Hael
Book a meeting
ISO 27001 · Consultancy

ISO 27001 consultancy services

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Six workstreams: gap analysis, implementation, internal audit, certification support, buyer security reviews and continuous assurance.
  • Your consultancy cannot certify you, and your certification body cannot consult on the system it certifies. That separation is structural.
  • Internal audit recurs annually, which makes it the most durable part of the relationship.
  • Fees commonly run £15,000 to £50,000 for a full implementation, with certification body fees always separate.
  • Ask who writes the Statement of Applicability. It is the document that separates advice from delivery.

What the work covers

ISO 27001 consultancy services cover the work of building an information security management system that will pass audit and keep working. The work divides into six workstreams, and knowing which of them a proposal includes is how to compare firms sensibly.

One rule shapes the market. Under ISO/IEC 17021, a certification body cannot consult on a system it will certify, and cannot perform your internal audit. Implementation and certification therefore always come from different suppliers, which protects the value of the certificate.

The six workstreams

Gap analysis. A clause-by-clause position against Clauses 4 to 10 and a control-by-control position against the 93 Annex A controls, stating what is met, what is not, and what closes each gap. This is our readiness and gap assessment, delivered as a fixed fee with a delivery call.

Implementation. Scope, information security policy, roles, the risk assessment method and risk treatment plan, the Statement of Applicability, the control set, and the documentation. Includes the eleven controls new in the 2022 edition, which is where most of the effort concentrates for organisations with existing security practice. Covered by our implementation service.

Internal audit. Required by Clause 9.2 before certification and every year afterwards, and it cannot be done by your certification body. Covered by our internal audit service.

Certification support. Selecting an accredited body, preparing for Stage 1 and Stage 2, briefing the people who will be interviewed, coordinating evidence and handling findings. Covered by our certification readiness and audit support service.

Buyer security reviews. Answering customer security questionnaires from the same evidence base, which for many organisations is the reason the certificate was needed. Covered by our buyer assurance and security reviews service.

Continuous assurance. Keeping the ISMS operating between audits and running the annual cycle. Covered by our continuous governance and assurance service.

What a consultancy cannot do

Certify you. Only an accredited certification body can, and it must be a different organisation.

Operate your controls. Access reviews, supplier assessments, change approvals and incident handling happen inside your business, performed by your people. A consultancy designs, documents, trains and chases.

Make an unrealistic date work. If the ISMS has not operated long enough to produce records, no supplier closes that gap. A firm that says so on the first call is doing you a service.

Typical fees

ServiceTypical fee
Gap analysis£5,000 to £15,000
Full implementation, small to mid-sized organisation£15,000 to £50,000
Internal audit, per annual cycle£4,000 to £12,000
Certification supportOften within the implementation fee, otherwise £4,000 to £10,000
Continuous assuranceRetainer, scope dependent
Certification body fees, always separate£5,000 to £20,000 initial cycle
Independent practitioner day rate£600 to £1,400

Confirm in writing that certification body fees sit outside the consultancy fee. They always do, and they should appear as a separate line.

The document that separates advice from delivery

Ask who writes the Statement of Applicability.

It records which of the 93 controls apply, which do not, why each decision was made, and how the applicable ones are implemented. Written well, it is the spine of the whole ISMS and the auditor's first reference. Written as a grid of ticks, it produces findings.

A firm that will write it, in language specific to your organisation, is selling delivery. A firm that will tell you what should go in it is selling advice. Both are legitimate products at different levels of effort for you.

How this interacts with a compliance platform

Platforms carry ISO 27001 content: control mappings, policy templates, evidence collection, continuous monitoring. They remove a substantial amount of manual work and are worth having for most organisations.

What they do not do is set your scope, run the risk assessment that justifies your control selection, or make the judgement calls the Statement of Applicability records. We work inside whichever platform you already own and configure it properly, and where there is none the engagement runs on the Hael platform, which is included and stays available to you afterwards.

The workstream that recurs

Internal audit comes back every year for as long as you hold the certificate. Your certification body cannot do it, and in most organisations under a few hundred people there is nobody with both the competence and the independence.

That makes it the most durable part of the relationship, and the part worth getting right. It is covered in full in ISO 27001 - Internal Audit Consultants.

What to do next

Establish your scope and your target certification date, then get proposals against both. Two proposals cannot be compared until they cover the same scope.

Our free readiness diagnostic gives a first view, and the ISO 27001 service page sets out how we deliver each workstream.

References

FAQ

What do ISO 27001 consultancy services include?

Gap analysis, implementation, internal audit, certification support, buyer security reviews and continuous assurance.

Can our consultant also certify us?

No. ISO/IEC 17021 prevents a certification body from consulting on a system it certifies, so the two are always different suppliers.

How much does ISO 27001 consultancy cost?

Commonly £15,000 to £50,000 for a full implementation, with certification body fees of £5,000 to £20,000 separate.

Do we need help with internal audit?

Usually. It is required annually, cannot come from your certifier, and most organisations lack anyone both competent and independent in house.

Will a compliance platform replace a consultancy?

It will reduce manual work substantially. It will not set scope, run your risk assessment, or make the judgement calls the Statement of Applicability records.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across ISO 27001, SOC 2, ISO/IEC 42001 and the EU AI Act. We are not a certification body, we do not issue certificates, and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO 27001, free.

Answer a short set of questions and see what ISO 27001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO 27001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO 27001.

Or speak to us about your deadline. Book a meeting.