"How much does ISO/IEC 27001 certification cost?" cannot be answered as asked, because the question mixes three different kinds of cost — different payees, different timing, different pricing logic.
If you are holding one quote for ¥2M and another for ¥3.2M, comparing them is meaningless. One includes audit fees; the other does not. One performs your internal audit; the other hands you document templates. One covers year one only; the other includes ongoing operational support. Numbers that are not on the same footing are not decision material.
This article decomposes the cost into audit fees, consulting fees, and internal effort, explains what drives each, and then sets out why you must compare across three years — plus a checklist for reading quotes. For the standard itself, see What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies.
Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Costs vary substantially with organisation size, scope, and certification body; confirm actual figures through individual quotes.
Cost Comes in Three Layers
| Layer | Paid to | How it is set | When it falls |
|---|---|---|---|
| ① Audit fees | Certification body | Auditor-days × rate; days driven by headcount and scope | Twice in year one, then annually |
| ② Consulting fees | Support firm | Scope and duration of support; varies hugely by what is delegated | Over the contract term |
| ③ Internal effort | Yourselves (payroll) | Hours of involvement × loaded cost | Concentrated during the build, continuing after |
These behave very differently. ① is an external, largely non-negotiable payment; ② varies enormously with how you buy; ③ never generates an invoice and so goes unnoticed. Cutting ② to save money frequently just inflates ③.
① Audit Fees — Not Reducible, but Comparable
Audit fees go to the third-party certification body and are normally not included in a support firm's price.
What drives them
The core driver is auditor-days, which follow from:
- Headcount within scope — the largest factor; watch how contractors and seconded staff are counted
- Number of sites in scope — multiple sites add travel and on-site verification
- Complexity of activities — development, operations, data centre work each add
- Whether audits are combined with an existing certification (Privacy Mark, ISO 9001, etc.)
Year one carries two audits: Stage 1 (documentation) and Stage 2 (on-site) — commonly 1–2 days and 2–3 days respectively for a small organisation. Surveillance audits in years two and three are typically shorter than the initial audit.
Published commentary suggests figures around ¥600k for a handful of staff and around ¥1M at 100 staff (verify against primary sources). Because both rates and day-count methods differ by body, budgeting from those numbers is risky. Competitive quotes from several bodies are the only reliable comparison.
Other payments to the certification body
Check whether these are itemised separately:
| Item | What it is |
|---|---|
| Application / registration fees | Administrative charges at application and at registration |
| Audit fees (Stage 1 and 2) | Based on auditor-days |
| Travel and expenses | Auditor travel and accommodation; higher with regional sites |
| Annual maintenance fee | Yearly charge to maintain the certification (names vary) |
| Re-audit / special audit | Follow-up where a major nonconformity is raised |
Travel and the annual maintenance fee are often omitted from headline figures and create real differences over three years. See Choosing a Certification Body and Comparing the Major Certification Bodies.
② Consulting Fees — What Are You Actually Buying?
Price differences between support firms are usually differences in scope, not in rate.
| Support model | Included | Left to you |
|---|---|---|
| Templates only | Procedure and register templates, Q&A | Adaptation, asset inventory, training, internal audit, audit response |
| Documentation support | Templates plus drafting from interviews | Asset inventory work, training, internal audit, audit response |
| Full accompaniment | The above plus project management, liaison with the body, audit support | Decisions, supplying your own data, attending training |
| Including internal audit | The above plus the external party serving as internal audit manager and auditors | Decisions, supplying data, training, approving audit results |
A cheap quote is not a bad quote. If you have experienced staff and only need templates, the first model is the rational buy. The failure mode is choosing a cheap contract with nobody internally to run it, and losing a year.
Variables that move the price
- Whether you need it faster than normal — compressing the timeline concentrates the supporting effort
- How far templates are customised — near-as-is versus fitting an existing internal procedure hierarchy
- How much already exists — existing procedures, registers, and logging reduce the work
- Sector-specific work — in healthcare, three-ministry guideline compliance is a separate workstream
- Technical implementation support — documenting controls and designing them into your product are different products
Pottech's pricing
For reference (all figures excluding tax, assuming organisations up to roughly 50 people and implementation using our document templates):
| Item | Content | Price |
|---|---|---|
| New certification support | First-time certification: overall design, documentation, risk assessment, training, liaison with the certification body, internal audit | from ¥1.2M / year |
| Operational support (year 2 onward) | Reviewing roles and scope, updating risk assessments, internal audit, surveillance and recertification audits | from ¥800k / year |
| Option: Stage 1 attendance | Full-day attendance for the 1-day Stage 1 audit | ¥100k |
| Option: Stage 2 attendance | Full-day attendance for the 2-day Stage 2 audit | ¥200k |
| Option: Three-ministry guideline compliance | Integrating ISMS documents with guideline compliance documents | from ¥1.5M |
| Option: Accelerated timeline | Where certification is needed faster than standard | ¥300k |
| Option: Security-aware PM support | Supporting the project management process | ¥400k |
| Option: Quality management process | Building a QM process alongside | ¥400k |
| Option: Technical support | Design and development support within your product | On request |
Payments to the certification body are not included; we obtain competitive quotes for you. Training material creation is included in the fee, and we can serve as internal audit manager and internal auditors.
③ Internal Effort — The Cost With No Invoice
The layer that never appears in a budget yet most often decides whether certification succeeds.
| Work | Who does it | Why it is heavy |
|---|---|---|
| Deciding scope | Executives + ISMS manager | A business decision with expensive rework |
| Inventorying information assets | Every department | Cross-functional; stalls when replies do not come |
| Risk evaluation and acceptance | ISMS manager + executives | Only you can decide what to accept |
| Reviewing and approving procedures | Department heads | Checking against reality cannot be delegated |
| Completing training | All staff | Headcount × time, chased to 100% completion |
| Management review | Executives | Required of top management; not delegable |
| Correcting audit findings | The departments involved | Proportional to findings, which peak in year one |
Even with external support, decisions, supplying your own information, and attending training always stay in-house. Everything else can, in principle, move outside.
How to estimate it
Precision is elusive; for an internal review, framing it this way moves the discussion along:
- ISMS manager: plan on a sustained share of their normal working time through the build
- Department contacts: concentrated bursts during the asset inventory and procedure review
- All staff: training time × headcount
- Executives: policy approval, management review, attendance at the audit
What matters is not the accuracy of the hours but agreeing in advance who stops normal work, and when. Organisations that skip this almost always run late. See ISMS Timeline: What Six Months Actually Looks Like.
Compare Over Three Years
Costs concentrate in year one, but comparing year one alone is a mistake — certification runs on a three-year cycle.
| Item | Year 1 | Year 2 | Year 3 |
|---|---|---|---|
| Audit fees | Stage 1 + Stage 2 | Surveillance audit | Surveillance audit |
| Annual maintenance fee | Yes | Yes | Yes |
| Consulting fees | New certification support | Operational support (if contracted) | Operational support (if contracted) |
| Internal effort | Heaviest | Internal audit, review, updates | Same |
| Other | Application and registration fees | — | Preparation for year-4 recertification |
Year four brings the recertification audit, close in scale to the initial one. So look at a three-year figure, then budget for the year-four peak.
Whether you can drop consulting fees from year two depends on whether operational know-how actually stayed in-house during year one. If documents were merely produced for you, year two stalls at the internal audit and the risk assessment update. See Preparing for Surveillance Audits and Preparing for the Year-Three Recertification Audit.
A Checklist for Comparing Quotes
Level these items before comparing numbers.
Scope of support
- Are payments to the certification body (audit fees, travel, annual maintenance) included or separate?
- Are procedures, registers, and the Statement of Applicability "templates", "drafting support", or "drafted for you"?
- How much of the asset inventory is covered?
- Who produces the risk assessment table?
- Is training material creation included, or charged separately?
- Is internal audit "supported", or will they serve as internal audit manager and auditors?
- Is attendance on audit days included, or an option?
- Is remediation support for nonconformities included?
Timeline and structure
- What duration is assumed, and what is the surcharge for compressing it?
- Up to what headcount does the price hold, and what happens beyond it?
- Meeting frequency and expected duration per session
- The internal effort they expect of you (be wary if no estimate is offered)
From year two
- What is the annual operational support fee?
- Without it, what must you have in place to run it yourselves?
- Is year-four recertification support charged separately?
Healthcare-specific
- Additional cost of doing three-ministry guideline compliance in parallel
- How handling of medical information is treated within scope
- Whether technical controls in your product can be supported
Handling ISMS and the three-ministry guidelines separately duplicates documentation and inflates running costs indefinitely. See Integrating ISMS Documents with the Three-Ministry Guidelines and The Three-Ministry Two-Guideline Framework.
Where to Cut, and Where Cutting Costs More
Legitimate savings
- Narrow the scope — limiting to specific businesses or sites reduces both auditor-days and documentation. Confirm what your clients actually require first; see Defining ISMS Scope
- Tender the certification body — rates and day-count methods genuinely differ
- Take stock before engaging — presenting existing procedures, registers, and logging lets a support firm narrow its scope
False economies
- Skipping training — attendance records are examined; catching up later costs more
- Going through the motions on internal audit — zero findings invites scrutiny; corrective action records are the evidence the system works
- Submitting templates unchanged — procedures that do not match reality breed nonconformities and re-audit costs
- Estimating internal effort at zero — nothing removes it entirely; plan for it
Conclusion
- Cost has three layers — audit fees, consulting fees, internal effort — with different payees and pricing logic; never compare a single blended number
- Audit fees follow auditor-days, driven by headcount and scope; competitive quotes are the only reliable comparison
- Consulting price differences are differences in scope, not rate: templates, drafting support, accompaniment, and internal-audit-included are different products
- The most overlooked layer is internal effort; decisions, supplying your data, and training cannot be outsourced
- Compare three-year totals, and budget the year-four recertification. Whether you can run alone from year two is decided by how year one is run
- Cut scope and tender the auditor. Cutting training, internal audit, or fidelity to reality costs more later
Pottech supports ISO/IEC 27001 certification for healthcare companies: new certification from ¥1.2M/year and operational support from ¥800k/year (excluding tax, assuming up to roughly 50 people). We obtain competitive quotes from certification bodies, include training material creation, and can act as your internal audit manager and internal auditors.
See ISMS Certification Support for details, or contact us for a quote based on your size and scope.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- Search of ISMS-certified organisations | ISMS-AC
- ISO/IEC 27001 Information security management systems | ISO
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: the general cost levels cited here are indicative figures found in published commentary and require verification against primary sources. Fee and day-count methods differ by certification body. Pottech's prices are current as of publication and subject to change.