How to choose an ISO 27001 consultant

Most businesses choose an ISO 27001 consultant by comparing day rates. It feels sensible. It's also the wrong number to look at.

The day rate tells you what the first few months will cost. It tells you nothing about what the next three years will cost, who will run the system once the consultant has gone, or what happens if you don't pass. Those are the things that decide whether ISO 27001 becomes a useful part of your business or an expensive annual headache.

Here's what to look at instead.

What should you look for in an ISO 27001 consultant?

Three things matter more than price.

A system you can run yourself. The best implementation is one your own team understands and can operate after the consultant leaves. If the system only makes sense to the person who built it, you will be paying them to come back every year.

Security, not just paperwork. ISO 27001 should make you more secure. A consultant who only writes policies will get you a folder of documents that don't match how your business works, and an auditor will spot the gap.

A clear view of the full certification cycle. Your certificate lasts three years, with surveillance audits every year and internal audits to run. A good consultant will be upfront about what happens after certification, not just before it.

Why are some ISO 27001 consultants so expensive?

Day rate is the biggest single factor, and larger consultancies charge more because they carry more overhead. In return you usually get more cover if your consultant is unavailable and a wider range of skills. That has real value, but it's worth knowing what you're paying for.

The second factor is complexity. Some consultants over-engineer the system, with more policies, more registers and more process than your business needs. More to build means more days. It also means more to maintain, which is where the real cost shows up in years two and three.

The third is travel. Some firms work on site whether it's needed or not, and hotels, travel and subsistence on a ten-day engagement can easily add another £1,000 or more. Most implementation work can be done remotely.

Why are some ISO 27001 consultants so cheap?

One or two person firms have low overheads, so they can charge less. Some are excellent. The risks are coverage and depth. If your consultant is ill or overbooked, your project stops. And a very small team may not have the technical skills to help you with the security controls themselves, only the documentation.

Cheap can also mean a template pack with your name on it. That gets you documents, not a working system.

Questions to ask before you sign

These will tell you more than any proposal.

  • Who runs the system after certification? If the honest answer is "we do", ask what that costs each year.
  • What will this cost over three years? Ask for implementation, internal audits, ongoing support and any software in one figure. Certification body fees sit on top whichever route you choose.
  • Who carries out the internal audits? They're required, and they're often left out of the initial quote.
  • Is your guarantee full or conditional? Some guarantees only cover the Stage 1 audit, which is a readiness check. Ask whether the guarantee covers certification itself.
  • Do you need to be on site? If so, are expenses included in the price?
  • What happens if my consultant is unavailable? Find out who picks up the work.
  • Will you help with the security controls, or just the documents? You need both.

Red flags to watch for

Be wary of a quote that covers the build but says nothing about years two and three. Be wary of a system so detailed that nobody on your team could explain it to an auditor. And be wary of anyone who talks about the certificate but never asks how your business actually works. ISO 27001 should fit your operations, not the other way round.

How we approach ISO 27001

We keep systems simple enough for your team to run, we work remotely unless there's a real reason to be on site, and we're clear about the full three-year cost from the start. We guarantee you pass first time or you don't pay, and we have a 100% success rate in UKAS audits.

For teams under 100, we also offer ISO 27001 on ComplyOrbit: implementation, the platform, every internal audit and three years of expert oversight for a fixed monthly fee. [LINK: ComplyOrbit landing page]

If you'd rather see figures first, our ISO 27001 certification cost guide breaks down what to budget, and our pricing calculator gives you an estimate in minutes.

Frequently asked questions

How much does an ISO 27001 consultant cost?

For most UK SMEs, consultant-led implementation runs from around £5,000 to £20,000, depending on size, complexity and how much is already in place. Ongoing support and internal audits are usually extra, so compare the full three-year cost rather than the build price.

Do I need a consultant to get ISO 27001?

No. You can implement ISO 27001 yourself if you have the time and someone with security and audit experience. Many businesses underestimate the effort, though, and projects that stall for a year or more often end up costing more than bringing in help.

Can an ISO 27001 consultant guarantee certification?

The certification decision always rests with the certification body. A consultant's guarantee is a commercial promise about their own work, so check exactly what it covers. A guarantee that only covers Stage 1 protects you far less than one that covers certification.

Talk to us

If you're comparing ISO 27001 consultants and want a straight answer on what your project should involve, get in touch. We'll tell you honestly whether we're the right fit.

View All Posts
Blog Image

October 2, 2026

Hacker Hub - October 2026

A single phone call to an IT help desk cost TfL a reported £29 million. Here's how help desk impersonation works and how to stop it.

Read More