How much does ISO 27001 cost in the UK?
Last verified 2026-08-19 · UK focus
Short answer
For a UK SME, first-year ISO 27001 costs typically land between £10,000 and £30,000 all-in. UKAS-accredited certification body fees are usually £5,000-£12,000 for a 10-50 person firm across Stage 1 and Stage 2, with consultancy, compliance software and internal staff time making up the rest. Ongoing years are cheaper: surveillance audits plus tooling generally run £4,000-£10,000.
Key facts
- Certification body fees are priced per auditor-day; day rates commonly sit between £1,000 and £1,600.
- Consultancy is the largest variable line and can be zero if you run it in-house.
- Year 2 and 3 costs are typically 30-50% of year one.
- Costs scale with headcount, number of sites and scope breadth, not with revenue.
Indicative UK ISO 27001 cost ranges (2026, ex VAT)
| Company size | Certification body (year 1) | Consultancy | Software | Typical year 1 total |
|---|---|---|---|---|
| 1-10 staff | £4,000-£7,000 | £0-£8,000 | £1,000-£3,000 | £6,000-£16,000 |
| 11-50 staff | £5,000-£12,000 | £5,000-£20,000 | £2,000-£6,000 | £12,000-£30,000 |
| 51-250 staff | £10,000-£20,000 | £15,000-£45,000 | £5,000-£15,000 | £30,000-£70,000 |
| 250+ staff | £18,000-£40,000+ | £30,000-£100,000+ | £12,000-£40,000 | £60,000-£150,000+ |
Excludes internal staff time, which is often the largest real cost.
Caveats
- Quotes vary widely between certification bodies; obtain at least three and compare auditor-days, not headline price.
- Non-accredited 'certificates' are cheaper but are frequently rejected by enterprise buyers.
- Remediation costs (MDM, logging, penetration testing) sit outside these ranges and depend on your starting posture.
Sources
- IAF MD 5 auditor-day tables (basis for certification body pricing). International Accreditation Forum, 2025-01-01.
- ISO-STANDARD.app UK market pricing review. ISO-STANDARD.app, 2026-08-19.
Check your own position
Run the free ISO 27001 gap analysis for an instant score against clauses 4-10 and Annex A, then manage risks, controls, owners and evidence in one workspace.
