ISO27K

ISO 27001 cost calculator (CAD)

Five questions, and the answer includes the number almost nobody publishes: what the full three-year certification cycle costs, not just year one.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

Year one is the number every vendor quotes and it is the wrong number to budget against. ISO 27001 certification is a three-year cycle with surveillance audits in years two and three and a recertification at the end of it, and a board that approved a year-one figure will be surprised twice. This works out both, in Canadian dollars.

The estimate below is built from audit day counts rather than from a flat rate, because that is how an accredited certification body actually prices. Nothing is emailed anywhere unless you ask for it at the end.

How many people are in the scope of the certification?

Everyone whose work touches the systems and services you intend to certify, including contractors who work like staff. Not your whole company if the scope is narrower.

How many sites are in scope?

Physical locations where in-scope work happens. A fully remote company with no office counts as one. Cloud regions are not sites.

What exists today?

This moves the consultant line and the internal time line more than anything else on this form.

How broad is the scope?

Narrow scopes cost less every year, not once. You can widen at recertification.

How will you resource it?

Will you use a compliance platform?

Platforms such as Vanta, Drata or Sprinto. Billed annually in advance, so it is a three-year cost.

How the estimate is built

The certification body line starts from audit days rather than from a price. Accredited bodies derive audit duration from the audit time tables in the ISO/IEC 27006 series, working from the effective number of people in scope and then adjusting for the number of sites and the complexity of what is being certified. This calculator uses the same shape: a base day count by headcount band, multiplied for sites and scope breadth, split roughly one part stage 1 to four parts stage 2, then priced at $2,000 to $3,200 CAD a day.

Surveillance audits are taken at about a third of the initial audit effort and recertification at about two thirds, which is the conventional pattern across accredited bodies. Your actual quote will differ, and the point of showing days is that days are the thing you can compare between two bodies when their totals are not comparable.

Consultant and internal time are estimated from what already exists, because that is what genuinely drives them. A company with a SOC 2 report has the evidence discipline already and needs the management system layer on top, which is a smaller piece of work than it sounds. A company with nothing written down is paying for the writing down, and that cost barely moves with headcount.

What this cannot know

Remediation. Whatever your gap assessment surfaces has to be bought, configured and sometimes licensed, and there is no way to predict it from six questions. Single sign-on for a company that did not have it, a logging platform, endpoint management, a backup restore that turns out not to work. Two to fifteen thousand Canadian dollars covers it for most small companies and occasionally it is much more. Treat every figure here as a planning range and get real quotes before committing a budget.

Common questions

Why is the three-year total so much higher than the year one figure?

Because certification is a cycle rather than a purchase. Years two and three carry a surveillance audit each, a recertification audit at the end, continuing penetration testing, any platform subscription, and the internal effort of actually running the management system. Companies that budget only year one meet the rest as an unpleasant surprise at the first renewal.

Are these figures in Canadian dollars?

Yes, every number this tool produces is CAD. Global certification bodies frequently quote Canadian clients in US dollars or euros, so confirm the currency in writing before comparing a proposal against this estimate, and confirm who carries the exchange risk across a three-year contract.

How accurate is this?

It is a planning range, not a quote. The audit day arithmetic is close to how bodies actually price, so the certification body line tends to be the most reliable part. The consultant line is the least reliable, because two firms will scope the same engagement very differently, which is covered on the consulting page.

Does the estimate include the internal audit?

Yes, in the other year one costs, at $6,000 to $15,000 CAD. Clause 9 requires an internal audit before certification and it cannot be performed by whoever built the management system, so small teams generally have to buy it even when they run everything else themselves.