
ISO 27001 Certification Cost: A Line-by-Line Breakdown
Stage 1, Stage 2, surveillance audits and recertification — plus the internal audit and management review that the standard requires and nobody prices.
GuardsArm Team
Security Experts

ISO 27001 costs more than SOC 2 in year one for most organisations, and less over five years. The reason is structural: ISO certifies a management system, so you are building something that runs continuously, then having it audited on a three-year cycle rather than re-audited annually from scratch.
The certification cycle
The three-year cycle is the thing to understand before budgeting. You are not buying an audit; you are entering a cycle with a fixed rhythm of surveillance and a recertification at the end.
The cost lines
Gap analysis. Where you stand against the standard and Annex A. One-off, and it determines everything downstream.
ISMS implementation. The bulk of year one. Scope definition, risk assessment methodology, Statement of Applicability, policy set, and the operational processes the standard requires. This is where organisations either build something real or build a binder.
Risk assessment. ISO is explicitly risk-based. You need a documented, repeatable methodology and evidence you applied it — not a spreadsheet produced once for the auditor.
Internal audit. Mandatory. Must be independent of the area audited, which usually means an external party for a smaller organisation. Recurring annually.
Management review. Mandatory, at planned intervals, with defined inputs and outputs. Cheap in money, real in executive calendar time, and a common non-conformity when skipped.
Certification body fees. Stage 1 and Stage 2, priced on organisation size, scope and complexity. Then surveillance annually and recertification at year three.
Internal effort. As with SOC 2, systematically underestimated.
What makes it cheaper or more expensive
| Factor | Effect on cost |
|---|---|
| Scope breadth | The single biggest lever — certify a product, not the company |
| Number of sites | Multi-site adds sampling and travel |
| Headcount | Certification body fees scale with it |
| Existing management systems | ISO 9001 already in place makes this much easier |
| Existing certifications | SOC 2 work transfers substantially |
| Choice of certification body | Accredited bodies vary; the cheapest may not be recognised by your buyers |
Scope is the lever. Certifying "the information security management system supporting the X platform and its supporting functions" is a fraction of the cost of certifying an entire company, and is usually what a customer asked for anyway. Check the scope statement on any certificate you are asked to match — buyers rarely read them, but a narrow scope is entirely legitimate.
Against SOC 2
Both are commonly requested; they answer different questions. SOC 2 is a report on controls over a period, prevalent in North America. ISO 27001 is a certification of a management system, recognised internationally, and generally the stronger signal outside North America.
If you are asked for both, sequence them: the control work overlaps substantially, and doing them together costs far less than two separate programmes. See SOC 2 versus ISO 27001.
Choosing a certification body
This decision is made casually and matters more than expected.
- Accreditation. A certificate from a body accredited by a recognised national accreditation body carries weight. One from an unaccredited certifier may be rejected by the customer who asked for it, which wastes the entire programme.
- Sector familiarity. An auditor who understands your industry spends less time on orientation and raises more useful findings.
- Auditor continuity across the three-year cycle reduces repeated explanation.
- Cost across the cycle, not the Stage 2 fee alone. Surveillance and recertification are where the difference accumulates.
Ask any prospective customer whether they require a specific accreditation before you select.
The ongoing cost nobody plans for
Certification is not the end of spending. Each year you need internal audits covering the scope, a management review with genuine executive attendance, risk assessment refresh, corrective actions from the previous surveillance, and evidence that the ISMS operated throughout.
Organisations that treat the certificate as the finish line arrive at the first surveillance audit with twelve months of nothing to show, and surveillance findings are considerably more awkward than initial ones.
Where to start
Write the scope statement first. One paragraph defining what the ISMS covers. It determines the size of every other line on the budget, and getting it wrong in the expansive direction is the most expensive mistake available in this process.
GuardsArm runs ISO 27001 implementation and pre-certification audits. See ISO 27001 services or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “ISO 27001 Certification Cost: A Line-by-Line Breakdown”
Talk to the GuardsArm team about how these services apply to your environment.


