ISO 27001 cost for a 50, 100 and 250-person company
How ISO 27001 preparation cost scales with headcount, the three separate lines to budget for, and the one people forget until the invoice arrives.
By Kellwick Team · July 15, 2026 · 3 min read
Headcount is the single biggest driver of ISO 27001 preparation cost, because it drives how much access, how many people and how much evidence an assessment has to cover. What it does not do is set the price on its own - two 100-person companies can be a long way apart depending on entities, scope and how organised their evidence is.
This article is about building a realistic budget for your size, and about the three separate lines it needs.
The three lines to budget
ISO 27001 is rarely one invoice. Plan for up to three, and know which one you are actually buying:
- Find the gaps - a readiness assessment, or the fixed $1,250 Mini Gap Review if you just need a fast snapshot first.
- Close the gaps - a Remediation Sprint, scaled to how many gaps you actually have. Nobody can size this before line 1 is done, and anyone who quotes it beforehand is guessing.
- Keep it running - ISMS Maintenance once certified, so the system does not go stale before surveillance.
Only the first line can be estimated up front. That is not evasion, it is the order the work happens in.
What scales with headcount
- Access reviews. More people, more systems, more joiners and leavers to evidence.
- Interviews. More control owners to talk to, across more teams.
- Entities. A 250-person group is often several legal entities, each multiplying the risk register and Statement of Applicability.
- Evidence volume. More activity produces more evidence - and more places for it to hide.
What each size usually looks like
| Size | The shape of the work |
|---|---|
| ~50 people, one product, one entity | Contained. One access review, few control owners, a single scope statement. Usually the lightest version of the assessment |
| ~100 people, two products | More teams and more joiners and leavers, so evidence gathering grows faster than headcount does. A first-time certification here nearly always needs a remediation line |
| ~250 people, often several entities | Multiple scopes, multiple risk registers, and coordination across teams. This is where an ongoing retainer starts to be cheaper than repeating the scramble |
Where you are also matters: delivery cost differs by market and on-site work adds travel, which is why these are shapes of work rather than figures.
The separate cost people forget
The certification body's audit fee, for Stage 1 and Stage 2, is billed by the CB and not by us. It surprises people who only budgeted for a consultant.
It also scales with headcount - but not the way most people assume. The number of audit days is determined by the standard, not by the body: accredited bodies work to ISO/IEC 27006-1, whose Annex C sets audit duration, and the input is the effective number of people rather than your raw headcount. European Accreditation's guidance on the 2024 revision states that "the square root of the head count of people performing each identical activity may be used to determine the effective number of people, which is used for audit duration calculations, rounded up to the next full number" - applied per category of identical, low-risk activity, and always subject to the body allocating enough time for an effective audit.
The practical consequence for your budget: ask each shortlisted body for the audit-day count and the day rate separately. The days come from the standard; the rate is theirs. If two quotes differ you will know immediately whether you are comparing a different reading of the standard or simply a more expensive body. There is more on this in consultant vs certification body.
Getting your own number
The five-question guide points you at the right engagement, and a short call turns it into a fixed price for your size, scope and market. If you would rather test the water first, the Mini Gap Review is $1,250 and comes off the assessment if you continue within 30 days.
Kellwick prepares you for certification; it does not perform it and cannot guarantee the outcome.
Source: European Accreditation - audit time determination to ISO/IEC 27006-1:2024 (C.3.4).
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.