ISO 27001 certification cost, itemised
This page takes the certification bill apart line by line and shows how each number is arrived at, so you can read a quote and tell whether it is fair before you sign it.
The certification body portion of ISO 27001 costs a Canadian company roughly $15,000 to $40,000 CAD for stage 1 and stage 2 together, and that is normally between a fifth and a third of what year one actually costs. The rest is consultant fees, an internal time bill nobody puts on paper, a penetration test, and the standards themselves. Below is each line, what it is for, and how the person quoting it worked the number out.
If you want the strategic version, which scope to pick and where the money is wasted, read the ISO 27001 cost breakdown for Canada. This page is the narrower one: the invoice.
How a certification body arrives at its number
A certification body does not price ISO 27001 the way a consultancy prices a project. It sells audit days at a day rate, and the number of days is not a commercial decision. Accredited bodies work from the audit time tables in the ISO/IEC 27006 series, which start from the effective number of people in scope and then adjust for complexity: how many sites, how many distinct technology environments, how much of the operation is outsourced, how much personal information is handled, and whether staff do broadly the same work or twenty different things.
Two consequences follow, and both are worth knowing before you open a quote. The first is that a body cannot discount days very far without putting its own accreditation at risk, so a quote that is dramatically cheaper is usually either a smaller scope than you asked for or an unaccredited certificate. The second is that day rate is the only part genuinely open to negotiation, and it is the part nobody asks about.
| Line | Typical (CAD) | What you are paying for |
|---|---|---|
| Application and contract review | $0 to $2,500 | Scope review and quotation. Often folded into stage 1. |
| Stage 1 audit | $3,000 to $8,000 | One to two days. Documentation and readiness review, usually remote. |
| Stage 2 audit | $9,000 to $25,000 | Three to eight days depending on size and sites. Interviews, sampling, evidence. |
| Certificate issue and registration | $500 to $2,000 | Administrative. Some bodies bundle it, some bill it annually. |
| Travel and expenses | $0 to $6,000 | Zero if the audit is remote. Real money if your sites are outside a major centre. |
| Surveillance audit, years 2 and 3 | $5,000 to $16,000 each | Roughly a third of the initial audit days, once a year. |
| Recertification, year 3 | $12,000 to $28,000 | Around two thirds of the original stage 2 effort. |
Ask for the day count, not the total
Request every quote as days per visit across the full three-year cycle: stage 1, stage 2, each surveillance, and recertification. Day counts are comparable between bodies and headline totals are not, because a body can price a thin stage 2 and recover the margin in surveillance years when you are no longer shopping. If a body will not break out days, that itself is the answer.
The consultant line
This is normally the largest single number, and unlike audit days it is genuinely a commercial negotiation. What you are buying is the difference between knowing what the standard says and knowing what an auditor accepts as evidence of it.
| Shape of engagement | Range (CAD) | Where it makes sense |
|---|---|---|
| Gap assessment alone | $8,000 to $20,000 | You have internal capacity and need to know the distance. |
| Templates and review, fixed fee | $15,000 to $30,000 | Someone internal owns the project and needs a second opinion. |
| Guided implementation | $25,000 to $50,000 | The common shape. They lead, your team writes and operates. |
| Full implementation | $45,000 to $90,000 | No internal owner and a customer deadline already set. |
| Independent internal audit | $6,000 to $15,000 | Required by clause 9, and it cannot be whoever built the system. |
Two structural points about this line. A consultant cannot certify you and your certification body cannot consult for you, because ISO/IEC 17021-1 forbids a body from certifying a management system it advised on, with a two-year cool off after the advice ends. Anyone offering both in one quote is either not accredited or not describing the arrangement accurately. And the internal audit has to come from a third party again: the person who wrote the policies cannot audit them, which is what catches out two-person security teams. What a consulting engagement covers and how to contract for it goes into the statement of work in detail.
The internal time bill
Nobody invoices you for this and it is frequently the biggest number on the page. A first certification takes a few hundred internal hours, and they are not evenly spread. They cluster in three places.
| Activity | Typical hours | Who |
|---|---|---|
| Asset, data and supplier inventory | 40 to 100 | Engineering, IT, whoever owns contracts |
| Writing down processes that exist only as habit | 60 to 150 | Security lead, engineering leads, HR |
| Risk assessment workshops | 20 to 50 | Cross-functional, plus an executive owner |
| First evidence collection | 40 to 120 | Whoever administers each system |
| Stage 2 audit week | 30 to 80 | Everyone the auditor interviews |
At a loaded cost of $80 to $150 CAD an hour, that is $15,000 to $75,000 CAD of company time. It is also the number that settles the consultant question: a firm that removes 150 hours from your engineering lead has covered a meaningful share of its own fee, and one that adds hours by sending templates you have to rewrite is worse than nothing.
The lines people forget
- The standards. ISO/IEC 27001 and ISO/IEC 27002 are copyrighted documents you have to buy, from ISO directly or through the Standards Council of Canada. Budget $400 to $900 CAD for the pair, more if you want the wider 27000 family.
- Penetration testing. $8,000 to $25,000 CAD for a typical SaaS scope, and auditors expect independent testing rather than a scanner report. See what an ISO 27001 auditor actually wants from a test.
- The compliance platform, if you use one. $8,000 to $30,000 CAD a year, billed annually in advance, and it renews long after the project that justified it ends.
- Remediation. Whatever the gap assessment surfaces. Single sign-on licensing, a logging tool, endpoint management, a backup restore that turns out not to work. $2,000 to $15,000 CAD covers this for most small companies and there is no way to predict it beforehand.
- Certificate marks and directory listings. Small, but some bodies charge for use of their accreditation mark.
A worked example
A forty-person Canadian SaaS company, one product, one cloud account, no on-premise infrastructure, personal information in scope, no existing management system, using a consultant for guided implementation.
| Line | Low | High |
|---|---|---|
| Certification body, stage 1 and stage 2 | $18,000 | $28,000 |
| Consultant, guided implementation | $28,000 | $45,000 |
| Independent internal audit | $6,000 | $12,000 |
| Penetration test | $10,000 | $20,000 |
| Platform, if used | $0 | $20,000 |
| Standards and remediation | $2,500 | $14,000 |
| Cash out, year one | $64,500 | $139,000 |
| Internal time, costed | $20,000 | $55,000 |
The spread is wide because the high column assumes a platform, a large testing scope and real remediation, and the low column assumes none of those. The cost calculator puts your own numbers through the same arithmetic and gives you the three-year total, which is the figure that should go to your board rather than the year-one one.
Get quotes you can compare on days
Tell us your scope and headcount and we will put it in front of Canadian certification bodies and consultants who will price it properly.
Get matchedCommon questions
How much does ISO 27001 certification cost, just the certificate?
If you mean only the accredited certification body and nothing else, $15,000 to $40,000 CAD covers stage 1 and stage 2 for most Canadian companies under 250 staff, plus $5,000 to $16,000 CAD a year for surveillance. That figure assumes your management system is already built, which for a first certification it will not be.
Why is the certification body quoting me in days rather than dollars?
Because accredited bodies derive audit duration from the audit time tables in the ISO/IEC 27006 series rather than setting it commercially. The days come from your effective headcount and scope complexity, and the price is days multiplied by a rate. This is good for you: days are directly comparable between bodies in a way that a bundled total is not.
Can I negotiate an ISO 27001 certification quote?
You can negotiate the day rate, the travel arrangement and the payment schedule. You cannot meaningfully negotiate the day count, because a body that cuts days below what its accreditation rules require is putting its own status at risk. If a body offers to halve the days, ask what changed about the scope, because something did.
Is the second year cheaper?
Considerably. Surveillance audits run about a third of the initial audit effort, and most of the consultant work does not repeat. Expect $10,000 to $30,000 CAD a year in years two and three including the surveillance audit, ongoing testing and whatever internal or fractional support keeps the management system running. Year three carries recertification, so it is the more expensive of the two.
Are these figures in Canadian dollars?
Yes, every number on this page is CAD. Global certification bodies frequently quote Canadian clients in US dollars or euros, so confirm the currency in writing before you compare two proposals, and confirm who carries the exchange risk over a three-year contract.