In short
For a mid-sized company (50–250 employees), ISO 27001 certification typically costs €50,000–80,000 in the first year: roughly €10,000–25,000 for the certification audit itself, the rest for building the ISMS, consulting, and internal effort of often 50–150 person-days. Smaller organizations with a tight scope manage with around €20,000–50,000. From project start to certificate usually takes 6–12 months; 3–6 months is achievable with a clear scope and tooling. The certificate is valid for three years, confirmed by annual surveillance audits.
How does ISO 27001 certification work?
The path to the certificate follows a fixed pattern, regardless of industry and size:
- Define the scope: which organizational units, locations, and systems the ISMS covers
- Gap analysis: assess the status quo against the standard's requirements and the 93 Annex A controls
- Build the ISMS: risk assessment, policies, Statement of Applicability (SoA), implement controls, collect evidence
- Prove operation: at least one internal audit and one management review before the certification audit — auditors want to see a system that is lived, not freshly written documentation
- Engage a certification body: choose an accredited body (DAkkS-accredited in Germany, UKAS in the UK, etc.) and secure the audit slot
- Stage 1 audit: review of documentation and audit readiness, often remote
- Stage 2 audit: on-site effectiveness review — interviews, sampling, evidence
- Close findings, certificate issued — followed by annual surveillance audits and recertification in year three
Certification today is exclusively against the current revision, ISO/IEC 27001:2022 — the transition period for certificates under the old 2013 edition ended on October 31, 2025.
What does ISO 27001 certification cost?
Total cost splits into three blocks: the certification audit, external support, and internal effort. Typical figures from the German/European market (as of 2026, indicative — always obtain quotes):
- Certification audit: roughly €6,000–15,000 for smaller organizations, €10,000–25,000 for mid-sized ones. Audit effort in person-days is standardized via ISO/IEC 27006 and driven mainly by headcount in scope, locations, and complexity
- Consulting and external support: roughly €15,000–85,000 depending on starting position and depth of support — from targeted coaching to full-service guidance
- Internal effort: often 50–150 person-days for project management, policy work, risk assessment, control implementation, and evidence collection — more in complex structures
- Tooling: an ISMS platform replaces scattered office files and cuts, above all, internal effort and audit preparation
Bottom line: smaller organizations with a tight scope often reach the certificate for €20,000–50,000 in year one; for mid-sized companies €50,000–80,000 is realistic — noticeably more with multiple sites and complex IT. The biggest cost block is rarely the audit itself but internal time.
What are the ongoing costs after certification?
The certificate marks the start of regular operation — which has recurring costs:
- Surveillance audits: annually in the two years after initial certification, each roughly one third to one half of the initial audit cost
- Recertification: in year three, close to the initial audit in effort
- Internal operation: keeping evidence current, internal audits, management reviews, training — plannable as a continuous part-time effort rather than a year-end sprint
- Tools and, where needed, external support for internal audits
Organizations that automate evidence collection and control monitoring consistently report that surveillance audits turn from projects into routine appointments — the difference lies almost entirely in tooling.
How long does it take to get certified?
For mid-sized companies, 6–12 months from project start to certificate is the norm. Smaller organizations with a clear scope, management backing, and tooling manage in 3–6 months. Three timeline factors are regularly underestimated:
- Lived operation: before the Stage 2 audit, an internal audit and a management review must have run, and the ISMS must demonstrably work — experience says that takes at least two to three months of operation
- Certification body lead times: audit capacity is tight, with NIS2 driving demand — book the audit slot several months ahead
- Closing findings: several weeks can pass between the Stage 2 audit and certificate issuance, depending on the findings
What drives the costs most?
Five factors shape the budget far more than the choice of certification body:
- Scope: every additional site and system increases audit effort and maintenance
- Headcount in scope: it drives the standardized audit person-days under ISO/IEC 27006
- Maturity: organizations that already have processes, inventories, and access concepts don't start from zero
- In-house work vs. consulting: internal know-how saves consulting days — but costs internal capacity
- Tooling: scattered spreadsheets create search effort and duplicate maintenance; a platform with framework mapping cuts the running effort significantly
How can you make certification cheaper and faster?
The most effective levers from practice:
- Start narrow: certify a clearly bounded scope (e.g. core product and central IT) and expand later
- Reuse what exists: integrate existing processes, registers, and continuity plans instead of documenting in parallel
- Automate evidence: pull recurring proofs (access reviews, backups, patching) from source systems instead of filing them manually
- Use consulting surgically: for risk methodology, the SoA, and audit preparation rather than full-time accompaniment
- Anchor ownership early: a named security officer role with a time budget beats any external document package
- Book the audit slot early: use the certification body's lead time in parallel with implementation
Flux Platform targets exactly the most expensive parts: asset inventory from the CMDB, a risk register with workflows, controls and Statement of Applicability mapped to ISO 27001, NIS2, SOC 2, and GDPR, automated evidence collection, and audit management with findings and remediation plans — so internal effort drops and the audit is prepared before it starts.
Frequently asked questions
How much does ISO 27001 certification cost in total?
Smaller organizations with a tight scope: typically €20,000–50,000 in the first year. Mid-sized companies (50–250 employees): usually €50,000–80,000, more with multiple sites and complex IT. This covers the certification audit (roughly €6,000–25,000), external support, and internal effort — the latter is almost always the largest block.
How long does it take to get ISO 27001 certified?
Typically 6–12 months from project start to certificate for mid-sized companies. With a clear scope, management backing, and tooling, 3–6 months is achievable. Plan for at least two to three months of demonstrably lived ISMS operation before the Stage 2 audit, plus the certification body's lead time.
How long is an ISO 27001 certificate valid?
Three years. Annual surveillance audits take place in the two years after initial certification, followed by recertification in year three with an audit close to the initial one in scope.
Is ISO 27001 certification legally required?
There is no general legal obligation. However, NIS2 requires systematic security risk management that an ISO 27001 ISMS largely covers, and in procurement and customer audits the certificate is increasingly a de-facto requirement — especially for IT providers and suppliers of regulated companies.
What happens if the audit finds nonconformities?
Findings are normal and do not automatically mean failure. Minor nonconformities are addressed with a corrective action plan and usually verified at the next audit; major nonconformities must be demonstrably closed before the certificate is issued, typically within a few weeks to about three months.
Can you get certified without external consultants?
Yes — with internal know-how on risk methodology and the standard's requirements plus suitable tooling, it is feasible. Without prior experience, targeted consulting accelerates the risk assessment, the Statement of Applicability, and audit preparation most. The most common mid-market model is a middle path: in-house work plus targeted coaching.