The budget-friendly ways to get ISO 27001 certified
- Scope is the biggest lever. It drives audit days, which drives the certification fee, and internal hours, which is the larger cost.
- Exclude controls your risk assessment does not justify. Implementing all 93 by default is expensive and unnecessary.
- Where you hold SOC 2, build one control set rather than a parallel ISO programme.
- Get quotes from three accredited bodies and ask each for proposed audit days, not just a fee.
- Do not economise on the risk assessment, the internal audit, or accreditation.
Where the money goes
The cheapest route to ISO 27001 is a correctly scoped ISMS with a control set your risk assessment actually justifies, prepared well enough that the audit is short. Most overspend comes from scoping too broadly, implementing all 93 controls by default, or arriving underprepared and paying for a longer audit and a return visit.
A realistic first-year total for a small to mid-sized organisation is £20,000 to £70,000 including implementation and certification. The decisions below move you towards the lower end.
| Line | Typical cost | Avoidable? |
|---|---|---|
| Gap analysis | £5,000 to £15,000 | No, and skipping it usually costs more |
| Implementation | £15,000 to £50,000 | Partly, through scope and control selection |
| Certification body, initial cycle | £5,000 to £20,000 | Partly, through scope, preparation and quotes |
| Internal audit | £4,000 to £12,000 | Partly, by combining with other frameworks |
| Penetration testing | £4,000 to £20,000 | Rarely, buyers expect it |
| Internal team time | Frequently the largest cost | Partly, through project management |
| Surveillance, years two and three | 20% to 40% of the initial audit fee | No |
1. Scope to what your buyers ask about
Scope drives audit days, which drives the certification fee, and it drives internal hours, which is the larger cost.
Start from the question you are being asked. If a customer wants assurance about one service, an ISMS scoped to that service and the teams supporting it answers them. Certifying the whole organisation because it sounds stronger buys audit days nobody requested.
The counterweight: a scope so narrow that the certificate's scope statement does not name the service your buyer cares about is the most expensive outcome, because you pay twice.
2. Exclude controls your risk assessment does not justify
Annex A is a list of possible controls, not a checklist. You select what applies based on risk, and record justified exclusions in the Statement of Applicability.
Organisations that implement all 93 by default spend money on controls they do not need and create maintenance obligations that recur every year. An organisation with no physical premises, no development function or no operational technology will legitimately exclude several.
The saving requires a real risk assessment first. Excluding controls without one is a nonconformity rather than an economy.
3. Build one control set if you hold SOC 2
The control substance overlaps heavily. What ISO 27001 adds is the management system layer: scope, risk method, risk treatment plan, Statement of Applicability, internal audit programme and management review.
Building on your existing SOC 2 control set and evidence base is materially cheaper than running a parallel ISO programme, and it prevents the two sets diverging, which is a cost that arrives later. See our SOC 2 service page.
The same applies in reverse, and to ISO/IEC 42001, where Annex D supports integrating the management systems.
4. Get three quotes and ask about audit days
Certification body fees follow audit days, calculated from your scope, headcount within scope and number of sites. Ask each body for its fee, its accreditation body and scope entry, and the number of audit days proposed.
Do not choose on price alone. An auditor with real competence in your sector makes for a better audit, and a body with no availability for five months costs you more than a higher fee would.
5. Prepare so the audit is short
Stage 1 exists to find things that would prevent a successful Stage 2. Arriving with an incomplete Statement of Applicability, no internal audit and no management review turns Stage 1 into a rehearsal and pushes Stage 2 out.
A gap analysis before booking the audit is the cheapest form of preparation. Our readiness and gap assessment is a fixed fee for that reason.
6. Combine internal audits across frameworks
Where you hold or are pursuing ISO 27001 alongside ISO/IEC 42001, one integrated internal audit across both management systems normally costs less than two and takes less of your people's time. The auditor still covers both requirement sets, but planning, interviews and reporting compress.
7. Name an internal owner
The most expensive arrangement is the implicit one, where the ISMS belongs to everybody and nobody. Tasks wait, the audit date does not move, and the final stretch gets bought at premium rates.
Naming an owner with protected hours costs nothing and is the highest-return decision available.
8. Plan for surveillance from the start
Surveillance audits in years two and three sample the year. An ISMS that stopped operating after the certificate arrived produces nonconformities and a remediation bill.
Keeping it running is a small ongoing cost. Rebuilding under surveillance pressure is not. That is what our continuous governance and assurance service is for.
What not to cut
The risk assessment. It justifies your control selection and your exclusions, and it is the first thing an auditor tests when a Statement of Applicability looks convenient.
The internal audit. Required annually, cannot come from your certification body, and an audit designed to reassure produces a comfortable report and a surprise at Stage 2.
Accreditation. A cheaper certificate from an unaccredited body is a false economy, because buyers check.
Penetration testing. Not required by the standard, but expected by most enterprise buyers alongside a certificate, and arriving without recent results usually delays the deal by longer than the test would have taken.
What to do next
Settle scope, then ask three accredited bodies for quotes including proposed audit days. Those two steps set most of your cost.
Our free readiness diagnostic gives an immediate first view, and the ISO 27001 service page sets out how we run the programme.
References
FAQ
What is the cheapest way to get ISO 27001 certified?
A scope matched to what your buyers ask about, a control set justified by a real risk assessment, built on any existing SOC 2 control set, with quotes from three accredited bodies.
Do we have to implement all 93 controls?
No. You select based on risk and record justified exclusions in the Statement of Applicability. Implementing all of them by default is expensive and usually unnecessary.
Does holding SOC 2 reduce the cost?
Substantially. The control substance transfers, leaving mainly the management system layer as new work.
Can we reduce the certification fee?
Partly. Fees follow audit days, which follow scope and headcount, and good preparation avoids a longer or repeated audit.
What are the ongoing costs?
Surveillance audits at 20% to 40% of the initial fee in years two and three, the annual internal audit, and internal time to keep the ISMS running.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. Every engagement has a named practitioner and an agreed scope, timetable and fee, with certification body costs shown separately. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.