The first question every UAE business owner asks us about ISO 27001 is the same one: what does it cost?
The honest answer is "AED 36,000 to AED 250,000+" — and that range, by itself, is useless. So let's break it down into the four cost drivers that actually matter.
The four cost drivers
- Scope of the ISMS — one office or fifteen? One product or a portfolio? Scope is the single biggest lever.
- Existing maturity — do you already have policies, change management, vendor reviews? If yes, we reuse. If no, we author.
- Number of Annex A controls in scope — the 2022 standard has 93 controls in 4 themes. Most engagements implement 60–80, the rest are formally excluded with documented justification.
- Whether you want us to operate the ISMS post-cert — or hand over to your team after audit.
Indicative ranges (AED)
| Company size | Headcount | Sites | Implementation | Annual maintenance | Year-1 total |
|---|---|---|---|---|---|
| Micro | <20 | 1 | 36,000 – 55,000 | 12,000 – 18,000 | ~AED 50K |
| Small | 20 – 100 | 1 – 2 | 55,000 – 88,000 | 18,000 – 30,000 | ~AED 80K |
| Mid-market | 100 – 500 | 2 – 5 | 88,000 – 160,000 | 30,000 – 55,000 | ~AED 130K |
| Multi-site / regulated | 500+ | 5+ | 160,000 – 250,000+ | 55,000 – 100,000+ | AED 220K+ |
These ranges are for implementation + audit-readiness only. Add separately:
- Certification body fees (typically AED 25,000 – 60,000 for a Stage 1 + Stage 2 audit)
- Internal control implementation costs (your IT team's time, any tooling you buy)
- Surveillance audit fees in Years 1 and 2, and recertification in Year 3
What inflates the cost (and what doesn't)
Inflates it:
- "Boil the ocean" scope ("certify everything") instead of a defined ISMS boundary
- Building documentation from scratch when you already have most of it in different formats
- Heavy customisation of a generic policy template instead of starting from your own context
- Stretching a 4-month engagement to 9 months because of slow internal sign-off
Doesn't inflate it as much as people fear:
- Whether you're in a regulated sector (BFSI, healthcare) — the controls are similar, the risk register changes
- Whether your tech stack is cloud, on-prem, or hybrid — the standard is technology-agnostic
- Whether you're a 5-year-old company or pre-revenue — what matters is what's in scope, not company age
What an honest scoping call looks like
When you call us, we ask:
- What's driving this — a specific contract, an investor, an insurance requirement, or proactive?
- What's the smallest ISMS scope that still satisfies the driver? (Often you don't need the whole company.)
- What governance, documentation, and security controls do you already have?
- What's your target certification date?
In about 45 minutes we can give you a written estimate within ±20% of the final number, and a 4–6 month implementation plan. No "we'll need to come on-site for two days first" theatrics.
Common mistakes that double the cost
- Hiring a generalist consultant who has never been a Lead Auditor. They author great-looking documentation that fails the Stage 1 audit.
- Not separating the implementation team from the certification body. The same firm cannot do both — and if they offer, walk away.
- Treating ISO 27001 as a paperwork exercise. The auditor will ask your team how they actually use the policies. If the answer is "what policies?" — you fail.
- Skipping the internal audit. It's mandatory before the external Stage 2. If you skip it, the external auditor will find the same things you would have found, but in a much more expensive room.
What we charge
For a typical mid-market UAE company (100–300 staff, single primary site, no regulated sector requirements):
- Implementation + audit-readiness: AED 88,000 – 130,000
- Internal audit: included
- Statement of Applicability + risk register + 23 mandatory policies: included
- Stage 1 + Stage 2 audit support (we sit with you in the room): included
- Timeline: 4 – 6 months
We are an ISO 27001:2022 Lead Auditor-led practice. Every document we author is something we'd accept if we were sitting on the other side of the audit.
If that maps to where you are, send us a brief and we'll come back within one working day with an indicative quote and a proposed timeline.