What ISO 27001 actually costs an SME, including the lines nobody quotes

The certification body is the smallest line on the invoice and the only one anyone quotes. Here is the full three-year cost of ISO 27001 for a company of 20 to 250 people, including the four lines that never appear in a proposal.

Daniel Grigorovich
Daniel Grigorovich
Founder · 4 Sept 2026 · 8 min read
ISO 27001CostSME
What ISO 27001 actually costs an SME, including the lines nobody quotes

Who should read this: anyone who has been asked to put a number in next year’s budget for ISO 27001 and has one quote in hand that they suspect is not the whole picture.

The suspicion is correct. A certification body quote covers the audit. A consultant quote covers the documentation. Between and around them sit four cost lines that appear in neither, and in a company of 20 to 250 people they are usually larger than both quotes combined.

Here is the whole thing, in the order the money leaves.

The certification body: the smallest line, and the only fixed one

This is the one cost with a published structure behind it. Audit duration is not negotiable marketing, it is set by the accreditation rules your certification body operates under, and it scales with headcount.

EmployeesTotal certification audit daysTypical fee at European day rates
1 to 105€7,000 to €9,000
11 to 156€8,500 to €11,000
16 to 257€10,000 to €13,000
26 to 458.5€12,000 to €16,000
46 to 6510€14,500 to €19,000
86 to 12512€17,500 to €22,500
176 to 27514€20,500 to €26,000

Auditor day rates in Western Europe sit at roughly €1,200 to €1,600 and have risen sharply in the last two years. Stage 1 takes 20 to 30 per cent of the total days, Stage 2 the rest.

Two things follow from this table that change how you budget.

Headcount, not revenue, sets the price. A forty person company with ten million in revenue pays the same audit fee as a forty person company with two million. If you are hiring through the certification year, the band you are quoted in January may not be the band you are audited in.

Scope reduces days. Audit duration is calculated on the people inside the ISMS scope, not the whole company. This is the single largest lever you control, and it is decided months earlier when you draw the boundary. Getting that wrong in either direction is expensive, which is why scope and the Statement of Applicability is worth more attention than it usually gets.

Budget for three years, because the certificate is a three-year object

An ISO 27001 certificate runs on a three-year cycle. Year one is the certification audit. Years two and three are surveillance audits, each roughly a third of the initial fee. At the end of year three you recertify, which costs approximately what year one cost.

YearEventCost relative to year one
1Stage 1 and Stage 2100%
2Surveillance~33%
3Surveillance~33%
4Recertification~100%

So a company of 50 people looking at €16,000 for certification is really looking at roughly €27,000 of certification body fees over three years, before anything else. A three-year total is the honest number to take to a board, and it is also the number that makes the annual cost look reasonable rather than alarming.

What the consultant quote covers

Consultant support for an SME programme runs from about €6,000 for coaching and templates to €45,000 for someone managing the whole thing. The wide range is not mostly about quality. It is about how much of the work stays with you.

What a consultant quote reliably includes: gap analysis, risk assessment method, the Statement of Applicability, the policy set, and preparation for the audit.

What it reliably excludes: fixing anything the gap analysis finds.

That distinction is the whole game, and it is the reason budgets built from a consultant quote come in at half the eventual cost.

The four lines nobody quotes

1. Your own people, which is the largest line

An ISO 27001 programme in a company of this size consumes somewhere between 0.3 and 0.6 of a full-time equivalent across the certification year, spread over an ISMS owner, process owners, IT, and management. At a loaded cost of €80,000 to €110,000 per head, that is €25,000 to €65,000 of internal time.

It never appears on an invoice, so it rarely appears in a budget, and it is almost always the biggest number on this page. It is also the number that determines whether the project finishes on schedule, because it is the one that gets quietly deprioritised when a customer escalation arrives in month four.

2. The remediation the gap list produces

The gap analysis is priced. Closing the gaps is not. What comes out depends entirely on where you are starting, but the recurring items in companies without a security function are consistent: multi-factor authentication extended past the main identity provider, centralised logging where there was none, endpoint management, backup verification that has actually been tested, a joiner and leaver process that runs reliably.

Depending on how much of that already exists, this line runs from a few thousand euros of licences to a serious infrastructure project. It is the line with the widest variance and the one worth quantifying before you sign anything, which is what a structured audit ahead of the programme is for.

3. Internal audit, and the independence problem

Clause 9.2 requires internal audits, and requires that auditors do not audit their own work. In a company of forty people, the person who built the management system is the only person who understands it, and they are therefore the one person who cannot audit it.

That leaves three options: train a second person, use another function or group entity, or buy it in. External internal audit for an SME scope runs €4,000 to €12,000 a year, every year, not once.

4. Penetration testing and technical assurance

ISO 27001 does not mandate a penetration test. Auditors ask about technical vulnerability assessment under A.8.8, and for most software and service companies a test is the practical answer, particularly when customers are asking for the report anyway. Budget €4,000 to €10,000 annually.

Three honest budget shapes

Year one, all in, for a company inside the 26 to 125 employee range:

ShapeCertification bodyExternal supportInternal timeRemediation and toolingYear one total
Lean, strong starting position€14,000€8,000€25,000€5,000~€52,000
Typical SME€16,000€22,000€40,000€18,000~€96,000
Consultant-led, weak starting position€18,000€45,000€55,000€35,000~€153,000

The published figure people quote each other for a mid-market SME is €50,000 to €80,000, and it is roughly the middle row with internal time removed. Whether that spend is the right one is a separate question, covered in is €50K for ISO 27001 worth it.

Where the money is actually wasted

Three patterns account for most of the overspend we see.

Paying consultants to write, then paying again to redo. Policies produced by someone outside the business describe a company that does not exist. At Stage 2 the auditor asks the people named in them what they do, and the gap becomes a finding. Writing takes hours. Rewriting takes months.

Running the calendar in the wrong order. Your management system has to have been operating for roughly three months before Stage 2 for the evidence to exist. Teams that perfect the documentation first and start the evidence clock afterwards add a full quarter, and a quarter of a programme at this burn rate is real money. This is covered in more detail in how long ISO 27001 really takes.

Treating 93 controls as 93 projects. Most of Annex A is already partly happening and needs recording rather than building. Sorting the controls by what kind of work they represent, rather than working through them in numerical order, removes weeks. That grouping is set out in the Annex A controls grouped for real work.

One structural change worth knowing about

Every valid ISO 27001 certificate is now issued against the 2022 version of the standard. The transition window for certificates issued under the 2013 edition closed on 31 October 2025, so a supplier presenting a 2013 certificate today is presenting an expired one.

This matters commercially rather than technically. If a customer questionnaire asks for your certificate and a competitor’s is stale, that is a live differentiator this year. It also means any implementation guidance published before 2023 is describing a control set that no longer exists.

The technical reality: what the cheapest path leaves open

There is a version of this programme that comes in at the bottom of every range. Narrow the scope hard, buy a template set, run the minimum evidence period, use the cheapest accredited body, and skip the technical remediation because Annex A does not force a specific standard of implementation.

It works. You get the certificate, and the certificate is genuine.

What it leaves is a control set that is documented rather than operating. A.8.8 says manage technical vulnerabilities, and a scanner that runs monthly into a report nobody reads satisfies it. A.8.15 says keep logs, and logs written to a disk nobody queries satisfy it. A.8.16 asks for monitoring, and this is where the gap is widest, because the control can be met with a documented procedure while nothing is actually watching.

The certificate answers the customer’s question. It does not answer whether you would notice an intrusion. Those are different questions, and the second one is not addressed by spending more on the first.

The cheaper approach is to know which gaps are documentation and which are technical before the programme starts, close the technical ones with tooling that produces its own evidence, and let the certificate fall out of work that was worth doing anyway. That way the audit records what is genuinely running rather than describing what was written down. A vCISO Security Audit exists to produce exactly that split, and the broader picture of getting there without a security team is in ISO 27001 for a company without a security team.

Daniel Grigorovich

Daniel Grigorovich · Founder

I believe that no business should suffer from "compliance checklists" or navigating vague regulatory text. While I still stand by the principle that all software products should be reliable and secure, I want to give companies a way to overcome the challenges faced when implementing these requirements.