ISO 27001 certification cost & timeline estimator

What will ISO/IEC 27001 certification cost over the three-year cycle, and how long until you have the certificate? Enter your headcount, or the audit days from a certification body quote, and get an estimate in which every figure links to its public source.

Estimate, not a quote. Sources checked 1 October 2026
1. Your organisation
Employees and contractors doing work under the scope, including part-timers.
Stage 1 plus Stage 2, from a certification body proposal. Overrides the size-based range.
Leave empty to use the published EUR 1 200 to 2 000 range. Used only with audit days.
To cost the 300 to 600 internal hours that implementation typically takes.
2. Optional items

Your result appears here as you fill in the form.

The basis of this tool. Certification bodies calculate audit time with the tables in Annex C of ISO/IEC 27006-1:2024. That standard is copyrighted, so we do not reproduce or approximate its tables. The estimate uses published market ranges (Secfix, heyData, Copla) and, if you have one, the number of audit days in your quote. Details below.

Why there is no audit-day table here

Accredited certification bodies must determine ISO/IEC 27001 audit time with ISO/IEC 27006-1:2024, Annex C. Its Table C.1 starts from the number of people doing work under the ISMS, and the 2024 edition adds the concept of persons performing identical activities (an "effective" number of personnel) plus adjustment factors for complexity and sites. The standard is copyrighted and sold by ISO and national standards bodies, so reproducing its tables on a free web page would not be legitimate.

The audit-time document that is public, IAF MD 5, covers quality, environmental and occupational health and safety management systems, not information security. We use it only for one thing: the common proportion of about one third of the initial audit time for each surveillance audit and two thirds for recertification, and only when you enter your own audit days. Check those proportions against your quote.

For a reliable number, ask two or three accredited certification bodies for a proposal. You can check accreditation with your national accreditation body: RvA in the Netherlands, Accredia in Italy, BELAC in Belgium, DAkkS in Germany.

The figures used

ItemRangeSource
Initial certification audit, 10-100 employeesEUR 6 000-14 000Secfix, April 2026
Initial certification audit, 100-500 employeesEUR 15 000-35 000Secfix, April 2026
Surveillance audit, years 2 and 3EUR 4 000-8 000 eachSecfix, April 2026
Auditor day rateEUR 1 200-2 000heyData, July 2026
Internal effort, first year300-600 hoursheyData, July 2026
Consulting supportEUR 3 000-35 000heyData, July 2026
Internal audit / penetration testEUR 3 000-5 000 / 6 000-12 000 per yearSecfix, April 2026
Time to certification< 50 people: 4-6 months; 50-150: 6-9; 150+: 9-12+Copla, 2026

These are published by compliance vendors, not by certification bodies or regulators, and they vary with scope, sites, complexity and travel. Treat the result as a planning range. Outside the published size bands (fewer than 10 or more than 500 people) the tool shows only a bound and says so.

The certification cycle

  1. Build the ISMS: scope, risk assessment, Statement of Applicability against the 93 Annex A controls of ISO/IEC 27001:2022, policies, and the controls themselves.
  2. Run it: operate the controls, then complete an internal audit (clause 9.2) and a management review (clause 9.3). Certification bodies expect both before Stage 2.
  3. Stage 1: the auditor reviews your documentation and readiness.
  4. Stage 2: the certification audit itself, testing that the controls work. Nonconformities must be corrected before the certification decision.
  5. Certificate: valid for three years, with surveillance audits in years 2 and 3 (the first within 12 months of the certification decision) and a recertification audit before expiry.

Certificates against the 2013 edition are no longer valid: the transition to ISO/IEC 27001:2022 ended on 31 October 2025.

An estimate based on public ranges, not a quote or advice. Certification body proposals are the only binding figures.

Questions

Why doesn't this tool calculate audit days from ISO/IEC 27006?

The audit-time tables certification bodies must use are in Annex C of ISO/IEC 27006-1:2024, a copyrighted standard sold by ISO and national standards bodies. IAF MD 5, the public audit-time document, covers quality, environmental and health and safety systems, not information security. We therefore use published price ranges and let you enter the audit days from your own quote.

How long does ISO 27001 certification take?

Published guidance puts it at about 4 to 6 months for organisations under 50 people, 6 to 9 months for 50 to 150, and 9 to 12 months or more above that. The ISMS needs to run long enough to show an internal audit and a management review before the Stage 2 audit.

What happens after the certificate is issued?

The certificate runs for three years. The certification body performs a surveillance audit in each of the following two years, the first within 12 months of the certification decision, and a recertification audit before the certificate expires.