[{"data":1,"prerenderedAt":10},["ShallowReactive",2],{"article:en:what-iso-9001-certification-costs-the-audit-days-iaf-md-5-fixes-by-headcount-the-day-rate-the-three-year-total-and-why-it-is-a-third-of-iso-27001":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"body":9},"en","what-iso-9001-certification-costs-the-audit-days-iaf-md-5-fixes-by-headcount-the-day-rate-the-three-year-total-and-why-it-is-a-third-of-iso-27001","What ISO 9001 certification costs: the audit days IAF MD 5 fixes by headcount, the day rate, the three-year total, and why it is a third of ISO 27001","Certification bodies do not publish prices, but the audit days are not their opinion: IAF MD 5 sets them by the number of people in scope, 1.5 days for up to five people, 3 for 16 to 25, 7 for 86 to 125, and the accreditation body holds the certifier to the table. Multiply by a day rate of 1,200 to 1,800 euros, add two surveillance audits at about a third each, and you have your number before anyone quotes you. Worked for six company sizes, with the ISO 27001 days beside them, what moves the number up or down, and what else you pay.","2026-09-12","\nNo accredited certification body publishes what an ISO 9001 certificate costs, which is why the question has 17,076 tenders behind it and no answer on any certifier's website. The fee is not arbitrary, though. It is auditor days multiplied by a day rate, and the day count is set by a document every accredited certifier is held to: IAF MD 5, the International Accreditation Forum's mandatory document on audit time for quality, environmental and occupational health and safety management systems. Its Table QMS 1 gives the audit time for an initial certification, Stage 1 plus Stage 2, by the effective number of personnel. This article is that table for the sizes a small company has, the arithmetic, and what changes it. It is the quality twin of [the ISO 27001 cost page](\u002Fiso-27001\u002Fcost), and the two use the same day rate so the comparison is honest.\n\n## The table, worked for six sizes\n\nIAF MD 5:2023, Annex A, Table QMS 1: 1.5 days for 1 to 5 people, 2 for 6 to 10, 2.5 for 11 to 15, 3 for 16 to 25, 4 for 26 to 45, 5 for 46 to 65, 6 for 66 to 85, 7 for 86 to 125, 8 for 126 to 175, 9 for 176 to 275, 10 for 276 to 425, and on up the table. The day rate is the band published practitioner sources give for accredited bodies in Europe, 1,200 to 1,800 euros, the same band the ISO 27001 page uses; quality audits are often quoted towards the lower end. Surveillance audits in years two and three are about a third of the initial time each (IAF MD 5, clause 5) and, the document notes, rarely less than one day. Fees are rounded to the nearest hundred.\n\n| People in scope | ISO 9001 days (Stage 1 + 2) | Initial audit fee | Three-year total, fees only | ISO 27001 days, for comparison |\n| --- | --- | --- | --- | --- |\n| 5 | 1.5 | €1,800 to €2,700 | €4,200 to €6,300 | 5 |\n| 10 | 2 | €2,400 to €3,600 | €4,800 to €7,200 | 5 |\n| 25 | 3 | €3,600 to €5,400 | €6,000 to €9,000 | 7 |\n| 50 | 5 | €6,000 to €9,000 | €10,000 to €15,000 | 10 |\n| 100 | 7 | €8,400 to €12,600 | €14,000 to €21,000 | 12 |\n| 250 | 9 | €10,800 to €16,200 | €18,000 to €27,000 | 14 |\n\nRead the last column against the second. For a company of 25 people, ISO 9001 is 3 auditor days where ISO 27001 is 7; for 100 people, 7 against 12. The quality audit is shorter because ISO 27001's table in ISO\u002FIEC 27006 assumes more to verify per person; a company that holds ISO 27001 and adds ISO 9001 pays for the shorter of the two audits on top, not for a second audit of the same size, and IAF MD 11 lets a certifier reduce the combined time further for an integrated system, by an amount it calculates from the level of integration.\n\n## What the certifier is counting\n\n\"Effective number of personnel\" is not the headcount on the payroll. IAF MD 5, clause 1.9, counts all personnel involved in the scope of certification, permanent, temporary and part-time, across shifts, and contractors where they are in scope; clause 2.3 lets part-time staff be converted to full-time equivalents and lets people whose work is repetitive or outside the certified activities be counted down, with the method recorded. A software company of 30 with 10 contractors and a support team on three shifts does not have 30 effective personnel, and the number it agrees with the certifier is the one that sets the band.\n\n## What moves the number\n\nThe table is a starting point, and clause 3.7 requires the certifier to adjust it for the factors that apply and record why. Upward: more than one building or site, staff in more than one language, highly complex processes or many unique activities, activities the document classes as high risk (its examples are food, pharmaceuticals, aircraft, construction, medical services, chemicals), and outsourced processes. Downward: a client that is not design responsible or excludes other elements from its scope, a very small site for the headcount, a mature system, a certifier that already knows the system because it certified the company to another standard, a client already certified or recognised by another scheme, a high level of automation, and off-site staff whose work can be audited from records. Activities the document classes as low risk may take less time than the table; software is not named in its examples, and the closest ones, office services and publishing, are low risk.\n\nFor a software company that already holds ISO 27001 from the same certifier, three of the downward factors apply at once: the certifier knows the system, the client is prepared, and the activities are low risk. That is the case for asking the certifier that already audits you for a combined quote before asking anyone else.\n\n## What else you pay\n\nThe audit fee is the only line that the table fixes. Around it: the auditor's travel and expenses, billed separately; the standard itself, around 130 euros for ISO 9001 from a national standards body; the certifier's application and certificate fees, which vary and which a quote should itemise; and your own people's time, which is the largest cost and appears in no quote. On the last one, a company that already runs a management system for ISO 27001 spends its time on [clause 8](\u002Farticles\u002Fiso-9001-for-a-software-company-what-clause-8-means-when-the-product-is-code-sub-clause-by-sub-clause), the operational clause, because clauses 4 to 7, 9 and 10 are the same skeleton it already maintains.\n\nGet three quotes on an identical brief: the effective personnel with the calculation, the sites, the scope statement, the risk category you propose and why, and the other standards you hold. A certifier that quotes without asking for the effective personnel has not applied the table.\n\n## Why it is worth knowing before you ask\n\nBecause a quote you cannot check is a quote you cannot negotiate. With the band, a 25-person company knows that 3 days at 1,200 to 1,800 euros is 3,600 to 5,400 euros for the initial audit, and that a quote of 9,000 euros is either applying upward factors it should name or padding. The same arithmetic tells it whether an unaccredited certificate at a third of the price is a bargain, and [the accreditation registers](\u002Farticles\u002Fhow-to-check-an-iso-9001-certificate-is-real-what-a-certificate-must-show-three-checks-that-take-ten-minutes-and-the-27-accreditation-registers) tell it why it is not. What the certificate is for, by country, is in [the count of EU tenders that name ISO 9001](\u002Farticles\u002Fiso-9001-in-eu-public-tenders-by-country).\n\n## Sources\n\n- IAF MD 5:2023, Issue 4, Version 3, issued 14 June 2023, Annex A Table QMS 1 and Table QMS 2, clauses 1.9, 2.3, 3.7, 5 and 6, read on 12 September 2026 from iaf.nu.\n- IAF MD 11, for the audit time of integrated management systems, cited by name.\n- ISO\u002FIEC 27006, Annex B, for the ISO 27001 days in the comparison column, as used on the ISO 27001 cost page.\n- The day-rate band, 1,200 to 1,800 euros, is the spread across published practitioner sources for accredited bodies in Europe; no accredited body publishes a price.\n\nThis is not a quote. The certifier sets the audit time under IAF MD 5 and records its reasons; the table above is the starting point it works from.\n",1789383983896]