"How much does ISO 27001 actually cost?" is the question every founder asks, and almost nobody answers honestly. Quotes range from £5,000 to £60,000, and the reason for that spread is rarely explained.
Here is the full picture for a UK company in 2026: the four cost buckets that make up the total, realistic numbers for each, and the ones you can genuinely control.
The four cost buckets
Every ISO 27001 budget is made of the same four things: the certification body, your internal time, external consultancy, and tooling. Most quotes only mention the first.
1. The certification body (the audit itself)
This is the one unavoidable external cost. A UKAS-accredited certification body charges by auditor-day, and the number of days is driven by your headcount, your number of sites, and the complexity of your scope.
For a typical UK SME, expect roughly:
- 10–20 staff: £4,000–£6,000 for Stage 1 and Stage 2 combined
- 30–50 staff: £6,000–£9,000
- 100+ staff: £10,000 and upwards
And remember this is not a one-off. Surveillance audits in years two and three typically run at 30–40% of the initial audit cost, and you re-certify every three years.
2. Your internal time (the cost nobody budgets)
This is the largest cost in almost every certification, and it never appears on a quote.
A first-time ISO 27001 implementation typically consumes 200–400 internal hours. At a blended £40/hour, that is £8,000–£16,000 of real staff time — usually your most senior technical people, who have other things to do.
What drives that number up? Almost always the same thing: archaeology. Hunting for the policy that was approved in a Slack thread. Rebuilding a risk register that lives in three spreadsheets. Proving a control was operating in March when the evidence is in someone's inbox.
3. Consultancy (optional, and often mis-spent)
A UK ISO 27001 consultant typically charges £5,000–£15,000 for a guided implementation, more for a full managed service.
Good consultants are worth it — for scoping decisions, risk methodology, and getting you audit-ready without learning by failure. Where companies waste money is paying consultant day rates for administrative work: chasing evidence, formatting documents, updating registers. That is not advice; that is data entry at £900/day.
4. Tooling (the line you fully control)
Here is where the £5,000-to-£60,000 spread really comes from.
- Spreadsheets: £0 in cash. But they are the single biggest driver of bucket #2 — they are why the 200-hour project becomes a 400-hour project.
- Enterprise GRC platforms: £10,000–£30,000+ per year. Powerful, and priced for companies with a dedicated compliance function.
- SME-priced compliance platforms: £500–£2,000 per year. Same core job — risk register, controls, evidence, policies, audit trail — without the enterprise price tag.
We built PilotVantage because we kept meeting 40-person companies who had been quoted £36,000 a year for software that a 40-person company simply does not need at that price. Our plans start at £49/month, and there is a free tier.
Worked example: a 30-person UK SaaS company
| Cost bucket | Realistic range |
|---|---|
| Certification body (Stage 1 + 2) | £6,000–£9,000 |
| Internal time (250–350 hrs) | £10,000–£14,000 |
| Consultant (partial support) | £5,000–£8,000 |
| Tooling (12 months) | £0–£30,000 |
| Year-one total | £21,000–£61,000 |
The difference between the bottom and the top of that range is not the standard. It is the choices you make about tooling and about how much of your own team's time you are willing to burn.
Where companies overspend
- Enterprise tooling at SME size. If you have no dedicated compliance team, you will not use 80% of what you are paying for.
- Consultants doing admin. Buy their judgement, not their typing.
- Over-broad scope. Every extra system and site in scope adds auditor-days. Scope to what your customers actually ask about.
Where companies underspend, and regret it
- Internal audit. Skipping it is the fastest route to a Stage 2 nonconformity.
- Management review. Auditors check that leadership is genuinely engaged. A 20-minute meeting with no minutes will be spotted.
- Evidence discipline. Collecting evidence continuously costs almost nothing. Reconstructing a year of it in the fortnight before an audit costs a fortune.
The honest summary
A 30-person UK company should budget £20,000–£30,000 for year one of ISO 27001 if it is sensible about scope and tooling, and £50,000+ if it is not.
The certification body's fee is fixed. Your internal hours are the biggest number, and they are driven directly by how findable your evidence is. That is the lever.
Not sure where you stand? Our free ISO 27001 gap assessment takes 10 questions and gives you an instant maturity score. No email wall, no "book a demo to see your results" — because you should be able to find out where your gaps are before you spend a penny.