ISO 27001 Guided
A fixed price, with your team executing the build.
Fixed
£7,000
Your team builds it, Goldline directs and reviews
UK · PUBLISHED · FIXED AFTER SCOPING
Compliance pricing is kept vague across this industry. Ten of the thirteen UK certification bodies we checked publish no price at all. Here is what we charge for everything we sell, what sets the number, and what your certification body will charge you on top.
How pricing scales
Tier is set on the free diagnostic, then fixed. Most organisations start at Diagnose.
99%
96%
90%
Cisco 2025 Data Privacy Benchmark Study. 2,600+ security and privacy professionals across 12 countries, surveyed autumn 2024.
EVERYTHING WE SELL
Each service links to its own page. Two items are scoped on the diagnostic rather than published, and they say so.
| Service | From | Duration | Best for | Action |
|---|---|---|---|---|
| ISO 27001 Readiness Assessment | £1,950 | Set at the free diagnostic | Setting the boundary before you commit | Enquire |
| DCC Requirement and Scope Review | £1,950 | Set at the free diagnostic | A prime has raised DEFCON 658 | Enquire |
| AI Governance Readiness Assessment | £2,500 | Set at the free diagnostic | ISO 42001 or an AI questionnaire | Enquire |
| Pre-Certification Readiness Audit | £3,500 | Set at the free diagnostic | You think you are ready and want it tested | Enquire |
| Integrated DPIA and AI Impact Assessment | £4,000 | Set at the free diagnostic | A high-risk processing or AI use case | Enquire |
| ISO 42001 Internal Audit | £4,500 | Set at the free diagnostic | Clause 9.2 on an AI management system | Enquire |
| DCC Level 1 Readiness Diagnostic | £4,500 | 4 to 8 days | Reaching Cyber Risk Profile Level 1 | Enquire |
| AI Trust Evidence Pack | £5,000 | Set at the free diagnostic | Answering an enterprise AI questionnaire | Enquire |
| ISO 27001 Guided | £7,000 | Alongside your team | You have a named owner and a base to build on | Enquire |
| ISO 27001 Sprint | £14,000 | Agreed at scoping | Full implementation to audit-ready | Enquire |
| ISO 42001 Sprint | £18,000 | Agreed at scoping | Full ISO 42001 implementation | Enquire |
| ISO 42001 Guided | £9,000 | Alongside your team | One to five AI systems and a named owner | Enquire |
| Integrated Guided (ISO 27001 and ISO 42001) | £12,500 | Alongside your team | Both certificates, one management system | Enquire |
| Integrated Sprint (ISO 27001 and ISO 42001) | From £26,000 | Timeline calibrated at scoping | Both certificates, full implementation | Enquire |
| Managed Compliance Retainer, one standard | £1,450 per month | 12 month minimum | Keeping one certified system running | Enquire |
| Managed Compliance Retainer, integrated | £1,950 per month | 12 month minimum | ISO 27001 and ISO 42001 on one schedule | Enquire |
| Fractional AI Governance Lead | £4,250 per month | 3 month minimum | You need the role, not the headcount | Enquire |
| ISO 27001 Internal Audit | From £4,500 | Set at the free diagnostic | Clause 9.2, priced by boundary size and control set | Enquire |
| Stage 2 Audit Defence | Scoped on the diagnostic | Duration of the audit | The audit is booked and you want cover | Enquire |
| DCC Level 0 Readiness Diagnostic | Scoped on the diagnostic | 2 to 4 days | Establishing the Level 0 position | Enquire |
All figures exclude VAT.
Three routes to the same certificate. What changes is how much of the work your team does.
A fixed price, with your team executing the build.
Fixed
£7,000
Your team builds it, Goldline directs and reviews
Full implementation to audit-ready, priced by tier.
Tier 1
£14,000 to £22,000
Single boundary, moderate complexity
Tier 2
£22,000 to £35,000
Larger boundary, more entities or higher complexity
Tier 3
£35,000 and above
Scoped individually, phased delivery
The boundary, the gaps and what closing them requires.
From
£1,950
Credits in full against a subsequent Sprint
For organisations facing an AI questionnaire, investor diligence or EU AI Act exposure.
Full ISO 42001 implementation, priced by tier.
Tier 1
£18,000 to £28,000
Single boundary, moderate complexity
Tier 2
£28,000 to £42,000
Larger boundary, more entities or higher complexity
Tier 3
£42,000 and above
Scoped individually, phased delivery
Your ISO 42001 position and where the gaps sit.
From
£2,500
Credits in full against a subsequent Sprint
The evidence set an enterprise buyer asks for.
From
£5,000
Answering an enterprise AI questionnaire
One assessment covering both obligations.
From
£4,000
A high-risk processing or AI use case
A fixed price, with your team executing the build.
Fixed
£9,000
Single entity under 50 people, one to five AI systems
One management system, two certificates. Buying the two programmes separately costs about 20 per cent more at every tier.
Both standards built together, executed by your team. £16,000 bought separately, so a saving of £3,500.
Fixed
£12,500
Both Guided eligibility tests met
Full integrated implementation, priced by tier. Tier is set on the diagnostic.
Tier 1
£26,000 to £40,000
Single boundary, contained AI estate
Tier 2
£40,000 to £62,000
Larger boundary, more entities or higher complexity
Tier 3
£62,000 and above
Scoped individually, phased delivery
Cyber Defence Contracts certification is a customer requirement set by MOD, not a legal obligation.
What the prime has actually asked you for.
From
£1,950
A prime has raised DEFCON 658
Preparation for the Level 1 position.
From
£4,500
Reaching Cyber Risk Profile Level 1
Preparation for the Level 0 position.
Price
Scoped on the diagnostic
Establishing the Level 0 position
Goldline will not audit a management system it implemented, and will not sell implementation and certification to the same organisation for the same scope.
Your readiness tested before the certification body tests it.
From
£3,500
You think you are ready and want it tested
Clause 9.2 on an AI management system.
From
£4,500
The final figure varies with the number of AI systems in scope
Clause 9.2, where Goldline did not implement.
From
£4,500
Set by the size of the boundary and the control set
Senior cover in the room for the certification audit.
Price
Scoped on the diagnostic
Set by the length of the booked audit
Keeping a certified management system running once the programme ends.
The operating rhythm a certified system needs.
One standard
From £1,450 per month
12 month minimum. 12 hours of reserved capacity a month
Integrated ISO 27001 and ISO 42001
From £1,950 per month
12 month minimum. 16 hours of reserved capacity a month
The accountable role, without the headcount.
From
£4,250 per month
3 month minimum
01
Every month
02
Every year
03
Integrated retainer only
The nonconformity register is the first thing a surveillance auditor opens, and it cannot be assembled the week before. That is why the term is twelve months.
Goldline does not perform the clause 9.2 internal audit on a system it implemented. An independent auditor is introduced and contracted by you.
This section carries no Goldline prices. The audit fee is separate from anything above and is paid to your certification body direct. Audit days are set by the number of people doing work inside the ISMS scope, not by company headcount, and the table below is the one in ISO/IEC 27006-1:2024 Annex C. A mid-market UKAS accredited body charges in the region of £1,250 a day in 2026.
| People in scope | Audit days |
|---|---|
| 1 to 10 | 5 |
| 11 to 15 | 6 |
| 16 to 25 | 7 |
| 26 to 45 | 8.5 |
| 46 to 65 | 10 |
| 66 to 85 | 11 |
| 86 to 125 | 12 |
| 126 to 175 | 13 |
| 176 to 275 | 14 |
The day figure covers Stage 1 and Stage 2 together. Surveillance is about one third of it annually. No compliant body may reduce the table figure by more than 30 per cent.
This section is an estimate of what a compliant body should arrive at. It is not a quotation and it does not bind any certification body.
Run your own numbers in the ISO 27001 Cost Calculator.
Free Statement of Applicability review, one document back within 48 hours.
CONSTANTS
01
Fixed after scoping
The tier is set on the diagnostic and the price does not move unless the scope changes and both parties agree in writing.
02
Readiness credits in full
Every readiness assessment credits in full against a subsequent Sprint, within twelve months.
03
No setup fees
No mobilisation charge, no change-order surprises.
04
Pass-through at cost
Certification body audit fees are billed separately and pass through at cost. GRC platform subscriptions are billed separately; where Goldline supplies the platform as a partner, the price is confirmed in writing before purchase and you are free to buy direct instead.
05
Senior practitioner delivery
The person who scopes it is the person who delivers it.
THE DRIVERS
Four factors, confirmed on the diagnostic. Device count is not one of them.
01
Scope boundary
The number of people doing work inside the boundary, the number of legal entities, and the systems and locations that sit inside it. Device count is not a driver.
02
Starting position
Whether policies, a risk method and evidence already exist in a usable state, or whether the management system is being built from nothing.
03
Internal capacity
How much time your own team can give the work. Where that time is available, delivery runs to schedule. Where it is not, the engagement extends and the price reflects it.
04
Evidence standard
A management system built to pass an audit and one built to withstand supervisory scrutiny are not the same artefact. Regulated organisations and defence suppliers need the second.
THE FALSE ECONOMY
A certificate issued outside an accreditation scheme is regularly rejected in enterprise supplier assurance and in public sector procurement. The saving disappears the first time a buyer looks at the mark on the certificate and asks who accredited the body that issued it.
A template management system that nobody inside the organisation owns fails at Stage 2. The auditor asks who runs the risk process and what changed after the last management review, and the documents cannot answer. You then pay for the audit twice, once for the visit that produced the findings and once for the visit that closes them.
A quote built on dropping you an audit band, using the reduction for identical activities, will not be honoured by a compliant body. That reduction applies per activity group and only to simple directed roles, so it rarely survives contact with the auditor who has to justify the day count.
QUESTIONS
We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.