Achieving ISO 27001 certification is a process that rewards careful preparation. ISO/IEC 27001 certification is a serious undertaking, and the ISO 27001 consultant you pick largely determines whether it goes smoothly or becomes a multi-year ordeal. A good consultant helps your organisation build an information security management system that actually fits how you work, supports you through the staged audit, and leaves your team able to maintain what you built. A poor one delivers a binder of generic policies your staff will never follow and your auditor will reject. This guide walks through the criteria that matter when deciding whether and how to hire an ISO 27001 consultant. It covers what separates capable ISO consultants from generalists and how to verify what you are buying.

Understanding the two distinct roles

The most important thing to understand before hiring is the separation between a consultant and a certification body. An ISO 27001 consultant helps you build and implement your ISMS, conduct risk assessment and gap analysis, develop your policies and controls, and prepare for the audit. An accredited certification body is the independent organisation that examines your management system and issues the certificate. These two roles must be kept separate; the body issuing the certificate must be independent of whoever helped you build the system.

A trustworthy provider of ISO 27001 consultancy services is upfront about this line. If a firm offers to both help you implement and then certify you, that is a red flag, not a convenience. The value of the certificate depends on the independence of the auditor who grants it.

Understanding this separation also clarifies what the consultant is responsible for. They are not there to hand you a certificate; they are there to help you build a system that earns it from an independent accredited body. A consultant who can help you achieve ISO 27001 compliance is focused on building something real and auditable, not just assembling paperwork.

Not sure where your current security posture stands?

Run the free 15-question self-assessment before you engage a consultant. It gives you a baseline to brief against.

Start the assessment →

Core criteria for choosing well

1. Verified ISO 27001 experience and a lead credential

The ISO 27001 standard has a specific structure and a defined set of requirements that differ from general information security frameworks. An expert ISO 27001 implementer who works with the standard regularly knows where implementations commonly go wrong, how auditors test controls, and how to handle the nuances of scoping and the Statement of Applicability.

For many organisations this will be their first ISO 27001 engagement. Ask for evidence of previous outcomes. Confirm you are talking to a dedicated security consultant with ISO 27001 specialisation, not a generalist who offers it as a side service. Ask how many organisations they have helped get certified and what sectors those were in. Confirm they hold a recognised ISO 27001 lead implementer or lead auditor qualification. A formal lead implementer credential is not a guarantee of quality, but it signals the person has been trained and examined in the standard. It also tells you they have committed to the discipline rather than treating it as one service line among many.

Also ask whether they can demonstrate specific knowledge of ISO/IEC 27001:2022. The current standard restructured and updated the Annex A controls significantly. As of the October 2025 transition deadline, accredited certification bodies certify only against ISO/IEC 27001:2022 and legacy 2013 certificates are no longer valid. A consultant who cannot explain the key changes may not have current knowledge.

2. A genuine gap analysis process

Before any implementation work begins, a competent consultant runs a structured gap analysis of your current state against the ISO 27001 requirements. This maps what you already have against what the standard requires, identifies what needs to be built, and surfaces priorities for your risk treatment plan.

Good readiness review work is specific to your organisation. It examines your actual security practices, your information asset inventory, your existing policies, and your controls. It does not start with a pre-filled template listing generic findings. The output should drive a realistic, prioritised remediation roadmap that the consultant can help you execute.

Ask to see an example gap analysis from a previous engagement. Ask how they approach it: do they interview staff, review documentation, and examine your technical environment, or do they hand you a questionnaire and fill in a template? The depth of the readiness assessment shapes everything that follows.

3. A risk assessment grounded in your actual environment

Risk assessment is the foundation of ISO 27001. Every control selection, every policy priority, and every decision about scope should flow from a genuine understanding of your information assets, the threats they face, and the vulnerabilities in your current environment. The Statement of Applicability, which justifies which Annex A controls apply to your organisation, is only meaningful when grounded in a real risk assessment.

A consultant who hands you a pre-populated risk register with twenty standard threats has not done risk assessment; they have produced paperwork. Genuine risk assessment requires understanding your business processes, your data flows, your third-party dependencies, and the threat landscape relevant to your sector. The result should reflect your organisation, not a hypothetical average company.

Good risk management documentation also needs a risk treatment plan showing what you are doing about each identified risk and why. This is what the auditor examines to confirm your controls are justified and proportionate.

4. Controls built for how your organisation actually works

ISO 27001 requires appropriate security measures from Annex A, but the standard is not prescriptive about how those measures must work. The flexibility allows organisations to implement security practices that fit their actual operations. A skilled consultant implements ISO 27001 security measures in ways that integrate with how your organisation already runs. Access management should reflect your real user provisioning process. Incident response procedures should name real roles. Change management should align with how your team deploys software.

If the security practices documented in your ISMS do not match reality, the auditor will find the discrepancy. Ask the consultant how they approach policy development. Do they build from your existing processes, or do they hand you templates? Do they work with your technical and operational teams to make sure the documented practices are ones people can actually follow?

5. Support through the full audit process

The ISO 27001 audit has two stages. Stage 1 is a documentation review: the auditor examines your ISMS design, your Statement of Applicability, and your key policies to determine whether the system is correctly designed and you are ready to proceed. Stage 2 is the main audit, where the auditor checks that your controls are implemented and operating effectively through interviews, evidence review, and testing.

An experienced consultant prepares you for both stages of the certification audit, helps you understand what evidence the ISO 27001 auditor will request, coaches your team on how to respond clearly and honestly, and is available during the audit process to help address questions. Ask what support is available if the auditor raises major nonconformities that require remediation before the certificate is issued.

The objective is to get certified on the first attempt. Organisations that prepare well with a knowledgeable consultant almost always achieve successful certification. Those that rush the implementation often face significant findings at Stage 2 that delay the outcome and cost more to fix under pressure.

6. A handover that builds your capability to maintain ISO 27001 compliance

After you achieve ISO 27001 certification, the work continues. The standard requires ongoing operation: internal audit cycles, management reviews, continuous risk management, and annual surveillance audits. At the end of a three-year cycle you face full recertification. All of this requires your team to understand the ISMS and be able to operate it without needing to hire a consultant for routine tasks.

A good engagement ends with your team in control. The consultant should train your internal auditors, document processes clearly enough for non-experts to follow, and ensure the people responsible for day-to-day operations know what they need to do. The goal is to sustain certification through surveillance and recertification without bringing the consultant back in for routine tasks. Ask how handover is structured, and whether internal auditor training is included. Ongoing dependency is a sign the system was not built properly.

7. Honest advice on tooling and specific needs

There is a growing market of platforms marketed as ways to make ISO 27001 faster and easier. Some tools genuinely help larger organisations manage evidence collection and track control performance. For others, they add cost without meaningful benefit. A consultant who recommends such tools regardless of your actual requirements may have commercial incentives to do so.

Ask why a specific tool is recommended and what the alternative looks like. A competent ISO 27001 consultant can help you judge this based on your actual context rather than pushing compliance automation for every client. Many organisations achieve certification and keep it current effectively without specialist software, especially when the ISMS is well-designed and the security posture work is done properly from the start. The right answer depends on your size, complexity, and the resources you can devote to ongoing operation.

Red flags that should stop you

Some behaviours from a consultant should immediately disqualify them:

  • Offering to both consult on your ISMS and act as the independent accredited certification body, or implying they can arrange certification through a connected firm without a fully independent certification audit. Accreditation requirements under IAF guidelines prohibit a certification body from certifying an ISMS it also helped build; any firm blurring this line is acting outside accreditation rules.
  • Starting implementation before conducting a gap analysis or risk assessment specific to your organisation.
  • Delivering policies and procedures as templates with minimal customisation to your actual environment.
  • Working to the 2013 version of the standard rather than ISO/IEC 27001:2022. As of the October 2025 transition deadline, accredited certification bodies certify only against ISO/IEC 27001:2022; legacy 2013 certificates are no longer valid.
  • Building a management system so complex or proprietary that your team cannot operate it independently.
  • Promising an unrealistically short timeline that does not allow for genuine implementation and evidence generation.
CriterionWhat good looks likeYour provider?
Experience + credentialVerified outcomes, ISO 27001 lead implementer qualification, ISO/IEC 27001:2022 knowledgeY / N
Gap analysisOrganisation-specific, interviews staff, reviews technical environment, not a templateY / N
Risk assessmentReflects your actual assets, threats, and sector; drives SoA and control selectionY / N
Controls fitBuilt around how you actually work, not handed as generic policiesY / N
Audit supportPrepares both Stage 1 and Stage 2, available for nonconformity resolutionY / N
HandoverInternal auditor training included; your team runs surveillance independentlyY / N
Honest tooling adviceRecommends based on your context, not default to every clientY / N
IndependenceStrictly separates consulting and certification; refers to independent accredited bodyY / N

How Onyx helps

Onyx provides a comprehensive ISO 27001 consulting service covering readiness, ISMS implementation, and ongoing support. Our engagements start with a structured readiness assessment of your current state against the standard's requirements, followed by a genuine risk assessment of your information assets and threat environment. We build the Statement of Applicability from that risk assessment, implement the ISO 27001 controls your risks require, and document practices that reflect how your organisation works.

We support you through the full certification process, from Stage 1 documentation review through Stage 2 and any nonconformity resolution. Our consultants hold lead implementer qualifications and can help you earn the certificate efficiently. We do not certify clients; all certifications are completed through independent accredited bodies. When the engagement closes, your team holds the knowledge and documentation to maintain ISO 27001 compliance, pass surveillance audits, and stay certified through recertification.

Our ISO 27001 services also extend beyond initial implementation. If SOC 2 is on your roadmap, we can advise on how to structure your work so the controls and evidence you build support both frameworks without duplication. A good consulting partner can help you plan this sequencing from the start, which is where Onyx adds the most value for information security maturity improvements that outlast the initial certification effort.

How to choose an ISO 27001 consultant: 7 criteria and the red flags to avoid, at a glance

Ready to talk through your ISO 27001 project?

We map your scope, timeline, and current maturity on a 30-minute call. No pressure, no obligation.

Book a scope call →

The bottom line

The right ISO 27001 consultant brings verified expertise, a genuine gap analysis and risk assessment process, knowledge of the current ISO/IEC 27001:2022 standard, an ISO lead implementer credential, support through the full audit process, and a commitment to leaving your team able to sustain the ISMS. They should help you understand your particular context clearly, address risks through controls and security practices that work in your organisation, and build an ISMS that maintains a strong overall security posture beyond the initial certificate. Take the time to verify experience, check credentials, and understand exactly how the consultant works before committing.

Starting your certification journey? Tell us your scope and timeline and we will map a path on a short call. Book a scope call or take our free security self-assessment. See also the ISO 27001 certification process, ISO 27001 certification cost, and our ISO 27001 service.

Common questions when comparing ISO 27001 consultant options

When organisations first evaluate options, several practical questions come up consistently. Understanding these helps you have a more focused conversation when meeting a provider.

What does an ISO 27001 certification project typically involve?

A well-run certification programme follows a defined sequence: readiness assessment, risk assessment, controls design and implementation, policy documentation, internal audit, management review, and the two-stage external audit that completes the certification process with an accredited body. ISO 27001 certification typically takes six to twelve months from start to certificate for a focused scope, though larger or more complex environments take longer. A qualified ISO 27001 expert can map the timeline for your specific context before you commit.

How do ISO 27001 consultants support the audit itself?

ISO 27001 consultants play a supporting role during the official audit: they help you prepare evidence packs, coach your team on what to expect, and are available to help address auditor questions during both Stage 1 and Stage 2. They do not conduct the audit themselves. Understanding how an ISO 27001 consulting partner helps your team before and during the audit, rather than just in the build phase, is an important factor in selecting a partner.

What happens if certification fails?

A failed certification attempt is rarely a full rejection; it usually means the auditor identified major nonconformities that must be resolved before the certificate is issued. A skilled consultant anticipates common failure points during implementation and addresses them proactively. If nonconformities are raised, your consultant should help you triage and resolve them quickly. Ask prospective consultants directly about their track record: how often do their clients face major findings, and what support do they provide when it happens? Regular awareness training and updates for your team throughout the process also reduce the risk of nonconformities by ensuring staff understand what the ISMS requires of them.

How does consultant cost relate to certification quality?

Consulting fees vary based on scope, engagement model, and the depth of support provided. A lower fee does not always mean better value; consultants who cut corners on readiness assessment, risk assessment, or ongoing support often cost more in the long run through rework, audit findings, or an ISMS that does not pass recertification. The best way to evaluate a consulting fee is to understand exactly what is included and what is not. Ask whether the fee covers support through both stages of the audit, internal auditor training, and post-certification handover. If you want to meet the ISO 27001 requirements in a way that gives you a durable certificate, investing in the right depth of engagement matters.

When does it make sense to accelerate ISO 27001 certification?

Sometimes business pressures, contract requirements, or competitive dynamics mean you need to move faster. A skilled consultant can help you achieve this by focusing scope tightly, prioritising controls with the highest audit impact, and running parallel workstreams where possible. However, be realistic: ISO 27001 certification typically requires time for ISMS operation and evidence generation before the audit can proceed. No consultant can legitimately compress this below a certain threshold and still deliver a system that fully meets the ISO 27001 standard.

What about pursuing ISO 27001 alongside SOC 2?

Many technology organisations face demand from both US buyers (who prefer SOC 2) and international enterprise buyers (who prefer ISO 27001). The good news is that these two frameworks share a large proportion of the underlying security work. A consultant who understands both can structure your ISO 27001 project to avoid duplicating controls, documentation, and evidence collection, making the second certification substantially easier once you have completed the first.

FAQ

What does an ISO 27001 consultant do?

An ISO 27001 consultant helps you build your ISMS: conducting a readiness assessment, running risk assessment, building the Statement of Applicability, implementing security measures and controls, and preparing you for the external audit. They do not issue the certificate; that is done by an independent accredited body. A strong consultant also transfers knowledge so your team can operate the ISMS and maintain the information security framework after certification.

Can the same company do my ISO 27001 consulting and certification?

No. The body that issues the ISO 27001 certificate must be independent of whoever helped build the security system. A trustworthy ISO 27001 consulting partner is explicit about this and refers you to independent accredited bodies for the external audit. An accredited certification body cannot certify an ISMS it also helped build; this independence rule comes from accreditation requirements under IAF guidelines (applied by bodies such as UKAS or DAkkS), not from ISO 27001 itself.

How do I choose an ISO 27001 consultant?

Look for verified experience helping organisations achieve ISO 27001 certification, a thorough current-state assessment and risk assessment process, knowledge of ISO/IEC 27001:2022, an ISO lead implementer qualification, support through the full audit, honest advice on your individual situation and tooling, and a handover approach that builds your internal capability to keep the ISMS running. Ask for references, check credentials, and confirm they keep the consulting and certification roles strictly separate.

Does my ISO 27001 consultant need to know the 2022 version?

Yes. ISO/IEC 27001:2022 updated the Annex A controls significantly. As of the October 2025 transition deadline, accredited certification bodies certify only against ISO/IEC 27001:2022 and legacy 2013 certificates are no longer valid, so working to the 2013 version creates real risk. Confirm your consultant works to ISO/IEC 27001:2022 before engaging.

How long does ISO 27001 certification take with a consultant?

It depends on your size, scope, and starting maturity. Organisations that want to achieve ISO 27001 certification on the first attempt typically run a multi-month programme covering readiness assessment, risk assessment, controls implementation, policy development, internal audit, and the staged external certification process. A competent consultant gives you a realistic timeline based on your actual situation and requirements, not an optimistic estimate designed to win the engagement.