ISO 27001 Consultants, UK
BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.5: a certification body “shall not offer or provide management system consultancy”. A consultant gets you ready. Only an accredited certification body issues the certificate. If one supplier is offering both, something is wrong with one of the offers.
This page is about the second of the two suppliers you will need, what the work actually consists of, and what it costs. It does not contain a list of consultancies or a ranking of them, for reasons set out below.
The same diagram as a table
| Role | Does | Cannot do |
|---|---|---|
| Accreditation body (UKAS) | Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1 | Issue you a certificate |
| Certification body | Stage 1, Stage 2, annual surveillance, issues the certificate | Provide management system consultancy to you (clause 5.2.5) |
| Consultancy | Gap analysis, risk assessment, Statement of Applicability, internal audit support | Issue or influence a certificate |
| This site | Publishes the rules and the cost arithmetic; sells advertising | Audit, certify, accredit or advise |
What a consultant can and cannot do
| Task | A consultant? | Note |
|---|---|---|
| Run a gap analysis against clauses 4 to 10 and Annex A | Yes | — |
| Facilitate your risk assessment and risk treatment | Yes | — |
| Draft the documented information clause 7.5 requires | Yes | — |
| Help build the Statement of Applicability | Yes | The justifications have to reflect your decisions, not a template’s |
| Carry out your clause 9.2 internal audit | Yes, if independent enough of what they built | Your certification body cannot — clause 5.2.6 |
| Sit with you through Stage 1 and Stage 2 | Yes | — |
| Issue or arrange your certificate | No | Only an accredited certification body issues certificates |
| Shorten the audit | No | Audit days come from ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21) |
| Guarantee certification | No | Nobody outside the certification body decides the outcome |
| Hold your management review | No | Clause 9.3 is your management’s, and minutes are the evidence |
The three “no” rows at the bottom are the ones worth reading twice, because all three are sometimes implied in sales conversations. Nobody outside the certification body decides whether you are certified. Nobody shortens the audit, because the day count comes from ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21) and is a function of your headcount and complexity. And the management review in clause 9.3 is your management’s meeting — a consultant can prepare the pack and cannot hold it for you.
The question to ask both firms, before engaging either
“What is the relationship between your firm and the certification body?” Under BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.7, consultancy from a body related to your certification body can bar that body from certifying you for 2 years. It costs nothing to ask and it is not a rude question — a good firm will have a clear answer ready.
What an engagement costs
For a 25-person scope our estimate is £6,000–£26,400 for a consultant-led build, or roughly 10 to 22 consultant days. That is an estimate and the day rates behind it are named on the methodology page.
The certification audit sits on top and is the same whoever prepares you: 7 days at that size, £7,700–£10,500. That is the single most useful thing to know before taking quotes, because it means the whole of the difference between a cheap proposal and an expensive one is in preparation, and preparation is comparable if you ask for it in days rather than in pounds.
The same diagram as a table
| Route | Low | High | What is in it |
|---|---|---|---|
| Toolkit | £95 | £1,500 | Your own people do the work |
| Consultant-led | £6,000 | £26,400 | 10–22 days bought in |
| Platform + help | £3,600 | £18,500 | Services only — no subscription |
All three then pay the same certification audit fee, because audit days are set by ISO/IEC 27006-1:2024 Table C.1 and not by how the management system was built.
The three routes compared covers when a consultant is and is not the right answer, and the calculator runs the arithmetic for your headcount.
By sector: what sits on top of the certificate
ISO 27001 rarely arrives on its own. What triggered it usually brings a second requirement, and in three of these four sectors the certificate does not satisfy that second requirement. Each page below is built on a different primary source.
| Sector | What usually triggers it | The rule that sits alongside |
|---|---|---|
| Saas and cloud businesses | An enterprise customer put it in a renewal, or a security questionnaire came back with it flagged. | The standard itself — scope, A.5.23 and SOC 2 overlap |
| Nhs and healthcare suppliers | An NHS trust or an NHS framework asked for security assurance, and the requirement named more than one thing. | NHS Data Security and Protection Toolkit |
| Public sector suppliers | A tender, a framework application, or a contract renewal. | PPN 014 and the “or equivalent” question |
| Financial services firms | A client's third-party risk assessment, a regulator's expectations, or a parent company requiring it. | FCA operational resilience |
Three of those four pages tell you that ISO 27001 will not, by itself, satisfy the requirement you are trying to meet. We are paid a fixed fee per enquiry by ISO 27001 consultancies and that fee does not change with what we publish, which is the only reason those pages can say so.
Why there is no list of consultancies on this page
It would be the obvious page to build and it would be the wrong one.
There is no register of ISO 27001 consultants in the UK, no licence to practise and no statutory qualification. Anyone may use the title. So a ranking would be assembled from self-reported information, testimonials we cannot verify and our own impressions — and presented with an authority none of that supports. Ranking suppliers we have no data about is precisely what this site is built not to do.
What we can offer instead: the questions that separate a good engagement from a bad one, the arithmetic that tells you whether a proposal is sensibly sized, and an enquiry form that puts your actual scope in front of firms advertising for your sector. You decide who, if anyone, you speak to.
The four questions worth asking every firm
- What will we be left with? An ISMS built for you rather than with you tends to fail its first surveillance audit, because the people who have to operate it were never in the room.
- Who does our internal audit in year two? Clause 9.2 requires one every year and your certification body is barred from it. If the answer is “us”, ask how they stay independent of what they built.
- What is your relationship with the certification body? Clause 5.2.7 again.
- Can we speak to a client of our size, in our sector? With no register and no credential that means much, references are the strongest available signal, and any established firm will have them.
Where to go next
Common questions
What does an ISO 27001 consultant actually do?
The work between deciding to certify and being ready to be audited: a gap analysis, scope, facilitating the risk assessment and risk treatment, drafting the documented information, building the Statement of Applicability, and often the internal audit clause 9.2 requires. What none of them can do is issue a certificate, shorten the audit or guarantee the outcome. The certificate comes from an accredited certification body, and the audit length comes from a published table — ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21).
Can the same firm prepare us and certify us?
No. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.5 states that a certification body “shall not offer or provide management system consultancy”. Clause 5.2.7 goes further: where a client has taken consultancy from a body related to a certification body, that body must not certify the management system for at least 2 years. So a single supplier offering both is either not what it appears, or is creating a problem for you. Ask both firms what their relationship is, before engaging either.
What does an ISO 27001 consultant cost in the UK?
Our estimate for a 25-person scope is around £6,000–£26,400 for a consultant-led build, which is roughly 10 to 22 consultant days. That is an estimate and it is shown as a range; the day-rate band behind it is published on our methodology page. The certification audit is separate and is the same whoever prepares you, because the day count is set by the published table rather than by the route you took.
Do we need a consultant at all?
No, and plenty of organisations certify without one. Under about fifteen people, with a technical team and somebody who has the time and the temperament for the documentation, a toolkit plus a couple of days of review is frequently enough. Where a consultant earns their fee is a tight deadline, a complex or multi-site scope, a regulated sector, or a team that has never operated a management system and would otherwise learn what a Statement of Applicability is during Stage 1.
How do you choose one?
We do not publish a ranking, because we hold no data that would justify one and any list would be stale within months. Three questions do more work than any badge. What will you leave us with, so our own people can run this after you have gone? Who does our internal audit in year two, given our certification body cannot? And what is your relationship, if any, with the certification body you are suggesting?
Do you vet the consultancies you send enquiries to?
No, and we say so plainly rather than implying otherwise. We do not rank, score or independently vet firms and we do not attempt to match an enquiry to the “right” one. Your enquiry goes to consultancies advertising for your sector and you decide who, if anyone, you speak to. Because our fee is a fixed amount per enquiry rather than a share of what a firm earns, we have nothing to gain from steering you.
What should we have ready before the first call?
Four things, and they take an hour rather than a week. Roughly how many people would be inside the scope — which decides the audit band and therefore most of the cost. What triggered this, because a named customer or a tender sets the deadline. Whether any date is contractual. And what already exists, honestly. A consultancy given those four can give you a real answer on the first call instead of booking a second one.
Is a consultant regulated or certified in some way?
No. There is no licence to practise, no register and no statutory qualification for ISO 27001 consultancy in the UK, and anyone can use the title. Individual auditors working for certification bodies are assessed as part of that body's accreditation, but that is a different role. Practical consequence: references from organisations of your size and sector are worth more than any credential on a website, and asking for them is normal.
Sources cited on this page
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
- ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- The Accreditation Regulations 2009 (SI 2009/3155), regulation 3
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Get a costed answer, not a call-back to discuss pricing
Five questions, all of them click-only. Your details are the last step, never the first.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.