COMPLIANCE PRICING
Menu

The CHF 155 document: what ISO 27001 costs before any software

Short answer

ISO sells ISO/IEC 27001:2022 (Edition 3, published 2022-10, 19 pages) for CHF 155. That price buys the requirements document only. Software, consulting and the certification audit are separate costs, and none of the seven vendors in our census publishes an ISO-specific price.

By The Cost Desk, Compliance Pricing · Published 2026-03-17 · Updated 2026-09-29 · 3 min read

STANDARDS

In a category where six of seven vendors publish no price, one number in the ISO 27001 budget is public: the standard itself.

What the standard costs

ISO's page for ISO/IEC 27001:2022 lists it as Edition 3, published 2022-10, 19 pages, with one amendment, from committee ISO/IEC JTC 1/SC 27, priced at CHF 155. ISO describes it as "the world's best-known standard for information security management systems (ISMS)", in its own words. Its full title is "Information security, cybersecurity and privacy protection: Information security management systems: Requirements".

What CHF 155 buys

The document sets the requirements an information security management system has to meet. It is what an ISO 27001 certification audit is assessed against. Reading it is a sensible first step, because it shows what the software and consultants are helping you do.

What it does not buy

  • Software. A compliance platform that maps controls, collects evidence and runs policies is a separate subscription.
  • Consulting. Help designing the ISMS, running risk assessments and preparing for audit is a separate service.
  • Certification. An ISO 27001 certificate is issued after an audit by a certification body, which is a separate engagement with its own fee.

Where ISO 27001 appears in the census

Here is what each vendor in our census publishes that bears on ISO 27001:

  • Drata's Foundation can use ISO 27001 as its one pre-mapped framework.
  • Vanta, Secureframe and Scytale list ISO 27001 among their frameworks, and their entry plans are stated as one framework; whether ISO 27001 can be that one framework is a question for the quote. Secureframe names ISO 27001:2022 on its frameworks page.
  • Scytale lists ISO 27001 among 80+ frameworks with cross-mapping (according to Scytale's pricing page; its framework library lists 35), along with ISO 27017, 27018, 27701, 42001 and others.
  • Sprinto lists 25+ frameworks automated out of the box on Foundation, without naming them on the card.
  • Thoropass lists ISO 27001 among the frameworks it covers.
  • Scrut states 70+ frameworks, without a list in the material we read.

None publishes a price specific to ISO 27001, and none publishes a certification audit fee.

ISO 27001 after SOC 2

Many buyers add ISO 27001 as a second framework after SOC 2. That makes it an add-on or tier question: Drata names additional frameworks as a Foundation add-on, and the one-framework entry plans at Vanta, Secureframe and Scytale mean a second framework needs a conversation. Cross-mapping, which several vendors describe, can reduce the new work, because many SOC 2 controls also serve ISO 27001 requirements. It does not remove the separate certification audit.

A budget outline

A first ISO 27001 budget has at least four lines:

  • The standard: CHF 155, published.
  • The platform: quote required at six of seven vendors; Secureframe Fundamentals starts at $7,500/year for one framework.
  • Consulting, if needed: bundled at Scytale in Build DFY and Build Stronger, through partners at Vanta and Drata.
  • The certification audit: priced by the certification body.

Certification vs attestation

ISO 27001 and SOC 2 end differently. ISO 27001 ends in a certificate issued by a certification body after a certification audit. SOC 2 ends in a report issued by a CPA firm. A platform can support both, but the two assessors, the two fees and the two timelines are separate, which is why a quote covering both frameworks should still show two audit lines.

Questions for a platform quote

  • Is ISO 27001 our one framework on the entry plan, or an add-on?
  • Which ISMS workflows are included, such as the risk register and the Statement of Applicability?
  • Does the quote include any support during the certification audit, or only readiness?

The takeaway

The only fully published number in an ISO 27001 budget is the cheapest one. Buy the standard, read it, and then price the platform, the help and the audit separately. Tick ISO 27001 in the calculator to see which published tier each vendor would quote.

More pricing notes