Skip to main content

UK · PUBLISHED · FIXED AFTER SCOPING

What Goldline costs, in 2026.

Compliance pricing is kept vague across this industry. Ten of the thirteen UK certification bodies we checked publish no price at all. Here is what we charge for everything we sell, what sets the number, and what your certification body will charge you on top.

How pricing scales

01DiagnoseFrom £1,950
02Guided£7,000
03DeliveredFrom £14,000

Tier is set on the free diagnostic, then fixed. Most organisations start at Diagnose.

  • Fixed after scoping
  • Readiness credits in full
  • No setup fees

99%

96%

90%

Cisco 2025 Data Privacy Benchmark Study. 2,600+ security and privacy professionals across 12 countries, surveyed autumn 2024.

EVERYTHING WE SELL

One table, every service.

Each service links to its own page. Two items are scoped on the diagnostic rather than published, and they say so.

Goldline published prices by service. All figures exclude VAT.
ServiceFromDurationBest forAction
ISO 27001 Readiness Assessment£1,950Set at the free diagnosticSetting the boundary before you commitEnquire
DCC Requirement and Scope Review£1,950Set at the free diagnosticA prime has raised DEFCON 658Enquire
AI Governance Readiness Assessment£2,500Set at the free diagnosticISO 42001 or an AI questionnaireEnquire
Pre-Certification Readiness Audit£3,500Set at the free diagnosticYou think you are ready and want it testedEnquire
Integrated DPIA and AI Impact Assessment£4,000Set at the free diagnosticA high-risk processing or AI use caseEnquire
ISO 42001 Internal Audit£4,500Set at the free diagnosticClause 9.2 on an AI management systemEnquire
DCC Level 1 Readiness Diagnostic£4,5004 to 8 daysReaching Cyber Risk Profile Level 1Enquire
AI Trust Evidence Pack£5,000Set at the free diagnosticAnswering an enterprise AI questionnaireEnquire
ISO 27001 Guided£7,000Alongside your teamYou have a named owner and a base to build onEnquire
ISO 27001 Sprint£14,000Agreed at scopingFull implementation to audit-readyEnquire
ISO 42001 Sprint£18,000Agreed at scopingFull ISO 42001 implementationEnquire
ISO 42001 Guided£9,000Alongside your teamOne to five AI systems and a named ownerEnquire
Integrated Guided (ISO 27001 and ISO 42001)£12,500Alongside your teamBoth certificates, one management systemEnquire
Integrated Sprint (ISO 27001 and ISO 42001)From £26,000Timeline calibrated at scopingBoth certificates, full implementationEnquire
Managed Compliance Retainer, one standard£1,450 per month12 month minimumKeeping one certified system runningEnquire
Managed Compliance Retainer, integrated£1,950 per month12 month minimumISO 27001 and ISO 42001 on one scheduleEnquire
Fractional AI Governance Lead£4,250 per month3 month minimumYou need the role, not the headcountEnquire
ISO 27001 Internal AuditFrom £4,500Set at the free diagnosticClause 9.2, priced by boundary size and control setEnquire
Stage 2 Audit DefenceScoped on the diagnosticDuration of the auditThe audit is booked and you want coverEnquire
DCC Level 0 Readiness DiagnosticScoped on the diagnostic2 to 4 daysEstablishing the Level 0 positionEnquire

All figures exclude VAT.

01

Information security, ISO 27001

Three routes to the same certificate. What changes is how much of the work your team does.

ISO 27001 Guided

A fixed price, with your team executing the build.

  • Fixed

    £7,000

    Your team builds it, Goldline directs and reviews

ISO 27001 Sprint

Full implementation to audit-ready, priced by tier.

  • Tier 1

    £14,000 to £22,000

    Single boundary, moderate complexity

  • Tier 2

    £22,000 to £35,000

    Larger boundary, more entities or higher complexity

  • Tier 3

    £35,000 and above

    Scoped individually, phased delivery

02

AI governance, ISO 42001

For organisations facing an AI questionnaire, investor diligence or EU AI Act exposure.

ISO 42001 Sprint

Full ISO 42001 implementation, priced by tier.

  • Tier 1

    £18,000 to £28,000

    Single boundary, moderate complexity

  • Tier 2

    £28,000 to £42,000

    Larger boundary, more entities or higher complexity

  • Tier 3

    £42,000 and above

    Scoped individually, phased delivery

AI Trust Evidence Pack

The evidence set an enterprise buyer asks for.

  • From

    £5,000

    Answering an enterprise AI questionnaire

ISO 42001 Guided

A fixed price, with your team executing the build.

  • Fixed

    £9,000

    Single entity under 50 people, one to five AI systems

02b

Both standards together, ISO 27001 and ISO 42001

One management system, two certificates. Buying the two programmes separately costs about 20 per cent more at every tier.

Integrated Sprint (ISO 27001 and ISO 42001)

Full integrated implementation, priced by tier. Tier is set on the diagnostic.

  • Tier 1

    £26,000 to £40,000

    Single boundary, contained AI estate

  • Tier 2

    £40,000 to £62,000

    Larger boundary, more entities or higher complexity

  • Tier 3

    £62,000 and above

    Scoped individually, phased delivery

03

Defence supply chain

Cyber Defence Contracts certification is a customer requirement set by MOD, not a legal obligation.

04

Audit and assurance

Goldline will not audit a management system it implemented, and will not sell implementation and certification to the same organisation for the same scope.

ISO 42001 Internal Audit

Clause 9.2 on an AI management system.

  • From

    £4,500

    The final figure varies with the number of AI systems in scope

ISO 27001 Internal Audit

Clause 9.2, where Goldline did not implement.

  • From

    £4,500

    Set by the size of the boundary and the control set

Stage 2 Audit Defence

Senior cover in the room for the certification audit.

  • Price

    Scoped on the diagnostic

    Set by the length of the booked audit

05

Ongoing

Keeping a certified management system running once the programme ends.

Managed Compliance Retainer

The operating rhythm a certified system needs.

  • One standard

    From £1,450 per month

    12 month minimum. 12 hours of reserved capacity a month

  • Integrated ISO 27001 and ISO 42001

    From £1,950 per month

    12 month minimum. 16 hours of reserved capacity a month

01

Every month

  • Continuous control monitoring, with a named owner against each control
  • Evidence collection and lifecycle management
  • The nonconformity and corrective action register, carried between visits with the date raised, the root cause, the action, the date closed and the evidence it worked
  • Policy review and maintenance
  • Risk register and risk assessment review
  • Supplier and sub-processor review
  • Security questionnaire handling, three a quarter on one standard and five a quarter on the integrated retainer, and beyond the included allowance, quoted on request
  • Trust centre kept current
  • A written monthly report

02

Every year

  • Surveillance audit preparation and coordination with your certification body
  • A management review input pack
  • The integrated obligation calendar, carrying both standards' clause obligations on one schedule

03

Integrated retainer only

  • AI estate change tracking: new and retired AI systems, model changes, new data sources and new AI suppliers, each checked against the inventory and the impact assessments

The nonconformity register is the first thing a surveillance auditor opens, and it cannot be assembled the week before. That is why the term is twelve months.

Goldline does not perform the clause 9.2 internal audit on a system it implemented. An independent auditor is introduced and contracted by you.

06

What your certification body charges

This section carries no Goldline prices. The audit fee is separate from anything above and is paid to your certification body direct. Audit days are set by the number of people doing work inside the ISMS scope, not by company headcount, and the table below is the one in ISO/IEC 27006-1:2024 Annex C. A mid-market UKAS accredited body charges in the region of £1,250 a day in 2026.

ISO/IEC 27006-1:2024 Annex C audit days by people in scope
People in scopeAudit days
1 to 105
11 to 156
16 to 257
26 to 458.5
46 to 6510
66 to 8511
86 to 12512
126 to 17513
176 to 27514

The day figure covers Stage 1 and Stage 2 together. Surveillance is about one third of it annually. No compliant body may reduce the table figure by more than 30 per cent.

This section is an estimate of what a compliant body should arrive at. It is not a quotation and it does not bind any certification body.

Run your own numbers in the ISO 27001 Cost Calculator.

Free Statement of Applicability review, one document back within 48 hours.

CONSTANTS

Five things that never change.

01

Fixed after scoping

The tier is set on the diagnostic and the price does not move unless the scope changes and both parties agree in writing.

02

Readiness credits in full

Every readiness assessment credits in full against a subsequent Sprint, within twelve months.

03

No setup fees

No mobilisation charge, no change-order surprises.

04

Pass-through at cost

Certification body audit fees are billed separately and pass through at cost. GRC platform subscriptions are billed separately; where Goldline supplies the platform as a partner, the price is confirmed in writing before purchase and you are free to buy direct instead.

05

Senior practitioner delivery

The person who scopes it is the person who delivers it.

THE DRIVERS

What actually sets the number.

Four factors, confirmed on the diagnostic. Device count is not one of them.

01

Scope boundary

The number of people doing work inside the boundary, the number of legal entities, and the systems and locations that sit inside it. Device count is not a driver.

02

Starting position

Whether policies, a risk method and evidence already exist in a usable state, or whether the management system is being built from nothing.

03

Internal capacity

How much time your own team can give the work. Where that time is available, delivery runs to schedule. Where it is not, the engagement extends and the price reflects it.

04

Evidence standard

A management system built to pass an audit and one built to withstand supervisory scrutiny are not the same artefact. Regulated organisations and defence suppliers need the second.

THE FALSE ECONOMY

Why the cheapest quote costs you twice.

A certificate issued outside an accreditation scheme is regularly rejected in enterprise supplier assurance and in public sector procurement. The saving disappears the first time a buyer looks at the mark on the certificate and asks who accredited the body that issued it.

A template management system that nobody inside the organisation owns fails at Stage 2. The auditor asks who runs the risk process and what changed after the last management review, and the documents cannot answer. You then pay for the audit twice, once for the visit that produced the findings and once for the visit that closes them.

A quote built on dropping you an audit band, using the reduction for identical activities, will not be honoured by a compliant body. That reduction applies per activity group and only to simple directed roles, so it rarely survives contact with the auditor who has to justify the day count.

QUESTIONS

Pricing questions.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.