
ISO 270017 min read
ISO 27001 Certification Cost: What You Actually Pay For
ISO 27001 certification cost depends on the route you choose. See where the money goes, what drives it up and when a self-assessment certificate is enough.
By Zertify Redaktion
ISO 27001 certification cost depends mainly on the route you take, not on the standard itself. An accredited audit combines audit fees, internal working time, and often consulting and tooling, while a self-assessment certificate such as Zertify's has one visible fee and a much smaller time commitment.
No honest article can give you one fixed number. Fees vary by certification body, company size and scope, and quoting figures without a source would mislead you. What we can do is show you every cost block, so that you can ask the right questions and compare quotes properly.
The short answer
There are two broad routes to an ISO 27001 certificate:
- Accredited third-party certification. An external certification body, itself accredited, audits your information security management system (ISMS). You pay for the audit, and usually for a lot of preparation.
- Self-assessment certification. You answer a structured assessment about your own practices. If you pass, a certificate is issued. Zertify works this way, with certificates issued by SICE (Swiss Institute of Certification and Education).
The second route is not an accredited certification. It shows that you have assessed and documented your approach to information security against the standard. It does not carry the weight of an independent audit. We explain that difference further down.
Where the money goes in an accredited route
Most owners only think about the auditor's invoice. In practice, it is often not the largest block. Here is the full picture.
1. Internal time
This is the cost that gets underestimated most often. Someone in your company has to define the scope, run a risk assessment, decide which controls apply, write policies and collect evidence. In a small business, that someone is usually the owner or a senior person who already has a full day job.
The work follows the structure of ISO 27001:2022. Clause 4 asks you to understand your context and set the scope of the ISMS. Clause 5 covers leadership and the information security policy. Clause 6 covers planning, including risk assessment and risk treatment. Clause 7 covers support, such as competence, awareness and documented information. Clause 8 covers operation. Clause 9 covers performance evaluation, including internal audit and management review. Clause 10 covers improvement.
Every one of these clauses takes hours, and those hours have a price even if they never appear on an invoice.
2. Consulting
Many companies hire a consultant to build the ISMS, write the documents and prepare them for the audit. Consulting can cost more than the audit itself, especially if you start from zero. It is optional. A small company with someone who has the time and the interest can do the groundwork alone, but it takes longer.
3. Tools and technical measures
ISO 27001:2022 includes Annex A with 93 controls in four themes: organizational, people, physical and technological. You do not have to implement all of them. You decide which apply and justify this in a Statement of Applicability. Still, gaps often show up. Typical examples are missing backups, no multi-factor authentication, unmanaged laptops or no formal onboarding and offboarding process.
Closing these gaps costs money for software, licences or hardware. Some of it you would have needed anyway. It is a security cost more than a certification cost, but it lands in the same budget.
4. Certification body fees
In an accredited route, the certification body charges for the audit work. The process normally runs in two stages. Stage 1 reviews your documentation and readiness. Stage 2 checks that the system works in practice. After you are certified, the certificate runs for three years, with surveillance audits in between and a recertification audit at the end of the cycle.
This means the audit is not a one-off cost. It repeats, and you should ask for the full three-year price in each quote, not just the first audit.
5. Ongoing upkeep
An ISMS has to be alive. You need to run internal audits, hold management reviews, update the risk assessment, handle incidents and keep records. This takes recurring time every year. If you budget only for the first certificate, you will be surprised in year two.
What drives the price up or down
Several factors change the total, whatever route you choose:
- Size and headcount. More people and more systems mean more audit effort.
- Scope. Certifying one product or one team costs less effort than certifying the entire company.
- Number of locations. Each additional site can add audit time.
- Starting maturity. If you already have access control, backups, policies and training in place, you mostly need to document and connect them.
- Complexity of your technology. Custom software, cloud infrastructure and many suppliers widen the risk assessment.
- Regulatory pressure. Clients in finance, health or the public sector may demand more evidence.
A ten-person agency with a clear scope and tidy cloud tools has a very different cost profile from a company with several sites and in-house data centres.
The self-assessment route and its cost
A self-assessment certificate removes most of the blocks above. There is no external auditor on site, no stage 1 and stage 2, and no surveillance cycle. You work through the assessment, answer honestly and see where you stand. The certificate fee is shown openly on the pricing page.
The assessment itself is not a formality. It asks you about the same topics the standard covers, and a weak result means no certificate. It also works as a useful gap check. You can see which areas of your information security are thin before a customer asks.
Speed is the other difference. Zertify issues the certificate within 4 hours after a passed assessment and payment. An accredited audit usually takes months from kick-off to certificate.
For a wider comparison of costs across ISO standards, read our guide to ISO certification cost.
When an accredited audit is worth the money
A self-assessment certificate is the wrong tool in some cases. Choose an accredited audit when:
- a tender explicitly requires accredited ISO 27001 certification,
- a customer contract names an accredited certificate as a condition,
- a regulator or an insurer asks for independent verification,
- you handle highly sensitive data for large clients who will check your supplier status.
In those cases, a self-assessment certificate will not be accepted, and spending on it would be wasted. Check the requirement in writing before you decide. Our article on accredited or not explains the difference in more detail.
If nobody is demanding an accredited certificate, a self-assessment can be a sensible first step. It documents your efforts, supports your sales conversations and prepares the ground if you later move to a full audit.
How Zertify fits in
Zertify offers a certificate for ISO 27001:2022 Information Security Management based on a self-assessment. It is aimed at small and medium businesses, agencies and start-ups that want a clear, documented position without a long audit project.
Here is how it works:
- You start the assessment and answer questions about your information security practices.
- If you pass, you pay the fee listed on the pricing page.
- The certificate is issued by SICE within 4 hours.
To be clear: this is not an accredited certification. It does not replace an independent audit where one is required. It is an honest, structured way to assess and show your approach to information security.
Checklist: build your ISO 27001 budget
Use this list before you request quotes or start an assessment.
A practical way to decide
Start with the requirement, not the price. If a customer or tender asks for accredited certification, the question is settled, and your job is to find a fair quote and plan the work. If the requirement is vague or absent, begin with a self-assessment. It shows your real position at low effort, and it gives you a document you can share.
You can always move to an accredited audit later. The work you do now on scope, risks and policies carries over.
Frequently asked questions
How much does ISO 27001 certification cost?
There is no single price. In an accredited route, the cost combines audit fees, internal working time, possible consulting and technical improvements, and it repeats through surveillance audits. A Zertify self-assessment certificate has a fee shown on the pricing page.
Is a self-assessment certificate the same as an accredited ISO 27001 certification?
No. A Zertify certificate rests on a self-assessment and is issued by SICE. It is not an accredited third-party certification. If a tender, contract or regulator requires an accredited certificate, you need an audit by an accredited certification body.
Why is the audit fee only part of the cost?
Preparing for the audit takes internal time, and you may need consulting, tools or security improvements. After certification, you still have to run internal audits, management reviews and surveillance audits every year.
How fast can I get a Zertify ISO 27001 certificate?
Zertify issues the certificate within 4 hours after a passed assessment and payment.
Can I start with a self-assessment and move to an accredited audit later?
Yes. The work on scope, risk assessment and policies carries over to a later accredited audit, so the self-assessment is a useful first step.

