ISO 27001 certification costs most startups $30,000–$70,000 in year one — the accredited certification-body audit is only part of it, alongside consulting, a GRC platform, and internal time, plus recurring annual surveillance audits. It’s the international standard most European and global enterprise buyers expect. With Folksoft’s hands-off, expert-guided approach, most startups reach certification-ready in a fraction of the time and cost — a real GRC analyst and accredited auditors, no dashboard to babysit.
What most startups pay across auditor, tooling, readiness and internal time — for a team of 11–25 on simple infrastructure.
Those are open-market figures. Leave your name and work email and someone from our team will come back to you with your price for this exact scope, or book a call and talk it through.
Indicative ranges based on what early-stage startups typically pay in the US and European markets — your figure depends on scope, cloud footprint and how widely you draw the scope of your ISMS.
Four line items make up an ISO 27001 budget. The certification-body audit — the one everybody quotes — is under a third of it.
An accredited certification body runs Stage 1 (a documentation review of your ISMS) and Stage 2 (the audit proper) and issues the certificate. Only an accredited body can do it, the fee scales with headcount and scope, and — unlike a SOC 2 report — it comes back every year as a surveillance audit.
Standing up the ISMS itself: a risk assessment, the Statement of Applicability, the policy set, an internal audit and a management review. This is the largest single difference from SOC 2 — ISO 27001 certifies a management system, not just a set of controls, so there is real system-building to pay for before an auditor will look at you.
An annual licence to hold the risk register, the SoA, the evidence and the audit trail. Most vendors price per employee, so it grows every time you hire — and it renews at full price in a surveillance year, when there is no certification project to justify it.
The line nobody budgets for. Engineers and founders pulled off the roadmap to run the risk assessment, write 20-odd policies, close Annex A gaps, sit the internal audit and front the management review. It scales on both axes at once — headcount and how much infrastructure is inside the scope statement.
Year one buys the certificate. Years two and three buy the right to keep it — and that bill never goes to zero.
Stage 1 reviews your ISMS documentation; Stage 2 audits it in operation. Pass both and the certificate is issued for three years.
A lighter surveillance audit in years two and three, then a full recertification in year four. The certificate lapses if you skip one.
Budget the cycle, not the certificate. Over three years the recurring side adds up to more than the initial audit did — which is why the scope statement you write in month one is the most expensive decision on the project. See the full ISO 27001 programme.
Most of the savings are in the scope statement and in sequencing, not in haggling with your certification body.
The ISMS scope decides how many systems, sites and people the auditor has to look at — every year, not just this one. A scope drawn around the product and the team that ships it costs a fraction of one drawn around the whole company.
Annex A and the Trust Services Criteria overlap heavily. If you already hold a SOC 2 report, most of your evidence, policies and access reviews carry across — you are paying for the management system and the audit, not for starting again. It works in the other direction too: price a SOC 2 alongside it before you commit to a sequence.
A consultant to build the ISMS, a platform to hold the evidence and a certification body to audit it is three invoices and three onboardings. The certification body has to stay independent — the other two do not have to be separate.
SOC 2, HIPAA and GDPR share most of their controls with ISO 27001. Running them through one ISMS costs far less than three separate projects — toggle them in the calculator above to see the difference.
What founders ask us before they budget for certification.
Book a DemoMost startups spend $30,000–$70,000 in year one, and a large scope on complex infrastructure can reach $88,000. That splits into the accredited certification-body audit ($10,000–$18,000 for Stage 1 and Stage 2 together), readiness and consulting to stand up the ISMS ($8,000–$20,000), a GRC platform licence ($8,000–$16,000 a year), and your own team’s time ($5,000–$34,000, depending on headcount and how much infrastructure is in scope). Folksoft covers the same scope for less. What that comes to depends on your environment, so we price it properly rather than guessing at it here — leave your details on the calculator above and we’ll come back with your price.
Expect $10,000–$18,000 for an initial certification, covering both Stage 1 (a review of your ISMS documentation) and Stage 2 (the audit itself). The fee is quoted in auditor-days, so it scales with headcount, the number of sites and how wide your scope statement is drawn. It has to be paid to an accredited certification body directly — that body must stay independent of whoever helped you prepare, which is why no consultant or platform can bundle it into their own price.
ISO 27001 costs more. A SOC 2 Type 2 year lands at $20,000–$51,500 on the open market against $31,000–$88,000 for an initial ISO 27001 certification. Two things drive the gap: the certification body charges more than a CPA firm, and ISO certifies a whole management system — a risk assessment, a Statement of Applicability, an internal audit and a management review — rather than a set of controls, so there is more to build before anyone audits you. Which one you need is usually decided by your buyers, not your budget: US buyers ask for SOC 2, European and global enterprise buyers ask for ISO 27001. If you need both, run them through one programme — see the SOC 2 cost calculator and add ISO 27001 to that estimate.
The surveillance audit itself runs $4,500–$8,500 — roughly 40–50% of the initial certification fee, because the auditor samples the ISMS rather than certifying it from scratch. But the audit is not the whole bill: expect $18,000–$49,500 for a full surveillance year once you add continued consulting or support, the GRC platform licence, which renews at full price, and the internal time spent on evidence and the annual internal audit. Certificates run on a three-year cycle — surveillance in years two and three, then a full recertification — and the certificate lapses if you skip one. Switch the calculator above to Recertification to see your own figure.
Typically 3–6 months from kickoff to certificate on the open market. Most of that is building the ISMS and running it long enough to have evidence — the Stage 1 and Stage 2 audits themselves are a matter of days. Certification bodies also want to see the internal audit and management review completed before Stage 2, which sets a floor on how fast anyone can go. Folksoft gets startups certification-ready in weeks to months, and the surveillance audits afterwards run in the background.
Fifteen minutes on a call and we’ll scope your ISMS, name the price and give you a date for the certificate.