[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:iso-27001-cost-of-implementation":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","iso-27001-cost-of-implementation","ISO 27001 cost of implementation: the three-year number, not the first invoice","Certification runs on a three-year cycle with surveillance audits each year. Budgeting only for the first audit is the most common way the total surprises people.","2026-08-20",{"who":10,"when":11,"do":12},"A company costing ISO 27001 for its budget: certification runs on a three-year cycle, initial certification in year one, surveillance audits in years two and three and recertification after, and the internal time to build and run the system is usually a larger line than the audit fee.","At the point the budget is set, before the first audit is booked, and again each year of the cycle, since a budget that quotes only the first audit meets the surveillance invoice a year later.","Take the auditor days for your headcount from ISO\u002FIEC 27006 Annex B, price them at roughly 1,200 to 1,800 EUR a day, add a surveillance audit at about a third of that in years two and three and recertification at about two thirds, and then add your own people's hours, which is the number most estimates leave out.","\nThe cost of implementing ISO 27001 is a three-year number, not a first invoice: for a 46 to 65 person company, initial certification is around 10 auditor days, 12,000 to 18,000 EUR at 1,200 to 1,800 EUR a day, then surveillance audits in years two and three at about a third of that each and recertification at about two thirds, plus the internal time to build and run the system, which is usually the larger line. Most estimates quote the first audit and stop.\n\n## The cycle\n\n**Year 0, initial certification.** Stage 1 and Stage 2, priced in auditor days from the ISO\u002FIEC 27006 Annex B chart. A 46 to 65 person company is around 10 days; at 1,200 to 1,800 EUR per day that is 12,000 to 18,000 EUR.\n\n**Years 1 and 2, surveillance.** Roughly a third of the initial audit time each year. The certificate is withdrawn if you skip them.\n\n**Year 3, recertification.** Roughly two thirds of the initial time, and the cycle restarts.\n\nSo the audit spend over three years is materially more than the first invoice suggests. [The cost page](\u002Fiso-27001\u002Fcost) totals it for your headcount.\n\n## The internal cost, which is usually larger\n\nThe auditor days are the visible number. The invisible one is the time your own people spend, and it splits in two.\n\n**Building the system.** Context, scope, risk assessment, Statement of Applicability across 93 Annex A controls, policies, an internal audit programme, a management review. This is front-loaded and finite.\n\n**Keeping it running.** This is the part that recurs, and it is where implementations quietly become expensive. Evidence has to exist for the period the auditor asks about. An organisation that collects it as it goes spends a little continuously; one that does not spends a concentrated block before each audit, every year, forever.\n\n## What actually reduces it\n\nNarrow the scope honestly. Be ready at Stage 1. And keep records as they happen rather than assembling them afterwards, because the assembling is the expensive half and it repeats annually.\n\nSoftware is a small line against the above. What matters is whether it leaves you with dated, complete records on the day an auditor asks. [Our clause-by-clause coverage](\u002Fiso-27001\u002Fcoverage) sets out what we hold and what we do not.\n",1789383986310]