"What does an ISMS audit cost?" is genuinely hard to answer in general terms. Audit fees are not a list price but a quote calculated from your organisation's conditions. Two companies of fifty people will be quoted differently depending on whether they operate from one site or three, and on whether development is in-house or outsourced.
The structure of the calculation, however, is common. The core of the fee is auditor-days multiplied by a rate, and the day count is driven by a small set of factors. Understand that and you can judge for yourself whether a quote is reasonable and where it could be reduced.
One more thing to fix early: audit fees and consulting fees are different products. Mixing them into a single "what does ISMS cost" figure guarantees confusion when comparing quotes.
This article covers what moves audit fees, how year one differs from the years after, how to compare across three years, and what to verify in competing quotes. For the full cost picture see The Full Cost of ISMS Certification; for the overall picture, What Is an ISMS (ISO/IEC 27001)?.
Disclaimer: This article is general information. Audit fees vary widely with certification body, organisation size, and scope. The figures cited below circulate in published commentary and require verification against primary sources. Confirm actual amounts through quotes from certification bodies. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies.
Fees Are Auditor-Days
Audit fee ≒ auditor-days × day rate + travel + administrative charges
The only part you can meaningfully influence is the day count. Day rates are largely fixed per body with limited room to negotiate. So "can we reduce the fee" is nearly always "can we reduce the days."
Who sets the day count
Auditor-days are not set at the certification body's discretion; they are calculated according to rules laid down by the accreditation body. In Japan that body is ISMS-AC (the Information Management System Accreditation Center); overseas accreditations such as UKAS and ANAB work within an equivalent international framework. See ISMS-AC, UKAS and ANAB.
Because those rules exist, quotes from different bodies for the same stated conditions will not diverge wildly in days. If they do, suspect that the premises differ — how headcount is counted, how sites are treated, how the scope was read.
Five Variables That Move the Fee
| Variable | Effect | Practical note |
|---|---|---|
| ① Headcount in scope | Largest; the basis of the calculation | Who counts is the contested part. Beyond permanent staff, whether fixed-term, agency, and on-site contractors are included is judged on the facts. Confirm how remote workers are treated |
| ② Number of sites | More sites, more days and more travel | Multi-site sampling (visiting only some sites) may be permitted; confirm the conditions with the body |
| ③ Complexity of activities | More kinds of activity, more days | Development, operations, data centre, 24-hour support — varied activities mean more to examine. A single-activity business is lighter |
| ④ Integration with other certifications | Can reduce total days | Taking Privacy Mark, ISO 9001, or ISO 27017 together or with the same body can eliminate duplicated effort |
| ⑤ Breadth of scope | Whole company versus one business line changes it substantially | Establish what your customers actually require first — excess breadth costs every year |
Variable ① produces the biggest discrepancies between quotes. A "50-person company" that becomes 70 once contractors are counted changes the calculation. When seeking competing quotes, present the same headcount definition and breakdown to every body.
Variable ⑤ is the one you can genuinely tune during the build. A narrower scope means fewer auditor-days and less documentation. But certifying one business line when the customer wants company-wide certification achieves nothing. See Defining ISMS Scope and Scope Design for Healthcare Companies.
On the numbers
Published commentary cites levels such as around ¥600,000 for an organisation of a few people and around ¥1 million at 100 people (verify against primary sources). These are described as rough first-year audit fees and move with the body, the number of sites, and the nature of the business. Do not fix a budget on them.
The only reliable method is competing quotes from several bodies, all given the same premises. See Choosing a Certification Body.
Year One Versus the Years After
| Year | Audit | Day count | Other charges |
|---|---|---|---|
| 1 | Stage 1 (documentation) + Stage 2 (on-site) | Heaviest. For a small organisation, roughly 1–2 days plus 2–3 days | Application and registration fees |
| 2 | Surveillance | Typically fewer than the initial audit | Annual maintenance fee |
| 3 | Surveillance | Similar to year two | Annual maintenance fee |
| Renewal | Recertification | More than surveillance, approaching the initial audit | Annual maintenance fee; recalculated if scope changed |
Year one is heavy because there are two audits. Stage 1 examines documentation and readiness; stage 2 examines actual operation (What Stage 1 Looks At, What Stage 2 Looks At).
Surveillance in years two and three is narrower and therefore fewer days — but not zero, and the annual maintenance fee recurs regardless. Budgeting as though certification were a one-off produces an unpleasant surprise in year two. See Preparing for the Surveillance Audit and Preparing for Recertification in Year Three.
When conditions change mid-cycle
Significant growth in headcount, a new site, a widened scope — each causes the next audit's days to be recalculated and the fee to rise. Scaling down and narrowing scope can reduce it.
Either way, changes must be reported to the certification body in good time. Discovered on audit day instead, the issue is no longer cost but a finding that scope and reality do not match.
The Full Set of Charges from the Body
Check whether each of these is included or separate. Items missing from the headline figure are where three-year totals diverge.
| Item | Content | What to verify |
|---|---|---|
| Application and registration fees | Administrative charges at application and at registration | Year one only, or also at renewal? |
| Audit fees (stages 1 and 2) | Priced on auditor-days | The day breakdown and the premises behind it |
| Travel | Auditor travel and accommodation | Included or reimbursed at cost; treatment of regional sites |
| Annual maintenance fee | Annual charge for holding certification (names vary) | Does it recur every year? Fixed or variable? |
| Surveillance audit fees | Years two and three | Are all three years in the quote? |
| Recertification fee | Every three years | Is an estimate provided up front? |
| Additional verification | Extra visit if a major nonconformity arises | The triggering conditions and how it is priced |
| Scope-change audits | Extra verification when adding sites or businesses | Procedure and indicative cost |
| Remote audit | Conducted online | What is permitted; can reduce travel |
Travel, annual maintenance, and surveillance fees are the ones most often absent from a first figure. That is where a quote that looked cheap turns out, over three years, to be the expensive one.
Compare Across Three Years
| Item | Year 1 | Year 2 | Year 3 | Renewal |
|---|---|---|---|---|
| To the certification body | Application and registration + stage 1 + stage 2 + maintenance | Surveillance + maintenance | Surveillance + maintenance | Recertification + maintenance |
| To the support partner | Initial certification support | Operational support (if contracted) | Operational support (if contracted) | Operational support + renewal work |
| Internal effort | Heaviest | Internal audit, review, updates | Same | Plus consolidating three years |
Whether you can take the support cost to zero from year two depends on whether operating know-how stayed in-house during year one. If documents were simply produced for you, year two stalls at the internal audit and the risk assessment update — and the spend returns anyway. Judge the contract by what remains with your team, not by the headline number.
How Pottech's pricing relates to this
For reference, our support pricing (all excluding tax, assuming an organisation of up to around 50 people and documentation following our templates):
| Service | Content | Price |
|---|---|---|
| ISMS initial certification support | First certification: overall design, documentation, risk assessment, training, dealings with the certification body, internal audit | From ¥1.2M per year |
| ISMS operational support (year two onward) | Reviewing roles and scope, updating the risk assessment, internal audit, handling surveillance and recertification | From ¥800K per year |
Payments to the certification body (audit fees) are not included. We obtain and present competing quotes instead. Stage 1 and stage 2 attendance are options (¥100K and ¥200K respectively); three-ministry guideline work starts at ¥1.5M. Full pricing is on ISMS Certification Support.
What to Verify in Competing Quotes
Level the premises
- Definition of headcount in scope (permanent, fixed-term, agency, on-site contractors, remote workers)
- Which sites are in scope, and where they are
- Which businesses, services, and departments are in scope
- Types of activity (development, operations, support, data centre)
- Whether you want integrated auditing with an existing certification
Check in the quote
- The auditor-day breakdown (days for each stage, number of auditors)
- That the premises behind the calculation match what you supplied
- Whether travel is included or reimbursed
- Whether an annual maintenance fee applies, and how much
- Whether surveillance fees for years two and three are stated
- Whether a recertification estimate is given
- Whether remote auditing is available, and for what
- Cost and conditions for additional verification after a major nonconformity
Compare on things other than price
- Experience auditing healthcare and medical information organisations
- Availability of auditors in your preferred window (busy seasons book out)
- The quality of audit reports (specificity of findings, usefulness of suggestions)
- Whether the appeals procedure is set out clearly
The last group does not show up in the price, but you are choosing a counterpart for at least three years. In healthcare especially, whether you get an auditor who understands medical information handling and the three-ministry guidelines changes the quality of the audit (The Three-Ministry Guidelines). See also Comparing the Major Certification Bodies.
Conclusion
- The fee is essentially auditor-days × day rate; the days are what you can influence
- Days follow the accreditation body's calculation rules, so identical premises produce broadly similar counts. A large divergence signals mismatched premises
- The drivers are headcount in scope, number of sites, complexity of activities, integration with other certifications, and breadth of scope — the last being the most adjustable
- Circulating figures (around ¥600K for a handful of people, around ¥1M at 100) require primary verification; do not fix a budget on them
- Year one is heaviest because of two audits. Later years are lighter, but the annual maintenance fee recurs
- Travel, maintenance, and surveillance fees are often missing from a first figure — compare three-year totals
- Audit fees and support fees are separate products; Pottech's pricing likewise excludes payments to the certification body
Pottech supports ISMS certification with a focus on healthcare, including obtaining and comparing quotes from certification bodies. Initial certification support starts at ¥1.2M per year and operational support at ¥800K per year (both excluding tax); payments to the certification body are not included.
See ISMS Certification Support for detail, or contact us — including at the stage where you simply want a second read on whether a quote is reasonable.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- ISO/IEC 17021-1 Conformity assessment — Requirements for bodies providing audit and certification of management systems | ISO
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: the fee levels cited here circulate in published commentary and require verification against primary sources. Audit fees vary widely with certification body, organisation size, scope, and number of sites. Day-count rules, the naming and composition of charges, and the availability of remote auditing all differ between bodies. Interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standard itself and the publications of the accreditation and certification bodies.