The certification body's audit fee, not ours
What ISO 27001 certification actually costs
- Our price
- StandardOS is €249/mo flat, on top of whatever the auditor charges; the numbers below are the auditor's.
- A 20-person company
- 7 auditor days for Stage 1 and Stage 2; €8,400 to €12,600 for initial certification; €14,000 to €21,000 over the three-year cycle with two surveillance audits, audit fees only.
- A 100-person company
- 12 auditor days for Stage 1 and Stage 2; €14,400 to €21,600 for initial certification; €24,000 to €36,000 over the three-year cycle with two surveillance audits, audit fees only.
- Where the numbers come from
- The days: the audit-time chart in ISO/IEC 27006 Annex B, by the people in scope, which accreditation bodies hold certification bodies to. The rate: €1,200 to €1,800 a day, the range across published European sources, because no accredited body publishes one. Surveillance: about a third of the initial audit each year.
- What is not in it
- The penetration test, the standard's own text, the auditor's travel, and your own people's time, which is the largest line and appears in nobody's quote. A certificate from a body that is not accredited costs less and is not certification.
Count contractors and freelancers, not just employees. The 2024 edition is explicit about this, and it is the mistake that most often pushes a company into the next band.
The sites and complexity adjustments are StandardOS's assumptions, half a day per additional site and a fifth either way for complexity, not the annex's factors; a certification body applies its own under ISO/IEC 27006, so ask every quote to state its days.
- Auditor days (Stage 1 + Stage 2)
- 7
- Initial certification
- €8,400 – €12,600
- Surveillance audit, years 2 and 3
- €2,800 – €4,200 / yr
- Three-year total, audit fees only
- €14,000 – €21,000
Day counts from the audit-time chart in ISO/IEC 27006 Annex B; surveillance is about a third of the initial audit and recertification at least two thirds, per the same annex. Day rates of €1,200–€1,800 are the range across published practitioner sources for accredited bodies in Europe. Nobody publishes an official figure, which is exactly why you should get three quotes on an identical brief. Travel is billed on top. The band can legitimately be cut by up to 30% for a simple, single-site, mature scope, and no further: that floor is in the annex too.
The audit fee by company size
Every band of the chart, one site, typical complexity, at €1,200 to €1,800 a day: the initial audit, each surveillance year, and the three-year total.
| People in scope | Auditor days | Initial certification | Surveillance, per year | Three-year total |
|---|---|---|---|---|
| up to 10 | 5 | €6,000 – €9,000 | €2,000 – €3,000 | €10,000 – €15,000 |
| up to 15 | 6 | €7,200 – €10,800 | €2,400 – €3,600 | €12,000 – €18,000 |
| up to 25 | 7 | €8,400 – €12,600 | €2,800 – €4,200 | €14,000 – €21,000 |
| up to 45 | 8.5 | €10,200 – €15,300 | €3,400 – €5,100 | €17,000 – €25,500 |
| up to 65 | 10 | €12,000 – €18,000 | €4,000 – €6,000 | €20,000 – €30,000 |
| up to 85 | 11 | €13,200 – €19,800 | €4,400 – €6,600 | €22,000 – €33,000 |
| up to 125 | 12 | €14,400 – €21,600 | €4,800 – €7,200 | €24,000 – €36,000 |
| up to 175 | 13 | €15,600 – €23,400 | €5,200 – €7,800 | €26,000 – €39,000 |
| up to 275 | 14 | €16,800 – €25,200 | €5,600 – €8,400 | €28,000 – €42,000 |
| up to 425 | 15 | €18,000 – €27,000 | €6,000 – €9,000 | €30,000 – €45,000 |
| up to 625 | 16.5 | €19,800 – €29,700 | €6,600 – €9,900 | €33,000 – €49,500 |
| up to 875 | 17.5 | €21,000 – €31,500 | €7,000 – €10,500 | €35,000 – €52,500 |
| up to 1175 | 18.5 | €22,200 – €33,300 | €7,400 – €11,100 | €37,000 – €55,500 |
StandardOS does not certify; an accredited body does, and you pay them directly.
What the audit fee pays for
- · Stage 1, the review of your documented system and its readiness.
- · Stage 2, the audit of the running system against the standard, on site or remote.
- · The audit report, the certification decision and the certificate.
- · The surveillance audits in years two and three, at about a third of the initial days each.
What else you will spend
- · A penetration test, expected by auditors and by your customers, typically €2,500–€5,000 for a SaaS application.
- · The standard itself, around €130 for ISO 27001; you will want ISO 27002 too.
- · Auditor travel and expenses, billed separately from the day rate.
- · Your own people's time, which is the largest cost and appears in nobody's quote. Reducing it is what we sell.
The questions people ask
- How much does ISO 27001 certification cost?
- Auditor days times a day rate, and the days are set by headcount: about 7 days for a 20-person company, €8,400 to €12,600 for the initial certification, and about 12 days for a 100-person company, €14,400 to €21,600. Surveillance audits in years two and three cost about a third of that each.
- What does an ISO 27001 audit cost per day?
- No accredited certification body publishes a day rate; across published European sources the range is €1,200 to €1,800. The days are the fixed part: the audit-time chart in ISO/IEC 27006 Annex B sets them by the people in scope, so two quotes for the same company should show the same days and differ only in the rate.
- What is the ISO 27001 accreditation cost?
- Accreditation is what a certification body pays its national accreditation body to be allowed to certify; a company pays for certification, not accreditation. When the search says accreditation cost it means the certification fee above, and the accreditation that matters to a company is the body's: check it in the national register before you sign.
- What are the ISO 27001 certification fees per year?
- Year one is the initial audit, Stage 1 and Stage 2. Years two and three are surveillance audits at about a third of the initial days each. Year four is recertification at about two thirds, and the cycle starts again. The software and your own people's time run every year and are not in the audit fee.
- How much does ISO 27001 cost for a small company?
- For up to 10 people in scope the chart gives 5 auditor days, so €6,000 to €9,000 for the initial certification and about a third of that in each surveillance year. Counting contractors and freelancers as people in scope is the mistake that most often moves a small company into the next band.
- Does the ISO 27001 cost depend on the industry?
- Barely. Headcount sets the days; the certification body can adjust for the complexity of the scope, the number of sites and the reliance on outsourcing, and travel is billed on top. Industry moves the price only through those factors.
No accredited certification body publishes its prices. DNV, Bureau Veritas, DQS, TÜV, BSI, Intertek, SGS, LRQA and Dekra all quote on request, so you cannot budget before the sales calls start. The fee is still auditor days × day rate, and the days are set by the audit-time chart in ISO/IEC 27006 Annex B, which the accreditation body holds the certifier to, so you can compute your own number before anyone quotes you.
ISO/IEC 27006 is international, so the day count holds in any country; the euro band is what practitioners publish for Europe. Certifying elsewhere, keep the days and put your own quoted rate through the same arithmetic.
How long it takes
Four to seven months is realistic for a small software company using tooling. The floor is around three months and it is a hard floor, for a reason worth understanding: Stage 2 samples your records. Clause 9.2 requires an internal audit and 9.3 a management review, and an auditor cannot sample a management review that has not happened. No software can compress that. What software can remove is the two-to-six months of building policies, the risk register and the SoA that normally comes first.
The trap worth naming
Nothing stops a company calling itself a certification body and selling certificates. A non-accredited certificate looks identical, costs roughly 40–50% less, and is routinely rejected in enterprise procurement, at which point you pay the full accredited fee again, because an unaccredited certificate generally cannot be transferred. Every EU country has one national accreditation body, named under Regulation (EC) 765/2008 and listed by European co-operation for Accreditation: DAkkS in Germany, COFRAC in France, RvA in the Netherlands, ENAC in Spain, ACCREDIA in Italy. Check your certifier on that register, or internationally via IAF, before you sign anything.
How to find an accredited certification body, and check them yourself
Further reading
- · ISO 27001 vs SOC 2 in Europe: which one buyers actually ask for, from EU tender data
- · How many auditor days an ISO 27001 certification takes, by headcount
- · ISO 27001 certification cost for a company, by headcount
- · ISO 27001 cost of implementation: the three-year number, not the first invoice
- · The cheapest ISO 27001 certification: where the floor is, by headcount
- · The cheapest way to get ISO 27001, and what it costs later
- · What ISO 9001 certification costs, from IAF MD 5, and why it is a third of ISO 27001
Worked examples
- · up to 10 people → 5 auditor days
- · 16–25 people → 7 auditor days
- · 46–65 people → 10 auditor days
- · 86–125 people → 12 auditor days
Reproduced as worked examples rather than as the chart itself, because ISO/IEC 27006 is copyrighted and we are not going to republish it. Check them against your own copy.
The audit fee is the big number. The software is not.
What you have just worked out is paid to a certification body, not to us. StandardOS is €249/mo excl. VAT, flat, and its job is to cut the largest cost on this page, your own people's time, which appears in nobody's quote.
No card to start · cancel in-app anytime
Every number above is auditor days × day rate. The days come from ISO/IEC 27006, which fixes them by headcount; the €1,200–€1,800 band is the range across published practitioner sources for accredited bodies in Europe, and no certification body publishes its own. The arithmetic is on this page precisely so you can redo it with a rate you have been quoted rather than ours. If a body quotes you far outside these ranges, ask them how many auditor days they have allocated and which edition of ISO/IEC 27006 they applied.