Certification

How to choose an ISO 27001 consultant: what to ask before you sign

A buyer's guide for UK organisations choosing ISO 27001 help: whether you need a consultant at all, why the consultant and the certification body must be separate, the experience that matters, how good consultants scope the work, and the red flags.

By the Threat Protect editorial team9 min readUpdated 6 October 2026

Choosing who helps you with ISO 27001 shapes how long the work takes, how much it disrupts the business, and whether the management system still works a year after the certificate arrives. The questions below apply to any ISO 27001 consultant you are considering, with the answers that should reassure you and the ones that should not.

If you are still deciding between ISO 27001 and Cyber Essentials, read which one you need first.

Do you need a consultant at all?

Not always. If someone in-house has taken an organisation through ISO 27001 before, and has the time, you may only need an independent gap analysis and a second opinion before the audit.

Most organisations use a consultant for three reasons: they have not done it before, the people who would do it already have full-time jobs, and a client or contract has set a deadline. A good consultant shortens the path and reduces the risk of findings at the Stage 2 audit. It should also leave your team able to run the system afterwards.

Why must the consultant and the certification body be separate?

Certification bodies are accredited against ISO/IEC 17021-1, whose impartiality rules mean they cannot design, write or implement the management system they then audit. So the organisation that helps you build your information security management system (ISMS) cannot be the one that certifies it.

In practice this means two relationships: a consultant (or your own team) for implementation, and an accredited certification body for the Stage 1 and Stage 2 audits. In the UK, check that the certification body is accredited by UKAS, because that is what most clients and procurement teams look for, and certificates from unaccredited bodies are often not accepted. You can check a certification body on the UKAS website. Be wary of any offer to implement and certify through the same organisation.

What experience should you look for?

  • The current standard. Certification is now against ISO/IEC 27001:2022 and its 93 Annex A controls. Ask how many organisations they have taken through it.
  • Your size and sector. A 50-person software company and a 400-person regulated firm need different scopes, risk registers and evidence. Sector experience also helps where other obligations overlap, such as DORA, the NHS Data Security and Protection Toolkit or client supplier audits.
  • Stage 2 experience. Ask what findings their clients most often receive at Stage 2, and what they do to avoid them. Specific answers are a good sign.
  • References. Ask to speak to a client of similar size, ideally one now in its surveillance years.

Advice, implementation or ongoing management?

Consultancy comes in three broad shapes, and proposals are easier to compare once you know which one you are looking at:

  • Advisory: the consultant guides and reviews; your team writes and runs everything.
  • Implementation: the consultant builds the ISMS with you, including the risk assessment, policies, Statement of Applicability and evidence.
  • Ongoing management: the consultant also helps run the system after certification, through internal audits, management reviews and surveillance audits.

The right shape depends on how much capacity you have, and whether you want the system to stay current year-round rather than being rebuilt before each audit.

How do they scope the work?

The scope of the ISMS drives almost everything else: effort, timeline, cost and how useful the certificate is to the clients who asked for it. A good consultant spends time on scope before quoting and can explain the trade-off between a tight scope that is faster to certify and a broader one that answers more client questions.

A quote produced before anyone has asked what your organisation does, which sites, systems and teams are involved, and who is asking for the certificate is a warning sign.

Will the documents fit how you work?

Templates are a reasonable starting point. A pack of templates with your name added is not an implementation. Auditors test whether the documents describe what really happens, and policies written for another organisation fail that test quickly.

Ask to see an example Statement of Applicability with the justifications filled in, and ask how they tailor the risk assessment to your business rather than a generic list.

Who will do the work?

Ask who your named consultant will be, how much of the work they will do personally, and what happens if they leave partway through. Continuity matters: the person who scoped your ISMS is the best person to defend it at Stage 2.

What happens at the audits, and after?

Ask whether the consultant prepares you for Stage 1 and Stage 2, whether they can be available during the audits, and how they help close any findings. Then ask about years two and three. Surveillance audits check that the management system is still operating, so the internal audit, management review and risk register need to stay current between audits.

Where do compliance platforms fit?

Compliance platforms can help collect and organise evidence, track tasks and keep policies under version control. They do not replace the risk assessment, the scoping decisions or the judgement about which controls apply. A good consultant can work with the platform you already use, or recommend one only if it fits your size, without tying the engagement to it.

Red flags

  • A guaranteed certificate, or a fixed date promised before scope is agreed.
  • An offer to implement and certify through the same organisation.
  • A template pack sold as implementation.
  • A quote with no written scope behind it.
  • No named consultant, or no references at your size.
  • No plan for the surveillance years.

A shortlist checklist

Before you sign, you should be able to answer yes to each of these:

  • The consultant is separate from your UKAS-accredited certification body.
  • They have taken organisations of your size through the 2022 edition.
  • The proposal is based on a written scope, with the trade-offs explained.
  • You know whether you are buying advice, implementation or ongoing management.
  • You know who will do the work.
  • The quote states what is included at Stage 1, Stage 2 and after certification.

Where Threat Protect fits

Threat Protect scopes the ISMS with you, runs the gap analysis, builds the controls, documentation and evidence, and keeps the management system running through continuous compliance, so surveillance audits stay routine. We do not certify anyone. Certification audits are delivered through certified assessment partners, UKAS-accredited certification bodies that audit independently of us, and the certification decision is theirs alone.

If you have proposals on the table, book a 30-minute call and we will go through them against the checklist above, ours included. For more on the standard itself, see our ISO 27001 page.

Found this useful?

Share it on LinkedIn so the right people in your network see it.

Share on LinkedIn

Frequently asked

Questions readers ask before getting in touch.

  • No. The certification decision belongs to the accredited certification body, after its own Stage 1 and Stage 2 audits. A consultant can make you ready, tell you honestly where the risks are, and help you close any findings, but a promise of guaranteed certification is a warning sign.

Talk to us

Want to talk through how this applies to your company?

A 30-minute call with a senior advisor. No pitch. We will read your situation against what is in this piece and tell you the smallest sensible next step.