Skip to content
compliancebase

ISO 27001 Stage 1 vs Stage 2 audit costs

Cost ranges

ItemRangeNotes
Stage 1 readiness review$4K–$15KReviews ISMS design, required information, scope, and Stage 2 readiness
Stage 2 certification audit$10K–$40K+Tests implementation and effectiveness across the certification scope
Travel and multi-site additions$2K–$20K+Remote eligibility, countries, and sampled sites affect fees
Annual surveillance audit$6K–$20K/yearCertification requires continuing surveillance and later recertification

What drives variance

Certification bodies price auditor-days, so employee count, sites, ISMS complexity, shift patterns, outsourcing, and scope exclusions drive cost. Stage 1 is not a lightweight certification: unresolved scope or documentation issues can delay Stage 2 and add auditor-days. Accredited certification-body quotes should state both stages, surveillance, travel, and recertification assumptions. Consultancy is separate from independent certification.

Sources & methodology

Frequently Asked Questions

Stage 2 tests whether Annex A controls and ISMS processes actually operate — more auditor days, interviews, and samples than Stage 1's documentation review.

Accredited certification paths require Stage 1 before Stage 2. Treat Stage 1 gaps as remediation time — rushing to Stage 2 with open major nonconformities wastes calendar and fees.

Incomplete SoA, missing risk treatment rationale, undocumented ISMS scope, or leadership not engaged — fix these before scheduling Stage 2.

More applicable controls mean more evidence to review in Stage 1 and more samples in Stage 2. A lean SaaS SoA can reduce auditor days if exclusions are defensible.

Use /tools/iso-27001-cost-calculator for a first-year heuristic, then obtain quotes from two accredited certification bodies against the same scope statement.

Framework versions referenced in this page:

Last verified: August 2026 · Primary sources linked above