ISO 27001 certification: what it costs, how long it takes, and what decides both
Two quotes for the same programme, and the gap is not a discount. Half of what is sold is derived under a normative annex and can be compared line by line. The other half cannot.
On this page (8)
- The half with an annex behind it
- "How many people" is not a headcount question
- Which edition the number came from
- You are buying a three-year programme, not an audit
- The half with nothing behind it
- The long pole in the timeline is on your side of the line
- The one decision that moves both invoices
- What a comparable quote names
Two quotes arrive for the same programme and the gap between them is not a discount. One half of what is being sold is derived under a normative annex and can be compared line by line. The other half is priced on how far your organisation currently sits from a standard, which nobody can read off a table — including the firm quoting you.
Knowing which half you are looking at is most of the work.
The half with an annex behind it
A certification body does not price an audit freehand. ISO/IEC 17021-1:2015 clause 9.1.4.1 requires it to hold documented procedures for determining the audit time needed to plan and accomplish a complete and effective audit. Clause 9.1.4.2 then sets what that determination has to consider — eight named aspects:
- a) the requirements of the management system standard
- b) complexity of the client and its management system
- c) technological and regulatory context
- d) any outsourcing of activities
- e) the results of any prior audits
- f) size and number of sites, and multi-site considerations
- g) the risks associated with the products, processes or activities of the organisation
- h) whether audits are combined, joint or integrated
Clause 9.1.4.3 requires the duration of the audit and its justification to be recorded. Clause 9.1.4.4 confines that duration to auditors: time spent by technical experts, translators, interpreters and observers sits outside it.
For an information security management system the scheme standard adds a layer on top. ISO/IEC 27006-1:2024 carries its own clause 9.1.4, Determining audit time, a normative Annex C, Audit time, and an informative Annex D, Methods for audit time calculations. Annex C is where the starting point for initial audit days is set against the number of persons doing work under the organisation's control, before the adjustments the standard provides for.
Note what that produces: a number of days, derived and recorded. What a day costs is a commercial matter between you and the body you engage.
"How many people" is not a headcount question
The 2024 edition changed how that population is counted, and the change is documented in primary text. IAF MD 29:2024, the mandatory transition document, lists among the main changes from ISO/IEC 27006:2015:
"ii) Updating the audit time calculation requirement (see Annex C). a) Introducing the concept of persons performing certain identical activities in C.2.1 and definition of the requirement for how to determine the initial number of persons in C.3.4 accordingly. b) New requirements for audit time for scope extensions in C.7. c) Further clarifying the approaches of calculating audit time of multiple sites in C.6."
So the count is built from activities, not from a payroll total. The text of C.3.4 reproduced in a question put to European Accreditation describes a reduction based on the risk of the activities associated with the tasks, using the square root of the head count of people performing each identical activity, rounded up, as the maximum reduction allowed.
European Accreditation's answer, FAQ 48.6 of September 2024, is its own text and settles how the reduction is applied:
"it is clear from ISO/IEC 27006-1 that the calculation cannot be applied directly to the entire number of FTEs of the organization (144) but rather to the head count of people performing each relevant identical activity, for which proper justification is presented."
It adds two constraints worth carrying into a conversation with a certification body. The reduction belongs to categories of similar, repetitive work — activities that "require limited skills/knowledge/education, are executed under direction by others, and what they do has a limited effect on the outcome of the management system or its scope". And: "the final consideration should always be that the CAB ensures that sufficient audit time is allocated for a complete and effective audit in line with cl. 9.1.4."
That is why a certification body asks for an organisation chart before it quotes, and why two firms of the same headcount receive different numbers.
Which edition the number came from
IAF MD 29:2024 section 3 records the dates: "ISO/IEC 27006-1:2024 was published in March 2024. As per an IAF decision, the dates below are calculated from 31 March 2024." Its table requires each accredited certification body to use ISO/IEC 27006-1:2024 for all clients no later than 31 March 2026 — twenty-four months from the end of the publication month.
That date has passed. An initial audit quoted now should be derived under the 2024 edition, and clause 9.1.4.3 means the derivation exists in writing. Ask which edition, and ask for the number of persons the audit time was calculated from.
One further change from the same list bears on the invoice. MD 29 records the "Removal of the requirements for obtaining approval from the AB if the remote auditing activities represent more than 30% of the planned on-site audit time". How much of your audit is delivered remotely is a live question again, and travel is a real component of an audit quote.
You are buying a three-year programme, not an audit
Clause 9.1.3.2 requires the audit programme to include a two-stage initial audit, surveillance audits in the first and second years, and a recertification audit in the third year prior to expiration of certification — the cycle beginning with the certification or recertification decision. Clause 9.1.3.3 sets the cadence: surveillance audits at least once a calendar year except in recertification years, with the first carried out not more than twelve months from the decision date.
Recertification is a fresh audit rather than a renewal fee. Clause 9.6.3.1.1 requires it to evaluate continued fulfilment of all the requirements of the standard. Clause 9.6.3.1.2 requires it to consider performance over the period of certification and to review previous surveillance audit reports. And clause 9.6.3.1.3 provides for a Stage 1 within recertification where there have been significant changes to the management system, the organisation, or the context in which the management system is operating — the standard's example is a change to legislation.
A single figure quoted for "certification" is therefore some part of a four-event programme. Ask for audit days broken out per event: Stage 1, Stage 2, surveillance year one, surveillance year two, recertification.
The half with nothing behind it
The other invoice covers work the organisation owns. Scope and boundary at ISO/IEC 27001:2022 clause 4.3. Risk assessment and risk treatment at 6.1.2 and 6.1.3. The Statement of Applicability at 6.1.3 d), two of whose four required contents are justifications. Competence at 7.2. Control implementation. The internal audit at 9.2 and the management review at 9.3.
None of that starts from a table, and three variables decide nearly all of it:
How far the controls now in place are from the controls your own risk treatment says are necessary. This is a property of your organisation on the day you start. It is not predicted by your size, your sector or anyone's methodology.
How wide the boundary is. Clause 4.3 is where the services, sites and people inside the management system are fixed, and everything downstream is counted against that decision.
Whether the evidence is produced or reconstructed. Records generated by controls as they run cost almost nothing. Records assembled after the fact, for a period that has already passed, cost a great deal and read as what they are.
If a proposal names a number without naming those three, the number is an estimate of somebody else's organisation.
The long pole in the timeline is on your side of the line
Stage 1 evaluates, among other things, whether internal audits and management review are being planned and performed. The clause 9.2 internal audit and the clause 9.3 management review therefore have to have happened before the certification body's first visit concludes — which is what actually sets the earliest date a certificate can issue, not an auditor's diary.
The party best placed to run that internal audit cannot be the certification body: the standard the certifier is accredited against bars it, and bars the certifier from consultancy besides. Why the firm that prepares you cannot be the firm that certifies you sets out the six clauses. For which party produces which document across the whole programme, and how the certification decision is separated from the audit team, see who issues an ISO 27001 certificate.
Read that way, "certified in twelve weeks" is a claim about your organisation rather than about the auditor.
The one decision that moves both invoices
Scope, at clause 4.3. Annex C starts from the number of persons doing work under the organisation's control, so the boundary sets the certification body's days. The readiness effort scales with what is inside the same boundary. It is also the sentence printed on the certificate: clause 8.2.2 f) requires the certification documents to identify the scope of certification with respect to the type of activities, products and services as applicable at each site, without being misleading or ambiguous. That wording is what a customer reads years later.
It is settled before either supplier is engaged, and it is the only decision in the programme that prices both halves at once.
What a comparable quote names
- Audit days per event — Stage 1, Stage 2, each surveillance audit, recertification — and the day rate against each
- The number of persons the audit time was derived from, and the edition of ISO/IEC 27006-1 used
- What is inside the day rate: travel, reporting, follow-up on nonconformities
- Which body issues the certificate, which accreditation body has accredited it, and for the ISMS scheme specifically
- Whether readiness work sits in the same document, and if so, who performs which half
On that fourth point, something changed recently enough that most published guidance has not caught up. The International Accreditation Forum ceased operations on 1 January 2026; its site now reads "This website is a legacy site maintained for archival/reference purposes only." It merged with ILAC to form Global Accreditation Cooperation Incorporated, which commenced full operations the same day and launched its own Multilateral Recognition Arrangement in place of the IAF MLA. IAF CertSearch continues to operate as the database. NABCB signed the IAF MLA for ISMS certification on 5 November 2015 in Milan, and that remains the historical fact it always was. A page or a proposal describing the IAF MLA as the current arrangement was written before January 2026 and has not been revisited since.
Security Brigade works the readiness half: scope and boundary definition, risk assessment and treatment, the Statement of Applicability, control implementation, the clause 9.2 internal audit, management review preparation, and the evidence base a certification body reads at Stage 1 and Stage 2. The certificate comes from an accredited certification body, on the programme above.
Every clause number, quotation and date above was checked against published text on 27 August 2026.
Continue reading
All articles →Why the firm that prepares you cannot be the firm that certifies you
No certification body may prepare you for its own audit, nor may any entity under its organisational control. Where a related body prepares you, it shall not certify you for two years.
Who issues an ISO 27001 certificate, and what every other party produces
An ISO 27001 programme produces four kinds of document and no party produces more than two. Who holds the certificate, the accreditation, and the Statement of Applicability.
The Indian law that names ISO 27001 — and what changes on 13 May 2027
One Indian rule names IS/ISO/IEC 27001 in its own text and deems an audited implementation compliance with the IT Act. A later Act omits the provisions it was made under.