The first question every UAE business owner asks us about ISO 27001 is the same one: what does it cost?

The honest answer is "AED 36,000 to AED 250,000+" — and that range, by itself, is useless. So let's break it down into the four cost drivers that actually matter.

The four cost drivers

  1. Scope of the ISMS — one office or fifteen? One product or a portfolio? Scope is the single biggest lever.
  2. Existing maturity — do you already have policies, change management, vendor reviews? If yes, we reuse. If no, we author.
  3. Number of Annex A controls in scope — the 2022 standard has 93 controls in 4 themes. Most engagements implement 60–80, the rest are formally excluded with documented justification.
  4. Whether you want us to operate the ISMS post-cert — or hand over to your team after audit.

Indicative ranges (AED)

Company size Headcount Sites Implementation Annual maintenance Year-1 total
Micro <20 1 36,000 – 55,000 12,000 – 18,000 ~AED 50K
Small 20 – 100 1 – 2 55,000 – 88,000 18,000 – 30,000 ~AED 80K
Mid-market 100 – 500 2 – 5 88,000 – 160,000 30,000 – 55,000 ~AED 130K
Multi-site / regulated 500+ 5+ 160,000 – 250,000+ 55,000 – 100,000+ AED 220K+

These ranges are for implementation + audit-readiness only. Add separately:

  • Certification body fees (typically AED 25,000 – 60,000 for a Stage 1 + Stage 2 audit)
  • Internal control implementation costs (your IT team's time, any tooling you buy)
  • Surveillance audit fees in Years 1 and 2, and recertification in Year 3

What inflates the cost (and what doesn't)

Inflates it:

  • "Boil the ocean" scope ("certify everything") instead of a defined ISMS boundary
  • Building documentation from scratch when you already have most of it in different formats
  • Heavy customisation of a generic policy template instead of starting from your own context
  • Stretching a 4-month engagement to 9 months because of slow internal sign-off

Doesn't inflate it as much as people fear:

  • Whether you're in a regulated sector (BFSI, healthcare) — the controls are similar, the risk register changes
  • Whether your tech stack is cloud, on-prem, or hybrid — the standard is technology-agnostic
  • Whether you're a 5-year-old company or pre-revenue — what matters is what's in scope, not company age

What an honest scoping call looks like

When you call us, we ask:

  1. What's driving this — a specific contract, an investor, an insurance requirement, or proactive?
  2. What's the smallest ISMS scope that still satisfies the driver? (Often you don't need the whole company.)
  3. What governance, documentation, and security controls do you already have?
  4. What's your target certification date?

In about 45 minutes we can give you a written estimate within ±20% of the final number, and a 4–6 month implementation plan. No "we'll need to come on-site for two days first" theatrics.

Common mistakes that double the cost

  1. Hiring a generalist consultant who has never been a Lead Auditor. They author great-looking documentation that fails the Stage 1 audit.
  2. Not separating the implementation team from the certification body. The same firm cannot do both — and if they offer, walk away.
  3. Treating ISO 27001 as a paperwork exercise. The auditor will ask your team how they actually use the policies. If the answer is "what policies?" — you fail.
  4. Skipping the internal audit. It's mandatory before the external Stage 2. If you skip it, the external auditor will find the same things you would have found, but in a much more expensive room.

What we charge

For a typical mid-market UAE company (100–300 staff, single primary site, no regulated sector requirements):

  • Implementation + audit-readiness: AED 88,000 – 130,000
  • Internal audit: included
  • Statement of Applicability + risk register + 23 mandatory policies: included
  • Stage 1 + Stage 2 audit support (we sit with you in the room): included
  • Timeline: 4 – 6 months

We are an ISO 27001:2022 Lead Auditor-led practice. Every document we author is something we'd accept if we were sitting on the other side of the audit.

If that maps to where you are, send us a brief and we'll come back within one working day with an indicative quote and a proposed timeline.