How ISO 27001 Audit Fees Are Actually Calculated (Audit Days Explained)
ISO/IEC 27006 tables, day rates, and why two CBs quote different fees for the same company — plus how to sanity-check any quote.
The formula
ISO 27001 audit fees follow a simple formula: audit days × day rate. Audit days are derived from ISO/IEC 27006 tables based on your in-scope headcount and complexity; the day rate is the CB's commercial choice. When a quote seems high, one of those two inputs is doing the work — find out which.
The day tables
ISO/IEC 27006 sets minimum audit durations from effective headcount. Roughly: a 10-person scope might need 3–4 audit days for Stage 2; a 50-person scope more like 5–7; a 200-person scope 9–12+. Complexity factors (multiple sites, high-risk processing, additional schemes) add days on top. These are floors, not ceilings — CBs can justify more, but they should be able to justify them.
Published day rates
Published 2026 sources put accredited-CB day rates around $1,500–$2,200/day in the US and £1,000–£1,500/day in the UK. Premium global brands sit at the top of the band; regional and specialist CBs toward the bottom. Travel and expenses may be extra — ask.
Why quotes differ
- Headcount assumptions. The biggest lever: one CB scopes 40 people, another scopes 65. Ask for the headcount band behind every quote.
- Site sampling. Multi-site programs add days per site sampled.
- Included extras. Gap assessments, training, and surveillance pricing are sometimes bundled, sometimes not.
- Day-rate positioning. Brand premium is real — compare audit-day counts and day rates separately.
How to compare quotes
Normalize every quote to the same table: Stage 1 days, Stage 2 days, day rate, travel, surveillance years 2–3, and recertification. Two quotes with the same total can hide very different day counts — the one with fewer, more expensive days is usually the senior team. Our RFP and quote worksheet gives you a printable comparison template.
Frequently asked
What is ISO/IEC 27006?
The standard that sets rules for bodies auditing and certifying ISMSs — including the audit-day tables CBs use to calculate engagement size. It's the reason fees are headcount-driven.
Can I negotiate audit days down?
You can challenge assumptions — headcount band, site sampling, complexity factors — but the 27006 tables are floors. A CB that undercuts the table minimum is a red flag, not a bargain.
Related reading
Get quotes from accredited CBs
One brief, matched certification bodies, comparable quotes. Free · 2 minutes · no obligation.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.
More guides
How to Choose an ISO 27001 Certification Body: 8 Questions to Ask
The vetting checklist we recommend: accreditation verification, audit teams, audit-day math, fees, and the red flags that signal a bad fit.
ISO 27001 Stage 1 vs Stage 2 Audits: What's Actually Different
Documentation review vs effectiveness testing: what each stage checks, how long each takes, and what sinks companies at each stage.
ISO 27001 vs SOC 2: Which One Do Your Customers Actually Need?
Certificate vs attestation report, international vs US expectations, and the combined program that covers both — sequenced honestly.