Skip to content

What ISO 27001 certification costs in the Netherlands

5 min read Last checked on

ISO 27001 certification has no fixed price. The external audit costs audit days times a day rate over three years, plus internal hours, consultancy and tooling where used. Audit days follow from ISO/IEC 27006-1 and depend mainly on the number of people in scope. The only fixed amount is the standard itself, 240 euros excluding VAT from NEN.

ISO 27001 certification has no fixed price: the external cost is the number of audit days times the certification body's day rate, spread over a three-year cycle. Internal hours, and optionally consultancy and tooling, come on top. The only amount that is the same for everyone is the standard itself: the Dutch edition costs 240 euros excluding VAT from NEN, the Dutch standards body.

This article therefore gives no average price. It shows which items make up the cost and how to work them out with your own quotes.

The cost items

Item What it depends on One-off or recurring
Standard Fixed price from NEN One-off, again with a new version
External audit Audit days times day rate, plus any travel and certificate fees Every year, in varying amounts
Internal hours Scope, starting point, how much already works Most in the first year, ongoing after that
Consultancy (optional) How much you can and want to do yourself Mainly in the first year
Tooling (optional) Spreadsheet, document management or ISMS software Ongoing with a licence
The controls themselves What your risk assessment calls for, such as a penetration test or better logging Varies

The last item is often forgotten. Certification does not require expensive technology, but an honest risk assessment can show that something is missing, and that costs money separate from the audit.

How the number of audit days is determined

For information security, the certification body determines audit duration according to ISO/IEC 27006-1, the standard setting requirements for bodies that certify an ISMS. The 2024 version contains the calculation rules in an annex and introduces the notion of an "effective number of personnel", so that a large group of people in identical roles does not count in full. Certification bodies had to move to this version by 31 March 2026.

IAF MD 5 is often quoted as the source for audit days, but that document covers quality, environmental and occupational health and safety management systems, not information security.

What affects the number of days:

  • Number of people in scope. The main factor. A scope of 25 people needs fewer days than one of 90.
  • Complexity. The type of information, the degree of development and outsourcing, and the legal requirements. Healthcare software handling patient data may weigh more heavily than an internal tool.
  • Sites. Several offices can add time. A fully remote company is stated as such on the certificate.
  • Cycle. Surveillance audits are shorter than the initial audit, with recertification somewhere in between.

Worked example with explicit assumptions

The figures below are assumptions to calculate with, not a table from the standard and not a market price. Replace them with the audit days and rate from your own quotes.

Assumptions: a software company with 40 people in scope; the body charges 7 audit days for stage 1 and stage 2 together, 3 days per surveillance audit and 5 days for recertification; the day rate is a working value T.

Year Audit Audit days Cost
1 Stage 1 and stage 2 7 7 × T
2 Surveillance 3 3 × T
3 Surveillance 3 3 × T
4 Recertification 5 5 × T

Over the first three-year cycle (years 1 to 3) that is 13 audit days. With a working value of T = 1,400 euros, that comes to 18,200 euros excluding VAT, or just over 6,000 euros a year on average. A different rate or number of days changes the outcome proportionally, so always compare quotes on days and rate across the whole cycle.

Internal hours

For a company of 10 to 100 people, internal hours are usually the largest item, even though they appear on no invoice. Work them out the same way: who works on it, how much time per week and for how long.

An example, again as an assumption: in the first year the ISMS owner spends on average one day a week on the project, the board a few half days on policy, risks and the management review, and team leads a few days each on their controls. After certification a smaller but fixed part of the week remains for maintenance, evidence and the annual cycle.

What keeps internal hours down:

  • Recording controls that already work, such as code reviews and access management, rather than reinventing them.
  • A scope that matches what customers ask for, and no larger.
  • Recording evidence when it is created, rather than hunting for it just before the audit.

Consultancy and tooling

A consultant can speed up the first year, particularly on the risk assessment and the Statement of Applicability. Consultancy rates vary widely; ask for a quote with a clear number of days and defined deliverables. Bear in mind that the consultant cannot be the same party as your certification body.

Tooling ranges from a spreadsheet with a document folder to ISMS software with an annual licence. A spreadsheet costs nothing to buy, but costs hours once several people work in it or a second standard is added. Make that trade-off on hours, not only on the licence price.

Where budgets go wrong

  • Budgeting only for the first year. The cycle runs for three years, and then the next one starts.
  • Scheduling the audit too early. A stage 2 that produces major nonconformities can lead to an extra visit or extra audit days for verification.
  • Extending the scope later. An extra product or office means extra audit days at the next audit.

How the process itself runs is covered in the article on certification. What to arrange per phase is in the checklist.

Frequently asked questions

How much does ISO 27001 certification cost?

There is no fixed price. The external cost is the number of audit days times the certification body's day rate, over a three-year cycle. For a company of 10 to 100 people, internal hours are usually the largest item.

What determines the number of audit days?

Mainly the number of people working within the scope, and also complexity, number of sites and risks. The certification body calculates it according to ISO/IEC 27006-1.

Do you need ISMS software to get certified?

No. The standard does not prescribe a tool. A spreadsheet with a document folder can be enough; software becomes the cheaper option once several people work on it or a second standard is added.

Are there annual costs after certification?

Yes. A surveillance audit follows every year, and a recertification audit in the third year. Maintaining the ISMS also takes time on an ongoing basis.

What does the standard itself cost?

The Dutch edition NEN-EN-ISO/IEC 27001:2023 costs 240 euros excluding VAT from NEN, the Dutch standards body (September 2026). The 2024 climate change amendment is free of charge.

Read next

Sources

  1. NEN, NEN-EN-ISO/IEC 27001:2023 nl
  2. NEN, NEN-EN-ISO/IEC 27001:2023/A1:2024 nl
  3. ISO, ISO/IEC 27006-1:2024 requirements for bodies certifying an ISMS
  4. Dutch Accreditation Council (RvA), ISO/IEC 27006-1:2024 published
  5. ANAB, transition to ISO/IEC 27006-1:2024 and audit time
  6. IAF MD 5:2019, audit time for QMS, EMS and OH&SMS
  7. IAS, text of ISO/IEC 17021-1:2015 section 9 (certification cycle)

Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing.

Become a design partner