Back to Columns
ISMS & Certification11 min read

How to Choose a Certification Body: What to Look for When Comparing Quotes

September 14, 2026

How to Choose a Certification Body: What to Look for When Comparing Quotes
Share this article

Sooner or later, every ISMS project reaches the question: which certification body do we apply to? This is where many project owners stall. Line up the names and the websites all say much the same thing, and none of them publish a price list. The usual outcome is to apply to whichever body someone happened to recommend.

But choosing a certification body decides more than year-one cost. It shapes your schedule, your internal workload, and how smoothly audit days run, for three years. And the material you need to compare does not exist until you ask for it on consistent terms. Describe the same company and the same scope differently to two bodies and their quotes rest on different assumptions — at which point the numbers cannot be compared at all.

This article covers what drives a certification body's quote, what you must settle before requesting one, and what to compare besides price. For the individual bodies, see Comparing the Main Certification Bodies: BSI, JQA, BV, SGS, DQS.

Disclaimer: This article is general information. Audit-day calculations, fees, and accreditation arrangements differ by body, and each body's published materials and quotation are authoritative. Base your decision on those.

What Differs Between Bodies — and What Does Not

Start with the premise. If a body is accredited, the certificate it issues carries the same force as any other. There is no "higher grade" certificate. A customer receiving it will treat an accredited certificate the same way regardless of which body issued it.

In Japan, the accreditation body for ISMS certification is ISMS-AC (Information Management System Accreditation Center). Overseas there are bodies such as UKAS in the UK and ANAB in the US, and some certification bodies hold more than one accreditation. That combination matters mainly when you show the certificate to overseas counterparties — see ISMS-AC, UKAS and ANAB: How Accreditation Bodies Differ.

So what does differ? In practice, three things.

Where differences appearSpecificallyWhat it affects
Fee and effort calculationHow auditor-days are counted, the day rate, treatment of travel and annual maintenance feesYear-one cost and three-year total
SchedulingAvailability of audit dates, support for compressed timelines, remote auditingWhen you actually certify — and whether you hit a commercial deadline
Auditor backgroundWhich sector and technical experience the assigned auditors bringHow much you must explain on the day; how usable the findings are

Put differently: the certificate does not vary; the path to it does. Knowing that focuses the comparison.

How the Quote Is Built — Auditor-Days

The core of an audit fee is effort, measured in auditor-days. Once the days are set, the rest is a day rate. Comparing quotes therefore means comparing how the days were calculated, plus the rate and the associated line items.

Days are driven by:

  • Headcount within scope — the largest factor. Not your total payroll, but the people inside the declared scope. How contractors, agency staff, and on-site outsourced personnel are counted changes the number, so settle this first
  • Number of sites in scope — each site adds on-site verification and travel. Sampling is sometimes permitted, but treatment varies by body
  • Complexity of activities — development, operations, data centre management, contract work; the more distinct activities, the more there is to verify
  • Integration with other certifications — auditing alongside ISO 9001 or the Privacy Mark can change the combined effort
  • Extent of remote working — it shifts the balance of on-site verification and changes how the audit is assembled

And looking only at days will mislead you, because quotes carry separate line items.

Line itemEasy to miss
Application / registration feeOne-off administrative charge; may sit outside the headline figure
Audit fees (stage 1 and 2)Year one has two audits. Check whether they are shown combined or separately
Travel and accommodationVaries widely if you have regional sites. Actual-cost versus flat-rate also differs
Annual maintenance feeAn annual charge to keep the certificate; named differently by each body
Re-audit / special auditTriggered by a major nonconformity. Ask the rate even if you hope not to need it

For the cost structure overall see The Full Cost of ISMS Certification, and for ranges see Audit Fee Benchmarks and What Moves Them.

Fix Your Assumptions Before Requesting Quotes

This is the part that decides whether the exercise is useful. Quotes requested without common assumptions cannot be compared. Each body applies its own guesses, and the cheapest-looking quote often turns out to have assumed a smaller headcount.

Prepare a single briefing document and send the same one to every body.

① Scope

  • The organisational unit (whole company, or a specific division)
  • The services and activities in scope
  • A list of sites with locations (head office, development site, data centre)
  • Whether and how much staff work from home

② Headcount

  • People within scope, split by employment type (permanent, contract, agency, on-site outsourced)
  • Breakdown by site
  • Expected growth over the next year, if significant

③ Nature of the business

  • Own product versus contract development; whether you run operations and maintenance
  • Outline of the cloud and data centre configuration you use
  • Whether you handle medical or personal information, and of what kind

④ What you want

  • Target certification date, including any commercial deadline
  • Certifications you already hold (ISO 9001, Privacy Mark, and so on)
  • Whether you want remote auditing

⑤ Current state

  • Progress of ISMS build-out (not started / documenting / internal audit complete)
  • Whether you have a support partner

If the scope itself is still unsettled, fix that before requesting quotes. Scope moves headcount, and headcount moves auditor-days. See Defining ISMS Scope and, for medical information, Scope Design for Healthcare Companies.

Five Things to Compare Besides Price

Once comparable quotes are in, weigh these five alongside the numbers. None of them appear in a quotation, so ask about them when you request it.

1. Accreditation

ISMS-AC alone, or also UKAS or ANAB? For domestic business, ISMS-AC is sufficient. If you may need to present the certificate to an overseas customer or parent company, a body holding overseas accreditation saves explanation later.

2. Scheduling flexibility

This is where differences surprise people. Ask:

  • The shortest lead time from application to stage 1
  • How tightly stage 1 and stage 2 can be spaced
  • What happens if you must move a booked date, including any cancellation charge
  • Whether remote auditing is supported, and for which parts

When you are working backwards from a commercial deadline, schedule certainty can matter more than a price difference.

3. Sector knowledge of the auditors

How well the auditors understand your domain and technology stack shows up directly in the effort of the audit days: less time spent on background, findings that fit reality. If you handle medical information, it is worth asking whether auditors familiar with healthcare and Japan's three-ministry guidelines are available.

Note that you generally cannot nominate a specific auditor. Ask instead whether auditors with that background are on the roster, and whether you can register a preference.

4. The three-year total

Comparing year-one audit fees alone leads you astray. Lay out surveillance audits in years two and three and the recertification audit in year four, and include annual maintenance fees in the total.

5. How easy they are to deal with

Response time and the specificity of answers during the quoting process are a fair proxy for what working with them during the audit will feel like. Treat the exercise as a sample of the relationship.

A Procedure for Getting Quotes

StepWhat you doRough duration
① Fix assumptionsOne page covering scope, headcount, sites, target date1–2 days
② ShortlistAround three bodies; mix different accreditation combinations1 day
③ RequestSend the same document and the same question list to all of them
④ Handle follow-up questionsEach body will probe headcount and activities — keep your answers internally consistent1–2 weeks
⑤ Receive and compareTabulate fees, days, line items, scheduling, accreditation1 week
⑥ Decide and applyProvisionally hold audit dates at the point of application

You do not need to wait until documentation is finished. Moving early is safer: audit slots fill on a first-come basis, and starting the search once the documents are ready can cost you the month you wanted. See ISMS Timeline: What Six Months Actually Looks Like.

In step ④, different bodies will speak to different people on your side. Keep your answers consistent — if headcount is counted differently for each, comparability is gone.

Common Mistakes

Comparing headline figures without the breakdown. The cheapest quote often excluded travel and the annual maintenance fee. Line items are grouped differently by each body, so rebuild them into one table before comparing.

Understating headcount. Tempting, but if the real number differs, effort is recalculated at audit time and you pay the difference. Report in-scope personnel accurately.

Applying without checking dates. The application is accepted; the month you wanted is already full. Apply and hold dates together.

Assuming the choice is permanent. You can change bodies, including transferring at recertification. There are conditions and procedures involved, so it is still best to choose as though you will stay three years.

Conclusion

  1. An accredited body's certificate is an accredited body's certificate. Differences lie in cost, scheduling, and auditor background — the process, not the outcome
  2. Audit fees are built on auditor-days, driven by headcount, sites, and complexity, with application, travel, and annual maintenance fees often billed separately
  3. Fix scope, headcount, sites, and target date on one page before requesting quotes. Without common assumptions the quotes cannot be compared
  4. Beyond price, compare accreditation, scheduling flexibility, sector knowledge, three-year total, and responsiveness
  5. Audit slots fill first-come — start before your documentation is finished
  6. Request from about three bodies on identical terms, then rebuild the responses into a single table before deciding

Pottech obtains quotes from multiple certification bodies as part of ISMS certification support, and helps you pick the body that fits your size, priorities, and timing. We lead the preparation of assumptions, the exchanges with each body, and the scheduling, so your team can concentrate on the comparison and the decision.

See ISMS Certification Support for scope and pricing, or contact us — we are happy to advise on body selection alone. For the wider picture, see What Is an ISMS (ISO/IEC 27001)?, and for the standard your hospital customers are held to, The Three-Ministry Guidelines.

References and Sources

Note: methods of calculating audit effort, fee structures, and accreditation arrangements vary by body and are subject to revision. Confirm current terms in each body's published materials and quotation.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.