iso27001partnersUK certification, costed Get a cost estimate

Information security consultant: what the role covers and the UK credentials behind it

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 8 min read
6 primary sources cited on this page. How we check what is on this site
The UK register Four titles, eight specialisms

“The UK Cyber Security Council awards four professional titles (Associate, Practitioner, Principal and Chartered)” — UK Cyber Security Council.

“Information security consultant” is not a protected title. It covers people who write ISO 27001 policies, people who test networks and people who design architectures. This page separates the work, shows the UK's professional register for it, and gives a way to match the credential to the job you actually need done.

What counts as consultancy

For management systems, the accreditation standard for certification bodies gives a definition: “participation in establishing, implementing or maintaining a management system”. Its examples:

Examples of management system consultancy (ISO/IEC 17021-1:2015 clause 3.3, verbatim)
Example
Preparing or producing manuals or procedures.
Giving specific advice, instructions or solutions towards the development and implementation of a management system.

That definition matters because of what follows from it: a certification body cannot also provide it, and a consultancy related to your certification body can stop that body certifying you for two years. The detail is on the ISO 27001 consultants page.

What an ISO 27001 consultant does, clause by clause

ISO/IEC 27001:2022 is built from clauses 4 to 10. The work a consultant can take on, and the decisions that stay with you, differ by clause:

ISO/IEC 27001 clauses (titles from the standard's contents) and the split of work (our reading)
ClauseTitleA consultant mayStays with you
4Context of the organisationWorkshops on issues and interested parties; drafting the scopeDeciding the scope
5LeadershipDrafting the policy and the rolesTop management's commitment and sign-off
6PlanningA risk assessment method, facilitating the assessment, drafting the Statement of ApplicabilityAccepting the risks and approving the treatment plan
7SupportAwareness material, document templates, a competence recordResources and people
8OperationAdvice on running the controlsRunning them
9Performance evaluationAn internal audit, if independent of the work auditedThe management review
10ImprovementA corrective action processFixing what is found

Why some things cannot be handed over

Clause 5 places leadership duties on top management, and the management review is “Top management shall review the organization’s [information security] management system, at planned intervals, to ensure its continuing suitability, adequacy and effectiveness.” in the common text the standard applies. A consultant can prepare those; the auditor will look for your management's own decisions. See management review.

The internal audit

A consultant can carry out your internal audit, but not one of their own work if the audit is to be objective. The rules are on the internal audit page.

The eight specialisms

The UK Cyber Security Council has “contextualised” its Standard for Professional Competence and Commitment for eight specialisms. Its definitions:

UK Cyber Security Council specialisms: definitions (verbatim) and status
SpecialismDefinitionRegistration
Cyber Security Audit & AssuranceThe verification of evidence that systems and processes meet the specified security requirements and that processes are in place to check on-going complianceOpen
Security TestingTesting the vulnerabilities of a network, system, product or design against the specified security requirements. Sometimes also known as penetration testing.Open
Secure System Architecture & Designthe designing of an IT system to meet its security requirements, balancing this with its functional requirements.Open
Secure OperationsThe management of an organisation’s information systems operations in accordance with the agreed security requirements.Open
Incident Responsethe preparation for, handling of and following up of cyber security incidents, to minimise the damage to an organisation and prevent recurrence.Open
Cyber Security Governance & Risk Managementthe monitoring of compliance with agreed cyber security policies and the assessment and management of relevant risks.Open
Secure System Developmentthe development and updating of a system or product, in conformance with agreed security requirements and standards, throughout its lifecycle.Pilot
Cyber Security Managementthe management of cyber security resources, staff and policies at an enterprise level in line with business objectives and regulatory requirements.Pilot

For the two marked Pilot: “Professional registration for this specialism is currently in the pilot phase and will be open to general applications in the near future.”

Where ISO 27001 work sits (our reading)

No specialism names ISO 27001. Building and running an ISMS is closest to Cyber Security Governance & Risk Management; auditing one is closest to Cyber Security Audit & Assurance; running the security function at enterprise level is Cyber Security Management.

The four professional titles

UK Cyber Security Council professional titles (descriptions quoted from the Council's title pages)
TitleThe Council says the holder
Associate Cyber Security Professional (ACSP)is either employed in an early career cyber role, or ready for their first role in cyber security
Practitioner Cyber Security Professional (PraCSP)operating at a level at which their professional expertise is being used effectively in their role
Principal Cyber Security Professional (PriCSP)will have practical experience in a specific Specialism, at which they are an expert practitioner, and have experience in other Specialisms
Chartered Cyber Security Professional (ChCSP)should have a particular Specialism at which they are an acknowledged expert

Specialised or not

Titles are awarded in a specialism, “other than Associate, which is unspecialised”. So a Practitioner, Principal or Chartered title tells you which kind of work the person was assessed in.

How the title is awarded

“When applying for a professional title, you’ll need to demonstrate that your knowledge and expertise align with our Standard for Professional Competence and Commitment and agree to abide by our code of ethics.” “We have a number of approved Licensed Bodies who handle your application and recommend to us whether you should be awarded a professional title.”

NCSC assurance for advisers

Separate from the Council's register, the NCSC assures individual Cyber Advisors for small and medium-sized organisations. “The focus of that advice and support is on the implementation of the technical controls set out in Cyber Essentials.” Each has passed an independent assessment of:

What an NCSC Cyber Advisor's assessment measured (verbatim)
Assessed
knowledge and understanding of the Cyber Essentials’ technical controls
competence in providing practical, hands-on support
ability to understand and work with small and medium sized organisations.

The NCSC's other schemes, including Assured Cyber Security Consultancy for high-risk organisations, are on NCSC assured cyber security consultancy.

Matching the credential to the job (our reading)

Which specialism and evidence fit which job (our reading)
The jobClosest UKCSC specialismAlso look for
Implementing an ISMS to ISO 27001Cyber Security Governance & Risk ManagementISO 27001 implementation experience; a lead implementer certificate is one kind of evidence
Getting audit-ready, or an internal auditCyber Security Audit & AssuranceIndependence from the work being audited
Architecture or product securitySecure System Architecture & Design; Secure System DevelopmentKnowledge of your technology stack
Penetration testingSecurity TestingFor public sector or CNI: the NCSC CHECK scheme
Incident readinessIncident ResponseNCSC Cyber Incident Response or Exercising schemes
A small business starting on Cyber Essentials—An NCSC Cyber Advisor

ISO 27001 personnel certificates

Lead implementer and lead auditor certificates are issued to individuals by personnel certification schemes; they are not the same as the Council's titles or the NCSC's assurance. Their requirements are on the lead auditor page.

What to ask

Which specialism the person works in, what evidence backs it (a title, an assurance scheme, a certificate, named past engagements), and whether their firm has any relationship with your certification body.

We do not consult, audit or certify, and are paid the same fixed fee per enquiry whichever firm you use. Definitions are quoted from the UK Cyber Security Council, the NCSC and ISO/IEC 17021-1; the matching tables are our reading.

Where this fits

Common questions

What does an information security consultant do?

Helps an organisation design, implement or improve how it protects information. Where the work is on a management system such as ISO 27001, ISO/IEC 17021-1 defines consultancy as “participation in establishing, implementing or maintaining a management system”, with examples such as “Preparing or producing manuals or procedures.”

What does an ISO 27001 consultant do?

Typically: helps set the scope, runs or facilitates the risk assessment, drafts the policies and the Statement of Applicability, prepares the organisation for its certification audit, and sometimes carries out the internal audit. Decisions that the standard puts on top management, such as accepting risks and reviewing the system, stay with you.

Is there a professional register for cyber security consultants in the UK?

Yes. “The UK Cyber Security Council awards four professional titles (Associate, Practitioner, Principal and Chartered)”. Registration is in eight specialisms, and applications are handled by Licensed Bodies: “We have a number of approved Licensed Bodies who handle your application and recommend to us whether you should be awarded a professional title.”

What is a Chartered Cyber Security Professional?

The highest of the UK Cyber Security Council's four titles (ChCSP). The Council says a Chartered professional “should have a particular Specialism at which they are an acknowledged expert”.

Which specialism covers ISO 27001 work?

The Council's specialisms do not name ISO 27001. The closest fit, in our reading, is Cyber Security Governance & Risk Management — “the monitoring of compliance with agreed cyber security policies and the assessment and management of relevant risks.” — with Cyber Security Audit & Assurance for audit work.

Is an NCSC Cyber Advisor an information security consultant?

An NCSC-assured adviser for small and medium-sized organisations. “The focus of that advice and support is on the implementation of the technical controls set out in Cyber Essentials.” For ISO 27001 implementation you would look for ISMS experience as well.

How much does an information security consultant cost?

No official rate exists. Our estimate for ISO 27001 consultancy in the UK is £600–£1,200 a day; it is an estimate, not a published figure. The cost page shows how it adds up.

Sources cited on this page

  1. UK Cyber Security Council, Become Professionally Registered
  2. UK Cyber Security Council, Professional titles (ACSP, PraCSP, PriCSP, ChCSP)
  3. UK Cyber Security Council, Cyber Security Specialisms
  4. NCSC, Cyber Advisor scheme
  5. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  6. ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Looking for ISO 27001 help?

Say what needs doing, your size, and any deadline a customer has set.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now