Sooner or later, every ISMS project reaches the question: which certification body do we apply to? This is where many project owners stall. Line up the names and the websites all say much the same thing, and none of them publish a price list. The usual outcome is to apply to whichever body someone happened to recommend.
But choosing a certification body decides more than year-one cost. It shapes your schedule, your internal workload, and how smoothly audit days run, for three years. And the material you need to compare does not exist until you ask for it on consistent terms. Describe the same company and the same scope differently to two bodies and their quotes rest on different assumptions — at which point the numbers cannot be compared at all.
This article covers what drives a certification body's quote, what you must settle before requesting one, and what to compare besides price. For the individual bodies, see Comparing the Main Certification Bodies: BSI, JQA, BV, SGS, DQS.
Disclaimer: This article is general information. Audit-day calculations, fees, and accreditation arrangements differ by body, and each body's published materials and quotation are authoritative. Base your decision on those.
What Differs Between Bodies — and What Does Not
Start with the premise. If a body is accredited, the certificate it issues carries the same force as any other. There is no "higher grade" certificate. A customer receiving it will treat an accredited certificate the same way regardless of which body issued it.
In Japan, the accreditation body for ISMS certification is ISMS-AC (Information Management System Accreditation Center). Overseas there are bodies such as UKAS in the UK and ANAB in the US, and some certification bodies hold more than one accreditation. That combination matters mainly when you show the certificate to overseas counterparties — see ISMS-AC, UKAS and ANAB: How Accreditation Bodies Differ.
So what does differ? In practice, three things.
| Where differences appear | Specifically | What it affects |
|---|---|---|
| Fee and effort calculation | How auditor-days are counted, the day rate, treatment of travel and annual maintenance fees | Year-one cost and three-year total |
| Scheduling | Availability of audit dates, support for compressed timelines, remote auditing | When you actually certify — and whether you hit a commercial deadline |
| Auditor background | Which sector and technical experience the assigned auditors bring | How much you must explain on the day; how usable the findings are |
Put differently: the certificate does not vary; the path to it does. Knowing that focuses the comparison.
How the Quote Is Built — Auditor-Days
The core of an audit fee is effort, measured in auditor-days. Once the days are set, the rest is a day rate. Comparing quotes therefore means comparing how the days were calculated, plus the rate and the associated line items.
Days are driven by:
- Headcount within scope — the largest factor. Not your total payroll, but the people inside the declared scope. How contractors, agency staff, and on-site outsourced personnel are counted changes the number, so settle this first
- Number of sites in scope — each site adds on-site verification and travel. Sampling is sometimes permitted, but treatment varies by body
- Complexity of activities — development, operations, data centre management, contract work; the more distinct activities, the more there is to verify
- Integration with other certifications — auditing alongside ISO 9001 or the Privacy Mark can change the combined effort
- Extent of remote working — it shifts the balance of on-site verification and changes how the audit is assembled
And looking only at days will mislead you, because quotes carry separate line items.
| Line item | Easy to miss |
|---|---|
| Application / registration fee | One-off administrative charge; may sit outside the headline figure |
| Audit fees (stage 1 and 2) | Year one has two audits. Check whether they are shown combined or separately |
| Travel and accommodation | Varies widely if you have regional sites. Actual-cost versus flat-rate also differs |
| Annual maintenance fee | An annual charge to keep the certificate; named differently by each body |
| Re-audit / special audit | Triggered by a major nonconformity. Ask the rate even if you hope not to need it |
For the cost structure overall see The Full Cost of ISMS Certification, and for ranges see Audit Fee Benchmarks and What Moves Them.
Fix Your Assumptions Before Requesting Quotes
This is the part that decides whether the exercise is useful. Quotes requested without common assumptions cannot be compared. Each body applies its own guesses, and the cheapest-looking quote often turns out to have assumed a smaller headcount.
Prepare a single briefing document and send the same one to every body.
① Scope
- The organisational unit (whole company, or a specific division)
- The services and activities in scope
- A list of sites with locations (head office, development site, data centre)
- Whether and how much staff work from home
② Headcount
- People within scope, split by employment type (permanent, contract, agency, on-site outsourced)
- Breakdown by site
- Expected growth over the next year, if significant
③ Nature of the business
- Own product versus contract development; whether you run operations and maintenance
- Outline of the cloud and data centre configuration you use
- Whether you handle medical or personal information, and of what kind
④ What you want
- Target certification date, including any commercial deadline
- Certifications you already hold (ISO 9001, Privacy Mark, and so on)
- Whether you want remote auditing
⑤ Current state
- Progress of ISMS build-out (not started / documenting / internal audit complete)
- Whether you have a support partner
If the scope itself is still unsettled, fix that before requesting quotes. Scope moves headcount, and headcount moves auditor-days. See Defining ISMS Scope and, for medical information, Scope Design for Healthcare Companies.
Five Things to Compare Besides Price
Once comparable quotes are in, weigh these five alongside the numbers. None of them appear in a quotation, so ask about them when you request it.
1. Accreditation
ISMS-AC alone, or also UKAS or ANAB? For domestic business, ISMS-AC is sufficient. If you may need to present the certificate to an overseas customer or parent company, a body holding overseas accreditation saves explanation later.
2. Scheduling flexibility
This is where differences surprise people. Ask:
- The shortest lead time from application to stage 1
- How tightly stage 1 and stage 2 can be spaced
- What happens if you must move a booked date, including any cancellation charge
- Whether remote auditing is supported, and for which parts
When you are working backwards from a commercial deadline, schedule certainty can matter more than a price difference.
3. Sector knowledge of the auditors
How well the auditors understand your domain and technology stack shows up directly in the effort of the audit days: less time spent on background, findings that fit reality. If you handle medical information, it is worth asking whether auditors familiar with healthcare and Japan's three-ministry guidelines are available.
Note that you generally cannot nominate a specific auditor. Ask instead whether auditors with that background are on the roster, and whether you can register a preference.
4. The three-year total
Comparing year-one audit fees alone leads you astray. Lay out surveillance audits in years two and three and the recertification audit in year four, and include annual maintenance fees in the total.
5. How easy they are to deal with
Response time and the specificity of answers during the quoting process are a fair proxy for what working with them during the audit will feel like. Treat the exercise as a sample of the relationship.
A Procedure for Getting Quotes
| Step | What you do | Rough duration |
|---|---|---|
| ① Fix assumptions | One page covering scope, headcount, sites, target date | 1–2 days |
| ② Shortlist | Around three bodies; mix different accreditation combinations | 1 day |
| ③ Request | Send the same document and the same question list to all of them | — |
| ④ Handle follow-up questions | Each body will probe headcount and activities — keep your answers internally consistent | 1–2 weeks |
| ⑤ Receive and compare | Tabulate fees, days, line items, scheduling, accreditation | 1 week |
| ⑥ Decide and apply | Provisionally hold audit dates at the point of application | — |
You do not need to wait until documentation is finished. Moving early is safer: audit slots fill on a first-come basis, and starting the search once the documents are ready can cost you the month you wanted. See ISMS Timeline: What Six Months Actually Looks Like.
In step ④, different bodies will speak to different people on your side. Keep your answers consistent — if headcount is counted differently for each, comparability is gone.
Common Mistakes
Comparing headline figures without the breakdown. The cheapest quote often excluded travel and the annual maintenance fee. Line items are grouped differently by each body, so rebuild them into one table before comparing.
Understating headcount. Tempting, but if the real number differs, effort is recalculated at audit time and you pay the difference. Report in-scope personnel accurately.
Applying without checking dates. The application is accepted; the month you wanted is already full. Apply and hold dates together.
Assuming the choice is permanent. You can change bodies, including transferring at recertification. There are conditions and procedures involved, so it is still best to choose as though you will stay three years.
Conclusion
- An accredited body's certificate is an accredited body's certificate. Differences lie in cost, scheduling, and auditor background — the process, not the outcome
- Audit fees are built on auditor-days, driven by headcount, sites, and complexity, with application, travel, and annual maintenance fees often billed separately
- Fix scope, headcount, sites, and target date on one page before requesting quotes. Without common assumptions the quotes cannot be compared
- Beyond price, compare accreditation, scheduling flexibility, sector knowledge, three-year total, and responsiveness
- Audit slots fill first-come — start before your documentation is finished
- Request from about three bodies on identical terms, then rebuild the responses into a single table before deciding
Pottech obtains quotes from multiple certification bodies as part of ISMS certification support, and helps you pick the body that fits your size, priorities, and timing. We lead the preparation of assumptions, the exchanges with each body, and the scheduling, so your team can concentrate on the comparison and the decision.
See ISMS Certification Support for scope and pricing, or contact us — we are happy to advise on body selection alone. For the wider picture, see What Is an ISMS (ISO/IEC 27001)?, and for the standard your hospital customers are held to, The Three-Ministry Guidelines.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- UKAS (United Kingdom Accreditation Service)
- ANAB (ANSI National Accreditation Board)
Note: methods of calculating audit effort, fee structures, and accreditation arrangements vary by body and are subject to revision. Confirm current terms in each body's published materials and quotation.