ISO 27001 cost: what is published, and what is not
Updated July 2026
No accredited certification body publishes an ISO 27001 rate card, and the audit-duration tables that shape every quote sit behind ISO's paywall. So we report the prices that are genuinely published, name the ones that are not, and show you what drives the number you will be quoted.
Published
GRC platform list prices on AWS Marketplace, read off the listings.
Paywalled
ISO/IEC 27006-1:2024 Annex C audit-time tables. We do not reproduce what we cannot read.
Quote-only
Certification-body audit fees and consultant rates. Priced per engagement.
What is actually published for your size
Set your headcount. We show the compliance-platform list prices published on AWS Marketplace for that band, and we separate them from the parts of the budget nobody publishes.
ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope, whether or not they are members of the organisation. Contractors and freelancers inside the scope count.
Published list prices
AWS Marketplace, checked July 2026Each figure below is a separate pricing dimension on a 12-month contract, read off the vendor's public AWS Marketplace listing. AWS publishes no combined total, so where we add two dimensions together we say so and show the working.
Drata
- Platform Feecapacity for a 100 FTE org, per 12-month contract$25,000
- ISO 27001 frameworkper 12-month contract$7,500
Secureframe
- Access the Secureframe Platformup to 100 employees, per 12-month contract$7,500
- First Frameworkchoice of any framework, per 12-month contract$7,500
Sprinto
FLOOR- Starter Platformup to 100 employees, per 12-month contract$7,500
- First Compliance Frameworkstarting at $2,000 each, per 12-month contract$2,000
Listing says: "starting at $2000 each"
Check the listingScytale
FLOOR- Software Platformbundles one framework, per 12-month contract$7,500
This listing publishes no employee band, so it does not tell us whether this figure covers 25 people. Treat it as a floor for any size.
Listing says: "starting price (get quote)"
Check the listingNo published band covers 25 people at: Vanta. Those listings publish figures for smaller bands only, so we report nothing for your size.
Quote-only: the certification audit
We do not print an audit fee here, because no certification body publishes one. Accredited bodies quote per engagement, and the audit-duration tables that shape the quote are published in ISO/IEC 27006-1:2024 Annex C, which ISO sells rather than publishes openly. Any site showing you a precise audit fee is showing you an assumed day count multiplied by an assumed day rate.
What actually drives the number you will be quoted:
Number of persons doing work under the organisation's control, within the ISMS scope
The primary input. ISO/IEC 27006-1:2024 counts people doing work under the organisation's control within the ISMS scope regardless of whether they are members of the organisation, so contractors and freelancers inside the scope count toward the total.
ISMS scope
What the certificate actually covers: which services, systems, teams and locations sit inside the boundary. A tightly drawn scope is the single largest lever a buyer controls.
Complexity and risk of the ISMS
Criticality of the information handled and the risk associated with the ISMS. Two organisations with identical headcount can attract different audit time on this basis.
Sites
Where scoped activities physically happen, and whether multi-site sampling applies.
Delivery mode
How much of the audit runs remotely versus on site. This drives auditor travel and expenses, which are usually quoted separately from audit time.
The standard that sets ISO 27001 audit time
Audit duration is not a matter of a certification body's preference. It is governed by the standard that accredits the body to issue the certificate in the first place.
The ISMS instrument
ISO/IEC 27006-1:2024
Information security, cybersecurity and privacy protection. Requirements for bodies providing audit and certification of information security management systems. Part 1: General
"This document specifies requirements and provides guidance for bodies providing audit and certification of an information security management system (ISMS), in addition to the requirements contained within ISO/IEC 17021-1."
- Annex A (normative) Knowledge and skills for ISMS auditing and certification
- Annex B (informative) Further competence considerations
- Annex C (normative) Audit time
- Annex D (informative) Methods for audit time calculations
- Annex E (informative) Guidance for review of implemented ISO/IEC 27001:2022, Annex A controls
Published March 2024. ISO catalogue entry
A different instrument
IAF MD 5:2023
Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems
"This document is mandatory for the consistent application of the relevant clauses of ISO/IEC 17021-1 for audits of quality, environmental and occupational health and safety management systems."
IAF MD 5 determines audit time for quality, environmental and occupational health and safety management systems. Information security management systems are outside its scope, and it carries no ISMS audit-time table. If you hold ISO 9001 alongside ISO 27001, MD 5 governs the audit time for the ISO 9001 side of the programme and ISO/IEC 27006-1:2024 governs the ISMS side.
Issue 4, Version 3, issued 14 June 2023. Read the document
Why we publish no audit-day table
The ISMS audit-time tables are in ISO/IEC 27006-1:2024 Annex C, which is normative. ISO sells the standard; the tables are not in the free preview. We have not read them, so we do not reproduce them, and we do not reconstruct them from a table written for a different scheme. Your certification body holds the standard, applies Annex C to your scope, and must be able to tell you the audit days it determined and why.
The layer that is genuinely published
Every GRC platform below publishes list-price dimensions on its public AWS Marketplace listing. These are real, public prices on 12-month contracts, read off the listings and checked July 2026. They are separate dimensions: AWS publishes no combined total, so we do not present one.
| Platform | Published dimensions (per 12-month contract) | Read the listing |
|---|---|---|
| Vantastarting price |
| AWS Marketplace |
| Drata |
| AWS Marketplace |
| Secureframe |
| AWS Marketplace |
| Sprintostarting price |
| AWS Marketplace |
| Scytalestarting price |
| AWS Marketplace |
Where a listing describes a figure as a starting price, it is a floor and we label it as one. Above roughly 100 people the published bands run out and every platform moves to a private offer.
Explore ISO 27001 costs
Audit and certification body fees
How audit time is determined, and why no body publishes a rate
Cost by company size
What scales with headcount, and what does not
Implementation cost
Phase by phase, from scoping to Stage 2
Consultant costs
Engagement models and what to ask before you sign
DIY vs consultant vs platform
The three routes, on published figures where they exist
The 3-year cycle
Surveillance audits, recertification, and ongoing maintenance
Hidden costs
The expenses most budget estimates miss entirely
UK certification
UKAS accreditation and what it means for procurement
Gap analysis
The go/no-go decision point that sets your scope
ROI and business case
Building a defensible case without borrowed statistics
ISO 27001 vs SOC 2
Scope, cycle, and which framework buyers ask you for
93 Annex A controls
All controls across the four themes
Buyer guides: per body, per platform, per stage
Certification-body pages carry accreditation status and quote drivers, because no body publishes a rate. Platform pages carry the published AWS Marketplace dimensions.
By certification body
BSI
Accreditation and quote drivers
NQA
Accreditation and quote drivers
Bureau Veritas
Accreditation and quote drivers
LRQA
Accreditation and quote drivers
DNV
Accreditation and quote drivers
SGS
Accreditation and quote drivers
TUV SUD
Accreditation and quote drivers
Schellman
Accreditation and quote drivers
By compliance platform
Vanta
from $6,000
lowest published dimension
Drata
$7,500
lowest published dimension
Secureframe
$7,500
lowest published dimension
Sprinto
from $2,000
lowest published dimension
Scytale
from $2,100
lowest published dimension
By stage and comparison
Startups (5-25 employees)
Where the published platform bands actually fit
SaaS by stage
Seed through scale-up, and dev/prod scope
Mid-market (100-500)
Where published pricing runs out
vs HITRUST CSF
When HITRUST is unavoidable for US healthcare
vs Cyber Essentials Plus
The UK procurement floor decision
2013 to 2022 transition
Post-deadline re-mapping work
Frequently asked questions
How much does ISO 27001 certification cost?
What determines the certification audit fee?
Which standard governs ISO 27001 audit duration?
What do compliance platforms actually cost?
What are the ongoing costs after certification?
What is the difference between ISO 27001 and SOC 2?
How do I get a defensible audit quote?
How can I check a certification body is genuinely accredited?
You're using a tool we built.
Digital Signet builds custom software and AI automation for compliance teams. Evidence collection, control mapping, audit prep, workflow automation.
See what we build →