Why there is no audit-day table here
Accredited certification bodies must determine ISO/IEC 27001 audit time with ISO/IEC 27006-1:2024, Annex C. Its Table C.1 starts from the number of people doing work under the ISMS, and the 2024 edition adds the concept of persons performing identical activities (an "effective" number of personnel) plus adjustment factors for complexity and sites. The standard is copyrighted and sold by ISO and national standards bodies, so reproducing its tables on a free web page would not be legitimate.
The audit-time document that is public, IAF MD 5, covers quality, environmental and occupational health and safety management systems, not information security. We use it only for one thing: the common proportion of about one third of the initial audit time for each surveillance audit and two thirds for recertification, and only when you enter your own audit days. Check those proportions against your quote.
For a reliable number, ask two or three accredited certification bodies for a proposal. You can check accreditation with your national accreditation body: RvA in the Netherlands, Accredia in Italy, BELAC in Belgium, DAkkS in Germany.
The figures used
| Item | Range | Source |
|---|---|---|
| Initial certification audit, 10-100 employees | EUR 6 000-14 000 | Secfix, April 2026 |
| Initial certification audit, 100-500 employees | EUR 15 000-35 000 | Secfix, April 2026 |
| Surveillance audit, years 2 and 3 | EUR 4 000-8 000 each | Secfix, April 2026 |
| Auditor day rate | EUR 1 200-2 000 | heyData, July 2026 |
| Internal effort, first year | 300-600 hours | heyData, July 2026 |
| Consulting support | EUR 3 000-35 000 | heyData, July 2026 |
| Internal audit / penetration test | EUR 3 000-5 000 / 6 000-12 000 per year | Secfix, April 2026 |
| Time to certification | < 50 people: 4-6 months; 50-150: 6-9; 150+: 9-12+ | Copla, 2026 |
These are published by compliance vendors, not by certification bodies or regulators, and they vary with scope, sites, complexity and travel. Treat the result as a planning range. Outside the published size bands (fewer than 10 or more than 500 people) the tool shows only a bound and says so.
The certification cycle
- Build the ISMS: scope, risk assessment, Statement of Applicability against the 93 Annex A controls of ISO/IEC 27001:2022, policies, and the controls themselves.
- Run it: operate the controls, then complete an internal audit (clause 9.2) and a management review (clause 9.3). Certification bodies expect both before Stage 2.
- Stage 1: the auditor reviews your documentation and readiness.
- Stage 2: the certification audit itself, testing that the controls work. Nonconformities must be corrected before the certification decision.
- Certificate: valid for three years, with surveillance audits in years 2 and 3 (the first within 12 months of the certification decision) and a recertification audit before expiry.
Certificates against the 2013 edition are no longer valid: the transition to ISO/IEC 27001:2022 ended on 31 October 2025.
An estimate based on public ranges, not a quote or advice. Certification body proposals are the only binding figures.