Do You Need an ISO 27001 Consultant, or Just a Platform?
The decision is not consultant versus platform, because they solve different halves of the problem. A compliance platform automates evidence collection against technical controls and keeps it current; it does not define your ISMS scope under clause 4.3, run the risk assessment under clause 6.1.2, write defensible justifications into your Statement of Applicability under clause 6.1.3 d, perform the internal audit under clause 9.2, or chair the management review under clause 9.3. Those five items are the management system, and ISO 27001 certifies a management system. So the real question is whether anyone on your staff has built one before and whether you have a dated customer deadline; if the answer is no and yes, you are buying help, and if it is yes and no, you probably are not.
Below: what each option actually covers, the honest hybrid most small companies land on, the certification-body red flags that cost people real money, and the cases where you should hire nobody at all.
Key takeaways
- Platforms and consultants are complements, not substitutes. The platform owns evidence; the management system needs a human who has built one.
- The five management-system deliverables a platform cannot produce for you are scope, risk assessment, SoA justifications, internal audit and management review.
- We publish no third-party market range for ISO 27001, deliberately. The planning bands we do publish are our own, in the budget planner and the certification cost breakdown; for effort, use the audit days your certification body derives under ISO/IEC 27006-1.
- A certification body may not provide management system consultancy to the organizations it certifies. A single vendor offering both is a red flag, not a convenience. An independent consultant plus a separate accredited body is a different arrangement entirely, and it is the normal one.
- If nobody has asked for the certificate and you have no security owner, the right purchase this quarter is probably neither a platform nor a consultant.
What a platform genuinely does
Give the category its due, because the value is real. A modern compliance platform connects to your cloud accounts, identity provider, ticketing system and endpoint tooling, and continuously checks configuration against a control set. It stores evidence with timestamps, chases policy acknowledgments, tracks security training, keeps a vendor inventory, and gives you a dashboard your auditor can be pointed at.
For the technical half of Annex A that is genuine leverage, and it removes the single most tedious failure mode in a first certification: the control that operated but produced no record.
What it does not do is decide anything. The platform does not know that your risk assessment concluded a control was unnecessary, or why. It ships a template Statement of Applicability whose justifications are generic by construction, because the vendor has never seen your risk register. As of August 2026 the vendors in this category (Vanta, Drata, Secureframe and similar) publish a great deal of useful ISO 27001 guidance, and all of them sell the software, so read their framing of the consultant question with that in mind. Our piece on GRC platforms versus people works through where the automation boundary actually falls.
The five things the platform cannot do for you
Define the scope. Clause 4.3 asks you to determine the boundaries of the ISMS considering internal and external issues, interested parties and interfaces with other organizations. That is a judgment about your business, and it is the decision with the largest downstream effect on audit days, evidence workload and credibility with customers.
Run the risk assessment. Clause 6.1.2 requires a defined process with criteria, repeatability, named risk owners and results you can reproduce. A spreadsheet generated from a template fails the "repeatable" test the first time an auditor asks how a score was arrived at.
Justify the SoA. Clause 6.1.3 d wants a reason per control that traces to your risk assessment or a legal, regulatory or contractual requirement. Identical boilerplate across dozens of rows is the pattern auditors look for first.
Perform the internal audit. Clause 9.2 requires an internal audit programme and auditors who are objective and impartial with respect to what they audit. Software cannot supply impartiality, and neither can the person who built the ISMS. Our piece on outsourcing the ISO 27001 internal audit covers who is allowed to do it.
Hold the management review. Clause 9.3 requires top management to review the ISMS against defined inputs and produce decisions. This one takes a calendar invite and executive attention, and no vendor can buy either for you.
The hybrid most companies actually land on
In the engagements we see, the pattern that works is not either pole. It is a consultant or fractional security leader for the front end, a platform for the middle, and internal ownership for the long run.
The front end is scope, risk assessment methodology, risk treatment and the SoA, which is where experience compounds most and where mistakes are most expensive to unwind. The middle is evidence, policy distribution, training records and vendor inventory, which is where software is genuinely better than people. The long run is the annual cadence: internal audit, management review, risk reassessment, and the surveillance audits that follow. That last part has to be owned by someone who works there, or it decays, which is what surveillance auditors find.
The sequencing that fails is buying the platform first, working through its ISO checklist for four months, and then discovering at Stage 1 that the risk assessment and SoA do not trace to each other. The platform did exactly what it promised. It just cannot produce the artifact clause 6.1.3 asks for.
Certification body red flags worth real money
This section is buyer protection and it is the part nobody selling ISO 27001 leads with.
Check accreditation, not just the logo. A certificate is only as meaningful as the accreditation behind the body that issued it. Verify the body is accredited by a recognized accreditation body such as ANAB in the United States or UKAS in the United Kingdom, both signatories to the International Accreditation Forum multilateral arrangement, and check the certificate itself in IAF CertSearch. An unaccredited certificate is a PDF. Enterprise procurement teams increasingly check, and finding out at that point is expensive.
"Guaranteed certification" is a disqualifier. No accredited body can guarantee an outcome it has not audited, and any consultancy promising one is either not describing an accredited certificate or is describing a relationship that would fail impartiality requirements.
One vendor selling you both consulting and the certificate. ISO/IEC 17021-1 requires certification bodies to be impartial and prohibits them from providing management system consultancy to the organizations they certify. A single vendor offering to build and certify your ISMS is offering something that would compromise the certificate's value, and that is true regardless of how the packaging is worded. To be clear about what this does not cover: hiring an independent consultant and then engaging a separate accredited certification body is not the problem being described. That is the standard arrangement, and it is the one we recommend below.
Audit days well below what the others quoted. If one quote is dramatically cheaper, ask each body for the audit days it derived and the basis it derived them on under ISO/IEC 27006-1, including your effective number of personnel and the adjustments applied. Price differences that come from day rates are fine. Price differences that come from fewer days than the derivation supports are the accreditation problem arriving later.
What we deliberately do not tell you
We do not publish a third-party market range for ISO 27001, and that is a policy rather than an omission. Our ISO 27001 and SOC 2 comparison explains why: the ranges circulating for this framework are wide enough to mislead more than they inform, and a number quoted without your scope, headcount and starting posture is closer to marketing than to information. What we plan against is the shape of the effort, roughly 300 to 700 hours of internal staff time for a first ISO 27001 certification against 300 to 500 for a first SOC 2, our own planning figures rather than a survey, with the difference sitting almost entirely in the ISMS documentation.
For money, the planning bands we stand behind are our own and they are published in one place, the ISO 27001 certification cost breakdown, kept identical to the budget planner, which takes your own inputs. For audit fees specifically, the honest path is to ask two or three accredited bodies for their derived audit days and their day rate, which turns a guess into arithmetic you can check.
When to hire nobody
We sell this work, so weigh the following accordingly. Three situations where the right purchase is neither a consultant nor a platform.
Nobody has asked for the certificate. ISO 27001 is procurement-driven for most companies. If no prospect has requested it and none of your target accounts require it, a nine-month project is being bought against a hypothesis. Ask two prospects whether a certificate would change their answer. The response is worth more than any vendor's ROI calculator.
You have an experienced security lead and a patient timeline. ISO 27001 is a demanding standard but it is not a secret one. A capable lead with time, the standard itself and a certification body willing to answer scoping questions can get there. The first audit will be rougher and you will spend more internal hours, and if the deadline is soft that is a perfectly good trade.
Your gaps are engineering, not documentation. If access reviews do not happen and logs do not retain, no consultant and no platform changes the Stage 2 outcome. Fix the control, then certify. A consultancy that takes the engagement anyway is selling you a deferral you could have had for free.
Where Top Floor fits
Where we are worth hiring is the management-system layer: a scope that survives Stage 1, a risk assessment that makes the SoA traceable, and the annual clause 9 cadence built so it keeps running after we leave. That is our ISO 27001 and compliance-as-a-service work. Where the underlying gap is that nobody owns security decisions at all, a vCISO is the more honest purchase than a certification project. And where you need the clause 9.2 internal audit performed by someone genuinely independent of the build, that sits in audit and assurance and we keep it separate on purpose.
How to decide this week
1. Ask two prospects whether an ISO 27001 certificate would change their procurement answer, and write down what they say. That single conversation decides more than any build-versus-buy analysis.
2. Name the person who will still own the ISMS in two years. If there is no name, fix that before choosing a vendor.
3. List which of the five management-system deliverables you can genuinely produce in house: scope, risk assessment, SoA justifications, internal audit, management review. Buy against the gaps, not against the whole project.
4. Ask two accredited certification bodies for derived audit days, the table row behind them, and their day rate. Compare the days first.
5. Verify any body you shortlist in IAF CertSearch and with its accreditation body, and drop anyone offering to both consult and certify.
Frequently asked questions
Can you get ISO 27001 certified without a consultant?
Yes, and plenty of organizations do. The standard is publicly available, certification bodies will answer scoping questions, and a security lead who has run a management system before can produce every required artifact. What you trade is time and a rougher first audit, because the expensive mistakes in a first certification are structural: a scope that does not survive Stage 1, or a Statement of Applicability whose justifications do not trace to the risk assessment. If you have an experienced lead and no hard customer deadline, doing it yourself is a reasonable trade. If you have neither, the deadline is what makes help worth paying for.
Will a compliance platform get you ISO 27001 certified on its own?
Not on its own. Platforms are genuinely good at the evidence half: continuous checks against technical controls, timestamped records, policy acknowledgments, training and vendor inventories. They cannot define your ISMS scope, run a repeatable risk assessment with named risk owners, write justifications that trace to that assessment, perform an impartial internal audit under clause 9.2, or hold the management review under clause 9.3. Those five are the management system that ISO 27001 certifies, and every one of them needs a person.
Can your certification body also help you build the ISMS?
No, and you should decline if offered. ISO/IEC 17021-1 requires certification bodies to be impartial and bars them from providing management system consultancy to organizations they certify. A body that builds and then certifies the same ISMS undermines the only thing the certificate is for, which is independent assurance. Keep the two relationships separate: one firm to help you build, an accredited body to certify. Note that this is a restriction on the certification body, not on you. Using an independent consultant and then going to an unrelated accredited body is fine, and is what most certified organizations do.
How do you check that an ISO 27001 certification body is legitimate?
Check the accreditation, not the branding. Confirm the body is accredited for ISO/IEC 27001 by an accreditation body that signs the International Accreditation Forum multilateral arrangement, such as ANAB in the United States or UKAS in the United Kingdom, and confirm the scope of that accreditation covers your sector. Then look the certificate itself up in IAF CertSearch, the global database of accredited certifications. If a certificate cannot be verified through an accreditation body and appears nowhere in that database, it is a document rather than a certification.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.