[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:how-many-auditor-days-iso-27001":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","how-many-auditor-days-iso-27001","How many auditor days an ISO 27001 certification takes, by headcount","Certification bodies do not publish prices, but the audit days are fixed by ISO\u002FIEC 27006 Annex B. Here is the arithmetic that turns your headcount into a number before anyone quotes you.","2026-08-11",{"who":10,"when":11,"do":12},"A company budgeting an ISO 27001 certification before any certification body has quoted: the auditor days are fixed by ISO\u002FIEC 27006 Annex B from the headcount inside the scope, contractors included, so the largest term of the fee can be worked out at the desk.","Before asking for quotes, so that a quote can be read against the published day count; again when the headcount crosses a band, since the next band means more days at the next audit; and before signing with any body that quotes far below the band.","Count everyone working under your control inside the scope, read the days off the annex (about 5 for up to 10 people, 7 for 16 to 25, 10 for 46 to 65, 12 for 86 to 125), multiply by a day rate of roughly 1,200 to 1,800 EUR, add a third of that for each surveillance year and at least two thirds for recertification, and get three quotes on the same brief from accredited bodies only.","\nAn ISO 27001 certification takes about 5 auditor days for a company of up to 10 people, 7 for 16 to 25, 10 for 46 to 65 and 12 for 86 to 125, Stage 1 and Stage 2 combined. The count comes from ISO\u002FIEC 27006 Annex B, which every accredited certification body is held to, so a quote is days times a day rate of roughly 1,200 to 1,800 EUR: 8,400 to 12,600 EUR for a 25-person company. Surveillance audits in years two and three take about a third of that time each, and recertification at least two thirds.\n\nNo accredited certification body publishes its prices. Not DNV, not Bureau Veritas, not DQS, TÜV, BSI, Intertek, SGS, LRQA or Dekra. Every one of them is \"request a quote\", which means you cannot budget before you start talking to salespeople.\n\nThat is a real problem when you are trying to decide whether to start at all. It is also solvable, because the largest term in the fee is not negotiable and not secret.\n\n## The fee is days times rate\n\nA certification quote is **auditor days × day rate**. The day rate varies by country and by body. The day count does not: it is set by the audit-time chart in **ISO\u002FIEC 27006 Annex B**, and the accreditation body that authorises your certifier holds them to it.\n\nSo the half of the formula that would otherwise be opaque is published, and it is keyed to one input you already know: how many people do work under your control, inside your ISMS scope.\n\nWorked examples, from the chart:\n\n| People in scope | Auditor days, Stage 1 + Stage 2 |\n| --- | --- |\n| up to 10 | 5 |\n| 16–25 | 7 |\n| 46–65 | 10 |\n| 86–125 | 12 |\n\nThese are worked examples with the clause cited rather than a reproduction of the chart, because ISO\u002FIEC 27006 is copyrighted and we are not going to republish it. Check them against your own copy.\n\n## Turning days into money\n\nAcross published practitioner sources, accredited bodies in Europe charge roughly **€1,200 to €1,800 per auditor day**. Nobody publishes an official figure, which is exactly why you should get three quotes on an identical brief.\n\nFor a 25-person company: 7 days, so €8,400 to €12,600 for initial certification.\n\nThen the recurring part, from the same annex. A surveillance audit is about a third of the initial audit time, and it happens in years two and three. Recertification is at least two thirds. So the three-year cost of the certificate for that same company is roughly **€14,000 to €21,000 in audit fees alone**.\n\n## The three things that change the number\n\n**Headcount counted wrongly.** The 2024 edition is explicit that contractors and freelancers count, not just employees. This is the single most common reason a company budgets for one band and gets quoted for the next one up.\n\n**Scope reductions.** The annex permits a reduction of up to 30% for a simple, single-site, mature scope, and no further. That floor is in the annex too, so a quote far below the band is a question to ask rather than a bargain.\n\n**Travel.** Billed on top of the day rate, always.\n\n## What is not in this number\n\nThe certificate is the fee you have just calculated. It is paid to a certification body, which is a separate company you contract with directly.\n\nEverything else is yours: a penetration test at typically €2,500–€5,000 for a SaaS application, a copy of the standard at around €130, and the largest cost of all, which appears in nobody's quote: your own people's time building the management system before the auditor arrives.\n\n## Check the certifier before you sign\n\nNothing stops a company calling itself a certification body and selling certificates. A non-accredited certificate looks identical, costs 40–50% less, and is routinely rejected in enterprise procurement. At that point you pay the full accredited fee again, because an unaccredited certificate generally cannot be transferred.\n\nEvery EU country has one national accreditation body, named under Regulation (EC) 765\u002F2008: DAkkS in Germany, COFRAC in France, RvA in the Netherlands, ENAC in Spain, DANAK in Denmark. Check your certifier on that register, or internationally through IAF, before you sign anything.\n",1789306943373]