Free ISO 27001 and ISO 42001 tools
Four tools, all free. Each gives you the answer on screen, and the email field underneath buys only the written version.
ISO certification is priced and scheduled differently from an attestation, and most of the confusion Canadian companies arrive with comes from reading American SOC 2 material and assuming it transfers. These four answer the questions that are genuinely specific to ISO.
ISO 27001 cost calculator
Five questions, and an answer that includes the figure almost nobody publishes: the full three-year certification cycle rather than year one. ISO certification runs on a three-year cycle with surveillance audits in years two and three, so a first-year number is not what certification costs, it is the deposit. Companies that budget from year one alone get an unpleasant surprise twice.
It splits the certification body's stage 1 and stage 2 fees from consultant support and internal time, because only the first of those is fixed by anything external.
Work out the three-year cost, then read the itemised breakdown.
Gap assessment
Six questions across the clause requirements and the four Annex A themes. ISO 27001 is 93 Annex A controls plus 25 clause requirements, and the clauses are the half that companies skip: you can have every technical control in place and still fail stage 1 because there is no management review, no internal audit and no Statement of Applicability.
The score, the blocking items and the order to work in all appear on the page. Assess your gap.
ISO 42001 readiness
The AI management standard is new enough that most of what is written about it is vague, and a good deal of it is vendors describing their own product. This asks the questions a certification body actually asks at scoping: what the AI system decides, who is accountable for it, what data trained it, and whether anybody is monitoring it after deployment.
It will tell you if you are not in scope. Check your readiness, or read the full guide to the standard.
ISO 27001 or SOC 2
These are less alternatives than answers to different buyers. European and UK procurement asks for ISO by name and frequently will not accept a SOC 2 report; North American buyers do the reverse. This works out which buyer you actually have, which to get first, and whether you will end up needing both, in which case the order matters because the second one costs far less on shared evidence.
Work out which, or read the longer comparison.
Common questions
Do I have to give you an email address to see the results?
No. Every result renders on the page as soon as you finish the questions. The field underneath sends the written version with its reasoning set out, which is useful for forwarding to a board or a finance team. Skipping it costs you nothing.
Why does the cost calculator ask about surveillance audits?
Because ISO certification is a three-year cycle, not a one-off. The certificate is valid for three years, with a surveillance audit in each of years two and three and a full recertification at the end. Budgeting only for the initial audit understates what certification costs by roughly a third.
Can a consultant certify us?
No, and this is the distinction that catches people. In Canada the Standards Council of Canada accredits certification bodies, the certification body issues the certificate, and a consultant can do neither. A consultant who implies they can certify you is either being loose with language or should be avoided.
Get quotes from Canadian firms
Tell us your scope and we will put it in front of firms doing ISO work in Canada.
Get matched