What ISO 27001 certification costs

Two invoices, from two different kinds of company. Here is what each one is for, what the published figures say, and what we charge for ours.

What does ISO 27001 certification cost? Two things, bought from two different kinds of company. One is the work of building and evidencing the management system. The other is the audit, performed by an accredited certification body. The audit is the part with published figures:

  • Vanta states that Stage 1 and Stage 2 are typically packaged together in terms of cost, and to expect the price to be in the $14,000-$16,000 range. Source, read 2026-09-28.
  • Drata states that, as part of the combined Stage 1 and Stage 2 package, smaller businesses can expect to pay a $15,000 fee, while larger organizations will pay at least $20,000 and can go upwards of $50,000. Source, read 2026-09-28.

Both describe the audit alone. Neither includes the months of preparation before it, and the preparation estimates further down are the same size or larger.

So the useful question is narrower than the search. Which of the two costs is a quote describing, and who sends the other one? This page takes them in order, then covers the two years after the certificate, then says what we charge.

The two invoices

ISO does not certify anyone. It writes the standard, and certification bodies audit against it. That split is where the two invoices come from.

Preparation
Scope, a risk assessment, the Statement of Applicability, policies, evidence, an internal audit and a management review. You can do it yourself, hire a consultant, or use a platform.
The certification audit
Stage 1 reviews the design and the documents. Stage 2 tests whether the system actually runs. An accredited certification body performs both and issues the certificate.

The two cannot be the same company. The standard for certification bodies sets rules on their impartiality, and consulting for a client you then certify is exactly the conflict those rules exist to stop.

  • ISO describes ISO/IEC 17021-1:2015 as containing principles and requirements for the competence, consistency and impartiality of bodies providing audit and certification of all types of management systems. Source, read 2026-09-28.

What sets the certification audit fee

Audit days. A certification body prices an engagement by how many auditor days it needs, and the number of days comes from your scope.

  • Schellman states that the number of employees in scope plays a part in the total number of audit days needed for Stage 1 and Stage 2, and names it among the factors ISO 27006 considers when calculating audit time. Source, read 2026-09-28.

Headcount is the biggest input. Sites, the number of systems in scope and how complex the management system is come next. A twelve person company with one office and a cloud stack sits at the bottom of every published range for that reason.

That is also the one lever you control. A scope drawn around the product customers actually buy is cheaper to audit than one drawn around the whole company. It is also easier to keep true for three years. Choosing a certification body covers what else to compare once the quotes arrive.

What preparation costs

This is the invoice with no fixed shape. It depends on whether you hire a consultant, buy a platform, or write everything yourself with an engineer’s spare hours. The published estimates cover the first two routes.

  • Drata puts preparation and implementation at $15,000 to $40,000+. Source, read 2026-09-28.
  • Secureframe states that, on average, companies can expect to pay up to $40,000 during the audit preparation process and $15,000+ for the certification audit itself. Source, read 2026-09-28.
  • ISO lists ISO/IEC 27001:2022 at CHF 155 in its store. Source, read 2026-09-28.

The standard itself is the smallest line. Neither vendor estimate counts your own team’s time, and that is real: someone has to own the risk register, answer the auditor, and run the internal audit.

Preparation is also where most of the calendar goes. How long ISO 27001 takes breaks the months down phase by phase, and Annex A for a small team shows which of the 93 controls a startup usually has to evidence and which it can justify excluding.

Years two and three

A certificate is not a one time purchase. It runs a three year cycle, and the certification body comes back in between.

  • Secureframe states that ISO 27001 certification is valid for three years, with a surveillance audit at the end of the first and second years and a recertification audit at the end of the third year. Source, read 2026-09-28.
  • Drata states that annual surveillance audits usually cost around $5,000 annually, and puts a recertification audit every three years at $15,000 to $50,000. Source, read 2026-09-28.
  • Vanta states that each recertification audit costs the same as an original certification audit, between $14,000-$16,000. Source, read 2026-09-28.
  • Schellman states that each surveillance review takes about 1/3 of the initial certification audit time and a recertification review about 2/3. Source, read 2026-09-28.

Budget for all three years before you sign anything. The first year is the expensive one. The next two are shorter visits, but the management system has to keep running between them: a fresh internal audit, a fresh management review and current evidence before each one.

What we charge

Polara G.R.C. prices the preparation half. It is $5,000 one time, and it gets a company ready for certification.

What you are buyingWho charges itPrice
Readiness for certificationPolara Labs$5,000 one time
Stage 1 and Stage 2 auditAn accredited certification bodyQuoted and billed by the body
Surveillance and recertification auditsThe same certification bodyQuoted and billed by the body

The readiness price covers scope and context, the risk assessment and treatment, the Statement of Applicability with all 93 Annex A controls, the policies, the evidence, the internal audit and the management review. It ends with a handoff package the certification body can read before Stage 1.

The audit itself is a separate engagement. The certification body quotes it and bills it, and we publish no figure for it. We would be guessing at somebody else’s price. The ISO 27001 product page lists what the readiness work includes, and the pricing page puts it beside everything else we sell.

Who certifies you

Polara Labs is not a certification body. Certification audits are performed by independent accredited certification bodies.

How to compare quotes

  1. Separate the two invoices. A quote that bundles preparation and the audit from one company deserves a hard look at who is doing the certifying.
  2. Ask for the audit days. A certification body can tell you how many days Stage 1 and Stage 2 will take. The day count is what makes two quotes comparable.
  3. Ask for all three years. The surveillance and recertification visits belong in the number you compare.
  4. Check the accreditation. A certificate from an unaccredited body may not satisfy the buyer who asked for it.

If a buyer asked for SOC 2 instead, or as well, the money works differently. SOC 2 vs ISO 27001 lays the two side by side, and what SOC 2 actually costs itemizes the report.

Questions

How much does ISO 27001 certification cost?
There are two costs. Preparing the management system is one, and the Stage 1 and Stage 2 audit by an accredited certification body is the other. Vanta and Drata both publish a Stage 1 and Stage 2 audit figure for a small company, and Drata and Secureframe publish preparation estimates. Each one is quoted on this page with its source and the date it was read.
What does Polara Labs charge for ISO 27001?
$5,000 one time to get ready for certification. That covers the risk assessment, the Statement of Applicability, the policies, the evidence, the internal audit and the management review. The certification audit is a separate engagement with an accredited certification body, which quotes and bills its own fee.
Why is the certification body fee not included?
Because the body that certifies you has to be independent of whoever helped you prepare. ISO/IEC 17021-1 sets impartiality requirements for certification bodies, and ISO itself does not certify anyone. Keeping the two invoices separate is what makes the certificate worth showing to a buyer.
What does ISO 27001 cost in years two and three?
A certificate runs three years. The certification body returns for a surveillance audit in each of the two years in between, and a recertification audit renews the certificate for another cycle. Published surveillance figures are lower than the first audit because a surveillance visit is shorter.
What makes a certification body quote higher or lower?
Mostly audit days. The number of people in scope, the number of sites and the complexity of the management system set how many days the auditor spends, and the quote follows the days. A narrow, well documented scope is the lever you actually control.

Get audit-ready without a compliance team.

The readiness assessment is free, with no payment and no card. $4,000 one time for SOC 2 Type 1 when you are ready, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Take the free assessment

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.