Cyber Security ISO 27001: What It Is and How to Achieve Certification
ISO 27001 cyber security certification proves your Information Security Management System meets an internationally recognized standard, verified by an accredited external auditor. Most businesses starting this journey get stuck on two questions: how long will it actually take, and why do cost quotes range so wildly. Both have clear, honest answers.
What is ISO 27001, and what does the certification journey look like?
ISO 27001 is the international standard for building an Information Security Management System, or ISMS. Certification runs through gap analysis, documentation, a two-part external audit known as Stage 1 Stage 2 audit, and results in a certificate valid three years, maintained through annual surveillance audits.
The full path typically follows this order: gap analysis against current ISO 27001 requirements, building your risk assessment and Statement of Applicability, implementing selected Annex A controls, running an internal audit, then engaging an accredited certification body for the external Stage 1 and Stage 2 audits. Skipping the internal audit step is the single most common reason organizations arrive at Stage 1 unprepared.
Stage 1 vs Stage 2: what each audit checks
Stage 1 is a documentation review confirming your ISMS is designed correctly and ready for testing. Stage 2 is the operational audit verifying those documented controls are actually implemented and working, through interviews, evidence sampling, and process walkthroughs.
| Audit Stage | Focus | Typical Duration |
| Stage 1 | Documentation, scope, SoA readiness | 1 to 3 days |
| Stage 2 | Control effectiveness, staff interviews, evidence | 2 to 15+ days |
Think of it this way: Stage 1 checks your blueprints, Stage 2 checks whether the building was actually constructed to those specifications. A clean Stage 1 doesn’t certify you, only Stage 2 does, but a weak Stage 1 outcome reliably predicts Stage 2 problems if the gaps aren’t closed first.
A realistic timeline, month by month
Certification timelines scale directly with organization size. Small businesses under 20 employees typically certify in 3 to 6 months, mid-sized organizations of 21 to 200 employees need 5 to 9 months, and larger enterprises can take 12 to 20 months.
| Organization Size | Typical Timeline |
| Under 20 employees | 3 to 6 months |
| 21 to 200 employees | 5 to 9 months |
| 200+ employees | 8 to 20 months |
The gap between Stage 1 and Stage 2 usually runs 30 to 60 days, giving time to close any documentation concerns the Stage 1 auditor flags. Businesses that skip a proper gap analysis at the start routinely add months back onto this timeline once Stage 1 surfaces problems that should have been caught internally first.
What does this cost, and why does the range vary so much?
First-year ISO 27001 certification typically costs $15,000 to $50,000 for small organizations, $50,000 to $150,000 for mid-sized ones, and $100,000 or more for large enterprises, with annual maintenance running 20% to 30% of the initial cost.
The wide range exists because certification body fees follow a fixed formula, not arbitrary pricing. Auditors calculate required audit days from IAF Mandatory Document 5 tables, based on your effective headcount, number of locations, and scope complexity, then multiply that day count by their current day rate. A 15-person single-site company and a 200-person multi-site company simply require a different number of audit days under the same published formula, which explains most of the spread you’ll see between quotes. Consultant fees, internal staff time, and any compliance platform subscription sit on top of that certification body fee and vary far more by choice than the audit fee itself does. Ask any quote you receive to show the audit-day calculation separately from consulting fees, since that’s the one line item that should be nearly identical across accredited bodies for your specific size and scope.
Why 60% of Stage 1 failures come down to documentation, not controls
Stage 1 rarely ends in outright failure, but auditors report that the large majority of Stage 1 corrective action requests trace back to documentation gaps, not missing or ineffective technical controls. Common culprits include a Statement of Applicability without clear risk-based justification and policies that don’t match what staff actually do.
This distinction matters because it changes what you should spend preparation time on. Businesses often over-invest in technical control implementation while under-investing in the specific documentation an auditor needs to see: a Statement of Applicability that clearly links each control decision back to a named risk, internal audit records showing the ISMS has actually run at least once before certification, and management review minutes demonstrating leadership engagement, not just a signed policy. A retail business we’ve seen this pattern with had genuinely strong access controls and encryption in place, technically sound, but their Statement of Applicability simply listed controls as “implemented” without any stated rationale tied to their risk assessment. The Stage 1 auditor flagged this immediately, not because the controls were weak, but because the documentation couldn’t prove the control selection was risk-driven rather than copied from a template. Closing that gap took two weeks of documentation work, not new technical implementation. If your organization has functioning controls but hasn’t stress-tested its SoA rationale and internal audit trail, budget preparation time there first, since that’s where Stage 1 outcomes are actually decided.
Should you pursue ISO 27001 or SOC 2 Type II first?
Choose based on where your revenue and pipeline sit geographically. If most of your customers are in the US, start with SOC 2 Type II, since it’s the de facto standard in American enterprise procurement. If you sell primarily into the UK, EU, or APAC, start with ISO 27001, which those markets expect by name.
| Factor | ISO 27001 | SOC 2 Type II |
| Type | Certification | Attestation report |
| Issued by | Accredited certification body | Licensed CPA firm |
| Dominant market | UK, EU, APAC, government | US enterprise, SaaS |
| Typical cost (first time) | $40,000 to $180,000+ | $30,000 to $150,000+ |
Between 65% and 75% of the underlying controls overlap across both frameworks, so if you’ll eventually need both, pursuing the second one after the first typically costs 40% to 60% less than starting from scratch, since most of the evidence base already exists. Companies selling on both sides of the Atlantic should lead with whichever market represents more current revenue and add the second framework within 12 to 24 months rather than delaying both indefinitely trying to decide which matters more.
Why auditor day rates have risen this year, and what it means for you
Accredited auditor day rates rose roughly 20% in 2026 compared to 2025, now averaging around £1,250 per day in the UK and $1,400 to $2,500 per day in the US. The increase stems from a genuine shortage of qualified accredited Lead Auditors, compounded by residual workload from the ISO 27001:2022 transition deadline.
This matters practically because the day rate is only half your audit fee, the number of required days, set by IAF MD 5 tables based on headcount and scope, is fixed regardless of which accredited body you choose. What you can influence is timing and body selection: booking your Stage 1 and Stage 2 further in advance avoids premium rush pricing from a constrained auditor pool, and smaller accredited certification bodies typically price 15% to 25% below premium brand names for comparable accreditation. If a quote you’ve received still reflects 2024 or 2025 pricing, treat it as stale and request a current one, since the 20% increase isn’t a temporary blip tied to one quarter, it reflects a structural auditor shortage likely to persist through the year.
Choosing a certification body worth paying
A worthwhile certification body holds accreditation specifically for ISO 27001 under ISO 27006, is a member of an IAF MLA signatory accreditation scheme like UKAS accreditation in the UK or ANAB in the US, and can be verified on that accreditation body’s public register before you sign anything.
The IAF Multilateral Recognition Arrangement is what makes a certificate genuinely portable internationally, a UKAS-accredited certificate is recognized as equivalent to one from Germany’s DAkkS or the US’s ANAB, because all IAF signatories audit against the same ISO 17021-1 and ISO 27006 rules. A non-accredited certification body can issue a document that looks similar, but it won’t carry that same cross-border recognition and may not satisfy enterprise procurement teams checking your credentials against a public accreditation database. Before signing, ask the certification body directly which accreditation body accredits them for ISO 27001 specifically, not just for other ISO standards, and confirm you can find them listed on that register, UKAS runs a public CertCheck database for exactly this purpose. Cyber Security Solutions Ltd routinely walks clients through this verification step before they commit to a certification body, since the cost difference between accredited and non-accredited bodies rarely justifies the procurement risk of holding a certificate that gets challenged later.
What does this cost specifically for a UK small business?
A UK small business under 10 employees pursuing a lean, DIY-documented certification can budget approximately £6,250 to £7,000 for year one, covering the mandatory UKAS-accredited audit fee and basic documentation tooling, rising to £15,000 to £20,000 or more if a consultant is engaged.
The minimum unavoidable cost is the certification body’s audit fee itself, calculated from the same IAF MD 5 headcount-based formula covered earlier, which for a micro-business typically starts around £6,250 at 2026 UKAS-accredited day rates. Adding a consultant to guide documentation and gap analysis roughly doubles to triples that figure but often shortens the timeline and reduces the risk of a delayed Stage 2. For a UK small business deciding between DIY and consultant-led paths, the honest trade-off is time versus money: a focused DIY effort can complete in as little as 90 days if someone internally has the bandwidth, while a consultant-led project typically runs 6 to 9 months but requires far less owner involvement.
Conclusion
ISO 27001 cyber security certification comes down to three honest numbers: a timeline of 3 to 20 months depending on size, a cost driven by a fixed audit-day formula rather than vendor markup, and a Stage 1 outcome decided almost entirely by documentation quality, not technical control strength. Get the gap analysis and Statement of Applicability right first, and the rest of the process becomes predictable. If you want help scoping your certification timeline and budget, Cyber Security Solutions Ltd can walk through it with you at cybersecuritysolutionsltd.com.
FAQs
ISO 27001 is the international standard for building and certifying an Information Security Management System, or ISMS. Certification is issued by an accredited external body after a two-stage audit process, proving to clients and regulators that an organization’s information security practices meet a recognized, independently verified standard.
Certification involves a gap analysis, building a risk assessment and Statement of Applicability, implementing selected Annex A controls, an internal audit, and a two-part external audit, Stage 1 documentation review followed by Stage 2 operational testing, conducted by an accredited certification body.
Not legally, but many small businesses pursue it to win enterprise contracts, satisfy UK government procurement requirements, or meet client security questionnaires. It’s not mandatory in most sectors, but for businesses selling into regulated industries or international markets, it frequently becomes a practical requirement.
Stage 1 is a documentation review confirming your ISMS is designed correctly, typically 1 to 3 days. Stage 2 is the operational audit testing whether documented controls are actually implemented and working, typically 2 to 15 days depending on organization size, through interviews and evidence sampling.
Timelines scale with organization size. Small businesses under 20 employees typically certify in 3 to 6 months, mid-sized organizations need 5 to 9 months, and larger enterprises can take 12 to 20 months. The gap between Stage 1 and Stage 2 usually runs 30 to 60 days.
First-year costs typically run $15,000 to $50,000 for small organizations, $50,000 to $150,000 for mid-sized ones, and $100,000 or more for large enterprises. Costs follow a fixed audit-day formula based on headcount and scope, plus variable consultant and internal staff time.
Choose based on where your revenue is concentrated. US-focused businesses typically start with SOC 2 Type II, since it dominates American enterprise procurement. UK, EU, or APAC-focused businesses typically start with ISO 27001. Since 65% to 75% of controls overlap, adding the second framework later costs significantly less.
