ISO 27001 certification Canada: cost, timeline
What certification costs in Canada, split between the consultant and the accredited certification body, how long each stage takes, and why your scope statement moves the price more than your headcount does.
The question behind the question
Most Canadian companies arrive at ISO 27001 the same way. A European or UK customer, or a public sector tender, asks for a certificate and procurement will not move without one. The first internal question is what it costs, the second is how fast it can be done, and the third, which almost nobody asks out loud, is whether the thing being demanded is really ISO 27001 at all.
This page answers the first two and settles the third along the way. Every figure is in Canadian dollars, and every figure is a band rather than a promise, because ISO 27001 pricing is driven by your headcount and scope rather than by a rate card.
What you are actually buying
ISO 27001 certifies an information security management system. It does not certify a product, a network, a cloud environment or a team. An independent certification body audits the management system against the standard and, if it holds up, issues a certificate valid for three years subject to annual surveillance.
That distinction shapes everything else. A customer asking for ISO 27001 wants evidence that your organization runs security as a governed, measured, continuously corrected process with named owners and records. Buying tools does not produce that, and neither does writing policies, although policies are a necessary step. Operating the system long enough to generate records is what produces it, and that operating period is the biggest reason timelines run longer than the sponsor expects.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Accreditation, and why a self-declared certificate is worth nothing
Three roles get confused constantly, and confusing them is the most expensive mistake in this market.
An accreditation body is a national organization that assesses and authorises certification bodies. Each country generally has one recognised body, and those bodies recognise each other through international agreements, which is how a Canadian certificate is accepted by a German buyer.
A certification body is the firm that audits you and issues the certificate. When it has been assessed by an accreditation body for ISO 27001 specifically, it is an accredited certification body, and its certificates carry the accreditation mark.
A consultant or readiness firm helps you build the management system. It cannot audit or certify you. Independence rules prohibit the same organization from consulting on a management system and then certifying it, and a body that offers to do both is telling you something about its accreditation status.
A self-declared certificate, or one issued by a body with no accreditation for ISO 27001, is cheaper because it is worth less. It is a document nobody assessed. When your customer's vendor risk team checks it against the accreditation body's public register and finds nothing, the procurement conversation restarts a year later with your credibility spent. Two checks protect you: confirm the body holds accreditation for ISO/IEC 27001 specifically rather than for some other standard, and confirm that accreditation is recognised internationally if your buyers are outside Canada.
How to select a certification body
Accredited bodies derive audit duration from published audit time tables rather than setting it commercially. The days come from your effective headcount and scope complexity, and the fee is days multiplied by a rate. When two quotes differ wildly, the day count usually differs, not the rate.
Ask each body, in writing:
- The number of audit days for stage 1, for stage 2, and for each surveillance
visit. This is the comparable number.
- The full three-year total, including surveillance and recertification. Some
quotes load the cost into later years.
- The currency. Bodies operating internationally frequently quote Canadian
clients in another currency, and over a three-year contract someone carries the exchange risk. Establish who.
- Whether the audit is remote, on site, or mixed, and who pays travel.
- Whether the assigned auditor has worked in your sector, and whether you may
review the auditor's profile before the engagement begins.
- What the body's accreditation actually covers, with the registration number.
- Lead time to book stage 2. In busy quarters this can add months, which is often
the real constraint on your date rather than your own readiness.
You cannot meaningfully negotiate the day count downward. A body that cuts days below what its accreditation rules require is risking its own status. If one offers to halve the days, something has changed about the declared scope, and it is worth finding out what.
Clauses 4 to 10, the part most projects skip
Annex A gets the attention because it is a list, and lists feel actionable. Teams build a spreadsheet of Annex A controls, work through it, and arrive at stage 2 with an auditor who spends the first morning on something else entirely.
The management system requirements live in clauses 4 to 10, and they are the only part of the standard you cannot exclude.
Clause 4, context. Which internal and external issues affect information security, who the interested parties are and what they require, and then the scope statement itself. Scope is a commercial decision as much as a technical one. Narrow and defensible beats broad and thin, and a scope that excludes a product your customer cares about will be noticed.
Clause 5, leadership. Top management must demonstrate commitment, publish an information security policy, and assign roles and authorities. Auditors test this by interviewing an executive. A sponsor who cannot describe the top risks or the objectives is a finding, and delegating the whole thing to one engineer is the most common structural failure in small companies.
Clause 6, planning. Risk assessment, risk treatment, and information security objectives. The risk assessment has to follow a documented method so that repeat runs are comparable. Objectives must be measurable, with plans that say who does what by when.
Clause 7, support. Resources, competence, awareness, communication and documented information. Competence means evidence that the people holding security duties are qualified to hold them, not simply that training was assigned.
Clause 8, operation. Running the processes you planned, keeping records, and controlling changes. This clause is where the operating period becomes visible, because clause 8 evidence is a trail of dated records rather than a document.
Clause 9, performance evaluation. Monitoring and measurement, internal audit, management review.
Clause 10, improvement. Nonconformity, corrective action, continual improvement. An ISMS with no recorded nonconformities is not a perfect ISMS, it is one that is not being used, and experienced auditors read it that way.
The Statement of Applicability
The Statement of Applicability is the document that ties Annex A to your risk work. For every Annex A control it records whether the control applies, the justification for including or excluding it, whether it is implemented, and where the supporting evidence lives.
It is the auditor's index, and a weak one is the clearest early signal that Annex A was treated as a checklist rather than as an output of risk treatment. Exclusions come back justified as "not applicable" with no reasoning, or every control is marked applicable to dodge the argument, which creates work you did not need and evidence you cannot produce. Write the risk assessment first and let the SoA fall out of it.
Internal audit and management review are prerequisites, not paperwork
Both are clause 9 requirements, and both must have happened, with records, before stage 2. They are not post-certification housekeeping.
The internal audit must be independent of the area being audited. The person who wrote the access control procedure cannot audit it. Small companies solve this by rotating internal auditors between functions or by bringing in an outside auditor who is not the firm that helped build the system.
The management review is a documented meeting where leadership reviews defined inputs, including audit results, nonconformities, objective performance, risk treatment status and improvement opportunities, then makes decisions with owners and dates. A review that produces no decisions reads as a review that did not happen.
Together these two activities typically take three to six weeks and they sit directly on the critical path. Projects that leave them until the last month either delay stage 2 or walk into it with nothing to show for clause 9.
Stage 1 and stage 2, and what each one tests
Stage 1 is a readiness and documentation review, usually one or two days. The auditor confirms the scope, reads the ISMS documentation, checks that the risk assessment and SoA exist and connect, verifies that internal audit and management review have been done, and forms a judgment on whether stage 2 can proceed. It is not a pass or fail exercise in the usual sense. It produces findings and areas of concern, and it is where you learn whether your date is real.
The gap between stage 1 and stage 2 is normally a few weeks to a few months. Closing stage 1 findings is the point of that gap.
Stage 2 tests whether the system described in stage 1 actually operates. The auditor samples records, interviews staff across functions, traces risks through treatment to controls to evidence, and looks for the dated trail. This is where a management system stood up three weeks earlier fails, because three weeks of records is three weeks of records and the auditor will say so.
Findings are graded. Minor nonconformities need a corrective action plan. Major nonconformities must be closed, with evidence, before the certificate is issued, and closing one can take weeks. The certificate typically arrives two to eight weeks after a clean stage 2.
A realistic timeline, and what moves it
From a standing start, plan on nine to fifteen months. A company with mature controls, a tight scope and a dedicated owner can do it in six to eight. Under six months from nothing is rare and usually involves a scope so narrow the customer questions it.
A typical shape:
| Phase | Duration |
|---|---|
| Set the scope | 1 to 3 weeks |
| Gap assessment | 2 to 6 weeks |
| Risk assessment | 3 to 6 weeks |
| Build and remediate | 3 to 8 months |
| Operate and accumulate records | 2 to 4 months |
| Internal audit and management review | 3 to 6 weeks |
| Stage 1, then close findings | 2 weeks to 3 months |
| Stage 2 | 2 to 5 days on site |
| Certificate issued | 2 to 8 weeks after stage 2 |
What moves the date: how many technical gaps the assessment finds, how fast leadership makes scope decisions, whether one person owns the project or it is everyone's third priority, supplier reviews that wait on other companies, and the certification body's booking calendar. What does not move it much is the number of policies, which is the thing teams tend to optimise.
Surveillance audits and the three-year cycle
The certificate is valid for three years and is conditional. A surveillance audit happens roughly annually, at about a third of the initial audit effort, sampling parts of the system rather than all of it. Year three carries recertification, which is longer and broader than a surveillance visit.
The cycle is why ISO 27001 cannot be treated as a project with an end date. A management system left untouched for eleven months and revived a fortnight before surveillance produces exactly the record trail that description implies. Continued certification depends on internal audits, management reviews, risk reassessment and corrective actions happening on a schedule.
The cost, in separate pieces
Keep these four apart. Bundled totals hide which number you can influence.
1. Certification body fees. For most Canadian companies under 250 staff, stage 1 and stage 2 together run $15,000 to $40,000 CAD, scaling with headcount: roughly $15,000 to $22,000 under 25 staff, $20,000 to $30,000 at 25 to 100, and $28,000 to $40,000 at 100 to 250. Above 250 staff or across multiple sites, bodies quote individually, usually above $40,000. Annual surveillance runs $5,000 to $16,000 depending on size.
2. Readiness work. A gap assessment alone runs roughly $8,000 to $20,000 and produces a findings report and a plan that you then execute. Guided implementation, where an outside firm supplies structure and reviews what your team produces, runs $25,000 to $50,000. Full implementation, where the firm builds most of the system, runs $45,000 to $90,000. Ongoing fractional security leadership, which covers the clause 5 accountability the standard asks for, runs $3,000 to $12,000 per month.
3. Internal time. The line nobody quotes and the one that usually dominates. A first certification consumes real hours from engineering, IT, HR, legal and leadership across the better part of a year. Costing it at zero is why projects read as over budget when they are only being honestly accounted.
4. Tooling and testing. A compliance platform subscription if you use one, plus a penetration test, plus any remediation spend such as logging, endpoint management or identity work the gap assessment surfaces. Certification predates the platforms by two decades and plenty of companies certify with a document repository and a spreadsheet. Under about 30 people with a single environment, the subscription often does not pay for itself in the first year.
All in, a first certification in Canada lands around $40,000 to $110,000 CAD in year one with outside help, and $20,000 to $45,000 CAD if the work is done internally. Years two and three run $10,000 to $30,000 CAD a year for the certification body and basic upkeep. Year one is the number vendors quote and it is the wrong number to budget against.
Why implementation is not a sprint
The standard asks for a system that operates, and operation takes elapsed time that no amount of parallel effort compresses. You can write every policy in a month. You cannot produce six months of access reviews, incident records, supplier assessments and corrective actions in a month, and stage 2 samples exactly those.
There is a second reason. A management system built at sprint pace is built by one person and understood by one person, and at stage 2 the auditor interviews people who were not in that room. By the first surveillance audit the sprint has long since ended, and whatever was not absorbed into how the company actually works has quietly stopped happening. The certificate survives three years only if the system was built to be lived in.
Where to start
Three things, in order. Decide the scope, because everything downstream is priced from it. Run a gap assessment, because remediation cannot be honestly scoped or priced before anyone knows what the gaps are. Then talk to certification bodies early, because their booking calendar is often the binding constraint on your date, not your readiness.
To compare accredited certification bodies and Canadian readiness firms on days, scope and three-year cost, use the quote request at iso27k.ca/get-quotes. It goes to multiple providers so the numbers arrive side by side rather than one at a time. This directory is published by TrazTech, a Canadian security and compliance consultancy, which is one of the firms that may respond.
Common questions
Once the certificate is issued, publishing your ISO 27001 certificate safely covers how to show it so buyers can verify it.
How long does ISO 27001 certification take?
Most first-time programs run nine to fifteen months from decision to certificate. The long pole is not the audit, it is operating the ISMS long enough to have records: risk assessment, internal audit and management review all have to have actually happened before stage 2.
Can we get certified without a consultant?
Yes. Plenty of organizations do, particularly if someone internal has run a management system before. What you cannot skip is the operating period, and what most internal attempts underestimate is clauses 4 to 10 rather than the Annex A controls.
What happens if stage 2 finds a nonconformity?
A minor nonconformity usually means you submit a corrective action plan and the certificate follows. A major one means the auditor cannot recommend certification until it is fixed and verified, which can add weeks or a return visit.
Get certification quoted on your scope
Certification cost turns on your scope statement more than your headcount. Send it once and compare Canadian consultants and accredited certification bodies.
Get matchedWhere to go from here
- ISO 27001 certification cost, itemised. The cost broken down between the consultant and the certification body.
- ISO 27001 scope statement. Your scope statement moves the price more than your headcount does.
- ISO 27001 stage 1 and stage 2 audits. What happens in each stage and what gets you held back from the second.
- ISO 27001 certification bodies in Canada. Which bodies are accredited to certify in Canada, and what accreditation means.