ISO27K

ISO 27001 certification cost, itemised

This page takes the certification bill apart line by line and shows how each number is arrived at, so you can read a quote and tell whether it is fair before you sign it.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

The certification body portion of ISO 27001 costs a Canadian company roughly $15,000 to $40,000 CAD for stage 1 and stage 2 together, and that is normally between a fifth and a third of what year one actually costs. The rest is consultant fees, an internal time bill nobody puts on paper, a penetration test, and the standards themselves. Below is each line, what it is for, and how the person quoting it worked the number out.

If you want the strategic version, which scope to pick and where the money is wasted, read the ISO 27001 cost breakdown for Canada. This page is the narrower one: the invoice.

How a certification body arrives at its number

A certification body does not price ISO 27001 the way a consultancy prices a project. It sells audit days at a day rate, and the number of days is not a commercial decision. Accredited bodies work from the audit time tables in the ISO/IEC 27006 series, which start from the effective number of people in scope and then adjust for complexity: how many sites, how many distinct technology environments, how much of the operation is outsourced, how much personal information is handled, and whether staff do broadly the same work or twenty different things.

Two consequences follow, and both are worth knowing before you open a quote. The first is that a body cannot discount days very far without putting its own accreditation at risk, so a quote that is dramatically cheaper is usually either a smaller scope than you asked for or an unaccredited certificate. The second is that day rate is the only part genuinely open to negotiation, and it is the part nobody asks about.

Certification body line items, first cycle, CAD
LineTypical (CAD)What you are paying for
Application and contract review$0 to $2,500Scope review and quotation. Often folded into stage 1.
Stage 1 audit$3,000 to $8,000One to two days. Documentation and readiness review, usually remote.
Stage 2 audit$9,000 to $25,000Three to eight days depending on size and sites. Interviews, sampling, evidence.
Certificate issue and registration$500 to $2,000Administrative. Some bodies bundle it, some bill it annually.
Travel and expenses$0 to $6,000Zero if the audit is remote. Real money if your sites are outside a major centre.
Surveillance audit, years 2 and 3$5,000 to $16,000 eachRoughly a third of the initial audit days, once a year.
Recertification, year 3$12,000 to $28,000Around two thirds of the original stage 2 effort.

Ask for the day count, not the total

Request every quote as days per visit across the full three-year cycle: stage 1, stage 2, each surveillance, and recertification. Day counts are comparable between bodies and headline totals are not, because a body can price a thin stage 2 and recover the margin in surveillance years when you are no longer shopping. If a body will not break out days, that itself is the answer.

The consultant line

This is normally the largest single number, and unlike audit days it is genuinely a commercial negotiation. What you are buying is the difference between knowing what the standard says and knowing what an auditor accepts as evidence of it.

Readiness engagement pricing in Canada, CAD
Shape of engagementRange (CAD)Where it makes sense
Gap assessment alone$8,000 to $20,000You have internal capacity and need to know the distance.
Templates and review, fixed fee$15,000 to $30,000Someone internal owns the project and needs a second opinion.
Guided implementation$25,000 to $50,000The common shape. They lead, your team writes and operates.
Full implementation$45,000 to $90,000No internal owner and a customer deadline already set.
Independent internal audit$6,000 to $15,000Required by clause 9, and it cannot be whoever built the system.

Two structural points about this line. A consultant cannot certify you and your certification body cannot consult for you, because ISO/IEC 17021-1 forbids a body from certifying a management system it advised on, with a two-year cool off after the advice ends. Anyone offering both in one quote is either not accredited or not describing the arrangement accurately. And the internal audit has to come from a third party again: the person who wrote the policies cannot audit them, which is what catches out two-person security teams. What a consulting engagement covers and how to contract for it goes into the statement of work in detail.

The internal time bill

Nobody invoices you for this and it is frequently the biggest number on the page. A first certification takes a few hundred internal hours, and they are not evenly spread. They cluster in three places.

Where internal hours actually go, first certification
ActivityTypical hoursWho
Asset, data and supplier inventory40 to 100Engineering, IT, whoever owns contracts
Writing down processes that exist only as habit60 to 150Security lead, engineering leads, HR
Risk assessment workshops20 to 50Cross-functional, plus an executive owner
First evidence collection40 to 120Whoever administers each system
Stage 2 audit week30 to 80Everyone the auditor interviews

At a loaded cost of $80 to $150 CAD an hour, that is $15,000 to $75,000 CAD of company time. It is also the number that settles the consultant question: a firm that removes 150 hours from your engineering lead has covered a meaningful share of its own fee, and one that adds hours by sending templates you have to rewrite is worse than nothing.

The lines people forget

  • The standards. ISO/IEC 27001 and ISO/IEC 27002 are copyrighted documents you have to buy, from ISO directly or through the Standards Council of Canada. Budget $400 to $900 CAD for the pair, more if you want the wider 27000 family.
  • Penetration testing. $8,000 to $25,000 CAD for a typical SaaS scope, and auditors expect independent testing rather than a scanner report. See what an ISO 27001 auditor actually wants from a test.
  • The compliance platform, if you use one. $8,000 to $30,000 CAD a year, billed annually in advance, and it renews long after the project that justified it ends.
  • Remediation. Whatever the gap assessment surfaces. Single sign-on licensing, a logging tool, endpoint management, a backup restore that turns out not to work. $2,000 to $15,000 CAD covers this for most small companies and there is no way to predict it beforehand.
  • Certificate marks and directory listings. Small, but some bodies charge for use of their accreditation mark.

A worked example

A forty-person Canadian SaaS company, one product, one cloud account, no on-premise infrastructure, personal information in scope, no existing management system, using a consultant for guided implementation.

Year one, forty-person Canadian SaaS company, CAD
LineLowHigh
Certification body, stage 1 and stage 2$18,000$28,000
Consultant, guided implementation$28,000$45,000
Independent internal audit$6,000$12,000
Penetration test$10,000$20,000
Platform, if used$0$20,000
Standards and remediation$2,500$14,000
Cash out, year one$64,500$139,000
Internal time, costed$20,000$55,000

The spread is wide because the high column assumes a platform, a large testing scope and real remediation, and the low column assumes none of those. The cost calculator puts your own numbers through the same arithmetic and gives you the three-year total, which is the figure that should go to your board rather than the year-one one.

Get quotes you can compare on days

Tell us your scope and headcount and we will put it in front of Canadian certification bodies and consultants who will price it properly.

Get matched

Common questions

How much does ISO 27001 certification cost, just the certificate?

If you mean only the accredited certification body and nothing else, $15,000 to $40,000 CAD covers stage 1 and stage 2 for most Canadian companies under 250 staff, plus $5,000 to $16,000 CAD a year for surveillance. That figure assumes your management system is already built, which for a first certification it will not be.

Why is the certification body quoting me in days rather than dollars?

Because accredited bodies derive audit duration from the audit time tables in the ISO/IEC 27006 series rather than setting it commercially. The days come from your effective headcount and scope complexity, and the price is days multiplied by a rate. This is good for you: days are directly comparable between bodies in a way that a bundled total is not.

Can I negotiate an ISO 27001 certification quote?

You can negotiate the day rate, the travel arrangement and the payment schedule. You cannot meaningfully negotiate the day count, because a body that cuts days below what its accreditation rules require is putting its own status at risk. If a body offers to halve the days, ask what changed about the scope, because something did.

Is the second year cheaper?

Considerably. Surveillance audits run about a third of the initial audit effort, and most of the consultant work does not repeat. Expect $10,000 to $30,000 CAD a year in years two and three including the surveillance audit, ongoing testing and whatever internal or fractional support keeps the management system running. Year three carries recertification, so it is the more expensive of the two.

Are these figures in Canadian dollars?

Yes, every number on this page is CAD. Global certification bodies frequently quote Canadian clients in US dollars or euros, so confirm the currency in writing before you compare two proposals, and confirm who carries the exchange risk over a three-year contract.