Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

ISO 27001 cost: what is published, and what is not

Updated July 2026

No accredited certification body publishes an ISO 27001 rate card, and the audit-duration tables that shape every quote sit behind ISO's paywall. So we report the prices that are genuinely published, name the ones that are not, and show you what drives the number you will be quoted.

Published

GRC platform list prices on AWS Marketplace, read off the listings.

Paywalled

ISO/IEC 27006-1:2024 Annex C audit-time tables. We do not reproduce what we cannot read.

Quote-only

Certification-body audit fees and consultant rates. Priced per engagement.

What is actually published for your size

Set your headcount. We show the compliance-platform list prices published on AWS Marketplace for that band, and we separate them from the parts of the budget nobody publishes.

1500+

ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope, whether or not they are members of the organisation. Contractors and freelancers inside the scope count.

Published list prices

AWS Marketplace, checked July 2026

Each figure below is a separate pricing dimension on a 12-month contract, read off the vendor's public AWS Marketplace listing. AWS publishes no combined total, so where we add two dimensions together we say so and show the working.

Drata

  • Platform Feecapacity for a 100 FTE org, per 12-month contract$25,000
  • ISO 27001 frameworkper 12-month contract$7,500
Our sum of the 2 published dimensions$32,500
Check the listing

Secureframe

  • Access the Secureframe Platformup to 100 employees, per 12-month contract$7,500
  • First Frameworkchoice of any framework, per 12-month contract$7,500
Our sum of the 2 published dimensions$15,000
Check the listing

Sprinto

FLOOR
  • Starter Platformup to 100 employees, per 12-month contract$7,500
  • First Compliance Frameworkstarting at $2,000 each, per 12-month contract$2,000
Our sum of the 2 published dimensions$9,500

Listing says: "starting at $2000 each"

Check the listing

Scytale

FLOOR
  • Software Platformbundles one framework, per 12-month contract$7,500

This listing publishes no employee band, so it does not tell us whether this figure covers 25 people. Treat it as a floor for any size.

Listing says: "starting price (get quote)"

Check the listing

No published band covers 25 people at: Vanta. Those listings publish figures for smaller bands only, so we report nothing for your size.

Quote-only: the certification audit

We do not print an audit fee here, because no certification body publishes one. Accredited bodies quote per engagement, and the audit-duration tables that shape the quote are published in ISO/IEC 27006-1:2024 Annex C, which ISO sells rather than publishes openly. Any site showing you a precise audit fee is showing you an assumed day count multiplied by an assumed day rate.

What actually drives the number you will be quoted:

  • Number of persons doing work under the organisation's control, within the ISMS scope

    The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.

  • ISMS scope

    What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.

  • Complexity and risk of the ISMS

    Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.

  • Sites

    Where scoped activities physically happen, and whether multi-site sampling applies.

  • Delivery mode

    How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.

The standard that sets ISO 27001 audit time

Audit duration is not a matter of a certification body's preference. It is governed by the standard that accredits the body to issue the certificate in the first place.

The ISMS instrument

ISO/IEC 27006-1:2024

Information security, cybersecurity and privacy protection. Requirements for bodies providing audit and certification of information security management systems. Part 1: General

"This document specifies requirements and provides guidance for bodies providing audit and certification of an information security management system (ISMS), in addition to the requirements contained within ISO/IEC 17021-1."
  • Annex A (normative) Knowledge and skills for ISMS auditing and certification
  • Annex B (informative) Further competence considerations
  • Annex C (normative) Audit time
  • Annex D (informative) Methods for audit time calculations
  • Annex E (informative) Guidance for review of implemented ISO/IEC 27001:2022, Annex A controls

Published March 2024. ISO catalogue entry

A different instrument

IAF MD 5:2023

Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems

"This document is mandatory for the consistent application of the relevant clauses of ISO/IEC 17021-1 for audits of quality, environmental and occupational health and safety management systems."

IAF MD 5 determines audit time for quality, environmental and occupational health and safety management systems. Information security management systems are outside its scope, and it carries no ISMS audit-time table. If you hold ISO 9001 alongside ISO 27001, MD 5 governs the audit time for the ISO 9001 side of the programme and ISO/IEC 27006-1:2024 governs the ISMS side.

Issue 4, Version 3, issued 14 June 2023. Read the document

Why we publish no audit-day table

The ISMS audit-time tables are in ISO/IEC 27006-1:2024 Annex C, which is normative. ISO sells the standard; the tables are not in the free preview. We have not read them, so we do not reproduce them, and we do not reconstruct them from a table written for a different scheme. Your certification body holds the standard, applies Annex C to your scope, and must be able to tell you the audit days it determined and why.

The layer that is genuinely published

Every GRC platform below publishes list-price dimensions on its public AWS Marketplace listing. These are real, public prices on 12-month contracts, read off the listings and checked July 2026. They are separate dimensions: AWS publishes no combined total, so we do not present one.

PlatformPublished dimensions (per 12-month contract)Read the listing
Vantastarting price
  • $14,000 Essentials Package (1-20 employees, per 12-month contract)
  • $21,500 Plus Package (1-20 employees, per 12-month contract)
  • $23,000 Professional Package (1-20 employees, per 12-month contract)
AWS Marketplace
Drata
  • $25,000 Platform Fee (capacity for a 100 FTE org, per 12-month contract)
  • $7,500 ISO 27001 framework (per 12-month contract)
AWS Marketplace
Secureframe
  • $7,500 Access the Secureframe Platform (up to 100 employees, per 12-month contract)
  • $7,500 First Framework (choice of any framework, per 12-month contract)
AWS Marketplace
Sprintostarting price
  • $7,500 Starter Platform (up to 100 employees, per 12-month contract)
  • $2,000 First Compliance Framework (starting at $2,000 each, per 12-month contract)
AWS Marketplace
Scytalestarting price
  • $7,500 Software Platform (bundles one framework, per 12-month contract)
  • $2,100 Additional Framework (per 12-month contract)
  • $4,000 Consulting (per 12-month contract)
AWS Marketplace

Where a listing describes a figure as a starting price, it is a floor and we label it as one. Above roughly 100 people the published bands run out and every platform moves to a private offer.

Frequently asked questions

How much does ISO 27001 certification cost?
Nobody publishes a total, and any site that gives you one has assembled it from assumptions. The certification audit is quoted per engagement by accredited certification bodies, none of which publishes a rate card or a day rate. The audit-duration tables that shape those quotes are published in ISO/IEC 27006-1:2024 Annex C, which ISO sells rather than publishes openly. What is genuinely published is the compliance-platform layer: several GRC vendors list real prices on AWS Marketplace, and those are the figures this site reports.
What determines the certification audit fee?
ISO/IEC 27006-1:2024 sets how accredited bodies determine ISMS audit time. The primary input is the number of people doing work under the organisation's control within the ISMS scope, counted regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count. Audit time also reflects the ISMS scope itself, the complexity and risk of the ISMS, the sites involved, and how much of the audit runs remotely rather than on site.
Which standard governs ISO 27001 audit duration?
ISO/IEC 27006-1:2024, 'Requirements for bodies providing audit and certification of information security management systems'. Its scope clause states that it 'specifies requirements and provides guidance for bodies providing audit and certification of an information security management system (ISMS), in addition to the requirements contained within ISO/IEC 17021-1'. Audit time sits in Annex C, which is normative, with methods for audit time calculations in the informative Annex D. IAF MD 5 is a different instrument: it determines audit time for quality, environmental and occupational health and safety management systems, and does not cover ISMS.
What do compliance platforms actually cost?
Several publish list prices on AWS Marketplace. Secureframe lists $7,500 per 12-month contract for platform access up to 100 employees, plus $7,500 for a first framework described as a choice of any framework. Sprinto lists $7,500 for its Starter platform up to 100 employees, with frameworks from $2,000 each. Drata lists a $25,000 platform fee for capacity for a 100 FTE organisation, plus $7,500 for ISO 27001. Vanta lists a $14,000 Essentials package for a 1-20 employee band. Scytale lists a $7,500 starting price bundling one framework. All checked July 2026. These are separate dimensions on 12-month contracts, not totals, and above roughly 100 people the published bands run out.
What are the ongoing costs after certification?
ISO 27001 certification runs on a three-year cycle: an initial audit in year one, surveillance audits in the intervening years, and a recertification audit before the certificate expires. Surveillance audits are shorter than the initial audit, and like the initial audit they are quoted per engagement rather than published. The platform subscription, where you use one, recurs annually at the list prices published on AWS Marketplace.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an internationally recognised certification standard audited on a three-year cycle by a body accredited for ISMS certification. SOC 2 is a US attestation report issued by a CPA firm and typically renewed annually. ISO 27001 is more often asked for by European buyers and in government procurement; SOC 2 is the common ask in US SaaS sales. The GRC platforms price them the same way: Drata lists every framework at $7,500 on AWS Marketplace, ISO 27001 and SOC 2 alike, and Secureframe's first-framework dimension is a choice of any framework.
How do I get a defensible audit quote?
Approach more than one accredited body and give each the same brief: the ISMS scope, the number of people doing work under your control inside that scope including contractors, your sites, and how much of the audit can run remotely. Ask each body to state the audit days it has determined and to confirm its accreditation for ISO/IEC 27001. Because the day count and the day rate are both set per engagement, the only way to learn your number is to ask for it.
How can I check a certification body is genuinely accredited?
Check the accreditation body's own register rather than the certification body's marketing material. UKAS publishes schedules of accreditation for UK bodies, and ANAB publishes an accreditation directory for US bodies. Both are public and searchable, and they state the exact schemes each body is accredited for. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001.
Built by Digital Signet

You're using a tool we built.

Ranks on Google, cited by leading AI assistants

Digital Signet builds custom software and AI automation for compliance teams. Evidence collection, control mapping, audit prep, workflow automation.

See what we build →

Updated July 2026