What ISO 27001 certification actually costs
StandardOS does not issue certificates, and cannot.
Only an accredited certification body can certify you. That is a separate company, you contract with them directly, and you pay them directly — we never see any of it. Our €249/mo gets your management system built and your evidence in order so that their audit goes well. Anyone selling you both the preparation and the certificate is selling you something an auditor will not accept.
Here is the awkward part of this market: no accredited certification body publishes its prices. Not DNV, not Bureau Veritas, not DQS, TÜV, BSI, Intertek, SGS, LRQA or Dekra. Every one is “request a quote”, which means you cannot budget before you start talking to salespeople.
But the fee is not arbitrary. It is auditor days × day rate, and the day count is not the auditor's opinion — it is set by the audit-time chart in ISO/IEC 27006 Annex B, which the accreditation body holds them to. So you can compute your own number before anyone quotes you.
Count contractors and freelancers, not just employees — the 2024 edition is explicit about this, and it is the mistake that most often pushes a company into the next band.
- Auditor days (Stage 1 + Stage 2)
- 7
- Initial certification
- €8,400 – €12,600
- Surveillance audit, years 2 and 3
- €2,800 – €4,200 / yr
- Three-year total, audit fees only
- €14,000 – €21,000
Day counts from the audit-time chart in ISO/IEC 27006 Annex B; surveillance is about a third of the initial audit and recertification at least two thirds, per the same annex. Day rates of €1,200–€1,800 are the range across published practitioner sources for accredited bodies in Europe — nobody publishes an official figure, which is exactly why you should get three quotes on an identical brief. Travel is billed on top. The band can legitimately be cut by up to 30% for a simple, single-site, mature scope, and no further: that floor is in the annex too.
How long it takes
Four to seven months is realistic for a small software company using tooling. The floor is around three months and it is a hard floor, for a reason worth understanding: Stage 2 samples your records. Clause 9.2 requires an internal audit and 9.3 a management review, and an auditor cannot sample a management review that has not happened. No software can compress that — what software can remove is the two-to-six months of building policies, the risk register and the SoA that normally comes first.
The trap worth naming
Nothing stops a company calling itself a certification body and selling certificates. A non-accredited certificate looks identical, costs roughly 40–50% less, and is routinely rejected in enterprise procurement — at which point you pay the full accredited fee again, because an unaccredited certificate generally cannot be transferred. In Denmark the accreditation body is DANAK; check your certifier on the DANAK register, or internationally via IAF, before you sign anything.
What else you will spend
- · A penetration test, expected by auditors and by your customers — typically €2,500–€5,000 for a SaaS application.
- · The standard itself, around €130 for ISO 27001; you will want ISO 27002 too.
- · Auditor travel and expenses, billed separately from the day rate.
- · Your own people's time, which is the largest cost and appears in nobody's quote. Reducing it is what we sell.
Worked examples
- · up to 10 people → 5 auditor days
- · 16–25 people → 7 auditor days
- · 46–65 people → 10 auditor days
- · 86–125 people → 12 auditor days
Reproduced as worked examples rather than as the chart itself — ISO/IEC 27006 is copyrighted and we are not going to republish it. Check them against your own copy.
The audit fee is the big number. The software is not.
What you have just worked out is paid to a certification body, not to us. StandardOS is €249/mo excl. VAT, flat, and its job is to cut the largest cost on this page — your own people's time — which appears in nobody's quote.
No card to start · cancel in-app anytime
Every number above is auditor days × day rate. The days come from ISO/IEC 27006, which fixes them by headcount; the €1,200–€1,800 band is the range across published practitioner sources for accredited bodies in Europe, and no certification body publishes its own. The arithmetic is on this page precisely so you can redo it with a rate you have been quoted rather than ours. If a body quotes you far outside these ranges, ask them how many auditor days they have allocated and which edition of ISO/IEC 27006 they applied.