Independent ISO 27001 certification-body directory

Find the right ISO 27001 certification body. Know the real cost.

We've profiled 17 accredited ISO 27001 certification bodies — their prices, their timelines, who to avoid. Tell us about your company and we'll match you with the best-fit CBs, then make them compete for your business with side-by-side quotes. Free. Two minutes. Signing with the first auditor who calls you is how companies overpay.

Free · 2 minutes · No obligation

93Annex A controls in ISO 27001:2022
3–9 moTypical kickoff-to-certificate
CB onlyCertificates must come from accredited CBs
$8k–$25kPublished Stage 1+2 audit-fee range

How quote matching works

  1. Tell us once — 4 questions, 2 minutes, free.
  2. We match you — licensed CPA firms filtered to your size, scope, and timeline.
  3. Auditors quote you — they send scoped quotes directly; you pick.
Certification-body directory

Accredited ISO 27001 certification bodies

Every CB below is a real, operating accredited certification body with a verified website. We are an independent directory — listings are not endorsements, and we encourage you to confirm each CB's accreditation before engaging.

Certification body

BSI Group

BSI Group originated the standard that became ISO 27001 (as BS 7799) and is one of the world's best-known certification bodies, with auditors in most …

London, United Kingdom · Accredited certification body (UKAS)
Certification body

SGS

SGS is the world's largest testing, inspection and certification company, with a management-systems certification arm covering ISO 27001 in dozens of …

Geneva, Switzerland · Accredited certification body (UKAS and others)
Certification body

Bureau Veritas

Bureau Veritas is a global testing, inspection and certification group dating to 1828, with ISO 27001 certification among a broad management-systems p…

Neuilly-sur-Seine, France · Accredited certification body (UKAS and others)
Certification body

NQA

NQA is a global management-systems certification body with an explicit focus on right-sized service for small and mid-sized companies. It certifies IS…

Dunstable, United Kingdom · Accredited certification body (UKAS / ANAB regionally)

See all 17 CBs →

Compare by stage

The right certification body depends on your stage

A 12-person startup and a 2,000-person enterprise should not hire the same CB. We've grouped the directory by buyer stage, with planning-range pricing for each.

Startups

First certification, small team, price-sensitive. CBs with low planning ranges and fast engagement cycles.

Growth-stage teams

Series A to mid-market. Credible certificates for bigger customers, with SOC 2 / ISO 27701 runway.

Enterprise buyers

Regulated, multi-site, or multi-framework programs — or a stakeholder that requires a globally recognized CB brand.

Start here

ISO 27001, explained honestly

ISO 27001 Cost Guide

Published audit-fee ranges, what drives price, and an interactive estimator.

ISO 27001 Timeline

How long each phase takes, from gap assessment to a certificate on the wall.

Readiness Check

A 2-minute scored quiz that tells you if you're certification-ready.

2026 Pricing Report

A meta-analysis of published ISO 27001 cost data, every number cited.

Choosing a Certification Body

Accreditation, audit days, and the 8 questions to ask before you sign.

ISO 27001 vs SOC 2

Which one your customers actually need — and the combined path.

Best CBs by Use Case

Buyer-matched picks: startups, SaaS scaleups, industrial, enterprise.

RFP & Quote Comparison

What to put in your brief, a printable comparison worksheet, and engagement red flags.

Our Methodology

How we vet certification bodies, label every price, and keep rankings unbought.

Common questions

ISO 27001 basics

What is ISO 27001 certification?

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). Certification means an accredited certification body audited your ISMS — Stage 1 (documentation review) and Stage 2 (on-site effectiveness testing) — and issued a certificate valid for three years, with annual surveillance audits.

How much does ISO 27001 certification cost?

Published 2026 sources put the Stage 1 + Stage 2 audit fee at roughly $8,000 to $25,000 for a small-to-mid company, with first-year all-in costs (implementation, tooling, audits) of $15,000 to $50,000. See our cost guide and the 2026 pricing report for sourced numbers.

How long does ISO 27001 certification take?

Typically 3 to 9 months from kickoff to certificate: 1–4 months of implementation and remediation, then Stage 1 and Stage 2 audits. See the timeline.

Who can issue an ISO 27001 certificate?

Only an accredited certification body (CB) — a body accredited by a national accreditation body such as UKAS (UK), ANAB (US), DAkkS (Germany), or RvA (Netherlands). Consultants can prepare you, but they cannot issue the certificate.

All frequently asked questions →

Get quotes from accredited certification bodies

Tell us about your company and timeline once. We'll match you with CBs who fit — no obligation, no spam.

Get a free quote