Guide
ISO 27001 (ISMS) Certification Cost: Audit, Consulting and Maintenance Breakdown
For a Japanese IT company with fewer than 100 employees, ISO/IEC 27001 (ISMS) certification generally costs somewhere between JPY 1.5 million and 7 million in the first year, plus roughly JPY 400,000 to 2 million per year to maintain. The range is wide because consulting fees and internal staff time, not the certification body audit fee, drive most of the total. This guide breaks the cost into six components, gives size-based benchmarks, explains what moves the number, and shows how to keep it under control.
Published: Last updated:
Split the Cost Into Year One and Ongoing Maintenance
The first thing to separate is one-off first-year cost and the recurring cost of keeping the certificate. Initial certification is carried out as a Stage 1 audit (documentation review) and a Stage 2 audit (on-site review), followed by a surveillance audit every year and a recertification audit every three years. Certification is a three-year cycle, not a one-time purchase, so budget it that way. The sequence itself is covered in how ISO 27001 certification works.
What drives the first-year total is usually not the certification body. In most companies, consulting fees plus the internal owner time account for 60 to 80 percent of the total. Those two levers are where cost control actually happens.
Cost Breakdown: Six Components
ISO 27001 cost can be decomposed as follows. Every figure is a general benchmark and moves with the certification body, the scope and the level of support you buy.
| Cost item | When it occurs | Typical range | Notes |
|---|---|---|---|
| Initial certification audit (Stage 1 + Stage 2) | At certification | JPY 400K-1.5M | Varies with scope, headcount and sites |
| Registration and annual administration fee | At certification and yearly | JPY tens of thousands to hundreds of thousands | Naming differs by certification body |
| Surveillance audit | Every year after certification | 30-50% of the initial audit fee | Lower because audit days are fewer |
| Recertification audit | Every three years | 60-80% of the initial audit fee | Re-registration of the certificate |
| Consulting fees | Preparation period (6-12 months) | JPY 1M-5M | The widest range of all items |
| Tooling and SaaS | Yearly | JPY tens of thousands to hundreds of thousands per year | Document, risk and training records |
| Internal effort (labour) | At certification and yearly | 0.3-0.5 FTE-month per month for 6-12 months | The most commonly overlooked cost |
| Training and awareness | Yearly | JPY tens of thousands to hundreds of thousands | Company-wide plus internal auditor training |
| Additional technical and physical controls | As needed | JPY 0 to several million | Depends on the maturity of your environment |
The Audit Fee Is Audit Days Multiplied by a Day Rate
Certification bodies normally derive audit days from the number of people and sites inside the scope, then apply a day rate. Doubling headcount therefore does not double the fee. When you collect quotes, compare the three-year total including surveillance and recertification audits rather than the initial audit alone.
Convert Hidden Internal Effort Into Money
Internal effort is the line most often underestimated. Producing the information security policy, the Statement of Applicability (SoA), risk assessment procedures, and the supporting procedures and records takes real time. The full inventory is listed in documents required for ISMS, but a realistic assumption is one owner spending 30 to 50 percent of their working hours for six to twelve months, which often converts to JPY 1M-3M of labour cost.
Benchmarks by Company Size
The figures below assume a typical IT company with a single site and an in-house IT function. Treat them as ranges, since scope and existing practice change the outcome.
| Headcount | Initial audit fee | Consulting fees | Year-one total | Annual maintenance |
|---|---|---|---|---|
| Around 10 | JPY 400K-800K | JPY 1M-2M | JPY 1.5M-3M | JPY 400K-800K |
| Around 30 | JPY 600K-1.1M | JPY 1.5M-3M | JPY 2.5M-4.5M | JPY 600K-1.2M |
| Around 100 | JPY 900K-1.5M | JPY 2.5M-5M | JPY 4M-7M | JPY 1M-2M |
Five Factors That Move the Price
- Scope: whole company or one business unit, and which sites are included. A wider scope means more audit days and more documentation work
- Number of sites: remote sites inside the scope add audit days and can add travel expenses
- Choice of certification body: accreditation, fee structure and auditor day rates differ, so collect several quotes
- Maturity of existing practice: if access control, logging, asset inventory and internal rules already exist, both investment and documentation effort shrink
- How much you delegate to consultants: having documents written for you versus buying review and advice can change the fee several times over
Of these, scope and consultant dependency are the two you control most directly. Rather than covering the whole company from day one, you can certify the business or service your customers actually ask about and widen the scope later.
Five Ways to Reduce the Cost
- Set the scope to what is necessary and sufficient: work backwards from why customers want the certificate, and resist over-expanding
- Use templates and SaaS: starting from prepared policies, forms and risk assessment structures removes most of the blank-page effort
- Grow an internal owner: investing in internal auditor training lets you run year two onwards in house, which lowers maintenance cost
- Buy consulting selectively: use external help for risk assessment review, Statement of Applicability (SoA) validation and a mock audit before Stage 2
- Check for public support schemes: availability depends on the local government and the fiscal year, so always confirm current information for your own municipality
On the last point, names, eligibility rules and application windows differ considerably by municipality and year. Verify eligibility against primary sources only.
The Cost of Not Certifying
A cost decision should also weigh what you lose by not certifying. Security questionnaires from enterprise buyers increasingly ask whether you hold the certificate, public sector tenders often award points for it, and SaaS procurement reviews frequently ask for third-party assurance of your information security posture.
If a single deal is worth several million yen, losing or delaying a handful of them can outweigh the entire cost of certification. In Japan many companies also hesitate between two schemes, so reading ISMS versus the Privacy Mark and confirming which one your customers actually require is the fastest way to avoid wasted spend.
Is Certifying Without a Consultant Realistic?
Nothing in the scheme requires you to hire a consultant. Where the company already has someone with hands-on information security experience, can read the standard and the Annex A controls, and can protect that person time, the consulting line can be removed entirely.
The do-it-yourself route carries its own risks. Risk assessment procedures that do not line up with the requirements, a Statement of Applicability (SoA) that cannot justify inclusion or exclusion of controls, and internal audit or management review records that are purely formal are the classic findings raised at Stage 2. If corrective action drags the audit out, the extra cost can erase the saving.
Reducing Internal Effort With Tooling
As the breakdown shows, ISO 27001 cost depends far more on people hours than on audit fees. Running document version control, risk assessment records, training records and internal audit evidence out of spreadsheets and shared folders means the maintenance effort simply accumulates from year two. Keeping all of it in one managed place lowers cost in the maintenance phase, not just at certification.
A good starting point is to understand where you stand today and where the effort is likely to concentrate. The ISMS readiness self-check walks through a short set of questions and returns the areas worth tackling first. Articulating your internal situation before requesting quotes also makes conversations with consultants and certification bodies far more productive.
Frequently asked questions
- What is the minimum cost of ISO 27001 certification?
- With around 10 employees, a single site and a tightly drawn scope, the initial audit fee can be around JPY 400,000, and a first-year total of roughly JPY 500,000 to 1 million is achievable if you run the project without a consultant. Internal staff time, which can exceed JPY 1 million in labour terms, is on top of that.
- Can we certify without a consultant?
- Yes. Companies with an experienced information security practitioner who can read the standard and the Annex A controls do run the project themselves. The risk is that weak risk assessment procedures or an unclear Statement of Applicability (SoA) lead to findings at Stage 2, and corrective action then extends both the timeline and the cost.
- Is there a cost every year after certification?
- Yes. A surveillance audit takes place each year after certification and a recertification audit in year three. Add the registration and annual administration fee, training, tooling and the internal effort for internal audit and management review, and the usual benchmark is JPY 400,000 to 2 million per year.
- Which costs more, the Privacy Mark or ISO 27001?
- Certification body fees are generally higher for ISO 27001. However, the Privacy Mark is limited to personal information while ISO 27001 covers information assets broadly, so rather than comparing prices directly, confirm which certificate your customers are actually asking for. The related article covers the comparison in detail.
- When do the payments fall due?
- Consulting fees are commonly split across contract signature and phase completions, while audit fees are usually invoiced around the Stage 1 and Stage 2 audits. Spending is concentrated in year one, so if the project crosses a fiscal year boundary it is safer to align budget approval early.
Check where your ISMS stands in 5 questions
Answers are processed only in your browser and are never sent from this app.
Start the self-checkThis article is for general information only and does not guarantee any audit outcome or certification. Schemes and costs change, so confirm the latest details with certification bodies.
Related articles
The ISO 27001 (ISMS) Certification Process and Timeline: 8 Steps from Kickoff to Registration
ISO 27001 (ISMS) certification in eight steps from kickoff to registration, why it usually takes 6 to 12 months, and what Stage 1 and Stage 2 audits check.
Required Documents for an ISMS (ISO 27001): Documented Information and Records, Organized
ISO/IEC 27001 documents in two layers: the documented information the standard explicitly requires, and the policies teams build around Annex A controls.
ISMS (ISO 27001) vs Privacy Mark: Which Certification Should a Japanese IT Company Choose?
ISMS (ISO/IEC 27001) vs the Japanese Privacy Mark: scope of protection, certification boundary, cost, timeline and audit cycle, and which fits a B2B IT company.