Back to Columns
ISMS & Certification12 min read

The Full Cost of ISMS Certification: Audit Fees, Consulting, and Internal Effort

September 14, 2026

The Full Cost of ISMS Certification: Audit Fees, Consulting, and Internal Effort
Share this article

"How much does ISO/IEC 27001 certification cost?" cannot be answered as asked, because the question mixes three different kinds of cost — different payees, different timing, different pricing logic.

If you are holding one quote for ¥2M and another for ¥3.2M, comparing them is meaningless. One includes audit fees; the other does not. One performs your internal audit; the other hands you document templates. One covers year one only; the other includes ongoing operational support. Numbers that are not on the same footing are not decision material.

This article decomposes the cost into audit fees, consulting fees, and internal effort, explains what drives each, and then sets out why you must compare across three years — plus a checklist for reading quotes. For the standard itself, see What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies.

Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Costs vary substantially with organisation size, scope, and certification body; confirm actual figures through individual quotes.

Cost Comes in Three Layers

LayerPaid toHow it is setWhen it falls
① Audit feesCertification bodyAuditor-days × rate; days driven by headcount and scopeTwice in year one, then annually
② Consulting feesSupport firmScope and duration of support; varies hugely by what is delegatedOver the contract term
③ Internal effortYourselves (payroll)Hours of involvement × loaded costConcentrated during the build, continuing after

These behave very differently. ① is an external, largely non-negotiable payment; ② varies enormously with how you buy; ③ never generates an invoice and so goes unnoticed. Cutting ② to save money frequently just inflates ③.

① Audit Fees — Not Reducible, but Comparable

Audit fees go to the third-party certification body and are normally not included in a support firm's price.

What drives them

The core driver is auditor-days, which follow from:

  • Headcount within scope — the largest factor; watch how contractors and seconded staff are counted
  • Number of sites in scope — multiple sites add travel and on-site verification
  • Complexity of activities — development, operations, data centre work each add
  • Whether audits are combined with an existing certification (Privacy Mark, ISO 9001, etc.)

Year one carries two audits: Stage 1 (documentation) and Stage 2 (on-site) — commonly 1–2 days and 2–3 days respectively for a small organisation. Surveillance audits in years two and three are typically shorter than the initial audit.

Published commentary suggests figures around ¥600k for a handful of staff and around ¥1M at 100 staff (verify against primary sources). Because both rates and day-count methods differ by body, budgeting from those numbers is risky. Competitive quotes from several bodies are the only reliable comparison.

Other payments to the certification body

Check whether these are itemised separately:

ItemWhat it is
Application / registration feesAdministrative charges at application and at registration
Audit fees (Stage 1 and 2)Based on auditor-days
Travel and expensesAuditor travel and accommodation; higher with regional sites
Annual maintenance feeYearly charge to maintain the certification (names vary)
Re-audit / special auditFollow-up where a major nonconformity is raised

Travel and the annual maintenance fee are often omitted from headline figures and create real differences over three years. See Choosing a Certification Body and Comparing the Major Certification Bodies.

② Consulting Fees — What Are You Actually Buying?

Price differences between support firms are usually differences in scope, not in rate.

Support modelIncludedLeft to you
Templates onlyProcedure and register templates, Q&AAdaptation, asset inventory, training, internal audit, audit response
Documentation supportTemplates plus drafting from interviewsAsset inventory work, training, internal audit, audit response
Full accompanimentThe above plus project management, liaison with the body, audit supportDecisions, supplying your own data, attending training
Including internal auditThe above plus the external party serving as internal audit manager and auditorsDecisions, supplying data, training, approving audit results

A cheap quote is not a bad quote. If you have experienced staff and only need templates, the first model is the rational buy. The failure mode is choosing a cheap contract with nobody internally to run it, and losing a year.

Variables that move the price

  • Whether you need it faster than normal — compressing the timeline concentrates the supporting effort
  • How far templates are customised — near-as-is versus fitting an existing internal procedure hierarchy
  • How much already exists — existing procedures, registers, and logging reduce the work
  • Sector-specific work — in healthcare, three-ministry guideline compliance is a separate workstream
  • Technical implementation support — documenting controls and designing them into your product are different products

Pottech's pricing

For reference (all figures excluding tax, assuming organisations up to roughly 50 people and implementation using our document templates):

ItemContentPrice
New certification supportFirst-time certification: overall design, documentation, risk assessment, training, liaison with the certification body, internal auditfrom ¥1.2M / year
Operational support (year 2 onward)Reviewing roles and scope, updating risk assessments, internal audit, surveillance and recertification auditsfrom ¥800k / year
Option: Stage 1 attendanceFull-day attendance for the 1-day Stage 1 audit¥100k
Option: Stage 2 attendanceFull-day attendance for the 2-day Stage 2 audit¥200k
Option: Three-ministry guideline complianceIntegrating ISMS documents with guideline compliance documentsfrom ¥1.5M
Option: Accelerated timelineWhere certification is needed faster than standard¥300k
Option: Security-aware PM supportSupporting the project management process¥400k
Option: Quality management processBuilding a QM process alongside¥400k
Option: Technical supportDesign and development support within your productOn request

Payments to the certification body are not included; we obtain competitive quotes for you. Training material creation is included in the fee, and we can serve as internal audit manager and internal auditors.

③ Internal Effort — The Cost With No Invoice

The layer that never appears in a budget yet most often decides whether certification succeeds.

WorkWho does itWhy it is heavy
Deciding scopeExecutives + ISMS managerA business decision with expensive rework
Inventorying information assetsEvery departmentCross-functional; stalls when replies do not come
Risk evaluation and acceptanceISMS manager + executivesOnly you can decide what to accept
Reviewing and approving proceduresDepartment headsChecking against reality cannot be delegated
Completing trainingAll staffHeadcount × time, chased to 100% completion
Management reviewExecutivesRequired of top management; not delegable
Correcting audit findingsThe departments involvedProportional to findings, which peak in year one

Even with external support, decisions, supplying your own information, and attending training always stay in-house. Everything else can, in principle, move outside.

How to estimate it

Precision is elusive; for an internal review, framing it this way moves the discussion along:

  • ISMS manager: plan on a sustained share of their normal working time through the build
  • Department contacts: concentrated bursts during the asset inventory and procedure review
  • All staff: training time × headcount
  • Executives: policy approval, management review, attendance at the audit

What matters is not the accuracy of the hours but agreeing in advance who stops normal work, and when. Organisations that skip this almost always run late. See ISMS Timeline: What Six Months Actually Looks Like.

Compare Over Three Years

Costs concentrate in year one, but comparing year one alone is a mistake — certification runs on a three-year cycle.

ItemYear 1Year 2Year 3
Audit feesStage 1 + Stage 2Surveillance auditSurveillance audit
Annual maintenance feeYesYesYes
Consulting feesNew certification supportOperational support (if contracted)Operational support (if contracted)
Internal effortHeaviestInternal audit, review, updatesSame
OtherApplication and registration feesPreparation for year-4 recertification

Year four brings the recertification audit, close in scale to the initial one. So look at a three-year figure, then budget for the year-four peak.

Whether you can drop consulting fees from year two depends on whether operational know-how actually stayed in-house during year one. If documents were merely produced for you, year two stalls at the internal audit and the risk assessment update. See Preparing for Surveillance Audits and Preparing for the Year-Three Recertification Audit.

A Checklist for Comparing Quotes

Level these items before comparing numbers.

Scope of support

  • Are payments to the certification body (audit fees, travel, annual maintenance) included or separate?
  • Are procedures, registers, and the Statement of Applicability "templates", "drafting support", or "drafted for you"?
  • How much of the asset inventory is covered?
  • Who produces the risk assessment table?
  • Is training material creation included, or charged separately?
  • Is internal audit "supported", or will they serve as internal audit manager and auditors?
  • Is attendance on audit days included, or an option?
  • Is remediation support for nonconformities included?

Timeline and structure

  • What duration is assumed, and what is the surcharge for compressing it?
  • Up to what headcount does the price hold, and what happens beyond it?
  • Meeting frequency and expected duration per session
  • The internal effort they expect of you (be wary if no estimate is offered)

From year two

  • What is the annual operational support fee?
  • Without it, what must you have in place to run it yourselves?
  • Is year-four recertification support charged separately?

Healthcare-specific

  • Additional cost of doing three-ministry guideline compliance in parallel
  • How handling of medical information is treated within scope
  • Whether technical controls in your product can be supported

Handling ISMS and the three-ministry guidelines separately duplicates documentation and inflates running costs indefinitely. See Integrating ISMS Documents with the Three-Ministry Guidelines and The Three-Ministry Two-Guideline Framework.

Where to Cut, and Where Cutting Costs More

Legitimate savings

  • Narrow the scope — limiting to specific businesses or sites reduces both auditor-days and documentation. Confirm what your clients actually require first; see Defining ISMS Scope
  • Tender the certification body — rates and day-count methods genuinely differ
  • Take stock before engaging — presenting existing procedures, registers, and logging lets a support firm narrow its scope

False economies

  • Skipping training — attendance records are examined; catching up later costs more
  • Going through the motions on internal audit — zero findings invites scrutiny; corrective action records are the evidence the system works
  • Submitting templates unchanged — procedures that do not match reality breed nonconformities and re-audit costs
  • Estimating internal effort at zero — nothing removes it entirely; plan for it

Conclusion

  1. Cost has three layers — audit fees, consulting fees, internal effort — with different payees and pricing logic; never compare a single blended number
  2. Audit fees follow auditor-days, driven by headcount and scope; competitive quotes are the only reliable comparison
  3. Consulting price differences are differences in scope, not rate: templates, drafting support, accompaniment, and internal-audit-included are different products
  4. The most overlooked layer is internal effort; decisions, supplying your data, and training cannot be outsourced
  5. Compare three-year totals, and budget the year-four recertification. Whether you can run alone from year two is decided by how year one is run
  6. Cut scope and tender the auditor. Cutting training, internal audit, or fidelity to reality costs more later

Pottech supports ISO/IEC 27001 certification for healthcare companies: new certification from ¥1.2M/year and operational support from ¥800k/year (excluding tax, assuming up to roughly 50 people). We obtain competitive quotes from certification bodies, include training material creation, and can act as your internal audit manager and internal auditors.

See ISMS Certification Support for details, or contact us for a quote based on your size and scope.

References and Sources

Note: the general cost levels cited here are indicative figures found in published commentary and require verification against primary sources. Fee and day-count methods differ by certification body. Pottech's prices are current as of publication and subject to change.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.