How Much Does ISO 27001 Certification Cost in the UK? An Honest Breakdown

Written by Marius van Aswegen | Sep 13, 2026, 11:05:13 PM

Ask three consultancies what ISO 27001 certification costs and you will get three different answers, usually because each is quietly describing a different scope. This article sets out the real cost components for a UK organisation, the ranges we see in practice, and the decisions that move the number up or down.

The four costs that make up the bill

Every ISO 27001 certification project, however it is packaged, breaks down into the same four components: implementation support, the certification audit itself, internal time, and tooling. Understanding them separately is the single best defence against a quote that looks cheap and is not.

1. Implementation support

This is the consultancy work: gap analysis, risk assessment, building the Information Security Management System (ISMS), drafting proportionate policies, running the internal audit and the management review, and preparing your team for audit day. For a UK SME of roughly 10 to 100 people, sensible implementation support typically lands in the low tens of thousands of pounds, with smaller, simpler organisations at the bottom of that range. Beware of two extremes: the very cheap templated bundle that leaves you with a binder nobody follows, and the open-ended day-rate engagement with no defined outcome.

2. The certification body

The certification audit is carried out by an independent certification body, not by your consultant, and it is a separate line on the bill. Expect a two-stage initial audit in year one, then smaller surveillance audits in years two and three before recertification. Fees scale with headcount and the complexity of your scope. For a typical SME the initial audit usually costs a few thousand pounds, with surveillance audits somewhat less each year. Accreditation matters here: a certificate from an accredited body carries weight with enterprise customers and tender assessors, and one from an unaccredited mill largely does not.

3. Your own time

The cost most often left out of quotes. Someone in your business owns the ISMS, attends the audits, and keeps evidence current, and leadership must show up for management reviews. A well-run project is designed to minimise this burden, but it can never be zero, and a consultancy that promises certification with no involvement from your side is describing a management system that exists only on paper. Auditors can tell.

4. Tooling

You do not need a compliance platform to get certified. Many of our clients run their ISMS from well-structured shared drives and their existing ticketing tools. Platforms earn their keep at scale, or when you are running several frameworks side by side; below that, they are often an annual subscription in search of a problem.

What moves the number

  • Scope: certifying one product line or office rather than the whole business is the biggest lever, and the most commonly misused one. Scope too narrowly and your customers will notice.
  • Existing maturity: if you already hold Cyber Essentials or run decent access control and onboarding processes, you are closer than you think.
  • Cloud estate: a tidy single-cloud SaaS stack is faster to evidence than a sprawl of legacy infrastructure.
  • Deadline pressure: certification driven by a specific enterprise deal or tender date compresses the timeline and usually raises the consultancy component.

How to keep the cost honest

Ask every consultancy the same three questions. What exactly is in scope for the fee? Who pays the certification body, and which body do you recommend and why? And how many days of our own people's time will this take, month by month? Clear answers to those three questions tell you more than any brochure.

Cybercontrols has guided hundreds of organisations to ISO 27001, with a 100 per cent first-time certification success rate, and we hold the certificate ourselves, audited by the same process we prepare our clients for. If you want a number for your organisation rather than a range in an article, a free 30-minute scoping call will give you one, whether or not you engage us.