There is no official price for ISO 27001 certification. ISO does not certify anyone, so it publishes no fee: in its own words, it "does not perform certification or issue certificates", and certification "is performed by external certification bodies". What ISO does sell is the standard. ISO/IEC 27001:2022 is listed on the ISO store at CHF 155, the ISO/IEC 27002:2022 guidance at CHF 227, and the 2024 climate action amendment is free. Everything else you pay is either your own people's time or a certification body's quote, and the quote is built from audit days.
Audit days are not a free choice either. ISO/IEC 27006-1:2024, the standard certification bodies are accredited against for information security, calculates audit time from the total number of persons doing work under the organisation's control, irrespective of their location. The certification cycle under ISO/IEC 17021-1 then fixes how many times you pay: a two stage initial audit, a surveillance audit in each calendar year, and a recertification audit to renew the three year cycle. This guide takes each cost line in turn and shows which ones you can move. What the standard asks you to build is in our guide to the 93 Annex A controls.
| Cost line | What sets it | Where it comes from |
|---|---|---|
| The standard itself | ISO store list price | CHF 155 for ISO/IEC 27001:2022, CHF 227 for ISO/IEC 27002:2022, amendment free |
| Building the ISMS | Your scope, your starting point, your people | Clauses 4 to 10 and Annex A of ISO/IEC 27001 |
| Initial audit | Audit days, in two stages | ISO/IEC 17021-1, clause 9.3.1; ISO/IEC 27006-1, Annex C |
| Surveillance | At least one audit each calendar year | ISO/IEC 17021-1, clause 9.1.3 |
| Recertification | A recertification audit to renew the three year cycle | ISO/IEC 17021-1 |
| Accreditation | One national accreditation body per Member State, not for profit | Regulation (EC) No 765/2008, Article 4 |
What does ISO 27001 certification cost?
It costs whatever three things add up to, and only one of them has a published price. The standard is a one off purchase measured in hundreds of Swiss francs. The certification body's fee is a commercial quote, driven by audit days and the body's day rate, repeated in every year of the cycle. The largest line in most first projects is neither: it is the internal time to write the risk methodology, run the risk assessment, produce the Statement of Applicability, operate the controls long enough to have records, and hold the internal audit and management review that clauses 9.2 and 9.3 require.
That internal line is also the one you control. A company that already runs access reviews, change control and supplier checks, and can show the records, is buying documentation and an audit. A company that runs none of them is buying an operating model. No quote from a certification body will tell you which one you are; a gap assessment against Annex A will. Our Statement of Applicability template is a reasonable place to start counting.
How does a certification body calculate the audit fee?
By multiplying audit days by a day rate, and the audit days come from a rule, not a negotiation. The European co-operation for Accreditation, answering a question on multisite audits, quotes clause C.6 of ISO/IEC 27006-1:2024: the total audit time for on-site audit "shall be calculated by considering the total number of persons doing work under the organization's control irrespective of their location." Contractors who work under your control count. Staff in another country count. Moving people out of the building does not move them out of the calculation.
There is one structural reduction. Clause C.3.4, quoted in the same series of EA answers, allows that "the square root of the head count of people performing each identical activity may be used". A company with a large team doing the same work, a support floor for instance, can see audit time grow more slowly than headcount. Whether it applies is the certification body's call on the facts, so ask for the calculation behind the quote rather than the total.
The table that turns headcount into days sits inside ISO/IEC 27006-1, which you have to buy, and we found no accreditation body that reproduces it. Treat any day count you read online as a certification body's quote, not as the standard. Also note which document a quote cites. IAF MD 5 is titled "Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems". It says some of its elements may be used for other schemes, but it is not the ISMS rule.
What do you pay for across the three year cycle?
Five audits, not one. ISO/IEC 17021-1:2015 requires the initial certification audit of a management system to be conducted in two stages, stage 1 and stage 2, and the three year certification cycle begins with the certification decision. Surveillance follows at least once a calendar year, except in recertification years, and the first surveillance audit after initial certification must fall no more than 12 months from the certification decision date. EA's answer on clause 9.1.3.3 puts it plainly: in each calendar year there shall be an audit, whether surveillance or recertification.
So a budget that stops at the certificate has priced two audits out of five. Surveillance is not optional. Recertification then starts the cycle again. The internal cost follows the same shape: internal audits, management reviews and corrective actions have to keep producing records every year, or the surveillance auditor has nothing to sample.

Does it matter which country the certification body is in?
Less than the price spread suggests, as long as the body is accredited. In the EU, Regulation (EC) No 765/2008 requires each Member State to appoint a single national accreditation body (Article 4(1)), to entrust it with accreditation as a public authority activity (Article 4(5)), and to have it operate on a not-for-profit basis (Article 4(7)). Article 6 adds that national accreditation bodies shall not compete with conformity assessment bodies. Article 3 applies the chapter to accreditation used on a voluntary basis too, which is where management system certification sits.
Recognition then crosses borders. Signatories of the EA multilateral agreement "recognize and accept the equivalence of the signatories' accreditation systems" and the reliability of the certificates issued under them. The practical consequence for cost: a certificate from an accredited body in one country carries the same accreditation standing as one from a more expensive body elsewhere. What does not carry it is a certificate from an unaccredited body. Check the accreditation mark and the scope of accreditation before comparing quotes, because the cheapest line on the page can be the one your customer will not accept.
What if we still hold an ISO 27001:2013 certificate?
Then you do not hold a valid one. IAF MD 26 set a three year transition to the 2022 edition ending on 31 October 2025, and states that all certifications based on ISO/IEC 27001:2013 "shall expire or be withdrawn at the end of the transition period." The Dutch accreditation body RvA also noted that from 1 May 2024 certification bodies could no longer conduct initial or reassessment audits against the 2013 edition. There is nothing left to transition. Price the work as certification against ISO/IEC 27001:2022, including the Annex A changes, and ask your certification body how it will treat your history.
What the other results get wrong
Page one for this query is almost entirely consultancies and software vendors, most quoting euro ranges by company size. Four points are easy to get wrong. The first is a range with no headcount attached. Because audit time follows persons under your control, a range that does not say how many people it assumes cannot be compared with your quote. The second is a day count presented as if the standard published it. The ISMS table is in ISO/IEC 27006-1, which is sold, not published, and tables borrowed from IAF MD 5 were written for quality, environmental and safety systems.
The third is the missing years. An estimate that prices the initial audit and stops ignores that ISO/IEC 17021-1 requires an audit in every calendar year of the cycle. The fourth is the idea that a company can be "ISO certified". ISO's position is that an organisation cannot be certified by ISO; it is certified by an accredited certification body to an ISO standard, and the accreditation is what gives the certificate standing.
Where does your organisation stand?
Fill this in before you ask for quotes. Two or three blank rows usually mean the internal line, not the audit fee, is the one to plan for.
| Question | Your answer | Why it matters |
|---|---|---|
| How many persons do work under your control inside the ISMS scope, including contractors? | ISO/IEC 27006-1, clause C.6. | |
| How many of them perform identical activities? | Clause C.3.4 may reduce audit time. | |
| What is in scope: which products, sites and legal entities? | ISO/IEC 27001, clause 4.3. Buyers read the scope statement. | |
| Is there a risk assessment and a Statement of Applicability today? | Clauses 6.1.2, 6.1.3 and Annex A. | |
| Have you run an internal audit and a management review? | Clauses 9.2 and 9.3. | |
| Is each certification body you are comparing accredited, and for this scope? | Regulation (EC) No 765/2008 and the EA MLA. | |
| Who owns surveillance in year two and year three? | ISO/IEC 17021-1, clause 9.1.3. |
If most rows are empty, start with a baseline. The free compliance check gives you one, and Venvera's ISO 27001 module holds the risk register, the Statement of Applicability, internal audits and evidence in one place so the surveillance years cost less than the first. If a US customer is also asking for a report, our guide to SOC 2 cost outside the US covers the other half of the budget.

Frequently asked questions
Does ISO charge for ISO 27001 certification?
No. ISO sells the standard but does not certify organisations or issue certificates. The certificate comes from a certification body, ideally one accredited by a national accreditation body.
How much does the ISO 27001 standard itself cost?
The ISO store lists ISO/IEC 27001:2022 at CHF 155 and ISO/IEC 27002:2022 at CHF 227. Amendment 1:2024, which adds climate change to clauses 4.1 and 4.2, is free.
How many audit days will we need?
It depends on the number of persons doing work under your control in scope, under ISO/IEC 27006-1 clause C.6, with a possible square root reduction for identical activities. Ask each certification body to show the calculation.
How often do we pay for an audit?
At least once every calendar year. The initial audit has two stages, surveillance follows each year with the first within 12 months of the certification decision, and recertification renews the three year cycle.
Is a certificate from a cheaper country worth less?
Not if the body is accredited by a signatory of the EA multilateral agreement, whose signatories recognise the equivalence of each other's accreditation. An unaccredited certificate is a different matter.
Primary sources
ISO's position on certification is from iso.org, Certification; prices from the ISO/IEC 27001:2022 store page and Amendment 1:2024. Audit time rules are quoted from ISO/IEC 27006-1:2024 in EA FAQ 48.5 and 48.6; the certification cycle from ISO/IEC 17021-1:2015 and EA FAQ 37.12; the transition from IAF MD 26:2023 and the RvA; the scope of IAF MD 5 from its title and clause 0.5; accreditation from Articles 3, 4, 6 and 11 of Regulation (EC) No 765/2008 and the EA MLA. Prices and accreditation scopes change; confirm them on the day you buy.





