The cost of implementing ISO 27001 is a three-year number, not a first invoice: for a 46 to 65 person company, initial certification is around 10 auditor days, 12,000 to 18,000 EUR at 1,200 to 1,800 EUR a day, then surveillance audits in years two and three at about a third of that each and recertification at about two thirds, plus the internal time to build and run the system, which is usually the larger line. Most estimates quote the first audit and stop.

The cycle

Year 0, initial certification. Stage 1 and Stage 2, priced in auditor days from the ISO/IEC 27006 Annex B chart. A 46 to 65 person company is around 10 days; at 1,200 to 1,800 EUR per day that is 12,000 to 18,000 EUR.

Years 1 and 2, surveillance. Roughly a third of the initial audit time each year. The certificate is withdrawn if you skip them.

Year 3, recertification. Roughly two thirds of the initial time, and the cycle restarts.

So the audit spend over three years is materially more than the first invoice suggests. The cost page totals it for your headcount.

The internal cost, which is usually larger

The auditor days are the visible number. The invisible one is the time your own people spend, and it splits in two.

Building the system. Context, scope, risk assessment, Statement of Applicability across 93 Annex A controls, policies, an internal audit programme, a management review. This is front-loaded and finite.

Keeping it running. This is the part that recurs, and it is where implementations quietly become expensive. Evidence has to exist for the period the auditor asks about. An organisation that collects it as it goes spends a little continuously; one that does not spends a concentrated block before each audit, every year, forever.

What actually reduces it

Narrow the scope honestly. Be ready at Stage 1. And keep records as they happen rather than assembling them afterwards, because the assembling is the expensive half and it repeats annually.

Software is a small line against the above. What matters is whether it leaves you with dated, complete records on the day an auditor asks. Our clause-by-clause coverage sets out what we hold and what we do not.