iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 Consultants, UK

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 10 min read
5 primary sources cited on this page. How we check what is on this site
The limit on what any of them can sell you Consultancy and certification cannot be the same firm

BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.5: a certification body “shall not offer or provide management system consultancy”. A consultant gets you ready. Only an accredited certification body issues the certificate. If one supplier is offering both, something is wrong with one of the offers.

This page is about the second of the two suppliers you will need, what the work actually consists of, and what it costs. It does not contain a list of consultancies or a ranking of them, for reasons set out below.

The three roles in ISO 27001 certification and the rule separating them Three boxes: UKAS accredits certification bodies; certification bodies audit and certify you; consultancies help you prepare. A crossed line between certification body and consultancy marks the bar in ISO/IEC 17021-1 clause 5.2.5. A footer notes that this site is none of the three. Accreditation body UKAS Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1 Issues no certificates to you Certification body Audits you Runs Stage 1 and Stage 2 Issues your certificate Surveillance every year Cannot consult for you Consultancy Helps you get ready Gap analysis, risk assessment Statement of Applicability Internal audit support Cannot certify you accredits barred by 17021-1 cl. 5.2.5 iso27001partners.co.uk is none of these three. We publish the rules and the arithmetic, and sell advertising to consultancies at a fixed fee per enquiry. We cannot audit, certify or accredit anything.
The body that audits you is barred from selling you the help to get ready. That is a requirement of the standard its accreditation is granted against, not a market convention.
The same diagram as a table
Who does what, and what each one is barred from doing
RoleDoesCannot do
Accreditation body (UKAS)Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1Issue you a certificate
Certification bodyStage 1, Stage 2, annual surveillance, issues the certificateProvide management system consultancy to you (clause 5.2.5)
ConsultancyGap analysis, risk assessment, Statement of Applicability, internal audit supportIssue or influence a certificate
This sitePublishes the rules and the cost arithmetic; sells advertisingAudit, certify, accredit or advise

What a consultant can and cannot do

The division of labour, and the rule behind it
TaskA consultant?Note
Run a gap analysis against clauses 4 to 10 and Annex AYes
Facilitate your risk assessment and risk treatmentYes
Draft the documented information clause 7.5 requiresYes
Help build the Statement of ApplicabilityYesThe justifications have to reflect your decisions, not a template’s
Carry out your clause 9.2 internal auditYes, if independent enough of what they builtYour certification body cannot — clause 5.2.6
Sit with you through Stage 1 and Stage 2Yes
Issue or arrange your certificateNoOnly an accredited certification body issues certificates
Shorten the auditNoAudit days come from ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
Guarantee certificationNoNobody outside the certification body decides the outcome
Hold your management reviewNoClause 9.3 is your management’s, and minutes are the evidence

The three “no” rows at the bottom are the ones worth reading twice, because all three are sometimes implied in sales conversations. Nobody outside the certification body decides whether you are certified. Nobody shortens the audit, because the day count comes from ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21) and is a function of your headcount and complexity. And the management review in clause 9.3 is your management’s meeting — a consultant can prepare the pack and cannot hold it for you.

The question to ask both firms, before engaging either

“What is the relationship between your firm and the certification body?” Under BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.7, consultancy from a body related to your certification body can bar that body from certifying you for 2 years. It costs nothing to ask and it is not a rude question — a good firm will have a clear answer ready.

What an engagement costs

For a 25-person scope our estimate is £6,000–£26,400 for a consultant-led build, or roughly 10 to 22 consultant days. That is an estimate and the day rates behind it are named on the methodology page.

The certification audit sits on top and is the same whoever prepares you: 7 days at that size, £7,700–£10,500. That is the single most useful thing to know before taking quotes, because it means the whole of the difference between a cheap proposal and an expensive one is in preparation, and preparation is comparable if you ask for it in days rather than in pounds.

Three ways to prepare for ISO 27001, priced side by side Three horizontal cost ranges: a documentation toolkit, a consultant-led engagement, and a compliance platform with support services. A note records that the toolkit route hides your own staff time and the platform route hides an unpublished subscription. Getting ready: three routes, 25 people in scope The certification audit itself is the same price on all three routes — £7,700 to £10,500 — because the day count is set by the table, not by how you prepared. Toolkit Your own people do the work £95–£1,500 Consultant-led 10–22 days bought in £6,000–£26,400 Platform + help Services only — no subscription £3,600–£18,500 What the bars do not show Toolkit: your own people’s time, which is the largest cost on that route and the one nobody prices. Platform: the subscription. No major compliance platform publishes a price, so this figure is the services only.
Whichever route you take, the certification audit costs the same. The day count comes from the published table and no amount of preparation changes it.
The same diagram as a table
Preparation cost by route, 25 people in scope. Estimates.
RouteLowHighWhat is in it
Toolkit£95£1,500Your own people do the work
Consultant-led£6,000£26,40010–22 days bought in
Platform + help£3,600£18,500Services only — no subscription

All three then pay the same certification audit fee, because audit days are set by ISO/IEC 27006-1:2024 Table C.1 and not by how the management system was built.

The three routes compared covers when a consultant is and is not the right answer, and the calculator runs the arithmetic for your headcount.

By sector: what sits on top of the certificate

ISO 27001 rarely arrives on its own. What triggered it usually brings a second requirement, and in three of these four sectors the certificate does not satisfy that second requirement. Each page below is built on a different primary source.

Where ISO 27001 sits in each sector's requirements
SectorWhat usually triggers itThe rule that sits alongside
Saas and cloud businessesAn enterprise customer put it in a renewal, or a security questionnaire came back with it flagged.The standard itself — scope, A.5.23 and SOC 2 overlap
Nhs and healthcare suppliersAn NHS trust or an NHS framework asked for security assurance, and the requirement named more than one thing.NHS Data Security and Protection Toolkit
Public sector suppliersA tender, a framework application, or a contract renewal.PPN 014 and the “or equivalent” question
Financial services firmsA client's third-party risk assessment, a regulator's expectations, or a parent company requiring it.FCA operational resilience

Three of those four pages tell you that ISO 27001 will not, by itself, satisfy the requirement you are trying to meet. We are paid a fixed fee per enquiry by ISO 27001 consultancies and that fee does not change with what we publish, which is the only reason those pages can say so.

Why there is no list of consultancies on this page

It would be the obvious page to build and it would be the wrong one.

There is no register of ISO 27001 consultants in the UK, no licence to practise and no statutory qualification. Anyone may use the title. So a ranking would be assembled from self-reported information, testimonials we cannot verify and our own impressions — and presented with an authority none of that supports. Ranking suppliers we have no data about is precisely what this site is built not to do.

What we can offer instead: the questions that separate a good engagement from a bad one, the arithmetic that tells you whether a proposal is sensibly sized, and an enquiry form that puts your actual scope in front of firms advertising for your sector. You decide who, if anyone, you speak to.

The four questions worth asking every firm

  1. What will we be left with? An ISMS built for you rather than with you tends to fail its first surveillance audit, because the people who have to operate it were never in the room.
  2. Who does our internal audit in year two? Clause 9.2 requires one every year and your certification body is barred from it. If the answer is “us”, ask how they stay independent of what they built.
  3. What is your relationship with the certification body? Clause 5.2.7 again.
  4. Can we speak to a client of our size, in our sector? With no register and no credential that means much, references are the strongest available signal, and any established firm will have them.

Where to go next

Common questions

What does an ISO 27001 consultant actually do?

The work between deciding to certify and being ready to be audited: a gap analysis, scope, facilitating the risk assessment and risk treatment, drafting the documented information, building the Statement of Applicability, and often the internal audit clause 9.2 requires. What none of them can do is issue a certificate, shorten the audit or guarantee the outcome. The certificate comes from an accredited certification body, and the audit length comes from a published table — ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21).

Can the same firm prepare us and certify us?

No. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.5 states that a certification body “shall not offer or provide management system consultancy”. Clause 5.2.7 goes further: where a client has taken consultancy from a body related to a certification body, that body must not certify the management system for at least 2 years. So a single supplier offering both is either not what it appears, or is creating a problem for you. Ask both firms what their relationship is, before engaging either.

What does an ISO 27001 consultant cost in the UK?

Our estimate for a 25-person scope is around £6,000–£26,400 for a consultant-led build, which is roughly 10 to 22 consultant days. That is an estimate and it is shown as a range; the day-rate band behind it is published on our methodology page. The certification audit is separate and is the same whoever prepares you, because the day count is set by the published table rather than by the route you took.

Do we need a consultant at all?

No, and plenty of organisations certify without one. Under about fifteen people, with a technical team and somebody who has the time and the temperament for the documentation, a toolkit plus a couple of days of review is frequently enough. Where a consultant earns their fee is a tight deadline, a complex or multi-site scope, a regulated sector, or a team that has never operated a management system and would otherwise learn what a Statement of Applicability is during Stage 1.

How do you choose one?

We do not publish a ranking, because we hold no data that would justify one and any list would be stale within months. Three questions do more work than any badge. What will you leave us with, so our own people can run this after you have gone? Who does our internal audit in year two, given our certification body cannot? And what is your relationship, if any, with the certification body you are suggesting?

Do you vet the consultancies you send enquiries to?

No, and we say so plainly rather than implying otherwise. We do not rank, score or independently vet firms and we do not attempt to match an enquiry to the “right” one. Your enquiry goes to consultancies advertising for your sector and you decide who, if anyone, you speak to. Because our fee is a fixed amount per enquiry rather than a share of what a firm earns, we have nothing to gain from steering you.

What should we have ready before the first call?

Four things, and they take an hour rather than a week. Roughly how many people would be inside the scope — which decides the audit band and therefore most of the cost. What triggered this, because a named customer or a tender sets the deadline. Whether any date is contractual. And what already exists, honestly. A consultancy given those four can give you a real answer on the first call instead of booking a second one.

Is a consultant regulated or certified in some way?

No. There is no licence to practise, no register and no statutory qualification for ISO 27001 consultancy in the UK, and anyone can use the title. Individual auditors working for certification bodies are assessed as part of that body's accreditation, but that is a different role. Practical consequence: references from organisations of your size and sector are worth more than any credential on a website, and asking for them is normal.

Sources cited on this page

  1. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  2. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
  3. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
  4. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
  5. The Accreditation Regulations 2009 (SI 2009/3155), regulation 3

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Get a costed answer, not a call-back to discuss pricing

Five questions, all of them click-only. Your details are the last step, never the first.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now