# How much does ISO 27001 cost in the UK?

> What ISO 27001 certification costs in the UK: the parts you pay for, what pushes the price up or down, and how to get an accurate figure.

Canonical: https://cybersecuritylondon.com/how-much-does-iso-27001-cost


By Cyber Security London, published 11 October 2026.

**In short:** The cost of ISO 27001 has three parts: the work to build your information security management system, the certification body's audits, and your own team's time. Size, scope and how much is already in place drive all three. A gap analysis is the quickest way to get an accurate figure for your business.

## What do you actually pay for?

| Cost | What it covers | When |
| --- | --- | --- |
| Implementation | Gap analysis, risk assessment, policies, the Statement of Applicability and putting controls in place, with a consultant or in-house | Before certification |
| Certification audit | The certification body's Stage 1 (documentation) and Stage 2 (in practice) audits | Year 1 |
| Surveillance audits | Shorter audits to confirm the system is still working | Years 2 and 3 |
| Recertification | A full audit to renew the certificate | Every three years |
| Your team's time | Workshops, evidence gathering, internal audit and management review | Throughout |

## What makes ISO 27001 cost more or less?

- **Scope:** certifying one service or office costs less than the whole organisation.
- **Size:** more people, sites and systems mean more audit days and more evidence.
- **Starting point:** existing policies, Cyber Essentials and good IT records cut the work.
- **Support level:** full implementation by a consultant costs more than targeted help.
- **Complexity:** many suppliers, cloud platforms or regulated data add work.

## How can you keep ISO 27001 costs down?

1. Start with a gap analysis so you only fix what is missing.
2. Set a sensible scope around the services your clients care about.
3. Get Cyber Essentials first: it covers many of the technical basics.
4. Build policies around how you already work, rather than generic templates you will never follow.

## Frequently asked questions

### How long does ISO 27001 certification take?

Typically several months for a small to medium business, depending on your starting point and the time your team can give.

### Is ISO 27001 a one-off cost?

No. The certificate lasts three years, with surveillance audits in years two and three, so budget for ongoing audit fees and the time to keep the system up to date.

### Who issues the ISO 27001 certificate?

An accredited certification body. Consultants help you prepare, but the certificate comes from the certification body after its audits.

## Sources

- [ISO/IEC 27001:2022, International Organization for Standardization](https://www.iso.org/standard/27001)
- [Cyber Essentials, National Cyber Security Centre](https://www.ncsc.gov.uk/cyberessentials/overview)

## How we can help

- [ISO 27001](https://cybersecuritylondon.com/iso-27001)
- [Cyber Essentials](https://cybersecuritylondon.com/cyber-essentials)

## Contact

Email enquiry@cybersecuritylondon.com or use the enquiry form at https://cybersecuritylondon.com/#contact. Cyber Security London, The Leather Market, London Bridge, London.
