ISO 27001 Stage 1 vs Stage 2 audit costs
Interactive estimators
Cost ranges
| Item | Range | Notes |
|---|---|---|
| Stage 1 readiness review | $4K–$15K | Reviews ISMS design, required information, scope, and Stage 2 readiness |
| Stage 2 certification audit | $10K–$40K+ | Tests implementation and effectiveness across the certification scope |
| Travel and multi-site additions | $2K–$20K+ | Remote eligibility, countries, and sampled sites affect fees |
| Annual surveillance audit | $6K–$20K/year | Certification requires continuing surveillance and later recertification |
What drives variance
Certification bodies price auditor-days, so employee count, sites, ISMS complexity, shift patterns, outsourcing, and scope exclusions drive cost. Stage 1 is not a lightweight certification: unresolved scope or documentation issues can delay Stage 2 and add auditor-days. Accredited certification-body quotes should state both stages, surveillance, travel, and recertification assumptions. Consultancy is separate from independent certification.
Sources & methodology
Frequently Asked Questions
Stage 2 tests whether Annex A controls and ISMS processes actually operate — more auditor days, interviews, and samples than Stage 1's documentation review.
Accredited certification paths require Stage 1 before Stage 2. Treat Stage 1 gaps as remediation time — rushing to Stage 2 with open major nonconformities wastes calendar and fees.
Incomplete SoA, missing risk treatment rationale, undocumented ISMS scope, or leadership not engaged — fix these before scheduling Stage 2.
More applicable controls mean more evidence to review in Stage 1 and more samples in Stage 2. A lean SaaS SoA can reduce auditor days if exclusions are defensible.
Use /tools/iso-27001-cost-calculator for a first-year heuristic, then obtain quotes from two accredited certification bodies against the same scope statement.