ISO 27001 consultant vs certification body: what you pay for what
Two separate bills people constantly confuse. What a readiness consultant charges, what the certification body charges, and why you need both.
By Kellwick Team · July 13, 2026 · 3 min read
There are two separate costs in getting ISO 27001, and they go to two different organisations that are not allowed to be the same one. A readiness consultant (like Kellwick) prepares you: finds the gaps, builds the evidence, gets you audit-ready. A certification body runs the actual Stage 1 and Stage 2 audit and issues the certificate. You pay both, and confusing the two is how budgets go wrong.
Here is what each side does and roughly what it costs.
Who charges you for what
| Readiness consultant | Certification body | |
|---|---|---|
| Role | Prepares you for the audit | Runs the audit, issues the certificate |
| Example work | Gap analysis, evidence, risk register, SoA, remediation | Stage 1 and Stage 2 audit, surveillance |
| How it is priced | Scoped per engagement; the entry review is a fixed $1,250 | Set by the CB, scales with size and scope |
| Can they also certify you? | No | Yes - that is their only job |
Why they have to be different
Accredited certification bodies cannot audit an ISMS they built themselves - that independence is the whole point of the certificate. So a consultant who prepares you cannot also be the body that certifies you, and any firm claiming to do both is not describing accredited certification. This is a feature, not a hassle: it is what makes the certificate mean something to your customers.
Kellwick sits firmly on the preparation side. We are an independent advisory practice, not a certification body, and we never issue certificates or guarantee outcomes.
What you pay a consultant for
The readiness assessment, any remediation to close the gaps, and often an ongoing retainer to keep the ISMS alive between audits. Scope, deliverables and the factors that move each price are published on the pricing page; the number is set on a scoping call, because delivery cost, scope and travel differ by market.
What you pay the certification body for
Their Stage 1 and Stage 2 audit fee, then an annual surveillance audit, and a recertification audit every three years.
Here is the part almost nobody is told, and it changes how you should negotiate: the certification body does not decide how long your audit takes. Accredited bodies are assessed against ISO/IEC 17021-1 and, for information security specifically, ISO/IEC 27006-1, whose Annex C determines audit duration. The 2024 revision broke that annex out further, with separate calculations for surveillance, recertification, multi-site and extensions of scope.
The input is not simply your headcount either. It is the effective number of people. European Accreditation's guidance on the 2024 revision puts it plainly:
"The square root of the head count of people performing each identical activity may be used to determine the effective number of people, which is used for audit duration calculations, rounded up to the next full number."
That reduction is applied per category of people doing genuinely identical, low-risk work - not to your whole company - and the body still has to satisfy itself that "sufficient audit time is allocated for a complete and effective audit". So it is a real mechanism, not a discount you can ask for.
What this means when you collect quotes
A certification body's fee is, in effect, mandated audit days multiplied by that body's own day rate. The days come from the standard. The rate is a commercial decision that is entirely theirs.
So when you shortlist bodies, ask each one for two things separately:
- How many audit days they have calculated for Stage 1, Stage 2 and each surveillance visit - and how they arrived at the effective number of people.
- Their day rate.
If two quotes differ, that comparison tells you whether you are looking at a different reading of the standard (worth questioning) or simply a more expensive body (worth shopping). A single blended number tells you neither.
Budgeting for both
A realistic first-year ISO 27001 budget has three parts: preparation (consultant), the certification audit (CB), and maintenance so it does not go stale before surveillance. The five-question guide will point you at the right preparation engagement; the CB quotes the rest, and now you know what to ask them for.
Sources: European Accreditation - audit time determination to ISO/IEC 27006-1:2024 (C.3.4); Assent Risk Management on the ISO/IEC 27006-1:2024 changes. ISO/IEC 27006-1:2024 itself is a purchasable standard; the audit-time tables are not reproduced here.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.