For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/compliance/what-iso-27001-costs-and-what-drives-the-price.md.
Compliance ↗

What ISO 27001 costs, and what drives the price

The price of ISO 27001 is the sum of consultant hours, tooling, a GRC system, your own people's time and the audit fee. Here is what moves each one.

There is no single number for what ISO 27001 costs. The total is five separate costs, and each of them moves with choices you have not made yet. What you can get before the first vendor meeting is the list of components and what makes each one grow or shrink.

I scope certification projects at FM CyberSecurity, and the budget conversation opens the same way every time. The leader asks for one number, and the useful answer is a breakdown. Here is that breakdown, and at the end, the six questions I would put to any vendor before signing, including us.

If the standard itself is new to you, start with what ISO 27001 is, and why you lose tenders without it. This article assumes the decision is made and the budget is next.

The five costs behind the certificate

An ISO 27001 budget is the sum of five components: external consultant hours, security tooling, a GRC system, your own people’s time, and the certification body’s audit fee. The first four build and run your management system. The fifth pays for the audit itself, and it is billed by the accredited certification body, not by your consultant.

This is why two quotes can look far apart and still describe the same work. They cover different slices of the five. A total without a component list tells you very little, so ask for the list first and compare after.

What makes each cost grow or shrink

Scope weighs heaviest: the more companies, locations and systems the certificate has to cover, the more all five components cost. Within a given scope, each component has its own logic.

Consultant hours follow two things: how much is documented already, and whether the consultant does the work or coaches your people through it. In the projects I scope, much of the underlying work already happens: access control, backups, incident handling. The gap is proof, not practice, and closing a proof gap takes fewer hours than building routines from zero.

Tooling depends on what you already run. The Annex A controls need something real behind them, like endpoint protection and central logging. If that is in place, this line stays small. If not, the certification budget has to cover the purchases too.

The GRC system is where policies, risks and audit evidence live. It is licensed per year, priced on users and modules, and the license does not stop when the certificate arrives.

Your own people’s time is the cost I most often see missing from the budget. Someone in your organization has to answer the risk questions, make the decisions and sit in the audit, and no consultant can do that for you. Slow answers drag out the run, and a run that drags out costs more than any hourly rate.

The audit fee is its own bill

The certification audit is performed by an accredited certification body, and that body sends its own invoice. The fee follows the size and scope of what you certify, because the rules for accredited bodies (ISO/IEC 27006) tie audit time to the number of people and sites the system covers.

The fee also recurs. The certificate is valid for three years, with a surveillance audit each year and a recertification audit in year three. So when you compare offers, ask whether this fee sits inside the quoted price or comes on top. Both models are workable. What breaks budgets is not knowing which one you are looking at.

One monthly price instead of a project budget

Secured by FM CyberSecurity packages the whole run as one fixed monthly subscription for small and medium-sized businesses: the tools, the operations, a vCISO and the certification work, gathered in one contract. Our own SOC monitors and responds around the clock, and we collect the evidence for the auditor in the GRC tool as we go.

A typical run is certification-ready in four to six weeks, and the pace follows how quickly you answer our questions. The audit itself is still performed by an accredited certification body. If it does not go through within the agreed window, we cover the next attempt. Gross negligence on the customer side voids the guarantee.

We do not publish a price for the subscription, because a serious number depends on your scope. Send us a message, and we price it for your organization as one monthly figure that goes straight into next year’s budget. If you would rather run certification as a standalone project with your own team, that route is ISO 27001 as a dedicated project.

Six questions to ask before you sign

Whoever you talk to, including us, the same six questions show what an offer covers:

  1. Which of the five cost components does your price include, and which come on top?
  2. Is the certification body’s audit fee inside the price, or billed separately by that body?
  3. How many hours do you need from our people each week, and from which roles?
  4. Who owns the GRC license and the documentation if we part ways?
  5. What does year two look like, with the surveillance audit and license renewals?
  6. If the offer includes a guarantee, what exactly does it cover and what voids it?

A vendor with a tidy offer answers all six in the first meeting. If the answers need a follow-up call, the price is not final yet.

Next step

The operational route is laid out in our ISO 27001 checklist for Norwegian SMBs. How the subscription model works, and the thinking behind it, is in ISO 27001 as a subscription. Or go straight to Secured by FM CyberSecurity and send us a message. We price it for your organization, and you get one number to take to the board.

Drafted with AI assistance, reviewed and edited by Johan Vorgaard and the FM CyberSecurity editorial team.

FAQ

What does ISO 27001 certification cost?

No single figure covers everyone, because the total is the sum of five components: consultant hours, security tooling, a GRC system, your own people’s time, and the certification body’s audit fee. Scope sets the level, and the components a quote includes decide how it compares. Ask for the breakdown before you compare totals.

Is the audit fee included in a consultant’s price?

The audit fee belongs to the accredited certification body that performs the audit. Some offers take it into the total, others leave it outside as the body’s separate invoice. Both work, but you need to know which one you are signing, so ask directly.

What does ISO 27001 cost per year after certification?

The costs continue after the certificate. The certificate is valid for three years with a surveillance audit each year, and the GRC license and the time to keep the management system alive run on. Budget ISO 27001 as an annual cost, not as a one-time project.

How fast can we be ready for the audit?

With Secured by FM CyberSecurity, a typical run is certification-ready in four to six weeks. The pace follows how quickly you answer our questions, because your decisions set the calendar, not our documents.

What does Secured by FM CyberSecurity cost?

We do not publish a price. The subscription is one fixed monthly amount covering the tools, the operations, a vCISO and the certification work, and the level depends on your scope. Send us a message, and we price it for your organization.

← Back to all insights
Questions or inquiry? [email protected] Contact us →