Any Questions?

Feel free to reach out if you would like to find out how Athereon GRC can support you with current governance, risk and compliance issues.

2.9.2026
8 minutes

ISO 27001 Certification: Costs at a Glance

€15,000 or €150,000. Both figures are correct answers to the question of what an ISO 27001 certification costs, depending on which company is behind it. Anyone looking for a single ballpark figure will be disappointed here. Anyone who wants to understand what makes up the price will find an answer here that actually allows for planning.

One point up front, because it changes the starting situation: The transition period for the revised ISO/IEC27001:2022 standard expired in October 2025. Anyone starting now will automatically be certified against the current version. A separate migration is therefore unnecessary, but the expanded requirements on topics such as threat intelligence or cloud security apply from the outset.

What Makes up the Costs of ISO 27001 Certification

Roughly speaking, four cost blocks can be distinguished, and they carry different weight:

  • Audit fees charged by the certification body: usually only 20 to 30% of total costs.
  • Consulting and internal personnel expenses: 60 to 75%. The actual focus, more on this below.
  • Software and technical measures: highly dependent on your own starting position.
  • Ongoing costs after initial certification: approximately 30 to 40% of the original audit costs per year; a line item that many budgets simply overlook in the first year.

The certification body's invoice may appear the most daunting at first glance, but it rarely accounts for the largest share.

What the certification body actually charges

The certification process is conducted in two stages: Stage 1 reviews the documentation. That is, the scope of the ISMS (Information Security Management System), the risk assessment, and the Statement of Applicability. Stage 2 examines actual practice on site. The certification body bills per audit day, typically between €1,200 and €2,000. The number of days required is determined not by company size alone but by the so-called effective headcount within thescope. In other words, how many people actually work within the ISMS scope, along with IT complexity and the number of locations.

For a smaller company with a clearly defined scope, two to five audit days are realistic; for a mid-sized company with multiple locations, five to ten is more likely. That amounts to a total of between €3,000 and €20,000 for the certification process alone. A figure that quickly seems small in relation to the other items.

One detail deserves a second look before the cheapest offer wins the bid: accreditation. A certification body with DAkkS accreditation (or an equivalent accreditation body) is subject to stricter requirements regarding audit time and auditor qualifications than a non-accredited provider, and issues correspondingly higher invoices. However, when it comes to customers, insurers, or tenders, usually only the accredited certificate carries any weight. Anyone saving here may be saving at the wrong end.

The real cost driver lies elsewhere

It's not the audit that drives up costs, but the preparation. Consulting services can be roughly divided into three tiers. A pure gap analysis, which compares the current state against the standard, costs between €3,000 and €6,000. Workshop-format support, in which the company writes the documentation itself and the consulting team only serves as a sparring partner, ranges from €8,000 to €15,000. Full project support over ten to twenty consulting days—including document creation—ranges between €15,000 and €35,000. Which level is the right fit depends on how much expertise and capacity are already available in-house.

Added to this is internal effort, which is often glossed over in proposals because it doesn't appear on any invoice: 20 to over 150 person-days, distributed across project management, IT, and executive leadership. These days are missing from day-to-day operations—a cost factor that many budgets simply fail to account for.

A typical scenario: A software company with around 80 employees allows itself six months to build the ISMS. The IT director invests about two days per week, executive leadership significantly less, but at critical junctures, when approving the risk methodology, for instance, or the security policy. If these internal hours are calculated at standard market rates, this item alone often exceeds the consulting invoice.

How software shifts the effort

This is where ISMS software comes in without making the certification itself any cheaper. Tools such as the Athereon GRC platform take over risk inventory, action tracking, and evidence management, which otherwise get lost in Excel spreadsheets and email threads. The effect: fewer person-days for project management and IT, offset by ongoing license costs of roughly €2,000 to €10,000 in the first year. Whether that pays off depends on the value of your own time—with tight IT resources, it usually does.

Technical measures: the costs missing from the proposal

One point that hardly ever appears in consulting proposals, because it isn't part of the core service, is that Annex A of the standard requires specific technical and organizational measures—and these have to be paid for independently of consulting and auditing. Multi-factor authentication, a backup concept that actually works in an emergency, regular training, and sometimes a penetration test to demonstrate effectiveness. Depending on the starting point, an additional €5,000 to €20,000 can accumulate here, sometimes considerably more if the IT infrastructure has so far evolved organically rather than been planned.

Anyone already running a solid security architecture will pay little extra here. Anyone starting from scratch should not treat this block as a footnote, but factor it in from the outset.

What comes after certification

Certificate in hand, the bill is not yet settled. Years one and two bring surveillance audits, which account for roughly 30 to 40% of the original audit costs. Year three brings recertification, meaning a complete reassessment that is nearly as extensive in effort as the initial audit. Anyone who budgets only for the initial certification will be caught off guard by the third year at the latest.

On top of that come ongoing obligations that rarely appear in quotes. The standard requires annual internal audits, usually outsourced because internal auditors cannot independently evaluate their own work, at €2,500 to €5,000 per cycle. Add to this awareness training for the workforce, maintenance of the risk assessment with every relevant change (new system, new location, new service provider), and ongoing support from the consulting team or an internal function. Anyone who underestimates this will notice at the latest during the surveillance audit, when records are missing that should have been generated throughout the year.

Calculated over the full three-year cycle, these follow-up costs are often on a similar scale to the initial certification itself. That's one more reason to include them in budget planning from the outset rather than renegotiating them year after year.

What This Means for Your Budget Planning

Anyone looking to realistically assess the effort involved in ISO 27001 certification should think not in terms of a single figure, but across three years. A small company typically ends up spending between €15,000 and €50,000 in total over the cycle, a mid-sized company more like €50,000 to €100,000, and larger organizations more than that. The exact range depends primarily on two levers: the scope (the more narrowly defined, the cheaper) and how much internal capacity is actually available.

When it comes to scope, a closer look pays off. Does the entire corporate group really need to be included in the ISMS, or is it enough at first to cover the business unit that actually handles sensitive customer data? An overly broad scope drives up audit days, consulting effort, and internal hours alike, without the additional protection necessarily being justified. Expanding the scope later on is significantly easier than scaling back a certification that was too ambitious on the first attempt.

Accordingly, the next sensible step is rarely a finished quote, but rather a gap analysis: an assessment that shows how far your own organization is from the requirements, which scope actually makes sense, and where the costs will concretely arise in your specific case. Only then is it possible to budget seriously. Everything before that remains a rule of thumb.

In a non-binding consultation with an expert from Athereon GRC, you can find out where your company stands today. Together we’ll assess which scope makes sense for your certification and how consulting and internal effort can be reduced from the outset with the right software.

Schedule a non-binding consultation with Athereon GRC now.

Would you like to learn more?

Book a noncommittal demo appointment with our team to analyze your individual use case with us.