Information security consultant: what the role covers and the UK credentials behind it
“The UK Cyber Security Council awards four professional titles (Associate, Practitioner, Principal and Chartered)” — UK Cyber Security Council.
“Information security consultant” is not a protected title. It covers people who write ISO 27001 policies, people who test networks and people who design architectures. This page separates the work, shows the UK's professional register for it, and gives a way to match the credential to the job you actually need done.
What counts as consultancy
For management systems, the accreditation standard for certification bodies gives a definition: “participation in establishing, implementing or maintaining a management system”. Its examples:
| Example |
|---|
| Preparing or producing manuals or procedures. |
| Giving specific advice, instructions or solutions towards the development and implementation of a management system. |
That definition matters because of what follows from it: a certification body cannot also provide it, and a consultancy related to your certification body can stop that body certifying you for two years. The detail is on the ISO 27001 consultants page.
What an ISO 27001 consultant does, clause by clause
ISO/IEC 27001:2022 is built from clauses 4 to 10. The work a consultant can take on, and the decisions that stay with you, differ by clause:
| Clause | Title | A consultant may | Stays with you |
|---|---|---|---|
| 4 | Context of the organisation | Workshops on issues and interested parties; drafting the scope | Deciding the scope |
| 5 | Leadership | Drafting the policy and the roles | Top management's commitment and sign-off |
| 6 | Planning | A risk assessment method, facilitating the assessment, drafting the Statement of Applicability | Accepting the risks and approving the treatment plan |
| 7 | Support | Awareness material, document templates, a competence record | Resources and people |
| 8 | Operation | Advice on running the controls | Running them |
| 9 | Performance evaluation | An internal audit, if independent of the work audited | The management review |
| 10 | Improvement | A corrective action process | Fixing what is found |
Why some things cannot be handed over
Clause 5 places leadership duties on top management, and the management review is “Top management shall review the organization’s [information security] management system, at planned intervals, to ensure its continuing suitability, adequacy and effectiveness.” in the common text the standard applies. A consultant can prepare those; the auditor will look for your management's own decisions. See management review.
The internal audit
A consultant can carry out your internal audit, but not one of their own work if the audit is to be objective. The rules are on the internal audit page.
The eight specialisms
The UK Cyber Security Council has “contextualised” its Standard for Professional Competence and Commitment for eight specialisms. Its definitions:
| Specialism | Definition | Registration |
|---|---|---|
| Cyber Security Audit & Assurance | The verification of evidence that systems and processes meet the specified security requirements and that processes are in place to check on-going compliance | Open |
| Security Testing | Testing the vulnerabilities of a network, system, product or design against the specified security requirements. Sometimes also known as penetration testing. | Open |
| Secure System Architecture & Design | the designing of an IT system to meet its security requirements, balancing this with its functional requirements. | Open |
| Secure Operations | The management of an organisation’s information systems operations in accordance with the agreed security requirements. | Open |
| Incident Response | the preparation for, handling of and following up of cyber security incidents, to minimise the damage to an organisation and prevent recurrence. | Open |
| Cyber Security Governance & Risk Management | the monitoring of compliance with agreed cyber security policies and the assessment and management of relevant risks. | Open |
| Secure System Development | the development and updating of a system or product, in conformance with agreed security requirements and standards, throughout its lifecycle. | Pilot |
| Cyber Security Management | the management of cyber security resources, staff and policies at an enterprise level in line with business objectives and regulatory requirements. | Pilot |
For the two marked Pilot: “Professional registration for this specialism is currently in the pilot phase and will be open to general applications in the near future.”
Where ISO 27001 work sits (our reading)
No specialism names ISO 27001. Building and running an ISMS is closest to Cyber Security Governance & Risk Management; auditing one is closest to Cyber Security Audit & Assurance; running the security function at enterprise level is Cyber Security Management.
The four professional titles
| Title | The Council says the holder |
|---|---|
| Associate Cyber Security Professional (ACSP) | is either employed in an early career cyber role, or ready for their first role in cyber security |
| Practitioner Cyber Security Professional (PraCSP) | operating at a level at which their professional expertise is being used effectively in their role |
| Principal Cyber Security Professional (PriCSP) | will have practical experience in a specific Specialism, at which they are an expert practitioner, and have experience in other Specialisms |
| Chartered Cyber Security Professional (ChCSP) | should have a particular Specialism at which they are an acknowledged expert |
Specialised or not
Titles are awarded in a specialism, “other than Associate, which is unspecialised”. So a Practitioner, Principal or Chartered title tells you which kind of work the person was assessed in.
How the title is awarded
“When applying for a professional title, you’ll need to demonstrate that your knowledge and expertise align with our Standard for Professional Competence and Commitment and agree to abide by our code of ethics.” “We have a number of approved Licensed Bodies who handle your application and recommend to us whether you should be awarded a professional title.”
NCSC assurance for advisers
Separate from the Council's register, the NCSC assures individual Cyber Advisors for small and medium-sized organisations. “The focus of that advice and support is on the implementation of the technical controls set out in Cyber Essentials.” Each has passed an independent assessment of:
| Assessed |
|---|
| knowledge and understanding of the Cyber Essentials’ technical controls |
| competence in providing practical, hands-on support |
| ability to understand and work with small and medium sized organisations. |
The NCSC's other schemes, including Assured Cyber Security Consultancy for high-risk organisations, are on NCSC assured cyber security consultancy.
Matching the credential to the job (our reading)
| The job | Closest UKCSC specialism | Also look for |
|---|---|---|
| Implementing an ISMS to ISO 27001 | Cyber Security Governance & Risk Management | ISO 27001 implementation experience; a lead implementer certificate is one kind of evidence |
| Getting audit-ready, or an internal audit | Cyber Security Audit & Assurance | Independence from the work being audited |
| Architecture or product security | Secure System Architecture & Design; Secure System Development | Knowledge of your technology stack |
| Penetration testing | Security Testing | For public sector or CNI: the NCSC CHECK scheme |
| Incident readiness | Incident Response | NCSC Cyber Incident Response or Exercising schemes |
| A small business starting on Cyber Essentials | — | An NCSC Cyber Advisor |
ISO 27001 personnel certificates
Lead implementer and lead auditor certificates are issued to individuals by personnel certification schemes; they are not the same as the Council's titles or the NCSC's assurance. Their requirements are on the lead auditor page.
What to ask
Which specialism the person works in, what evidence backs it (a title, an assurance scheme, a certificate, named past engagements), and whether their firm has any relationship with your certification body.
We do not consult, audit or certify, and are paid the same fixed fee per enquiry whichever firm you use. Definitions are quoted from the UK Cyber Security Council, the NCSC and ISO/IEC 17021-1; the matching tables are our reading.
Where this fits
Common questions
What does an information security consultant do?
Helps an organisation design, implement or improve how it protects information. Where the work is on a management system such as ISO 27001, ISO/IEC 17021-1 defines consultancy as “participation in establishing, implementing or maintaining a management system”, with examples such as “Preparing or producing manuals or procedures.”
What does an ISO 27001 consultant do?
Typically: helps set the scope, runs or facilitates the risk assessment, drafts the policies and the Statement of Applicability, prepares the organisation for its certification audit, and sometimes carries out the internal audit. Decisions that the standard puts on top management, such as accepting risks and reviewing the system, stay with you.
Is there a professional register for cyber security consultants in the UK?
Yes. “The UK Cyber Security Council awards four professional titles (Associate, Practitioner, Principal and Chartered)”. Registration is in eight specialisms, and applications are handled by Licensed Bodies: “We have a number of approved Licensed Bodies who handle your application and recommend to us whether you should be awarded a professional title.”
What is a Chartered Cyber Security Professional?
The highest of the UK Cyber Security Council's four titles (ChCSP). The Council says a Chartered professional “should have a particular Specialism at which they are an acknowledged expert”.
Which specialism covers ISO 27001 work?
The Council's specialisms do not name ISO 27001. The closest fit, in our reading, is Cyber Security Governance & Risk Management — “the monitoring of compliance with agreed cyber security policies and the assessment and management of relevant risks.” — with Cyber Security Audit & Assurance for audit work.
Is an NCSC Cyber Advisor an information security consultant?
An NCSC-assured adviser for small and medium-sized organisations. “The focus of that advice and support is on the implementation of the technical controls set out in Cyber Essentials.” For ISO 27001 implementation you would look for ISMS experience as well.
How much does an information security consultant cost?
No official rate exists. Our estimate for ISO 27001 consultancy in the UK is £600–£1,200 a day; it is an estimate, not a published figure. The cost page shows how it adds up.
Sources cited on this page
- UK Cyber Security Council, Become Professionally Registered
- UK Cyber Security Council, Professional titles (ACSP, PraCSP, PriCSP, ChCSP)
- UK Cyber Security Council, Cyber Security Specialisms
- NCSC, Cyber Advisor scheme
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Looking for ISO 27001 help?
Say what needs doing, your size, and any deadline a customer has set.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.