Skip to content

Methodology

How ISMSCalculator models ISO 27001 cost

Every multiplier, floor, default rate and audit-time assumption used by the engine is published here. Nothing is hidden behind a sales call, and no ISO standard text or table is reproduced.

Engine versionISO_COST_ENGINE_2_0

Saved, shared and exported estimates are always recalculated server-side with this engine version — a value produced in the browser is treated as a preview only.

Base implementation effort (person-days)

Modelled
Micro (1–10 employees)
5.5 d
Small (11–50)
25 d
Medium (51–250)
70 d
Large (251–1000)
180 d
Enterprise (1000+)
400 d

Minimum effort floors (irreducible ISMS core)

Modelled
Micro (1–10 employees)
5 d
Small (11–50)
12 d
Medium (51–250)
30 d
Large (251–1000)
75 d
Enterprise (1000+)
160 d

Sector complexity multipliers

Modelled
Finance & Banking
×1.45
Healthcare
×1.35
Government
×1.30
Technology
×1.05
Manufacturing
×1.22
Retail & E-commerce
×1.10
Education
×1.08
Energy & Utilities
×1.25
Telecom & Media
×1.20
Insurance & Legal
×1.38
Logistics & Transport
×1.15
Other
×1.00

Infrastructure multipliers

Modelled
Cloud
×0.90
On-Premise
×1.15
Hybrid
×1.00

Maturity multipliers (interpolated 1–5)

Modelled
Level 1
×1.35
Level 2
×1.15
Level 3
×1.00
Level 4
×0.80
Level 5
×0.65

Existing control-framework reuse

Modelled
SOC2
−10%
GDPR
−8%
ISO9001
−6%
NIST
−7%
PCIDSS
−5%
HIPAA
−6%
Maximum combined reduction
−30%

Certification audit time

ISO-informed
Model
Personnel-based duration, ISO/IEC 27006-1 principles
Scope adjustment ceiling
30% (never exceeded)
Minimum audit duration
3.5 d
Certification-body day rate (default)
€1,300
Multi-site
Square-root site sampling, +1 day per additional sampled site

Default day rates

Default assumption
Internal
€600
Consultant
€1,200

Fixed cost blocks — training

Default assumption
Micro (1–10 employees)
€400
Small (11–50)
€2,000
Medium (51–250)
€8,000
Large (251–1000)
€18,000
Enterprise (1000+)
€40,000

Fixed cost blocks — tooling / GRC software

Default assumption
Micro (1–10 employees)
€500
Small (11–50)
€5,000
Medium (51–250)
€20,000
Large (251–1000)
€60,000
Enterprise (1000+)
€150,000

Implementation phases (share of effort)

Modelled
Gap Analysis
10%
Risk Assessment
15%
Policy Development
20%
Implementation
30%
Internal Audit
10%
Certification Audit
15%

Estimate confidence bands (planning range)

Estimated
High (score ≥ 0.75)
88% – 115% of the modelled total
Moderate (score ≥ 0.5)
80% – 125% of the modelled total
Low (score ≥ 0)
68% – 145% of the modelled total

Scenario analysis

Every scenario, sensitivity point and 3-year outlook is recalculated server-side by the same authoritative engine. A browser total is never trusted, and a saved scenario keeps the exact recurring assumptions it was saved with.

Editable assumptions

User provided

These assumptions can be overridden per estimate. An override substitutes the modelled default for that estimate only — the published default never changes and an edited value is a user planning input, not a verified market rate.

employees · locations · infraType · overallMaturity · mixRatio · internalRate · consultantRate · certBodyDayRate · trainingCost · toolsCost

Cost sensitivity

Modelled
Method
One variable at a time, full engine recalculation per point
Consultant day rate
±25%
Internal day rate
±25%
Security maturity
±1
Locations in scope
±1
IT systems in scope
±50%
Infrastructure model
alternatives
Delivery model
alternatives
Existing control-framework reuse
none / max

3-Year Planning Outlook

Default assumption
Outlook model version
ISO_TCO_MODEL_1_0
Internal ISMS operation (% of Year-1 implementation effort per year)
25
Surveillance allowance (% of modelled initial audit days per year)
33
Recurring tooling (% of the Year-1 allowance per year)
100
Awareness refresh (% of the Year-1 allowance per year)
40
External support (consultant days per year)
0
Recertification
Not included in the 3-year outlook
Open methodology verification
Surveillance allowance

A planning outlook over three years, not a representation of the formal certification cycle. Recurring values are ISMSCalculator default assumptions, not industry averages.

The surveillance allowance is modelled as a share of the modelled initial audit duration. It is a default assumption, not an ISO-required or ISO-calculated figure; the precise basis in ISO/IEC 27006-1 still requires methodology verification.

Not included in this 3-year planning outlook. Recertification normally falls at the end of a certification cycle, outside this horizon.

Limitations

  • Model-generated references are not observed market data and no empirical percentile or pass-rate statistics are published.
  • The estimate confidence indicator expresses how organisation-specific your inputs are; it is not a statistical confidence interval.
  • Certification audit time is finally determined by your certification body, not by this model.
  • Surveillance and recertification cycles are outside the current model scope.