How much does an ISO 27001 readiness assessment cost?
What actually drives the price of an ISO 27001 readiness assessment, how to place your own company before you talk to anyone, and the one figure we publish.
By Kellwick Team · July 14, 2026 · 3 min read
The honest answer is that it depends on four things you can assess yourself in about ten minutes: how many people you have, how wide the ISMS scope is, how many legal entities are in it, and how organised your evidence already is. This article is about how to place yourself against those four, so the conversation starts from a real position rather than a guess.
We publish one price, and it is the one that does not move: the Mini Gap Review is $1,250 fixed, delivered remotely, and 100% of it is credited toward a readiness assessment booked within 30 days. Everything larger is quoted on a short call, because it genuinely differs by market, by scope, and by whether anyone needs to be on site.
What drives your number
| What we look at | Why it moves the price |
|---|---|
| Employee count | More people means more access to review, more joiners and leavers, and more interviews |
| ISMS scope | One product on one cloud account is a different job from five products, two data centres and an on-prem estate |
| Number of legal entities | A group structure multiplies the risk register, the Statement of Applicability and the evidence behind both |
| Audit date | A compressed deadline needs more hands working in parallel, not the same work done faster |
| Evidence quality today | If evidence is already organised the assessment is quick. If it is spread across Drive, Slack and inboxes, finding it is part of the work |
| Where you are | Delivery cost differs by market, and on-site work adds travel |
The last row is why you will not find a single published range here. A number that is right for a 60-person company in one country is wrong for the same company in another, and quoting one range for both would mean overcharging one of them.
Place yourself in about ten minutes
Count your employees. Write down what is in scope - products, environments, entities. Then ask one honest question about evidence: if an auditor asked for proof that access reviews happened last quarter, how long would it take to produce it? If the answer is "an hour", your assessment is at the light end of the work. If it is "I would have to ask three people and search Slack", locating and grading evidence will be a real part of it.
That single question predicts more about the effort than headcount does.
What you actually get
A readiness assessment is not a checklist. It covers clauses 4-10 and Annex A, reviews your risk register and Statement of Applicability, includes interviews and evidence review, and hands back a readiness score, a gap register ranked by audit impact, a view of your Stage 1 and Stage 2 risks, and a 30/60/90 remediation plan. The full inclusions are on the pricing page.
The cheapest way to get a real number
Two routes, both without a sales process. Take the five-question guide to see which engagement fits, or start with the fixed-price Mini Gap Review - it tells you the size of the problem for $1,250, and the fee comes off the assessment if you continue within 30 days.
Kellwick is an independent advisory practice, not a certification body. We prepare you for certification; the certification body's audit fee is separate and quoted by them.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.