ISO 27001 Compliance Consultants
- Consultants come from three backgrounds: management systems and audit, security engineering, and regulatory practice. A programme needs all three capabilities.
- The market is mature, so unlike newer standards you can and should ask how many ISMSs the individual has taken through Stage 2.
- Ask for a redacted Statement of Applicability. It shows whether they reason or tick.
- Day rates commonly run £600 to £1,400. Fixed fees are usually better for a first certification.
- A good consultant raises the internal audit independence question before you do.
What they do
ISO 27001 compliance consultants build the information security management system, prepare the documentation, run the internal audit where you have nobody independent, and take you through the certification audit.
This guide is about the people. Where they come from, what credentials mean, and how to test capability in a market old enough that real track records exist.
Where they come from
Management systems and audit. Practitioners from ISO 27001, ISO 9001 or internal audit backgrounds. Their strength is building a system that runs and produces evidence repeatedly, which is exactly what Stage 2 tests. Their limit tends to be technical depth on modern infrastructure, which shows when the eleven newer controls are addressed on paper only.
Security engineering. Practitioners who have built and run security programmes. Their strength is making controls genuinely work in real environments, particularly the cloud, configuration, monitoring and secure development controls. Their limit tends to be the management system discipline, which is a distinct craft.
Regulatory practice. Practitioners who have taken organisations through supervision or examination. Their strength is judgement about what an examiner accepts as sufficient. This is our own background, described on the about page.
A programme needs all three. The question is whether the firm brings them or expects you to.
What credentials mean
There is no licence to advise on ISO 27001. Common qualifications include ISO 27001 Lead Implementer and Lead Auditor, CISA, CISM and CISSP. They indicate training completed rather than systems delivered.
Because this market is mature, you can ask a harder question than you could for a newer standard: how many information security management systems has this individual personally taken through a Stage 2 audit, at organisations of roughly your size and on roughly your infrastructure. Expect a specific number.
The document that reveals capability
Ask for a redacted Statement of Applicability.
It records which of the 93 Annex A controls apply, which do not, why, and how the applicable ones are implemented. A good one reasons in language specific to the organisation, and the exclusions are justified rather than asserted. A weak one is a grid of ticks with boilerplate.
Ten minutes with that document tells you more than a reference call, because it is the first thing your auditor will read too.
What a good consultant does differently
They scope from what your buyers actually ask about, and can explain why each unit or service is in or out.
They run a real risk assessment and let control selection follow from it, rather than selecting controls and reverse-engineering risks.
They tell you early when a target date is unachievable, and show the arithmetic: build, operate long enough to produce records, internal audit, management review, Stage 1, Stage 2, plus certification body scheduling.
They design controls that leave records automatically, because a control that operates without evidence fails at Stage 2 and again at surveillance.
They raise internal audit independence before you ask, because most organisations have nobody who qualifies and discover it late.
They check whether your certification body is accredited and can name the accreditation body.
How they charge
| Model | Typical range |
|---|---|
| Gap analysis, fixed fee | £5,000 to £15,000 |
| Full implementation, fixed fee | £15,000 to £50,000 |
| Internal audit, per cycle | £4,000 to £12,000 |
| Day rate | £600 to £1,400 |
| Continuous assurance retainer | Scope dependent |
Fixed fee per phase generally beats a day rate for a first certification, because it forces the scope conversation before the work starts. Confirm in writing that certification body fees sit outside.
What no consultant can do
Certify you. Only an accredited certification body can, and it must be a different organisation.
Perform your internal audit and have it count as independent, if they built the ISMS. Some firms separate practitioners; ask how.
Guarantee certification. The certification body decides. A firm promising the outcome is describing a commercial position rather than a regulatory one.
What to do next
Work out which capability you are short of. If your engineering is strong but nothing is documented, you need the management system skill set. If your documentation is fine but the newer technical controls do not exist, you need the opposite.
Our free readiness diagnostic gives a first view, and the ISO 27001 service page sets out how we work.
References
FAQ
What qualifications should an ISO 27001 consultant have?
No licence is required. Lead Implementer, Lead Auditor, CISA, CISM and CISSP are common. Systems personally taken through Stage 2 matter more.
How do I test a consultant's capability?
Ask for a redacted Statement of Applicability, and ask how many ISMSs they have personally taken to certification.
Can our consultant certify us?
No. ISO/IEC 17021 prevents a certification body from consulting on a system it certifies.
How much does an ISO 27001 consultant cost?
Day rates commonly £600 to £1,400. Fixed fees for a full implementation commonly £15,000 to £50,000, with certification fees separate.
Can the same firm do implementation and internal audit?
Some do, with separate practitioners. Ask how independence is preserved, because an audit of your own work is worth little at surveillance.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of regulatory practice advising firms through authorisation, supervision and examination. Every engagement has a named practitioner and an agreed scope, timetable and fee. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.