Book a Security Assessment letstalk@networklondon.co.uk · London Bridge
Compliance

How much does ISO 27001
cost in the UK?

By Cyber Security London · · 2 min read

In short

The cost of ISO 27001 has three parts: the work to build your information security management system, the certification body's audits, and your own team's time. Size, scope and how much is already in place drive all three. A gap analysis is the quickest way to get an accurate figure for your business.

What do you actually pay for?

CostWhat it coversWhen
ImplementationGap analysis, risk assessment, policies, the Statement of Applicability and putting controls in place, with a consultant or in-houseBefore certification
Certification auditThe certification body's Stage 1 (documentation) and Stage 2 (in practice) auditsYear 1
Surveillance auditsShorter audits to confirm the system is still workingYears 2 and 3
RecertificationA full audit to renew the certificateEvery three years
Your team's timeWorkshops, evidence gathering, internal audit and management reviewThroughout

What makes ISO 27001 cost more or less?

  • Scope: certifying one service or office costs less than the whole organisation.
  • Size: more people, sites and systems mean more audit days and more evidence.
  • Starting point: existing policies, Cyber Essentials and good IT records cut the work.
  • Support level: full implementation by a consultant costs more than targeted help.
  • Complexity: many suppliers, cloud platforms or regulated data add work.

How can you keep ISO 27001 costs down?

  1. Start with a gap analysis so you only fix what is missing.
  2. Set a sensible scope around the services your clients care about.
  3. Get Cyber Essentials first: it covers many of the technical basics.
  4. Build policies around how you already work, rather than generic templates you will never follow.

Frequently asked questions

Typically several months for a small to medium business, depending on your starting point and the time your team can give.

No. The certificate lasts three years, with surveillance audits in years two and three, so budget for ongoing audit fees and the time to keep the system up to date.

An accredited certification body. Consultants help you prepare, but the certificate comes from the certification body after its audits.

Sources

  1. ISO/IEC 27001:2022, International Organization for Standardization
  2. Cyber Essentials, National Cyber Security Centre
Contact

Start with
an assessment.

Tell us a little about your business. We'll arrange a short, no-obligation conversation and suggest a sensible first step.

Studio

The Leather Market
London Bridge

Dealing with a live incident? Put “urgent” in your message or email letstalk@networklondon.co.uk. We use your details only to reply, see our privacy notice.