iso27001partnersUK certification, costed Get a cost estimate

Toolkit, consultant or platform: the three routes, priced

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 10 min read
4 primary sources cited on this page. How we check what is on this site
Before anything else The audit costs the same on all three

Audit days come from your headcount and complexity under ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21), not from how you prepared. So the entire price difference between these routes sits in getting ready — which is also the part with no published rule behind it.

This comparison is difficult to find anywhere neutral, for a structural reason. The version published by a toolkit vendor finds for the toolkit. The version published by a compliance platform finds for the platform. Both are perfectly honest about their weaknesses in the places where being honest costs them nothing.

We sell none of the three. Consultancies pay us a fixed fee per enquiry, agreed in advance, and it does not change with which route you choose, how large the engagement is, or whether you go ahead at all. If this page persuades you to buy a toolkit and spend nothing else, our revenue is identical.

Three ways to prepare for ISO 27001, priced side by side Three horizontal cost ranges: a documentation toolkit, a consultant-led engagement, and a compliance platform with support services. A note records that the toolkit route hides your own staff time and the platform route hides an unpublished subscription. Getting ready: three routes, 25 people in scope The certification audit itself is the same price on all three routes — £7,700 to £10,500 — because the day count is set by the table, not by how you prepared. Toolkit Your own people do the work £95–£1,500 Consultant-led 10–22 days bought in £6,000–£26,400 Platform + help Services only — no subscription £3,600–£18,500 What the bars do not show Toolkit: your own people’s time, which is the largest cost on that route and the one nobody prices. Platform: the subscription. No major compliance platform publishes a price, so this figure is the services only.
Whichever route you take, the certification audit costs the same. The day count comes from the published table and no amount of preparation changes it.
The same diagram as a table
Preparation cost by route, 25 people in scope. Estimates.
RouteLowHighWhat is in it
Toolkit£95£1,500Your own people do the work
Consultant-led£6,000£26,40010–22 days bought in
Platform + help£3,600£18,500Services only — no subscription

All three then pay the same certification audit fee, because audit days are set by ISO/IEC 27006-1:2024 Table C.1 and not by how the management system was built.

What each route costs, at four sizes

Single site, no adjusting factors. The last column is the same on every row of a given size, which is the point.

Preparation cost by route and size. Estimates; the audit column is days × a rate band.
ScopeToolkitConsultant-ledPlatform servicesCertification audit (all routes)
12 people£95–£1,500£6,000–£26,400£3,600–£18,500£6,600–£9,000
25 people£95–£1,500£6,000–£26,400£3,600–£18,500£7,700–£10,500
80 people£95–£1,500£12,000–£54,000£7,200–£37,800£12,100–£16,500
200 people£95–£1,500£18,000–£78,000£10,800–£54,600£15,400–£21,000

The platform column is professional services only. No major compliance platform publishes a subscription price, so there is no figure to add. Over three years that missing line is frequently the largest in the exercise. How these are calculated.

Good at, weak at

Documentation toolkit

A set of policies, procedures and templates you buy once and adapt. Outlay is the smallest of the three by a wide margin.

Good at

  • Cheapest outlay by an order of magnitude
  • You keep everything and can reuse it
  • Forces your own people to understand the system they will have to operate
  • No ongoing licence

Weak at

  • Your staff time is the real cost and nobody prices it
  • A generic Statement of Applicability is visible to an auditor as a generic Statement of Applicability
  • No help when Stage 1 produces a finding you do not understand
  • Needs at least one person with the time and the temperament for this

Consultant-led

A consultancy runs the build with you: scope, risk assessment, Statement of Applicability, documentation, internal audit support.

Good at

  • Fastest route for a team with no management system experience
  • The Statement of Applicability reflects your actual risk, because somebody interviewed you
  • Somebody who has sat through Stage 2 before is in the room when you do
  • Internal audit can be bought from them — it cannot be bought from your certification body

Weak at

  • Most expensive route
  • Knowledge can leave with them unless the engagement is structured to prevent it
  • Quality varies enormously and there is no register to check anyone against
  • An ISMS built for you rather than with you fails its first surveillance audit

Compliance platform

Software that maps controls, collects evidence from your systems automatically and tracks the state of the management system.

Good at

  • Evidence collection is genuinely automated, and evidence collection is genuinely tedious
  • Continuous rather than annual, which suits the surveillance cycle
  • Good when you will also need SOC 2 or other frameworks — controls are reused
  • Keeps the ISMS visible between audits, which is when most of them quietly stop

Weak at

  • No major platform publishes a price, so it cannot be compared before a sales call
  • It cannot decide your scope, write your risk treatment or hold your management review
  • A subscription is permanent and usually exceeds the one-off saving within three years
  • A platform full of evidence against a scope nobody thought about is still a Stage 1 finding

And what this site is worse at than any of them

We have never implemented a management system, never sat on either side of a Stage 2 audit, and cannot tell you whether a particular control will satisfy a particular auditor. Everything here is read out of published rules and checked against its source, which is a genuine strength for questions about what the rules require and no substitute at all for somebody who has done the work. A toolkit vendor and a consultancy both know things about the texture of this that we do not.

Which route, for which situation

A starting point, not a rule
If this is youUsuallyWhy
Under about 15 people, technical team, time availableToolkit, plus a few days of reviewThe work is genuinely doable in-house at this size, and the audit is the smallest band in the table. Buy a day or two of consultant time to review the Statement of Applicability rather than the whole engagement.
A tender deadline inside three monthsConsultant-ledThis is the case where the expensive route is the cheap one. The constraint is clause 9.2 and 9.3 and the certification body's waiting list, and somebody who has done it before sequences around both.
You will need SOC 2 or other frameworks as wellPlatform, plus servicesControl reuse across frameworks is the strongest argument for a platform and the one case where the subscription pays for itself on arithmetic rather than convenience.
Already certified, keeping it aliveToolkit or platform, plus bought-in internal auditThe expensive part of year two onwards is the annual internal audit you cannot get from your certification body.
Regulated, or certifying a complex multi-site scopeConsultant-ledScope design is where the money is made or lost here, the multi-site sampling rule bites, and it is the least suitable decision to take from a template.

The cost that decides it, and nobody publishes

Comparing a one-off consultancy fee against a platform subscription is comparing two different shapes of number, and the shape matters more than the size.

A consultant-led build at 25 people lands somewhere around £6,000–£26,400 once, and then the knowledge either stays with your people or it does not. A platform is a subscription that renews for as long as you hold the certificate — at minimum three years to the first recertification, and realistically for as long as the customer who asked for the certificate remains a customer.

We cannot tell you where the crossover is, because the input is not published. What we can tell you is what to ask on the sales call: the three-year total, in writing, including renewal uplift. A platform that will not put that in an email before a trial is telling you something.

The question that applies to all three routes

“Who does our internal audit in year two?” Clause 9.2 requires one every year, and BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.6 bars your certification body from doing it. Toolkits do not do it, platforms do not do it, and a consultancy that built your ISMS needs to think about whether it is independent enough of the thing it is auditing. It is the recurring cost that surprises people in year two, and asking about it in year zero costs nothing.

Mixing them is normal

These are archetypes for comparing costs, not products anyone has to buy whole. The shape that turns up most often in practice is a toolkit for the documented information, a small number of consultant days spent on the scope and the risk assessment — the two decisions that are genuinely hard to take from a template and the two that cost the most to get wrong — and bought-in internal audit from year two.

That combination is not in any vendor's comparison table, for the obvious reason.

Where to go next

Common questions

Does the route I choose change the audit fee?

No, and this is the most useful thing on this page. Audit days are a function of your headcount, sites and complexity under ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21). They are not a function of how the management system was built or who built it. Everyone pays the same for the audit, so the entire price difference between the three routes is in preparation.

Why is there no price for compliance platforms here?

Because none of them publishes one. We report that as a finding rather than filling it with a guess: the figures in the platform column are the professional services only. It matters more than it sounds, because a subscription is permanent. Over the three years the certificate is valid, the subscription is frequently the largest single line in the whole exercise, and it is the one you cannot compare before booking a sales call.

Can a platform get us certified on its own?

No. A platform cannot decide your scope, cannot write your risk treatment, cannot hold your management review and cannot be your certification body. What it does well is the part that is tedious rather than difficult: collecting evidence from your systems on a schedule and showing you what is missing. That is real value, and it is roughly a third of the work rather than all of it.

Is a toolkit just templates we could write ourselves?

In principle yes, and in practice the value is structure rather than prose — knowing which documents the standard actually expects to exist and which it does not. The risk is shipping the templates as written. An auditor who reads Statements of Applicability for a living recognises an unmodified one immediately, and it invites exactly the questions you least want at Stage 2.

How do we tell a good consultancy from a bad one?

There is no register and no rating that would survive scrutiny, so we do not publish one. Three questions do more work than any badge. First: what will you leave us with that lets our own people run this after you have gone? Second: who will do our internal audit in year two, given our certification body cannot? Third: what is your relationship, if any, with the certification body you are suggesting — because under BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.7, consultancy from a related body can bar that body from certifying you for 2 years.

Can we mix the routes?

Most organisations do, and it is usually the right answer. A common shape is a toolkit for the documentation, a handful of consultant days for scope and the risk assessment, and bought-in internal audit from year two. The routes in this table are archetypes for comparing costs, not packages anyone has to buy whole.

What does this site get paid for each route?

The same fixed amount per enquiry, agreed in advance, whichever route you pick and whichever consultancy receives it. We have no commercial relationship with any toolkit vendor or platform, and no revenue changes if this page persuades you to buy a toolkit and spend nothing else.

Sources cited on this page

  1. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
  2. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
  3. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  4. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Get all three routes priced for your scope

The last question asks which route you are leaning towards. “Not decided” is the most common answer and the most useful one.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now