ISO 27001 certification cost: the honest 2026 breakdown
Most cost estimates for ISO 27001 certification quietly hide the biggest line — internal effort — and inflate the ones vendors want to sell you. This guide breaks down every cost line for a UK/EU SME certifying in 2026, with realistic ranges and where software-led delivery genuinely reduces the total.
Michael McCarroll— Founder, ISO-STANDARD.app · ISO 27001 lead implementer 14 min read Updated June 2026
The four real cost lines
Every ISO 27001 certification budget, whether the organisation is 10 people or 500, reduces to the same four cost lines. Any quote that does not name all four is incomplete.
Certification body fees — the UKAS-accredited registrar that conducts Stage 1, Stage 2, annual surveillance and three-yearly recertification.
Consultancy or template costs — external help drafting policies, running the risk assessment, and preparing for audit. Optional in principle, near-universal in practice.
Tooling — the ISMS platform (or the spreadsheets, SharePoint sites and email chains that stand in for one).
Internal effort — the person-hours from leadership, IT, HR, legal and the ISMS owner. Usually the largest line, almost always missing from vendor quotes.
Registrar fees: what you actually pay a certification body
UKAS-accredited certification bodies price per auditor day. In 2026, day rates for SME-focused registrars sit in the £900–£1,400 range. A typical small SaaS scope looks like this:
Stage 1 (documentation review): 1 day — £900–£1,400
Stage 2 (implementation audit): 2–3 days — £1,800–£4,200
Certificate issue and admin: £300–£700
Year-one registrar total: ~£3,000–£6,300
Annual surveillance (years 2 and 3): 1 day each — £900–£1,400 per year
Recertification (year 3): similar to Stage 2 — £2,700–£4,200
Two rules of thumb: always request itemised quotes from at least three UKAS-accredited bodies, and never pay a non-accredited certificate — insurers, procurement teams and enterprise customers routinely reject them.
Consultancy and templates: the biggest variable
This is where quotes diverge wildly. A full-service consultancy typically charges £15,000–£40,000 to take an SME through certification. A template pack plus a few days of remote support might come in at £2,000–£4,000. A software-led approach with embedded guidance, drafted policies and a live control catalogue can be as little as the platform subscription itself.
The realistic 2026 ranges:
Full-service consultancy: £15,000–£40,000
Template pack + light support: £2,000–£6,000
Software-led ISMS with built-in guidance: £0–£1,500 in optional expert hours
Tooling: the ISMS platform (or the lack of one)
Many SMEs "save" on tooling by running the ISMS in spreadsheets, SharePoint and email. That saving is illusory: it moves the cost from software into internal effort, and it creates the exact evidence-gathering nightmare that surfaces at Stage 2.
Realistic 2026 ranges for a small SME:
Spreadsheets / SharePoint (implicit cost): nominally £0, but adds ~80–160 hours of internal effort in year one
Legacy GRC platforms (Vanta, Drata, OneTrust SME tiers): £8,000–£25,000 per year
IT / DevOps: 40–80 hours (technical controls, evidence)
HR: 20–40 hours (starter/leaver, training records, background checks)
Leadership: 10–20 hours (management review, statement of applicability sign-off)
Other functions (legal, finance, ops): 20–40 hours combined
At a blended £45/hour internal cost, that is £9,000–£18,000 of hidden effort — often more than the entire external spend. This is precisely where a software-led ISMS pays back: pre-drafted policies, a control catalogue mapped to Annex A, an evidence store linked to controls, and audit-ready exports remove the reconciliation work that eats most of those hours.
Year-one total: three realistic scenarios
Putting the four lines together for a 10–50 person UK SME with a single-site SaaS scope:
Same certificate, same UKAS accreditation, same Annex A coverage. The difference is entirely in how much reconciliation, drafting and evidence-hunting the team has to do by hand.
Ongoing cost after year one
After certification, run-rate settles substantially:
Surveillance audit: £1,500–£3,000/year
Platform subscription: £500–£2,000/year for a software-led ISMS
Recertification (every 3 years): budget the year-one Stage 2 cost
Total ongoing run-rate for a small SME: £4,000–£8,000/year.
Where the money is genuinely wasted
Three cost lines are usually pure waste for an SME:
Bespoke policy drafting from scratch. Every SME needs the same ~25 policies. Paying a consultant to write them from a blank page is a solved problem.
Consultancy day-rates for spreadsheet maintenance. If the "ISMS" is a spreadsheet, the consultant is paid to keep the spreadsheet tidy. Replace both.
Separate tools for risk, controls, policies, evidence and audit. Integration overhead exceeds the cost of a single integrated platform.
Frequently asked questions
How much does ISO 27001 certification cost a UK SME in 2026?
For a typical 10–50 person SME, expect £8,000–£18,000 in year one all-in: roughly £4,000–£8,000 in registrar fees across Stage 1 and Stage 2, £2,000–£6,000 in consultancy or template costs, and £1,500–£4,000 in tooling. Larger scopes, regulated sectors and multi-site organisations trend higher; a lean single-site SaaS scope can land under £8,000.
What is the biggest single cost line?
Internal effort. A first-time ISMS build typically consumes 200–400 person-hours across leadership, IT, HR and the ISMS owner. That is the cost line most cost estimates hide — and the one an integrated GRC platform reduces the most, by removing spreadsheet reconciliation, evidence chasing and policy drafting from scratch.
Do registrar fees vary much between UKAS-accredited bodies?
Yes. Quoted day-rates for UKAS-accredited certification bodies in 2026 range roughly £900–£1,400 per auditor day. Stage 1 is usually one day, Stage 2 two to three days for a small scope, followed by annual surveillance (about one day) and a three-yearly recertification. Always request itemised quotes from at least three UKAS bodies.
How does ISO-STANDARD.app reduce the total cost of certification?
By replacing three cost lines — consultancy for policy drafting, a spreadsheet-and-email ISMS, and separate risk / audit / evidence tools — with a single workspace that produces auditor-ready evidence, a live risk register and the full Annex A control set out of the box. Typical saving vs a consultancy-plus-spreadsheets baseline is 40–70% in year one.
What ongoing costs should I budget for after year one?
Annual surveillance audit (~£1,500–£3,000), recertification every three years (roughly year-one Stage 2 cost), continuous ISMS maintenance effort (~40–80 person-hours a year for a small scope), and platform subscription. Total ongoing run-rate for an SME is usually £4,000–£8,000 per year.
Certify ISO 27001 without the £40k consultancy bill
ISO-STANDARD.app ships the full Annex A control catalogue, a live risk register, drafted policies, and audit-ready evidence exports — the three cost lines a traditional programme charges the most for, included from day one.
ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.