Hael
Book a meeting
ISO 27001 · Cost

The budget-friendly ways to get ISO 27001 certified

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Scope is the biggest lever. It drives audit days, which drives the certification fee, and internal hours, which is the larger cost.
  • Exclude controls your risk assessment does not justify. Implementing all 93 by default is expensive and unnecessary.
  • Where you hold SOC 2, build one control set rather than a parallel ISO programme.
  • Get quotes from three accredited bodies and ask each for proposed audit days, not just a fee.
  • Do not economise on the risk assessment, the internal audit, or accreditation.

Where the money goes

The cheapest route to ISO 27001 is a correctly scoped ISMS with a control set your risk assessment actually justifies, prepared well enough that the audit is short. Most overspend comes from scoping too broadly, implementing all 93 controls by default, or arriving underprepared and paying for a longer audit and a return visit.

A realistic first-year total for a small to mid-sized organisation is £20,000 to £70,000 including implementation and certification. The decisions below move you towards the lower end.

LineTypical costAvoidable?
Gap analysis£5,000 to £15,000No, and skipping it usually costs more
Implementation£15,000 to £50,000Partly, through scope and control selection
Certification body, initial cycle£5,000 to £20,000Partly, through scope, preparation and quotes
Internal audit£4,000 to £12,000Partly, by combining with other frameworks
Penetration testing£4,000 to £20,000Rarely, buyers expect it
Internal team timeFrequently the largest costPartly, through project management
Surveillance, years two and three20% to 40% of the initial audit feeNo

1. Scope to what your buyers ask about

Scope drives audit days, which drives the certification fee, and it drives internal hours, which is the larger cost.

Start from the question you are being asked. If a customer wants assurance about one service, an ISMS scoped to that service and the teams supporting it answers them. Certifying the whole organisation because it sounds stronger buys audit days nobody requested.

The counterweight: a scope so narrow that the certificate's scope statement does not name the service your buyer cares about is the most expensive outcome, because you pay twice.

2. Exclude controls your risk assessment does not justify

Annex A is a list of possible controls, not a checklist. You select what applies based on risk, and record justified exclusions in the Statement of Applicability.

Organisations that implement all 93 by default spend money on controls they do not need and create maintenance obligations that recur every year. An organisation with no physical premises, no development function or no operational technology will legitimately exclude several.

The saving requires a real risk assessment first. Excluding controls without one is a nonconformity rather than an economy.

3. Build one control set if you hold SOC 2

The control substance overlaps heavily. What ISO 27001 adds is the management system layer: scope, risk method, risk treatment plan, Statement of Applicability, internal audit programme and management review.

Building on your existing SOC 2 control set and evidence base is materially cheaper than running a parallel ISO programme, and it prevents the two sets diverging, which is a cost that arrives later. See our SOC 2 service page.

The same applies in reverse, and to ISO/IEC 42001, where Annex D supports integrating the management systems.

4. Get three quotes and ask about audit days

Certification body fees follow audit days, calculated from your scope, headcount within scope and number of sites. Ask each body for its fee, its accreditation body and scope entry, and the number of audit days proposed.

Do not choose on price alone. An auditor with real competence in your sector makes for a better audit, and a body with no availability for five months costs you more than a higher fee would.

5. Prepare so the audit is short

Stage 1 exists to find things that would prevent a successful Stage 2. Arriving with an incomplete Statement of Applicability, no internal audit and no management review turns Stage 1 into a rehearsal and pushes Stage 2 out.

A gap analysis before booking the audit is the cheapest form of preparation. Our readiness and gap assessment is a fixed fee for that reason.

6. Combine internal audits across frameworks

Where you hold or are pursuing ISO 27001 alongside ISO/IEC 42001, one integrated internal audit across both management systems normally costs less than two and takes less of your people's time. The auditor still covers both requirement sets, but planning, interviews and reporting compress.

7. Name an internal owner

The most expensive arrangement is the implicit one, where the ISMS belongs to everybody and nobody. Tasks wait, the audit date does not move, and the final stretch gets bought at premium rates.

Naming an owner with protected hours costs nothing and is the highest-return decision available.

8. Plan for surveillance from the start

Surveillance audits in years two and three sample the year. An ISMS that stopped operating after the certificate arrived produces nonconformities and a remediation bill.

Keeping it running is a small ongoing cost. Rebuilding under surveillance pressure is not. That is what our continuous governance and assurance service is for.

What not to cut

The risk assessment. It justifies your control selection and your exclusions, and it is the first thing an auditor tests when a Statement of Applicability looks convenient.

The internal audit. Required annually, cannot come from your certification body, and an audit designed to reassure produces a comfortable report and a surprise at Stage 2.

Accreditation. A cheaper certificate from an unaccredited body is a false economy, because buyers check.

Penetration testing. Not required by the standard, but expected by most enterprise buyers alongside a certificate, and arriving without recent results usually delays the deal by longer than the test would have taken.

What to do next

Settle scope, then ask three accredited bodies for quotes including proposed audit days. Those two steps set most of your cost.

Our free readiness diagnostic gives an immediate first view, and the ISO 27001 service page sets out how we run the programme.

References

FAQ

What is the cheapest way to get ISO 27001 certified?

A scope matched to what your buyers ask about, a control set justified by a real risk assessment, built on any existing SOC 2 control set, with quotes from three accredited bodies.

Do we have to implement all 93 controls?

No. You select based on risk and record justified exclusions in the Statement of Applicability. Implementing all of them by default is expensive and usually unnecessary.

Does holding SOC 2 reduce the cost?

Substantially. The control substance transfers, leaving mainly the management system layer as new work.

Can we reduce the certification fee?

Partly. Fees follow audit days, which follow scope and headcount, and good preparation avoids a longer or repeated audit.

What are the ongoing costs?

Surveillance audits at 20% to 40% of the initial fee in years two and three, the annual internal audit, and internal time to keep the ISMS running.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. Every engagement has a named practitioner and an agreed scope, timetable and fee, with certification body costs shown separately. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO 27001, free.

Answer a short set of questions and see what ISO 27001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO 27001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO 27001.

Or speak to us about your deadline. Book a meeting.