01Define the ISMS boundary
State the legal entities, products, sites, people, technology, and exclusions inside scope. Headcount alone does not describe audit effort; complexity and the number of locations also change audit days.
There is no honest single average. Price six lines separately: implementation, Stage 1 and Stage 2, tooling, internal labor, surveillance, and recertification. Certification bodies scope the audit from duration and day rates; consultant and tooling examples are separate purchases.
Your budget needs six distinct classes: implementation advice, the initial Stage 1 and Stage 2 audit, tooling, internal labor, surveillance in each following year, and recertification. Add optional remediation and training only when the scoped gap analysis identifies them.
| Lifecycle line | Published example or method | Scope and limitation |
|---|---|---|
| Stage 1 + Stage 2 | Scope-priced quote | Audit duration and day rates vary with the certified scope. Source, verified 2026-08-05. |
| Implementation advice | £8,500–£11,500 | Published starting fees for guided through full SME support (10–49 employees). Source, verified 2026-08-05. |
| ISMS tooling | €99–€799 / month | One software vendor’s published company-size bands, billed annually. Source, verified 2026-08-05. |
| Internal labor | Model from internal hours | Program hours × each contributor’s loaded hourly cost. Source, verified 2026-08-05. |
| Surveillance audit — each year | Scope-priced quote | Separate quote lines for surveillance in years 1 and 2. Source, verified 2026-08-05. |
| Year-3 recertification | Scope-priced quote | A separate recertification line in the certification-body quote. Source, verified 2026-08-05. |
Quoted fees remain in their source currency. We do not convert or add them because exchange rates, organization sizes, tax treatment, inclusions, and billing periods differ.
Build three scenarios from your own scope: internal-led, consultant-assisted, and managed. In each, use the same certification-body quote and change only who performs implementation, evidence, internal audit, and ongoing maintenance.
For internal labor, use the ledger method: hours for each contributor multiplied by that contributor’s loaded hourly cost. A blank labor line is unknown, not zero.
Request a three-year schedule, not only a first-year total. The schedule should identify the audit days and day rate for Stage 1, Stage 2, both surveillance audits, and recertification, plus application, certificate, travel, and follow-up charges.
NQA says certification quotes are based on audit duration and day rates and should separate Stage 1, Stage 2, annual surveillance in years 1 and 2, and recertification in year 3. No universal fee is published.
These records are price anchors and quote methods, not a blended market benchmark. Provider-published figures show what that provider advertised for a defined scope on the verification date. Certification-body accreditation and quote inclusions still need direct confirmation.
A low number can be a software subscription, a consultant’s readiness work, or only the certification-body audit. It is useful only when the scope and renewal obligations travel with it.
Do not add the examples on this page into one total: they use different scopes, company sizes, billing bases, and currencies.
| Factor | What it pays for | What it does not prove |
|---|---|---|
| Consultant | ISMS scope, risk process, Statement of Applicability, policies, implementation support, and audit preparation | Authority to issue the certificate |
| Certification body | Independent Stage 1 and Stage 2 audits, certification decision, surveillance, and recertification | That implementation consulting or tooling is included |
| ISMS platform | Workflow, documents, evidence, risk and control records, depending on the product | That the ISMS works or that an accredited body will certify it |
| Internal team | Decisions, control operation, evidence, remediation, interviews, and management review | A vendor invoice — the cost must be modeled from time |
The cleanest comparison is one scope sheet sent to consultants and certification bodies, with recurring work visible before you choose either provider.
State the legal entities, products, sites, people, technology, and exclusions inside scope. Headcount alone does not describe audit effort; complexity and the number of locations also change audit days.
Request implementation or readiness support from a consultant and the certification audit from an accredited certification body. Keep both statements of work visible so no one sells preparation as the certificate.
Require Stage 1, Stage 2, application and certificate fees, travel, each surveillance audit, and recertification. Record audit days and day rates, not only the final total.
Model internal labor by role and hours. Add tooling, remediation, technical controls, training, and outsourced internal audit only when your scope requires them.
The distinctions that keep an audit quote from being mistaken for an all-in program budget.
Send your ISMS boundary, employee count, sites, current maturity, and target date. We manually review the request before routing it to relevant ISO 27001 providers.
Free and anonymous. We’ll follow up by email.