Audit time is not a matter of negotiation, it follows binding accreditation rulebooks. Pick your standards, enter the number of people in scope and see what to budget for.
A rough grouping from our project experience. The segments say nothing about any particular certification body, and nobody is bound by these figures.
Our estimate: €1,400 to €1,800
Pick at least one standard and we will do the maths.
For ISO 9001, 14001 and 45001, IAF MD 5:2023 sets out how many audit days an initial certification takes at a given headcount. For ISO/IEC 27001, ISO/IEC 27006-1:2024 does the same in Annex C. Both rulebooks are binding for accredited certification bodies. A provider may deviate, but has to justify and document the deviation.
Count everyone working in scope, including contractors and freelancers. Part-time counts proportionally. What matters is who actually falls under the management system, not the headcount on the company register.
Data centre operations and many critical processes increase the effort. A workforce doing similar, repetitive tasks with restricted access reduces it. Downward the adjustment is limited: both rulebooks allow a reduction of at most 30 percent.
If you run an integrated management system, shared processes get audited once instead of twice. The more tightly the systems are linked, the larger the discount on total audit time.
A certification cycle runs for three years. Years 2 and 3 each carry a surveillance audit at roughly one third of the initial audit time. That makes the three-year total the more honest number than the year one price.
Planning ISO 27001 specifically? Read the detailed breakdown of ISO 27001 costs. Go to the ISO 27001 cost breakdown