How much does an ISO 27001 readiness assessment cost?
A straight answer with real ranges: what an ISO 27001 readiness assessment costs, what moves the number, and how to narrow yours before you commit.
By Kellwick Team · July 14, 2026 · 2 min read
A full ISO 27001 readiness assessment typically runs from $4,500 to $8,500, depending mostly on your headcount, the size of your ISMS scope and how good your evidence already is. A smaller team with a single product and one entity sits at the bottom of that range; a 200-person company with multiple entities sits at the top.
That is the honest answer up front. Below is how the number is built, so you can place yourself in the range before you talk to anyone. If you only need a fast, low-cost snapshot rather than the full picture, that is a different (and cheaper) product - the Mini Gap Review at a fixed $1,250.
The range
| Company size | Typical readiness assessment |
|---|---|
| Up to 50 employees | from $4,500 |
| 51-150 employees | from $6,000 |
| 151-250 employees | from $7,500 |
| Multiple entities or complex scope | custom |
These are indicative ranges, not a quote. The final fixed price is set on a short scoping call. You can also get an instant estimate from the pricing calculator.
What changes the price
- Employee count. More people means more access to review, more joiners and leavers, and more interviews.
- ISMS scope. One product and one cloud account is faster than five products, two data centres and an on-prem estate.
- Number of entities. Group structures multiply the risk register, the Statement of Applicability and the evidence.
- Audit date. A tight deadline compresses the work and sometimes needs more hands.
- Current evidence quality. If your evidence is already organised, the assessment is faster. If it is scattered across Drive, Slack and inboxes, finding it is part of the job.
What you actually get
A readiness assessment is not a checklist. It covers clauses 4-10 and Annex A, reviews your risk register and Statement of Applicability, includes interviews and evidence review, and hands back a readiness score, a gap register ranked by audit impact, a view of your Stage 1 and Stage 2 risks, and a 30/60/90 remediation plan. See the full inclusions on the pricing page.
A worked example
An 80-person SaaS company with one product, AWS-only infrastructure and an audit five months out lands around $6,000. Their evidence exists but is scattered, so a meaningful part of the work is locating and grading it. They come out with a scored gap register and a plan - and a realistic view of whether their date is achievable.
How to narrow your number
The cheapest way to get a precise figure is a short scoping call. If you would rather sanity-check the size of the problem first, start with the fixed-price Mini Gap Review - and 100% of that fee is credited toward a readiness assessment booked within 30 days.
Kellwick is an independent advisory practice, not a certification body. We prepare you for certification; the certification body's audit fee is separate and quoted by them. Figures here are indicative and not a binding quote.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.