
ISO 27001 Cost Guide for Small Businesses
ISO 27001 Certification Cost for Small Businesses
What You Actually Need to Budget
For a small business, ISO 27001 certification is rarely a single audit fee. You are paying for two different things: building an information security management system that can survive scrutiny, and paying an independent certification body to audit it. Confusing those two numbers is how a tidy-looking quote turns into a rather untidy budget.
As a practical 2026 planning range, a small company with a focused scope and reasonably mature controls may need roughly US$10,000 to US$35,000 in first-year external spending. A greenfield, consultant-heavy, multi-site, highly regulated, or technically complicated project can move materially above that range. Internal staff time can be just as important as the invoices.
This guide separates certification fees from implementation, remediation, tools, internal labour, surveillance audits and the smaller charges that have a habit of wandering into the budget after everyone has already congratulated themselves on finding a cheap auditor.
The useful number is not “How much is the certificate?” It is “What will this ISMS cost us to build, certify and maintain for three years?” 🔐
Snapshot
Best for: founders, security leads, IT managers and compliance owners at small US and UK businesses preparing for their first ISO/IEC 27001 certification. You will be able to: estimate a realistic budget, identify the variables that change an auditor’s quote, decide how much outside help is justified and compare certification proposals without paying for unnecessary scope.
Table of Contents
Before You Act
This is a budgeting and procurement guide, not a certification guarantee or individualized legal or regulatory opinion. Your scope, customer contracts, jurisdictions, systems, accreditation requirements and existing security maturity can materially change the answer. Confirm the final scope and audit assumptions with appropriately accredited certification bodies before committing budget.

How much does ISO 27001 certification cost for a small business?
A sensible starting assumption for a small, reasonably prepared organization is roughly US$10,000 to US$35,000 of first-year external spending for implementation support, certification and related readiness costs. This is a planning range, not an official ISO price schedule.
A company that already has mature security controls, competent internal staff, good evidence and a carefully bounded certification scope may spend less. A business starting almost from zero, relying heavily on consultants, including several locations or discovering major technical weaknesses can spend US$35,000 to US$75,000 or more.
The certification audit itself is only one slice of that total. Published UK planning data provides a useful illustration: using an assumed £1,250 auditor day rate, initial Stage 1 and Stage 2 certification auditing was estimated at approximately £6,250 for a one-person organization, £7,500 at 11 employees, £11,250 at 26 employees and £12,500 at 46 employees. Actual certification bodies calculate their own audit time and fees, so these are reference figures rather than guaranteed prices.
| Example organization size | Published audit-day example | Illustrative UK audit cost | What is not included |
|---|---|---|---|
| 1 employee | 5 days | £6,250 | Implementation, remediation, internal labour |
| 11 employees | 6 days | £7,500 | Implementation, remediation, internal labour |
| 26 employees | 9 days | £11,250 | Implementation, remediation, internal labour |
| 46 employees | 10 days | £12,500 | Implementation, remediation, internal labour |
The table is most useful for one lesson: employee count influences audit effort, but your audit invoice is not your total ISO 27001 project cost.
Key cost rule: Budget twice. First calculate the cash you will pay vendors and the certification body. Then calculate internal labour and remediation separately. The second number is often where the surprise lives.
The current standard matters when you request quotes
The current base standard is ISO/IEC 27001:2022. ISO also published Amendment 1:2024 concerning climate-action changes to management-system context requirements. The previous ISO/IEC 27001:2013 edition is withdrawn.
When requesting certification proposals in 2026, specify ISO/IEC 27001:2022 and ask the certification body to confirm the applicable current certification requirements. You can review the official ISO/IEC 27001 standard page before buying documentation or training that may have an old edition number printed across the cover.

What are you actually paying for?
The cleanest way to budget is to stop treating “ISO 27001 cost” as one category. It is a stack of costs that arrive at different points.
1. The standard and supporting material
You need access to the requirements you are implementing. At the August 2026 review date, ISO’s own store listed ISO/IEC 27001:2022 at CHF 155. Prices through national standards bodies or packages can differ.
This is usually one of the smallest project expenses. Saving a few dollars here while assigning six weeks of staff time to unnecessary paperwork is excellent optimization if your aim is to optimize the wrong number.
2. Gap analysis and ISMS implementation
You must determine where your existing processes differ from the standard’s requirements, define the ISMS scope, establish responsibilities, perform information-security risk assessment and treatment, select controls, maintain a Statement of Applicability and operate the management system.
A mature SaaS company may already have useful pieces: MFA, logging, vulnerability management, backups, vendor reviews, onboarding and offboarding, incident procedures and security policies. A smaller business may own plenty of technology but have almost no repeatable governance around it. The second company usually has more expensive work ahead.
3. Remediation
Remediation is where a compliance project can turn into a security program. You may discover that a policy is missing, which is cheap to fix. You may instead discover unmanaged administrator accounts, weak backup testing, missing endpoint controls or supplier risks that need technical and operational changes.
Do not treat every Annex A control as a mandatory shopping list. ISO 27001 is risk-based. Your control decisions should follow your risks, obligations and scope, with inclusions and exclusions justified through the Statement of Applicability.
4. Internal audit, Stage 1 and Stage 2
Your ISMS needs internal evaluation before external certification. The external certification process then normally includes a Stage 1 audit focused on readiness and the documented management system, followed by Stage 2, where the auditor evaluates whether the ISMS has actually been implemented and is effective within its certified scope.
ISO itself does not issue your certificate. Certification is performed by external certification bodies.
The ISO 27001 budget equation
Stage 1 + Stage 2
Risk, policies, evidence
Security gaps and fixes
Only where useful
Surveillance + recertification
Add internal staff time and contingency to see the real economic cost.
What changes the price most?
The answer changes when: the certification scope gets broader, more people and sites become relevant, the technology environment becomes harder to audit, evidence is weak, remediation is substantial or your certification deadline leaves little room for efficient internal work.
| Cost driver | Lower-cost situation | Higher-cost situation |
|---|---|---|
| ISMS scope | One service or clearly bounded business operation | Whole company, many products or mixed business units |
| Personnel | Small team with simple roles | Large effective workforce, shifts, contractors or complex responsibilities |
| Locations | One operating location or simple remote model | Multiple sites with different activities |
| Technology | Centralized SaaS/cloud environment | Hybrid infrastructure, legacy systems, data centres or many platforms |
| Security maturity | Controls and evidence already operating | Policies, ownership and controls being built from scratch |
| Customer/regulatory obligations | Limited contractual complexity | Highly regulated data or extensive customer commitments |
| Existing assurance work | Reusable governance and evidence | No established compliance program |
Scope is the budget lever founders often underestimate
A 15-person startup does not automatically need every laptop, side project, office process and experimental environment inside its first certification scope. The scope needs to be legitimate and defensible, but it can often be centered on the service, systems, people and supporting processes relevant to the customer assurance requirement.
Artificially shrinking the scope until the certificate becomes commercially useless is not clever either. Ask the question from the customer’s side: Will this certified scope actually cover the product, service and information they care about?
Scope rule: Remove irrelevant complexity, not relevant risk. A cheaper certificate that excludes the service your enterprise buyer is reviewing can become very expensive decorative paper.
Where the cost comes from
What Changes the Quote
Certification bodies price the engagement largely around required audit effort. Expect them to ask about the scope, people performing in-scope activities, sites, technical complexity and business activities.
This is why two companies with 25 employees can receive very different proposals. One might operate one cloud service with centralized controls. The other may have three locations, contractors, customer-hosted systems, sensitive data and bespoke operational processes. The employee count is identical. The audit problem is not.
Three realistic small-business budget scenarios
Scenario A: 12-person cloud SaaS startup
Imagine a 12-person B2B SaaS business pursuing ISO 27001 because enterprise prospects keep asking for it. The company already uses centralized identity, MFA, managed endpoints, cloud logging, backups, code review and basic security policies.
Its cheapest sensible route may be an internally led implementation with templates or lightweight compliance tooling, a targeted external gap review or internal audit if needed, and an accredited certification body. A US$10,000 to US$25,000 first-year external budget may be a reasonable planning envelope if significant remediation does not emerge.
Scenario B: 35-person professional-services firm
Now consider a 35-person firm storing sensitive client information across Microsoft 365, several SaaS platforms and employee laptops. Its technical controls are decent, but vendor management, risk ownership, information classification, internal auditing and policy evidence are inconsistent.
The certification audit itself may still be manageable, but the business may need more implementation support and staff time. A planning range around US$20,000 to US$40,000 becomes easier to justify because the expensive problem is creating a repeatable management system, not merely scheduling the external auditor.
Scenario C: 60-person regulated or multi-site company
A 60-person business with multiple locations, regulated customer data, legacy systems and numerous third parties presents a different audit problem. Broader scope can mean more audit time, more interviews, more evidence and more remediation.
A US$35,000 to US$75,000-plus program may be possible once consulting, technical remediation, training, internal audit assistance and certification are considered. The upper number is not a badge of seriousness. It simply reflects more work.
None of these scenarios is a quote. Their purpose is to prevent the classic budgeting error of applying a five-person cloud startup’s audit price to a company with completely different operational complexity.
Hidden costs and the three-year certification cycle
A low initial quote can be perfectly legitimate. It can also be incomplete.
Certification normally operates on a three-year cycle. After successful Stage 1 and Stage 2 audits and a positive certification decision, surveillance audits are normally performed during the certification cycle, with recertification at the end of the three years.
Ask for three-year total cost, not the launch price
| Cost | When it appears | Question to ask |
|---|---|---|
| Stage 1 audit | Initial certification | Is this included in the headline quote? |
| Stage 2 audit | Initial certification | How many audit days are assumed? |
| Travel or expenses | Initial and ongoing audits | Are these fixed, capped or billed separately? |
| Surveillance audit 1 | Following certification | What is the projected fee? |
| Surveillance audit 2 | Following certification | What is the projected fee? |
| Recertification | End of cycle | What assumptions drive the expected cost? |
| Scope change | When business changes | How are acquisitions, sites or services priced? |
| Follow-up work | If findings require additional auditor time | What charges can apply? |
| Annual platform fees | If software is used | What is the three-year subscription cost? |
Internal labour is a cost even when nobody sends an invoice
If your compliance lead spends eight hours per week for 16 weeks, that is already 128 hours. Add engineering reviews, HR evidence, vendor work, management meetings, internal audit preparation and remediation, and the economic cost can be substantially higher than the vendor budget.
A simple internal-cost formula is:
(Project lead hours + control-owner hours + management hours + audit preparation hours) × loaded hourly employment cost = internal project cost.
You do not need perfect accounting. Even a rough estimate makes a build-versus-buy discussion much more intelligent.
DIY, software or consultant: which route makes financial sense?
| Approach | Best fit | What you are buying | Main risk |
|---|---|---|---|
| DIY-led | Small, simple company with capable security/compliance staff | Mostly certification, training and perhaps templates | Internal time, interpretation errors and rework |
| Software-assisted | Cloud/SaaS team with many repeatable evidence tasks | Evidence collection, workflow, ownership and control mapping | Paying for automation that does not solve actual security gaps |
| Consultant-assisted | Limited internal expertise, complex scope or hard deadline | Implementation expertise, project structure and targeted remediation guidance | High spend or dependency if knowledge stays outside the company |
| Hybrid | Most capable small businesses | Internal ownership plus help on difficult or independent activities | Poor division of responsibility if roles are unclear |
Do it free or mostly DIY when…
- You have an internal owner who can understand management-system requirements.
- Your ISMS scope is small and technically straightforward.
- Existing controls and records are already mature.
- Your team can perform risk assessment, documentation and evidence management without derailing normal work.
- You can arrange a suitably independent internal audit.
Pay for software when…
- Evidence is spread across many cloud systems and manual collection is repetitive.
- Several employees own controls and need workflow reminders.
- You expect to maintain multiple security frameworks or customer assurance requirements.
- Continuous evidence visibility will remain useful after certification.
A compliance platform does not replace risk judgment, technical remediation, management accountability or an accredited certification audit. It can reduce administrative friction. Those are different jobs.
Pay for professional implementation help when…
- No one internally has enough ISO 27001 knowledge to own the project confidently.
- You have a contractual certification deadline.
- The scope crosses several business functions or locations.
- Risk assessment or Statement of Applicability work is stalling.
- You need an independent internal audit and cannot provide suitable independence internally.
- Failed readiness work would delay a strategically important sale or procurement process.
Important separation: implementation support and certification are different functions. Your certification body’s independence matters. Do not choose a provider merely because someone promises to “do everything and guarantee the certificate.”
How to compare ISO 27001 certification quotes
Do not ask three certification bodies, “How much for ISO 27001?” and compare the three numbers. Send all of them the same scope brief first.
Your quote-preparation brief
- Legal entity or entities to be certified.
- Proposed ISMS scope statement.
- Products or services included.
- Number of people performing in-scope activities.
- Locations and remote-working model.
- Main cloud, infrastructure and business environments.
- Types of sensitive information handled.
- Relevant regulatory or contractual requirements.
- Existing certifications or management systems.
- Desired certification date and the business reason for it.
Then ask each certification body these questions
- Are you accredited to certify organizations to ISO/IEC 27001:2022?
- What exact entity, products, services and locations are assumed in the quote?
- How many auditor days are allocated to Stage 1 and Stage 2?
- Which factors caused an increase or reduction in audit time?
- Which work is remote and which requires on-site attendance?
- Are travel, application, administration or certificate fees additional?
- What are the estimated surveillance costs for the following two years?
- How will recertification be priced?
- Can extra fees arise when nonconformities require additional auditor work?
- What happens to pricing if our scope, employee count or locations change?
- What is the cancellation or rescheduling policy?
- How can customers independently verify the certificate after issue?
Quote red flags
- A suspiciously low price with no defined certification scope.
- No explanation of accreditation.
- Language suggesting your company will be “certified by ISO.” ISO does not perform certification.
- A proposal centered on the withdrawn 2013 edition rather than ISO/IEC 27001:2022.
- No visibility into surveillance or recertification charges.
- A certification promise before anyone understands your ISMS.
- Pressure to buy a large package of technical products before risks and control needs have been established.
The cheapest credible proposal can absolutely be the right proposal. The goal is not to buy the fanciest auditor. It is to make sure each number represents the same job.
What must be ready before the certification audit?
The fastest way to waste audit money is to book certification before the management system has enough evidence behind it.
A practical readiness sequence
- Define the ISMS scope. Identify boundaries, interfaces, people, information, systems and locations.
- Establish ownership. Assign leadership responsibility and operational control owners.
- Understand interested parties and obligations. Include relevant customer, contractual, legal and regulatory expectations.
- Perform information-security risk assessment. Use a repeatable methodology.
- Create the risk treatment plan and Statement of Applicability.
- Implement required controls. Technical, organizational, people and physical controls should operate rather than merely exist on paper.
- Collect evidence. Records should demonstrate that processes are actually being followed.
- Measure and review the ISMS. Track relevant performance and security information.
- Conduct internal audit activity. Identify nonconformities and weaknesses before the certification body does.
- Complete management review and corrective action.
- Proceed through Stage 1. Use any resulting findings to strengthen readiness.
- Proceed to Stage 2 when the ISMS can be demonstrated in operation.
For many small businesses, this process is measured in months rather than days. A mature business can move faster because the job is largely organizing and evidencing controls that already exist. A greenfield ISMS takes longer because operating evidence has to be created naturally through real processes.
Readiness test: if most answers to an auditor’s questions begin with “we are planning to,” you are probably still implementing. Stage 2 needs evidence of what the organization actually does.
How to reduce ISO 27001 cost without creating false economy
1. Freeze the first certification scope before buying tools
Tool purchasing before scope definition is backwards. First decide what is being certified. Then identify risks and gaps. Then spend where the gap genuinely demands it.
2. Reuse working security evidence
If you already maintain access reviews, incident tickets, vendor assessments, vulnerability records, change approvals or backup-test evidence, do not recreate everything in an “ISO folder” simply to make it look ceremonial.
A strong ISMS should fit the way the company actually works. Duplicate compliance-only processes generate maintenance cost long after the consultant has gone home.
3. Spend expert money on hard judgment, not typing
Templates can help with structure. Software can help with repetitive evidence. Internal staff can usually provide business context. External specialists are most valuable where interpretation, risk methodology, independence, difficult scoping or audit readiness is genuinely slowing the project.
4. Fix major security gaps before the certification clock starts
If you know privileged access is poorly controlled, supplier governance is missing or backups are not tested, address the underlying issue. Writing a polished policy around a broken process merely gives the broken process nicer stationery.
Check what certification actually means
ISO explains that ISO itself does not certify organizations. Understanding that distinction makes it easier to evaluate accreditation claims, logos and sales language.
Read ISO’s certification guidance
FAQ
Can a five-person company get ISO 27001 certified?
Yes. ISO/IEC 27001 is designed for organizations of different sizes and sectors. A very small organization can have a small ISMS, but it still needs to satisfy the applicable requirements within its defined scope and demonstrate that the management system is operating.
Is the ISO 27001 certification audit the same as a penetration test?
No. ISO 27001 certification evaluates the information security management system against the standard. Technical security testing may form part of your broader security and risk-treatment program, but an ISO 27001 certification audit is not a substitute for penetration testing, vulnerability management or other technical assurance activities.
Can we certify only one product or service?
The certificate applies to an organization’s ISMS within a defined scope rather than turning a standalone software product into an “ISO-certified product.” A scope can center on the people, systems and processes supporting a particular service, provided the boundaries and dependencies are legitimate and accurately represented.
Do we need all 93 Annex A controls?
Not automatically. ISO/IEC 27001:2022 uses a risk-based approach. Your organization determines necessary controls through risk treatment and other requirements, compares them with Annex A and records applicability and justification in the Statement of Applicability.
Will a compliance automation platform reduce the certification audit fee?
Not necessarily. Software can reduce evidence-collection and workflow effort, but a certification body’s required audit effort is determined by the certification scope and applicable audit requirements. Better organization can improve readiness without automatically reducing the prescribed audit time.
Should we choose a UKAS- or ANAB-accredited certification body?
US businesses commonly encounter ANAB-accredited certification bodies, while UK buyers commonly look for UKAS accreditation. The important procurement question is whether the certification body’s accreditation is appropriate for ISO/IEC 27001 and acceptable to the customers, regulators or contracting parties that care about your certificate.
What if an enterprise customer needs certification urgently?
Start by confirming the customer’s exact requirement and deadline. Ask whether accredited ISO/IEC 27001 certification is mandatory before contract signature, required by a later milestone or simply preferred. That distinction can change both project urgency and how much outside implementation support is financially rational.
Your 15-minute ISO 27001 budget check
Before requesting prices, spend 15 minutes creating a one-page certification scope brief. Do not begin with vendor demos or a giant control spreadsheet.
Write down these five items:
- What needs to be certified: the product, service or business operation creating the customer requirement.
- Who is involved: approximate number of employees, contractors and control owners performing in-scope work.
- Where it operates: offices, remote workforce, cloud environments and other relevant sites.
- What already exists: risk management, policies, access controls, logging, backups, vendor reviews, training, incident management and previous assurance work.
- Why and when: the customer, tender, board objective or contractual deadline driving certification.
That single page gives you enough information to begin meaningful conversations with accredited certification bodies and to decide whether your first purchase should be software, implementation help, an internal audit service or simply the certification engagement itself.
The central budgeting principle is pleasantly unglamorous: scope first, gaps second, buying third. Once those three are in the correct order, ISO 27001 becomes far easier to cost without either starving the project or feeding it money simply because the word “certification” appeared in a sales proposal.
Last reviewed: 2026-09
- CMMC Compliance Cost: What Small Businesses Should Budget
- SOC 2 Compliance Checklist for Startups
- Security Tool Stack Cost Calculator for Small Businesses
- Vendor Security Questionnaire: What Businesses Need to Prepare
- SOC 2 Budget Calculator: Estimate Compliance Costs