Costs

How ISO 27001 Audit Fees Are Actually Calculated (Audit Days Explained)

ISO/IEC 27006 tables, day rates, and why two CBs quote different fees for the same company — plus how to sanity-check any quote.

The formula

ISO 27001 audit fees follow a simple formula: audit days × day rate. Audit days are derived from ISO/IEC 27006 tables based on your in-scope headcount and complexity; the day rate is the CB's commercial choice. When a quote seems high, one of those two inputs is doing the work — find out which.

The day tables

ISO/IEC 27006 sets minimum audit durations from effective headcount. Roughly: a 10-person scope might need 3–4 audit days for Stage 2; a 50-person scope more like 5–7; a 200-person scope 9–12+. Complexity factors (multiple sites, high-risk processing, additional schemes) add days on top. These are floors, not ceilings — CBs can justify more, but they should be able to justify them.

Published day rates

Published 2026 sources put accredited-CB day rates around $1,500–$2,200/day in the US and £1,000–£1,500/day in the UK. Premium global brands sit at the top of the band; regional and specialist CBs toward the bottom. Travel and expenses may be extra — ask.

Why quotes differ

How to compare quotes

Normalize every quote to the same table: Stage 1 days, Stage 2 days, day rate, travel, surveillance years 2–3, and recertification. Two quotes with the same total can hide very different day counts — the one with fewer, more expensive days is usually the senior team. Our RFP and quote worksheet gives you a printable comparison template.

Frequently asked

What is ISO/IEC 27006?

The standard that sets rules for bodies auditing and certifying ISMSs — including the audit-day tables CBs use to calculate engagement size. It's the reason fees are headcount-driven.

Can I negotiate audit days down?

You can challenge assumptions — headcount band, site sampling, complexity factors — but the 27006 tables are floors. A CB that undercuts the table minimum is a red flag, not a bargain.

Related reading

Get quotes from accredited CBs

One brief, matched certification bodies, comparable quotes. Free · 2 minutes · no obligation.

Get a free quote

More guides

Certification bodies

How to Choose an ISO 27001 Certification Body: 8 Questions to Ask

The vetting checklist we recommend: accreditation verification, audit teams, audit-day math, fees, and the red flags that signal a bad fit.

Fundamentals

ISO 27001 Stage 1 vs Stage 2 Audits: What's Actually Different

Documentation review vs effectiveness testing: what each stage checks, how long each takes, and what sinks companies at each stage.

Comparisons

ISO 27001 vs SOC 2: Which One Do Your Customers Actually Need?

Certificate vs attestation report, international vs US expectations, and the combined program that covers both — sequenced honestly.