How much does ISO 27001 certification cost: a real cost breakdown
By the QuantumSec team
The cost of ISO 27001 certification is not a single figure: it's three separate line items — implementation consulting, certification audit and annual maintenance — that many companies only half-budget because they only ask about the first one. This guide breaks down each line item so the budget has no surprises halfway through the project.
Line item 1: implementation consulting
Covers the gap analysis, scope definition, risk assessment, drafting policies and procedures, and implementing controls. It's the most variable line item: it depends on the ISMS scope, how much documentation and controls already exist, and whether you need technical control implementation (not just documentation). For an SMB with a narrow scope, a full project usually falls in the range of a few thousand euros; for a mid-sized organization with a wide scope (multiple departments, locations or critical systems), the figure grows in proportion to the real analysis and implementation effort.
Line item 2: certification audit (the cost the consultant doesn't control)
This cost is set by the certification body, not the consultant, and is calculated based on the required audit days — determined by standardized industry formulas (like IAF guidance) that factor in the number of employees within scope and ISMS complexity. It includes Stage 1 (documentation review) and Stage 2 (on-site audit), plus travel if applicable. Requesting quotes from 2-3 ENAC-accredited bodies before deciding is the only way to compare with any rigor.
Line item 3: annual maintenance (the cost people forget)
The certificate is valid for 3 years, but requires surveillance audits in years 1 and 2, plus the renewal audit in year 3 — all billed separately by the certification body. On top of that, if you want the ISMS to keep working for real and not just on paper, add a maintenance contract with the consultant to update the risk assessment, review the SoA and prepare for each surveillance audit. Ignoring this line item in the initial budget is the most common mistake.
What makes the cost go up or down
Goes up: a wide scope (multiple locations, systems, business units), a total absence of prior documentation or controls, needing to implement complex technical controls (encryption, SIEM, identity management). Goes down: a narrow, well-defined scope from the start, existing reusable policies or controls, and prior team experience with similar frameworks (NIS2, ENS) that already cover common ground.
FAQ
Is the certification audit cost negotiable?
The number of audit days is calculated using standardized criteria and shouldn't be negotiated downward without real justification — doing so compromises the validity of the certification. What does vary between bodies is the day rate, and that's where comparing quotes makes sense.
Is it cheaper to do ENS and ISO 27001 together rather than separately?
Usually yes, because they share a significant part of the risk assessment, policies and controls. Approaching them as a single consulting project, even if certified separately, reduces total effort compared to doing them at different times.
Are there public grants to help fund ISO 27001 certification?
There are sometimes digitalization or cybersecurity grant programs (national or regional) that can cover part of the cost. Programs change frequently, so it is worth checking what is currently available when starting the project rather than assuming a specific grant applies.