Hael
Book a meeting
ISO 27001 · Selection

ISO 27001 consultant recommendation

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 6 min read
Key takeaways
  • The market is mature, so a recommendation based on a completed certification is genuinely available. Ask for one.
  • Ask what the certificate's scope statement says. A narrow scope certified quickly tells you little.
  • Your certification body sees the finished work of many consultancies and can often name firms it found well prepared.
  • Verify the named practitioner, whether Stage 2 was reached first time, and any commercial arrangement.
  • Ask for a redacted Statement of Applicability. It is faster and more informative than a reference call.

Where recommendations come from

ISO 27001 has been certifiable for two decades and more than 70,000 organisations hold it, so unlike newer standards you can reasonably expect a recommendation based on a completed certification rather than an ongoing programme. Ask for one.

A recommendation tells you a firm delivered for somebody. It does not tell you the scope, the fee model, who did the work, or whether the certificate came from an accredited body.

Organisations that hold the certificate. The strongest source. Ask what the certificate covers as well as who helped.

Your certification body. If you have already selected one, it sees the finished work of many consultancies and knows which arrive well prepared. It cannot consult on your system or advise you on passing its own audit, but naming firms it has encountered is a different thing and generally allowed. This is the most underused source in the market.

Your SOC 2 auditor or consultant. Many firms do both, and the control overlap means a good SOC 2 practitioner often has genuine ISO capability. Ask whether they have taken systems through Stage 2 or only prepared documentation.

Your compliance platform's partner directory. Vanta, Drata, Secureframe and others list ISO 27001 partners who know that platform well. Ask whether referral fees pass in either direction.

Your insurer or broker. Cyber insurers see security programmes across many organisations and sometimes hold views worth hearing.

Sector networks. Peers facing the same buyer questions are a good source, and the conversation is usually specific.

What to ask the person recommending

What does the certificate's scope statement say? A certificate covering one product team is a different engagement from one covering a whole organisation across three sites.

Did you pass Stage 2 first time, and were there major nonconformities? This is the question that separates a real recommendation from a polite one.

Who did the work? Names, not the firm. People move.

Did they do your internal audit, and how was independence handled? The answer reveals how the firm thinks about the rules.

Did the fee hold? Ask whether the final invoice matched the proposal and if not, why.

Would you use them for the surveillance cycle? Future intent is more honest than past satisfaction.

What a recommendation does not tell you

That your scope is comparable. That the same practitioner is available. That the engagement ran through to certification rather than stopping at documentation. That the ISMS is still running, which surveillance will eventually test.

None of that is a reason to disregard a recommendation. All of it is a reason to treat it as a starting point.

The verification that beats a reference call

Ask the firm for a redacted Statement of Applicability they have written.

It records which of the 93 Annex A controls apply, which do not, why, and how the applicable ones are implemented. A good one reasons in language specific to the organisation. A weak one is a grid of ticks with boilerplate justifications.

Ten minutes with that document tells you what two reference calls will not, because it is the first thing your own auditor will read.

Three checks before you act

The named practitioner and their committed hours. Ask who runs your programme and how much of their week it gets.

Whether the referenced programme reached Stage 2 cleanly. "We worked with them" and "they took us to certification without major nonconformities" are different statements.

Commercial arrangements. Ask whether the firm pays or receives referral fees, or takes commission from certification bodies. We take none, which is stated on our about page.

If nobody in your network has certified

Shortlist three firms from different sources, give all three the same scope, and ask each how they would handle your internal audit requirement. That question separates firms quickly because it forces them to address independence rather than describe a methodology.

The full question set is in Recommendations for a Good ISO 27001 Compliance consultant.

What to do next

Draft a provisional scope before asking anyone for a recommendation. Cost and effort scale with scope, so a recommendation given against a vague brief arrives against a vague engagement.

Our free readiness diagnostic gives a starting view, and the ISO 27001 service page sets out how we work.

References

FAQ

Where can I get an ISO 27001 consultant recommendation?

From organisations that hold the certificate, your certification body, your SOC 2 practitioner, compliance platform partner directories, your cyber insurer and sector networks.

Can our certification body recommend a consultant?

It can generally name firms it has found well prepared. It cannot consult on the system it will certify.

What should I ask a reference?

What the certificate's scope says, whether Stage 2 passed first time, who did the work, whether the fee held, and whether they would use the firm again.

What is the best single verification?

Ask for a redacted Statement of Applicability the firm has written.

Should the same firm do implementation and internal audit?

Only with genuine separation of practitioners. Ask how independence is preserved before accepting it.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. Every engagement has a named practitioner and an agreed scope, timetable and fee. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO 27001, free.

Answer a short set of questions and see what ISO 27001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO 27001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO 27001.

Or speak to us about your deadline. Book a meeting.