Buying guide

The ISO 27001 RFP & quote comparison worksheet

What to put in your brief, how to normalize CB quotes, and the engagement-letter red flags that cost companies real money.

Your RFP brief (one page is enough)

  1. Company facts: industry, total and in-scope headcount, sites and countries.
  2. ISMS scope: which systems, teams, and data are in scope — and what's excluded.
  3. Current state: existing policies, prior audits, tooling, internal security staff.
  4. Schemes: ISO 27001 only, or plus ISO 27701 / SOC 2.
  5. Timeline: target certification date and any deal-driven deadlines.
  6. Ask for: Stage 1 days, Stage 2 days, day rate, travel, surveillance pricing (years 2–3), recertification pricing, named audit team, and accreditation details.

Quote comparison worksheet

Normalize every quote to the same columns before comparing totals:

Line itemCB ACB BCB C
Accreditation (body + ISO 27001 scope)
Stage 1 audit days
Stage 2 audit days
Day rate
Travel & expenses
Gap assessment (if included)
Surveillance, year 2
Surveillance, year 3
Recertification (year 4)
3-year total

Engagement-letter red flags

Skip the spreadsheet? Our quote form sends the same brief to matched CBs and the quotes come back comparable. Free · 2 minutes.

Request comparable quotes