ISO 27001 Certification in the UK โ€” Everything You Need to Know

A practical guide to getting ISO 27001 certified in the UK โ€” covering costs, the certification process, how to choose an auditor, and the fastest route to your first certificate.

What Does ISO 27001 Certification Actually Mean in the UK?

ISO 27001 is an internationally recognised standard for information security management. In the UK, certification is increasingly required by enterprise clients, government frameworks, and procurement processes โ€” particularly in IT services, SaaS, managed services and professional services.

Achieving ISO 27001 certification means an independent certification body has audited your Information Security Management System (ISMS) and confirmed it meets the requirements of the standard. It’s not a self-assessment โ€” it requires an external audit.

The certificate typically lasts three years, with annual surveillance audits to maintain it.

The ISO 27001 Certification Process in the UK

The typical certification process is the same whether you use a UK-based or international certification body. It follows a structured sequence that typically takes 8โ€“12 weeks once your ISMS is ready.

1

Build your ISMS

Establish your scope, complete your risk assessment, implement your controls and produce your mandatory documentation. This is the bulk of the work โ€” typically 60โ€“90 days for an SME starting from scratch.

2

Stage 1 Audit โ€” Documentation Review

Your chosen certification body reviews your documentation to confirm you’re ready for Stage 2. They’ll flag any gaps before the main audit โ€” giving you a chance to fix them.

3

Stage 2 Audit โ€” Evidence Review

The auditor verifies that your ISMS is operational โ€” not just documented. They’ll interview staff, review records and test controls. Non-conformances raised here must be addressed before certification is granted.

4

Certificate Issued

Once any non-conformances are closed, your certificate is issued. Valid for three years, with annual surveillance audits and a recertification audit in year three.

Choosing a UK Certification Body

In the UK, UKAS (United Kingdom Accreditation Service) is the national accreditation body. A UKAS-accredited ISO 27001 certificate is universally recognised โ€” required for government procurement, NHS contracts and most enterprise supplier frameworks. However, there are also auditors who offer non-accredited

UKAS Accredited

The gold standard for UK certification โ€” widely required for government and enterprise contracts.

Non-Accredited

A faster, cheaper route. Recognised by many commercial clients but not government frameworks.

FactorUKAS AccreditedNon-Accredited
Government contractsโœ“ Requiredโœ— Not accepted
Enterprise clientsโœ“ Always acceptedOften accepted
Audit timeline3 months min evidenceCan be faster
Typical cost (SME)ยฃ5,500โ€“ยฃ12,000ยฃ1,500โ€“ยฃ4,000
Annual surveillance
โœ“ Required
Varies by body
International recognitionโœ“ IAF MLA memberLimited

How Long Does ISO 27001 Certification Take in the UK?

Timeline depends on where you’re starting from, how many resources you can commit, and which type of certification you’re targeting. Here’s a realistic view for a UK SME.

Weeks 1 to 2

Kick-off & Scope

Define your ISMS scope, assign roles, establish your Information Security Policy.

Weeks 3 to 4

Risk Assessment

Identify and evaluate information security risks, build your risk treatment plan.

Weeks 5 to 6

Statement of Applicability

Evaluate all 93 Annex A controls and document your decisions in the SoA.

Weeks 7 to 9

Implementation & Evidence

Implement controls, run internal audit, conduct management review.

Weeks 10 to 11

Certification Audit

Stage 1 audit with your chosen UKAS certification body.

or

Non-accredited audit & certification awarded

+1 to 3 months (Depending on auditor)

Stage 2 Certification (UKAS Only)

Data & record build up demonstrating running of your ISMS


ISO 27001 Certification Costs in the UK

Costs vary significantly depending on whether you use a consultant, DIY with templates, or take a hybrid approach. The two main costs are implementation (getting ready) and auditor fees (the certification body’s charges).

Do-It-Yourself

Self-Implemented

ยฃ2,000โ€“ยฃ6,000 total. Templates + auditor fees. Requires significant internal time investment.

Coaching

Guided Consultancy

ยฃ5,500โ€“ยฃ12,000 total. Fixed-fee consultant + auditor fees. Faster, lower risk of failure.

Third-Party

Traditional Consultancy

ยฃ15,000โ€“ยฃ40,000+. Full-service engagement. Slower, higher cost, usually for larger organisations.

ISO 27001 Complexity Calculator Screenshot

My ISO 27001 cost & complexity calculator

Not sure how much, how long, or how complex your ISO 27001 implementation will be?

Find out here with my rapid calculator tool.

FULL COST BREAKDOWN GUIDE

I’ve gone into greater detail about overall costs in the following article

๐Ÿ“– ISO 27001 certification costs in the UK โ€” complete guide

Ready to Get ISO 27001 Certified in the UK?

Fixed-fee consultancy, fully remote, with a first-pass guarantee. Most UK clients certified within 90 days. Book a free 30-minute discovery call to discuss your timeline and requirements.

What UK Clients Say

A sample of some of my client feedback
helpthemove logo
โ˜…โ˜…โ˜…โ˜…โ˜…
Kept us on task and made sure we sailed through our assessment. Highly recommend!
Jenna Cooper
Helpthemove, UK
โ˜…โ˜…โ˜…โ˜…โ˜…
A great, down-to-earth, no-nonsense help in achieving our UKAS-accredited ISO 27001 certification.
Bryn
Periculum Security Group, UK

FAQs

Do I need UKAS accreditation for ISO 27001 in the UK?

Not always. UKAS accreditation is required for government procurement and NHS contracts, but many commercial clients accept non-accredited certificates โ€” especially in the early stages of a supplier relationship. If you’re unsure, check your client’s contract requirements before committing to a certification body.

How much does ISO 27001 certification cost in the UK?

For a UK SME, total costs typically range from ยฃ3,500 to ยฃ15,000 depending on approach. This includes both implementation (consultant or DIY) and auditor fees. UKAS-accredited auditors for smaller organisations typically charge ยฃ2,500โ€“ยฃ6,500 for the initial certification audit.

How long does ISO 27001 certification take in the UK?

Most UK SMEs achieve certification within 90 days when they have dedicated resource and expert guidance. The fastest UKAS-accredited certification we’ve delivered was 68 days. Non-accredited certificates can be achieved faster โ€” as quickly as 20 days in some cases.

Which certification bodies offer ISO 27001 in the UK?

UKAS-accredited bodies operating in the UK include BSI, Bureau Veritas, DNV, LRQA, NQA and Alcumus ISOQAR. For non-accredited certificates, there are additional options. Fees vary significantly between bodies โ€” always get at least two or three quotes.

Can a small business get ISO 27001 certified in the UK?

Yes โ€” ISO 27001 is designed to be scalable. Some of the easiest certifications to achieve are for small, well-defined organisations with a clear scope. A five-person SaaS company can be certified just as legitimately as a 500-person enterprise โ€” the ISMS just looks different.

How long is my ISO 27001 certificate valid for?

ISO 27001 certification is valid for three years and requires an organisation to undergo annual surveillance audits to maintain compliance.

ISO 27001 Certification Articles

Everything you need to know about getting ISO 27001 certified โ€” costs, choosing an auditor, what happens at each audit stage, and how to prepare.


GUIDE

How to Pass Your ISO 27001 Audit First Time

My guide on ISO 27001 audit tips for how to make sure you pass your ISO 27001 certification first time.

Read more โ†’

GUIDE

ISO 27001 Certification: UKAS vs Non-UKAS โ€” Does It Matter?

Explore the differences between UK certifications: UKAS vs Non-Accredited certificates. How the differ, and does it matter?

Read more โ†’

GUIDE

ISO 27001 Surveillance Audits: What to Expect

What happens after certification? The ISO 27001 surveillance audit in years 1 and 2, and the recertification audit in year 3 process explained.

Read more โ†’

GUIDE

What Do ISO 27001 Auditors Actually Look For?

ISO 27001 auditors go well beyond checking your policy documents. Here's what experienced ISO 27001 auditors actually look for.

Read more โ†’

GUIDE

ISO 27001 ROI: How to Measure the Value of Certification

ISO 27001 is an investment, but what do you actually get back? This guide explains how to measure the ISO 27001 ROI for certification.

Read more โ†’

GUIDE

How to Choose an ISO 27001 Certification Body (UK Guide)

Not all ISO 27001 certification bodies are equal. This guide explains UKAS-accredited and non-accredited bodies, how to shortlist, and what to ask.

Read more โ†’

GUIDE

How to Prepare for an ISO 27001 Stage 2 Audit

How to prepare for an ISO 27001 Stage 2 audit; what evidence auditors examine, and how to make sure your team is ready on the day.

Read more โ†’

GUIDE

How to Prepare for an ISO 27001 Stage 1 Audit

Learn what happens in an ISO 27001 Stage 1 audit, what the auditor is looking for, and how to be ready on the day so you can move confidently to Stage 2.

Read more โ†’

GUIDE

How Long Does ISO 27001 Take?

How long does ISO 27001 take? I explore a realistic timeline for ISO 27001 from kick-off to certified and what speeds the process up and what slows it down.

Read more โ†’

GUIDE

What Happens If You Fail an ISO 27001 Stage 2 Audit?

Failing an ISO 27001 Stage 2 audit doesn't mean the end of your certification journey. Here's what actually happens โ€” and how to avoid being in that position.

Read more โ†’