Skip to content

iso-27001

What does ISO 27001 certification cost for a mid-sized company?

Auditor days are tied to accreditation and are not negotiable, the day rate is. Market ranges for the audit, consulting and internal effort.

By KaitoSec Team · Published 29 August 2026 · 16 min read

The cost of an ISO 27001 certification breaks into five blocks: the certification audit, internal staff effort, optional consulting, the tool you run the ISMS in, and the recurring cost across the three-year cycle. The number of auditor days is tied to accreditation requirements and is not negotiable. Only the day rate is, and the one thing you can influence is whether additional effort arises at all.

What makes up the cost of an ISO 27001 certification?

Five blocks determine the price, and only one of them ends up on an invoice from the certification body. The certification audit is the most visible of them; next to it sits the internal staff effort for building and running the ISMS. External consulting stays optional, as does the question of which tool you keep the ISMS in.

There is a regulatory reason why the third block exists at all. An accredited certification body may not advise you and certify you at the same time. The separation follows from the independence requirement placed on the body. Anyone who wants support building the system has to buy it elsewhere or do it in house.

For budget planning the split matters more than it first appears, because the five blocks are approved by different people. The audit fee is an external invoice with a clear recipient, the internal effort never shows up in an approval and is paid in staff capacity anyway, and the recurring costs belong in multi-year planning, otherwise the recertification appears unexpectedly in year three. Roll everything into a single figure and you lose exactly the information the approval needs. What the certificate actually requires in substance is summarised in our ISO 27001 overview.

One cost driver runs through all five blocks: the scope. It determines how many employees enter the audit-time calculation, how many processes have to be documented and how much evidence you keep current every year. A scope that covers the whole company out of caution, when only one business unit needs certifying, raises every single block at once. It is the only lever that works before the first invoice is written.

What does the certification audit itself cost?

The audit effort splits into two figures with completely different room for negotiation: the number of days and the price per day. Asking the certification body for a cheaper audit almost always means negotiating in the wrong place.

The number of auditor days derives from accreditation requirements, essentially from the number of employees in scope. An accredited body may not go below that base without putting its own accreditation at risk. Anyone offering you noticeably fewer days than the competition is either giving you a weaker audit or is not working under accreditation.

Ask the certification body to put its derivation of the audit days in writing. A serious body will disclose which employee count it starts from, which additions and reductions it applies for complexity, the number of sites and the external services you use, and how Stage 1 and Stage 2 follow from that. A body unwilling to explain it is the wrong offer.

The audit runs in two stages. In Stage 1 the auditor reviews the documentation and establishes whether you are audit-ready at all. In Stage 2 they test effectiveness in operation. Both stages are billed, and a weak Stage 1 regularly extends Stage 2.

The day rate, by contrast, is open to discussion. Published provider figures for 2026 reach up to 2,500 euros per auditor day. In practice the range for the Mittelstand sits closer to 1,000 to 1,500 euros, with outliers in both directions, because the rate depends on the expertise and seniority of the auditing body rather than on a price list. Since the day base is fixed, the day rate is the only direct price lever, and it justifies collecting several offers.

Accreditation, on the other hand, is not negotiable. In Germany the DAkkS accredits certification bodies. A certificate without that basis is worth considerably less in tenders and supplier assessments, and it costs you the money a second time. Whether a body is genuinely accredited for ISO 27001 is something you can check yourself in the DAkkS database before you request an offer.

What internal effort arises alongside the external costs?

The largest cost block never appears on an invoice because it is already paid as salary. That is why almost every plan underestimates it. What brings projects to a halt in the end is this block, not the audit invoice.

The work behind it can be named concretely: you define the scope, run a risk assessment, produce the Statement of Applicability, write policies, implement controls, collect evidence, conduct an internal audit and document the management review. Every one of those points is working time from people who keep operations running anyway.

The order of magnitude can at least be bracketed. Two independent provider publications arrive at 90 to 150 person-days for the initial build in a company of around a hundred employees. A third calculates in full-time equivalents instead and reaches a comparable range with half to one full information security officer over twelve months. In the reality of the Mittelstand this rarely spreads across a team. It sits with one person, often part-time, often alongside day-to-day IT operations.

The total figures published online appear to vary by more than tenfold, from 15,000 euros to over 200,000 euros. The reason is almost always the same system boundary: whether internal staff effort is counted or not. Calculations without internal effort land at 15,000 to 60,000 euros for smaller mid-sized companies. Calculations including it land at 90,000 to 150,000 euros, and three mutually independent sources overlap there. Both figures can be correct, they simply answer different questions.

For your own planning that means: settle first which question you are answering. If it is the budget you need approved, the second figure counts. If it is the invoices arriving from outside, the first one does.

What does external consulting cost, and when is it worth it?

Consulting does not replace internal effort, it shortens it. Day rates range by seniority from 500 euros for junior profiles to well above 1,500 euros, and ten to twenty consulting days are realistic in a mid-sized project. It is never mandatory: the standard requires no external support.

Three models have established themselves. The day rate is the most flexible and shifts the volume risk to you. Fixed-price packages for bounded deliverables such as a gap analysis or audit support shift it to the provider. A retainer for an external information security officer covers ongoing operation, not the project.

Day rates are tiered by experience. Junior profiles sit between 500 and 800 euros, experienced consultants between 1,000 and 1,500 euros, specialist boutiques and large audit firms considerably above that. The range is open at both ends because it depends on expertise and seniority. KaitoSec charges from 1,150 euros per day for remote consulting, which places it in the middle of that band. Full terms are on the pricing page, the services under consulting.

Where you apply it weighs more than the rate. Consulting pays off where experience is missing and a mistake is expensive: cutting the scope for the first time, choosing the risk methodology, preparing for the audit. It does not pay off for legwork. Gathering evidence, putting policies into your own language and clarifying responsibilities is something nobody does better than your own organisation, and otherwise you pay a day rate for work that is cheaper and usually better done in house.

Consulting stays optional in the end. A company with an existing documentation culture and one person allowed the time to learn will manage without it.

What does an ISMS tool cost, and what does it take off your plate?

An ISMS tool reduces neither the audit days nor the need for expertise. It works on the third lever: making sure no additional effort arises. Market figures for the Mittelstand sit at 3,000 to 15,000 euros in the first year, because these are almost always annual subscriptions.

Within that range what matters most is how many people need access and how many frameworks the tool is meant to carry in parallel. For subsequent years the same sources name a similar order of magnitude. A comparison of the available tools is worth more here than with audit costs, because the functional scope varies more between providers than the price does.

What a tool cannot do matters as much as what it can. The auditor days stay unchanged; they depend on the employee count, not on your software. And the decisions you would otherwise buy consulting for are not taken off your hands by any tool: how you cut the scope, which risk methodology you choose and which controls you exclude on what grounds remains professional judgement.

What a tool does take off your plate is the upkeep. Evidence sits where the auditor expects it instead of across four folder structures. The Statement of Applicability stays current because it derives from the controls rather than from a spreadsheet somebody has to update. Risks are maintained continuously instead of reconstructed once a year. And anyone running ISO 27001 alongside NIS2 or BSI IT-Grundschutz maintains the same evidence once instead of three times.

That upkeep is precisely the effort that becomes visible in the audit. It shifts out of internal staff effort and into a predictable annual fee.

One honest limit remains: for a very small scope with a few dozen pieces of evidence, a clean folder structure will do. A tool pays off when several people work in it, when more than one framework is involved, or when the body of evidence grows past the point where anyone can hold it in their head. A badly maintained tool costs money and saves nothing.

The difference from consulting lies in how you buy it. Consulting you buy in days for a decision, and it ends. A tool you pay for annually to maintain a state, and it does not end.

What recurring costs come after the certificate?

The certificate is valid for three years, but it costs money in each of those years. Two surveillance audits at 4,000 to 10,000 euros each and a recertification between 10,000 and 20,000 euros come on top. Budget only for the initial certification and you have planned one third of the cycle.

The rhythm is fixed: initial certification is followed by two annual surveillance audits, with recertification in the third year. Surveillance audits are shorter than the initial audit; the sources evaluated put them in a range of roughly 4,000 to 10,000 euros each. Recertification sits in between, typically at 10,000 to 20,000 euros, because it examines the system in full once more.

Alongside that, internal operation continues. Risks have to be maintained, controls evidenced, and the internal audit and management review carried out every year. The PDCA rhythm is the reason the cost of an ISMS never drops to zero.

It gets expensive where that operation falls asleep. Let the system rest between two audits and reconstruct the evidence four weeks before the appointment, and you pay twice: once in overtime and once in audit time, because incomplete evidence slows the auditor down. Continuous operation is the cheaper variant overall, even if it feels more expensive month by month. Resilience is a cost figure at this point: an ISMS that runs produces its evidence as a by-product. One that only wakes up for the audit date produces it under time pressure and pays for it twice.

Extending the scope mid-cycle, a new site or an acquired company for instance, raises the audit base and with it the cost of the remaining audits. Plan foreseeable acquisitions or site openings into the first scope cut for that reason. A scope built with the right structure from the start can be extended later without having to justify the entire system boundary again.

Where can you actually save on audit costs?

You do not lower the audit price by negotiating, you lower it by not stealing the auditor's time. The number of audit days is tied to accreditation, the day rate sits at 1,000 to 1,500 euros in the market, and only the third item genuinely rests with you. Three categories separate cleanly:

  • Not negotiable: the number of audit days. It is tied to accreditation and derives from the employee count in scope. Any attempt to push here either goes nowhere or leads to a body whose certificate is worth less.
  • Negotiable: the day rate. It is the only direct price lever you have. Collect several offers from accredited bodies and have each one supply its derivation of the days. Only then are you actually comparing like with like.
  • Influenceable: whether additional effort arises. The auditor does not examine your company, they examine your evidence. If it is complete, current and findable, the base effort holds. Whether you secure that with a folder structure or a tool is secondary, as long as it works reliably. If the evidence is not in that state, extra effort arises: an extended Stage 2, nonconformities with corrective actions and a follow-up check, in the worst case an additional special audit.

Above all three stands the scope. It lowers the day base, the internal effort and the risk of nonconformities at the same time, and it is the only lever that takes effect before the first invoice.

In the Mittelstand one further case almost always applies. Anyone documenting ISO 27001, NIS2 and BSI IT-Grundschutz in separate repositories maintains the same evidence several times over. That produces exactly the reconstruction work that costs time in the audit. A shared data model across the frameworks therefore acts directly on the audit effort.

What does the calculation look like in practice?

Starting point

A manufacturing company with 120 employees at one site. The scope is limited to IT operations and product development; production stays outside. There is no existing ISMS, but the IT documentation is maintained. One IT manager takes on the project with roughly thirty percent of their working time.

All figures below come from the market range across several provider publications for the German Mittelstand. They are a worked example, not an offer and not a benchmark.

The sequence in detail

For a scope of 120 employees the market aggregation yields seven to ten auditor days for Stage 1 and Stage 2 combined. At a day rate of 1,000 to 1,500 euros the audit fee therefore lands at roughly 7,000 to 15,000 euros, plus travel costs for on-site appointments.

The internal effort sits at roughly 90 to 150 person-days in the first year, spread over about ten months. At thirty percent project time for one person that is not enough, so departments have to contribute or the timeline stretches.

For consulting, ten to twenty days are realistic in this constellation if they are used deliberately for the scope cut, the risk methodology and audit preparation. At 1,150 euros per day that amounts to 11,500 to 23,000 euros.

For an ISMS tool the order of magnitude at this company size sits at roughly 8,000 to 14,000 euros in the first year.

In years two and three, one surveillance audit at 4,000 to 10,000 euros plus ongoing internal operation come on top, with recertification at 10,000 to 20,000 euros in the third year instead.

Count only the external invoices and you land at roughly 27,000 to 52,000 euros in the first year. Include the internal effort and you arrive at a multiple of that. The conversation with your management gets considerably easier if you say from the outset which of the two figures you mean.

What shifts the calculation

Two levers move the result noticeably, and the scope is the first of them. Had this company included production, considerably more employees would have entered the audit base, affecting the auditor days, the documentation volume and the internal effort at once.

The second is the groundwork already done. Existing and maintained IT documentation shifts the internal effort to the lower end of the range. A company starting from zero and building its asset inventory in parallel sits at the upper end or beyond it.

Frequently asked questions about ISO 27001 costs

What is the minimum an ISO 27001 certification costs?

A meaningful lower bound can only be given with the number of employees in scope, because the auditor days depend on it. For very small organisations with fewer than ten people in scope, the sources evaluated name two to four auditor days, which at market rates produces an audit fee of roughly 2,000 to 6,000 euros. Internal effort comes on top in every case.

Can I get certified without consulting?

Yes. The standard requires no external support. It is realistic when one person is genuinely allowed to take responsibility, is given time for it, and documentation discipline exists in house. If one of those three conditions is missing, the route without consulting is usually not cheaper, only longer.

How long does it take to get the certificate?

Realistic project timelines for the Mittelstand run eight to twelve months. Duration and cost depend on the same factor, namely the scope and the groundwork already in place. The timeline in our ISO 27001 checklist breaks the individual steps down.

Is ISO 27001 cheaper than BSI IT-Grundschutz?

The two cannot be set against each other directly, because they work differently. BSI IT-Grundschutz works with predefined modules and a protection-needs assessment, ISO 27001 with a risk assessment of your own. The effort shifts rather than disappears. One date shifts the calculation further: Grundschutz++ becomes certifiable on 1 January 2027, specifically as ISO 27001 on the basis of Grundschutz++. From that point the two routes converge rather than exclude each other. For getting started with Grundschutz, the Grundschutz starter guide is the right entry point.

Does certification pay for itself?

There is no defensible return figure for it, and anyone quoting one has estimated it. The real drivers are more concrete: tenders that presuppose a certificate, customers demanding it in supplier audits, and the effort for security questionnaires, which drops noticeably once the answers are documented anyway. If you regularly lose time on those three points in sales, certification tends to pay for itself faster than the pure cost calculation suggests. How much revenue is actually at stake depends on two figures only you know: your average deal size and the number of deals recently lost or delayed over a missing certificate. Enter both and our ROI calculator gives you a scenario for it.

  • iso-27001
  • kosten
  • zertifizierung
  • kmu
  • mittelstand
  • isms
  • audit

Back to the blog