If you’ve started pricing out ISO 27001 certification, you’ve probably noticed the numbers you find online are all over the place — quotes from “a few thousand dollars” to well into six figures. That’s not vague marketing; it’s because ISO 27001 cost genuinely depends on the size and complexity of what’s being certified, and no two organisations have the same scope.
This guide breaks down where the money actually goes, so you can sanity-check any quote you receive and understand what drives it up or down.
The two cost buckets people confuse
Almost every conversation about “ISO 27001 cost” conflates two completely separate expenses:
- Implementation and consulting — the work of building your Information Security Management System (ISMS): gap analysis, risk assessment, policies, the Statement of Applicability, control implementation, and internal audit. This is paid to a consultant (or absorbed as internal staff time if you self-implement).
- Certification audit fees — paid directly to an accredited certification body (e.g. DNV, BSI, SAI Global) to actually audit and certify you. This is separate from consulting and is priced independently, usually based on your headcount and number of sites.
A quote that only covers one of these isn’t a full picture of what you’ll spend to get certified. Ask explicitly whether a quote includes certification body fees or only the implementation work.
Typical cost ranges in Australia
These are indicative ranges based on typical Australian market engagements — treat them as a sense-check, not a quote. Actual pricing depends on scope, existing security maturity, and how many locations and systems are in play.
| Organisation size | Implementation & consulting | Certification body audit (Stage 1 + 2) |
|---|---|---|
| Micro / startup (1–15 staff, single site, cloud-native) | Lower end of the market | Lower end of the market |
| Small-to-mid (15–75 staff) | Mid-range, scales with scope | Mid-range, scales with headcount |
| Mid-to-large (75–250+ staff, multiple sites or complex infrastructure) | Higher end, often staged | Higher end, priced per site/headcount |
The single biggest driver inside each band isn’t headcount on its own — it’s scope. A 40-person company with one cloud environment and no physical sites to secure will cost less than a 40-person company running its own data centre across three offices.
What actually moves the price
- Scope of the ISMS. Certifying “the whole company” costs more than certifying a specific product, team, or business unit — and a tightly scoped ISMS is often a legitimate, faster path to your first certificate.
- Existing maturity. If you already have documented policies, an asset register, and some access controls in place, a consultant has less to build from scratch.
- Infrastructure complexity. Pure SaaS/cloud shops are generally cheaper to certify than businesses running physical servers, multiple offices, or regulated environments (health, finance, government supply chain).
- Number of sites. Certification bodies charge per site for audit days — a business with one office is cheaper to audit than the same business spread across three.
- Industry-specific obligations. Businesses in health, finance, or government supply chains often need additional evidence and controls mapped to other frameworks (e.g. the Essential Eight, APRA CPS 234), which adds implementation time.
- How the consultant prices. Hourly billing is genuinely unpredictable — scope creep and slow client-side turnaround both inflate the final bill. Fixed-price engagements put that risk on the consultant, not you.
Costs that don’t stop at certification
The certificate isn’t a one-off purchase — it’s a three-year cycle:
- Year 1 and Year 2: annual surveillance audits with your certification body, typically priced lower than the original Stage 1+2 audit.
- Year 3: a recertification audit, roughly comparable in scope to the original certification audit.
- Ongoing internal cost: someone needs to own the ISMS — running internal audits, updating the risk register, and keeping policies current. This is real time even if you never pay a consultant again after year one.
Budgeting for the full three-year cycle, not just the first certificate, avoids an unpleasant surprise at the year-one surveillance audit.
Why fixed-cost pricing matters more than the headline number
The most common way ISO 27001 engagements blow their budget isn’t a bad initial quote — it’s hourly billing meeting a slow-moving project. Document reviews stall, stakeholders are hard to schedule, and the clock keeps running.
A fixed-cost engagement, scoped properly up front against your actual environment (not a generic template), removes that risk entirely. You know the number before you start, and it doesn’t move because your team took three weeks instead of one to review a policy draft.
Getting an accurate number for your business
Every range above is a starting point for a conversation, not a quote. The only way to get an accurate number is a short scoping conversation covering your headcount, sites, infrastructure, and what (if anything) you already have documented.
If you want a fixed-price quote rather than another range, book a free consultation and we’ll scope it properly before you commit to anything.