, a management review with genuine executive attendance, risk assessment refresh, corrective actions from the previous surveillance, and evidence that the ISMS operated throughout.

Organisations that treat the certificate as the finish line arrive at the first surveillance audit with twelve months of nothing to show, and surveillance findings are considerably more awkward than initial ones.


Where to start

Write the scope statement first. One paragraph defining what the ISMS covers. It determines the size of every other line on the budget, and getting it wrong in the expansive direction is the most expensive mistake available in this process.

GuardsArm runs ISO 27001 implementation and pre-certification audits. See ISO 27001 services or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “ISO 27001 Certification Cost: A Line-by-Line Breakdown”

Talk to the GuardsArm team about how these services apply to your environment.