The existing budgeting indication on this knowledge base for a small, clearly bounded ISO 27001 project is EUR 4,000–15,000 in external first-year expenditure. This is an editorial estimate, not a quotation, market survey or official ISO fee. Internal working time is additional. Actual scope and included services determine whether the range is relevant.
Compare equivalent budgets
Request quotations using the same scope, sites and staffing assumptions. Separate certification audits, consultancy, software, training and remediation. Record exclusions. The table carries the existing Dutch page’s indications; a stage-1-only quotation cannot be compared with a combined stage 1 and stage 2 budget.
Internal time must be counted
The existing table uses 80–200 internal hours as an indication for the described small-scope scenario. Multiply those hours by your own internal cost rate. Complex organisations may need considerably more.
Plan through evidence milestones
Build the timetable around scope, risk assessment, implemented controls, evidence of operation, internal audit and management review. Allow time to resolve findings. Purchasing software or paying an audit invoice does not guarantee certification. Confirm audit availability with the certification body.
Include recurring years
Budget for surveillance audits, maintenance, internal reviews and recertification separately. Compare offers across the certification cycle rather than only the first invoice. Check how a change in locations, scope or services affects the quotation.
Four questions for each quotation
- Which services, sites and activities are included?
- Which audit stages, reports and follow-up are covered?
- Which internal work and technical improvements are excluded?
- What changes financially if the audit is delayed, findings require extra work or scope expands?
Use the implementation roadmap to sequence the work. ISO Ready is our own commercial offering; compare options against the same operational requirements.