Pricing · Fixed-price packages
One fixed price. No day-rate surprises.

We price every engagement as a fixed package, agreed after a short scoping call, so you know the full cost before we start. These are the starting prices for our ISO 42001 packages. Your fixed price depends on the size of your organisation, the AI systems in scope and the complexity of your operations.

ISO/IEC 27001:2022Certified · SANCERT ISO/IEC 42001:2023Certified · SANCERT Cyber EssentialsCertified Government Commercial AgencyApproved Supplier · G-Cloud 15
ISO 42001 packages

AI governance, certified, at a price you know up front.

Every package is delivered by senior lead auditors who hold ISO 42001 certification themselves. All prices exclude VAT and certification body fees.

ISO 42001 for ISO 27001 holders

From £10,200

Fixed price, typically £10,200 to £12,000

For organisations that already run a certified ISMS. We extend your existing management system to cover AI governance, rather than building a second one.

  • Gap analysis against ISO 42001
  • AI system inventory and AI policy
  • AI risk and impact assessments
  • Annex A controls and Statement of Applicability
  • Integration with your ISO 27001 system
  • Support through Stage 1 and Stage 2

ISO 42001 complete

From £12,750

Fixed price, typically £12,750 to £15,000

For organisations starting from scratch. We build the full AI management system, from context and leadership through to Annex A controls and certification readiness.

  • Scoping and gap analysis
  • Context, leadership and AI policy
  • AI system inventory, risk and impact assessments
  • Annex A controls and Statement of Applicability
  • Training for your AIMS owners
  • Support through Stage 1 and Stage 2

ISO 42001 internal audit

From £3,400

Fixed price, typically £3,400 to £4,000

An independent internal audit to clause 9.2, carried out by lead auditors who know what the certification body will test.

  • Risk-based audit plan
  • Interviews, sampling and evidence review
  • Graded findings and management summary
  • Corrective action follow-up
  • Available remote or on-site
  • Combine with ISO 27001 for one integrated audit
Why Cybercontrols

We hold the certificate we implement.

ISO 42001Certified by SANCERT
ISO 27001Certified by SANCERT
100%Certification success for ISO 27001 and ISO 42001 clients
G-Cloud 15UK Government approved supplier
How pricing works

From conversation to fixed price.

Scope

A short call to understand your organisation, your AI systems and your target date.

Quote

A written fixed price with defined deliverables, so there are no open-ended day rates.

Deliver

Senior lead auditors build the system with your team, to the agreed plan.

Certify

We prepare you for Stage 1 and Stage 2 and stay alongside you through both.

Questions

Pricing, answered plainly.

Why do you price as a fixed package rather than a day rate?

Because you should know the full cost before you commit. We agree the scope in a short call, confirm a fixed price in writing, and carry the risk if the work takes longer than planned.

What affects the final price?

The size of your organisation, the number and type of AI systems in scope, whether you already run ISO 27001, and how complex your operations and supply chain are. Your fixed quote reflects all of these.

Are certification body fees included?

No. Your certification body quotes its Stage 1 and Stage 2 audit fees directly. We help you choose an accredited certification body and prepare you for both stages.

How long does an ISO 42001 project take?

We agree the timeline at scoping, built around your team's availability and your target certification date. Our ISO 42001 cost and timeline guide explains the typical phases.

Do you offer fixed prices for other standards?

Yes. ISO 27001, ISO 27701, ISO 9001, SOC 2 and internal audits are all priced the same way. Email hello@cybercontrols.io for a fixed quote.

Get your fixed quote.

Email hello@cybercontrols.io or book a short scoping call, and we will confirm a fixed price in writing.