Back to Columns
ISMS & Certification12 min read

Audit Fees: Ranges and What Moves Them

September 14, 2026

Audit Fees: Ranges and What Moves Them
Share this article

"What does an ISMS audit cost?" is genuinely hard to answer in general terms. Audit fees are not a list price but a quote calculated from your organisation's conditions. Two companies of fifty people will be quoted differently depending on whether they operate from one site or three, and on whether development is in-house or outsourced.

The structure of the calculation, however, is common. The core of the fee is auditor-days multiplied by a rate, and the day count is driven by a small set of factors. Understand that and you can judge for yourself whether a quote is reasonable and where it could be reduced.

One more thing to fix early: audit fees and consulting fees are different products. Mixing them into a single "what does ISMS cost" figure guarantees confusion when comparing quotes.

This article covers what moves audit fees, how year one differs from the years after, how to compare across three years, and what to verify in competing quotes. For the full cost picture see The Full Cost of ISMS Certification; for the overall picture, What Is an ISMS (ISO/IEC 27001)?.

Disclaimer: This article is general information. Audit fees vary widely with certification body, organisation size, and scope. The figures cited below circulate in published commentary and require verification against primary sources. Confirm actual amounts through quotes from certification bodies. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies.

Fees Are Auditor-Days

Audit fee ≒ auditor-days × day rate + travel + administrative charges

The only part you can meaningfully influence is the day count. Day rates are largely fixed per body with limited room to negotiate. So "can we reduce the fee" is nearly always "can we reduce the days."

Who sets the day count

Auditor-days are not set at the certification body's discretion; they are calculated according to rules laid down by the accreditation body. In Japan that body is ISMS-AC (the Information Management System Accreditation Center); overseas accreditations such as UKAS and ANAB work within an equivalent international framework. See ISMS-AC, UKAS and ANAB.

Because those rules exist, quotes from different bodies for the same stated conditions will not diverge wildly in days. If they do, suspect that the premises differ — how headcount is counted, how sites are treated, how the scope was read.

Five Variables That Move the Fee

VariableEffectPractical note
① Headcount in scopeLargest; the basis of the calculationWho counts is the contested part. Beyond permanent staff, whether fixed-term, agency, and on-site contractors are included is judged on the facts. Confirm how remote workers are treated
② Number of sitesMore sites, more days and more travelMulti-site sampling (visiting only some sites) may be permitted; confirm the conditions with the body
③ Complexity of activitiesMore kinds of activity, more daysDevelopment, operations, data centre, 24-hour support — varied activities mean more to examine. A single-activity business is lighter
④ Integration with other certificationsCan reduce total daysTaking Privacy Mark, ISO 9001, or ISO 27017 together or with the same body can eliminate duplicated effort
⑤ Breadth of scopeWhole company versus one business line changes it substantiallyEstablish what your customers actually require first — excess breadth costs every year

Variable ① produces the biggest discrepancies between quotes. A "50-person company" that becomes 70 once contractors are counted changes the calculation. When seeking competing quotes, present the same headcount definition and breakdown to every body.

Variable ⑤ is the one you can genuinely tune during the build. A narrower scope means fewer auditor-days and less documentation. But certifying one business line when the customer wants company-wide certification achieves nothing. See Defining ISMS Scope and Scope Design for Healthcare Companies.

On the numbers

Published commentary cites levels such as around ¥600,000 for an organisation of a few people and around ¥1 million at 100 people (verify against primary sources). These are described as rough first-year audit fees and move with the body, the number of sites, and the nature of the business. Do not fix a budget on them.

The only reliable method is competing quotes from several bodies, all given the same premises. See Choosing a Certification Body.

Year One Versus the Years After

YearAuditDay countOther charges
1Stage 1 (documentation) + Stage 2 (on-site)Heaviest. For a small organisation, roughly 1–2 days plus 2–3 daysApplication and registration fees
2SurveillanceTypically fewer than the initial auditAnnual maintenance fee
3SurveillanceSimilar to year twoAnnual maintenance fee
RenewalRecertificationMore than surveillance, approaching the initial auditAnnual maintenance fee; recalculated if scope changed

Year one is heavy because there are two audits. Stage 1 examines documentation and readiness; stage 2 examines actual operation (What Stage 1 Looks At, What Stage 2 Looks At).

Surveillance in years two and three is narrower and therefore fewer days — but not zero, and the annual maintenance fee recurs regardless. Budgeting as though certification were a one-off produces an unpleasant surprise in year two. See Preparing for the Surveillance Audit and Preparing for Recertification in Year Three.

When conditions change mid-cycle

Significant growth in headcount, a new site, a widened scope — each causes the next audit's days to be recalculated and the fee to rise. Scaling down and narrowing scope can reduce it.

Either way, changes must be reported to the certification body in good time. Discovered on audit day instead, the issue is no longer cost but a finding that scope and reality do not match.

The Full Set of Charges from the Body

Check whether each of these is included or separate. Items missing from the headline figure are where three-year totals diverge.

ItemContentWhat to verify
Application and registration feesAdministrative charges at application and at registrationYear one only, or also at renewal?
Audit fees (stages 1 and 2)Priced on auditor-daysThe day breakdown and the premises behind it
TravelAuditor travel and accommodationIncluded or reimbursed at cost; treatment of regional sites
Annual maintenance feeAnnual charge for holding certification (names vary)Does it recur every year? Fixed or variable?
Surveillance audit feesYears two and threeAre all three years in the quote?
Recertification feeEvery three yearsIs an estimate provided up front?
Additional verificationExtra visit if a major nonconformity arisesThe triggering conditions and how it is priced
Scope-change auditsExtra verification when adding sites or businessesProcedure and indicative cost
Remote auditConducted onlineWhat is permitted; can reduce travel

Travel, annual maintenance, and surveillance fees are the ones most often absent from a first figure. That is where a quote that looked cheap turns out, over three years, to be the expensive one.

Compare Across Three Years

ItemYear 1Year 2Year 3Renewal
To the certification bodyApplication and registration + stage 1 + stage 2 + maintenanceSurveillance + maintenanceSurveillance + maintenanceRecertification + maintenance
To the support partnerInitial certification supportOperational support (if contracted)Operational support (if contracted)Operational support + renewal work
Internal effortHeaviestInternal audit, review, updatesSamePlus consolidating three years

Whether you can take the support cost to zero from year two depends on whether operating know-how stayed in-house during year one. If documents were simply produced for you, year two stalls at the internal audit and the risk assessment update — and the spend returns anyway. Judge the contract by what remains with your team, not by the headline number.

How Pottech's pricing relates to this

For reference, our support pricing (all excluding tax, assuming an organisation of up to around 50 people and documentation following our templates):

ServiceContentPrice
ISMS initial certification supportFirst certification: overall design, documentation, risk assessment, training, dealings with the certification body, internal auditFrom ¥1.2M per year
ISMS operational support (year two onward)Reviewing roles and scope, updating the risk assessment, internal audit, handling surveillance and recertificationFrom ¥800K per year

Payments to the certification body (audit fees) are not included. We obtain and present competing quotes instead. Stage 1 and stage 2 attendance are options (¥100K and ¥200K respectively); three-ministry guideline work starts at ¥1.5M. Full pricing is on ISMS Certification Support.

What to Verify in Competing Quotes

Level the premises

  • Definition of headcount in scope (permanent, fixed-term, agency, on-site contractors, remote workers)
  • Which sites are in scope, and where they are
  • Which businesses, services, and departments are in scope
  • Types of activity (development, operations, support, data centre)
  • Whether you want integrated auditing with an existing certification

Check in the quote

  • The auditor-day breakdown (days for each stage, number of auditors)
  • That the premises behind the calculation match what you supplied
  • Whether travel is included or reimbursed
  • Whether an annual maintenance fee applies, and how much
  • Whether surveillance fees for years two and three are stated
  • Whether a recertification estimate is given
  • Whether remote auditing is available, and for what
  • Cost and conditions for additional verification after a major nonconformity

Compare on things other than price

  • Experience auditing healthcare and medical information organisations
  • Availability of auditors in your preferred window (busy seasons book out)
  • The quality of audit reports (specificity of findings, usefulness of suggestions)
  • Whether the appeals procedure is set out clearly

The last group does not show up in the price, but you are choosing a counterpart for at least three years. In healthcare especially, whether you get an auditor who understands medical information handling and the three-ministry guidelines changes the quality of the audit (The Three-Ministry Guidelines). See also Comparing the Major Certification Bodies.

Conclusion

  1. The fee is essentially auditor-days × day rate; the days are what you can influence
  2. Days follow the accreditation body's calculation rules, so identical premises produce broadly similar counts. A large divergence signals mismatched premises
  3. The drivers are headcount in scope, number of sites, complexity of activities, integration with other certifications, and breadth of scope — the last being the most adjustable
  4. Circulating figures (around ¥600K for a handful of people, around ¥1M at 100) require primary verification; do not fix a budget on them
  5. Year one is heaviest because of two audits. Later years are lighter, but the annual maintenance fee recurs
  6. Travel, maintenance, and surveillance fees are often missing from a first figure — compare three-year totals
  7. Audit fees and support fees are separate products; Pottech's pricing likewise excludes payments to the certification body

Pottech supports ISMS certification with a focus on healthcare, including obtaining and comparing quotes from certification bodies. Initial certification support starts at ¥1.2M per year and operational support at ¥800K per year (both excluding tax); payments to the certification body are not included.

See ISMS Certification Support for detail, or contact us — including at the stage where you simply want a second read on whether a quote is reasonable.

References and Sources

Note: the fee levels cited here circulate in published commentary and require verification against primary sources. Audit fees vary widely with certification body, organisation size, scope, and number of sites. Day-count rules, the naming and composition of charges, and the availability of remote auditing all differ between bodies. Interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standard itself and the publications of the accreditation and certification bodies.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.