Methodology
How ISMSCalculator models ISO 27001 cost
Every multiplier, floor, default rate and audit-time assumption used by the engine is published here. Nothing is hidden behind a sales call, and no ISO standard text or table is reproduced.
Saved, shared and exported estimates are always recalculated server-side with this engine version — a value produced in the browser is treated as a preview only.
Base implementation effort (person-days)
Modelled- Micro (1–10 employees)
- 5.5 d
- Small (11–50)
- 25 d
- Medium (51–250)
- 70 d
- Large (251–1000)
- 180 d
- Enterprise (1000+)
- 400 d
Minimum effort floors (irreducible ISMS core)
Modelled- Micro (1–10 employees)
- 5 d
- Small (11–50)
- 12 d
- Medium (51–250)
- 30 d
- Large (251–1000)
- 75 d
- Enterprise (1000+)
- 160 d
Sector complexity multipliers
Modelled- Finance & Banking
- ×1.45
- Healthcare
- ×1.35
- Government
- ×1.30
- Technology
- ×1.05
- Manufacturing
- ×1.22
- Retail & E-commerce
- ×1.10
- Education
- ×1.08
- Energy & Utilities
- ×1.25
- Telecom & Media
- ×1.20
- Insurance & Legal
- ×1.38
- Logistics & Transport
- ×1.15
- Other
- ×1.00
Infrastructure multipliers
Modelled- Cloud
- ×0.90
- On-Premise
- ×1.15
- Hybrid
- ×1.00
Maturity multipliers (interpolated 1–5)
Modelled- Level 1
- ×1.35
- Level 2
- ×1.15
- Level 3
- ×1.00
- Level 4
- ×0.80
- Level 5
- ×0.65
Existing control-framework reuse
Modelled- SOC2
- −10%
- GDPR
- −8%
- ISO9001
- −6%
- NIST
- −7%
- PCIDSS
- −5%
- HIPAA
- −6%
- Maximum combined reduction
- −30%
Certification audit time
ISO-informed- Model
- Personnel-based duration, ISO/IEC 27006-1 principles
- Scope adjustment ceiling
- 30% (never exceeded)
- Minimum audit duration
- 3.5 d
- Certification-body day rate (default)
- €1,300
- Multi-site
- Square-root site sampling, +1 day per additional sampled site
Default day rates
Default assumption- Internal
- €600
- Consultant
- €1,200
Fixed cost blocks — training
Default assumption- Micro (1–10 employees)
- €400
- Small (11–50)
- €2,000
- Medium (51–250)
- €8,000
- Large (251–1000)
- €18,000
- Enterprise (1000+)
- €40,000
Fixed cost blocks — tooling / GRC software
Default assumption- Micro (1–10 employees)
- €500
- Small (11–50)
- €5,000
- Medium (51–250)
- €20,000
- Large (251–1000)
- €60,000
- Enterprise (1000+)
- €150,000
Implementation phases (share of effort)
Modelled- Gap Analysis
- 10%
- Risk Assessment
- 15%
- Policy Development
- 20%
- Implementation
- 30%
- Internal Audit
- 10%
- Certification Audit
- 15%
Estimate confidence bands (planning range)
Estimated- High (score ≥ 0.75)
- 88% – 115% of the modelled total
- Moderate (score ≥ 0.5)
- 80% – 125% of the modelled total
- Low (score ≥ 0)
- 68% – 145% of the modelled total
Scenario analysis
Every scenario, sensitivity point and 3-year outlook is recalculated server-side by the same authoritative engine. A browser total is never trusted, and a saved scenario keeps the exact recurring assumptions it was saved with.
Editable assumptions
User providedThese assumptions can be overridden per estimate. An override substitutes the modelled default for that estimate only — the published default never changes and an edited value is a user planning input, not a verified market rate.
employees · locations · infraType · overallMaturity · mixRatio · internalRate · consultantRate · certBodyDayRate · trainingCost · toolsCost
Cost sensitivity
Modelled- Method
- One variable at a time, full engine recalculation per point
- Consultant day rate
- ±25%
- Internal day rate
- ±25%
- Security maturity
- ±1
- Locations in scope
- ±1
- IT systems in scope
- ±50%
- Infrastructure model
- alternatives
- Delivery model
- alternatives
- Existing control-framework reuse
- none / max
3-Year Planning Outlook
Default assumption- Outlook model version
- ISO_TCO_MODEL_1_0
- Internal ISMS operation (% of Year-1 implementation effort per year)
- 25
- Surveillance allowance (% of modelled initial audit days per year)
- 33
- Recurring tooling (% of the Year-1 allowance per year)
- 100
- Awareness refresh (% of the Year-1 allowance per year)
- 40
- External support (consultant days per year)
- 0
- Recertification
- Not included in the 3-year outlook
- Open methodology verification
- Surveillance allowance
A planning outlook over three years, not a representation of the formal certification cycle. Recurring values are ISMSCalculator default assumptions, not industry averages.
The surveillance allowance is modelled as a share of the modelled initial audit duration. It is a default assumption, not an ISO-required or ISO-calculated figure; the precise basis in ISO/IEC 27006-1 still requires methodology verification.
Not included in this 3-year planning outlook. Recertification normally falls at the end of a certification cycle, outside this horizon.
Limitations
- Model-generated references are not observed market data and no empirical percentile or pass-rate statistics are published.
- The estimate confidence indicator expresses how organisation-specific your inputs are; it is not a statistical confidence interval.
- Certification audit time is finally determined by your certification body, not by this model.
- Surveillance and recertification cycles are outside the current model scope.