An ISO 27001 certification takes about 5 auditor days for a company of up to 10 people, 7 for 16 to 25, 10 for 46 to 65 and 12 for 86 to 125, Stage 1 and Stage 2 combined. The count comes from ISO/IEC 27006 Annex B, which every accredited certification body is held to, so a quote is days times a day rate of roughly 1,200 to 1,800 EUR: 8,400 to 12,600 EUR for a 25-person company. Surveillance audits in years two and three take about a third of that time each, and recertification at least two thirds.

No accredited certification body publishes its prices. Not DNV, not Bureau Veritas, not DQS, TÜV, BSI, Intertek, SGS, LRQA or Dekra. Every one of them is "request a quote", which means you cannot budget before you start talking to salespeople.

That is a real problem when you are trying to decide whether to start at all. It is also solvable, because the largest term in the fee is not negotiable and not secret.

The fee is days times rate

A certification quote is auditor days × day rate. The day rate varies by country and by body. The day count does not: it is set by the audit-time chart in ISO/IEC 27006 Annex B, and the accreditation body that authorises your certifier holds them to it.

So the half of the formula that would otherwise be opaque is published, and it is keyed to one input you already know: how many people do work under your control, inside your ISMS scope.

Worked examples, from the chart:

People in scope Auditor days, Stage 1 + Stage 2
up to 10 5
16–25 7
46–65 10
86–125 12

These are worked examples with the clause cited rather than a reproduction of the chart, because ISO/IEC 27006 is copyrighted and we are not going to republish it. Check them against your own copy.

Turning days into money

Across published practitioner sources, accredited bodies in Europe charge roughly €1,200 to €1,800 per auditor day. Nobody publishes an official figure, which is exactly why you should get three quotes on an identical brief.

For a 25-person company: 7 days, so €8,400 to €12,600 for initial certification.

Then the recurring part, from the same annex. A surveillance audit is about a third of the initial audit time, and it happens in years two and three. Recertification is at least two thirds. So the three-year cost of the certificate for that same company is roughly €14,000 to €21,000 in audit fees alone.

The three things that change the number

Headcount counted wrongly. The 2024 edition is explicit that contractors and freelancers count, not just employees. This is the single most common reason a company budgets for one band and gets quoted for the next one up.

Scope reductions. The annex permits a reduction of up to 30% for a simple, single-site, mature scope, and no further. That floor is in the annex too, so a quote far below the band is a question to ask rather than a bargain.

Travel. Billed on top of the day rate, always.

What is not in this number

The certificate is the fee you have just calculated. It is paid to a certification body, which is a separate company you contract with directly.

Everything else is yours: a penetration test at typically €2,500–€5,000 for a SaaS application, a copy of the standard at around €130, and the largest cost of all, which appears in nobody's quote: your own people's time building the management system before the auditor arrives.

Check the certifier before you sign

Nothing stops a company calling itself a certification body and selling certificates. A non-accredited certificate looks identical, costs 40–50% less, and is routinely rejected in enterprise procurement. At that point you pay the full accredited fee again, because an unaccredited certificate generally cannot be transferred.

Every EU country has one national accreditation body, named under Regulation (EC) 765/2008: DAkkS in Germany, COFRAC in France, RvA in the Netherlands, ENAC in Spain, DANAK in Denmark. Check your certifier on that register, or internationally through IAF, before you sign anything.