What an ISO 27001 Consultant Does
An ISO 27001 consultant builds the Information Security Management System that the certification body will audit. In practice that is six things: defining the ISMS scope, running the risk assessment and treatment plan, producing the Statement of Applicability, implementing the Annex A controls that apply to you, writing the policy set, and running the internal audit and management review that ISO requires before anyone external arrives.
What a consultant cannot do is certify you. Certification comes only from an accredited certification body, and a consultancy is not permitted to audit an ISMS it built. Avantcert prepares you and works alongside accredited bodies who perform the audit. Any firm implying it issues the certificate itself is not describing accredited certification.
Our Engagement, Stage by Stage
Scoped to a 60-day maximum. Most companies finish sooner; certification body scheduling is usually what moves the date.
1. Scope definition. Which systems, locations and legal entities sit inside the ISMS. This decides your cost more than anything else, because audit days scale with scope and you pay for them again at every surveillance audit for three years.
2. Risk assessment and treatment. Assets, threats, a rated risk register with owners, and a treatment plan that says what you are doing about each one.
3. Statement of Applicability. Every Annex A control, marked applicable or not, with justification either way. The auditor reads this first.
4. Control implementation. Closing the gaps across the applicable controls, with the evidence assembled as we go rather than hunted for later.
5. Internal audit and management review. Both are mandatory clauses, not optional good practice. Findings caught here cost a fix; findings caught at Stage 2 cost a fix plus a follow-up audit.
6. Stage 1 and Stage 2 support. We prepare your team for interviews and sit with you through both audits.
Not sure where you stand? Start with an where you stand against ISO 27001.
Annex A and the Statement of Applicability
ISO 27001:2022 lists 93 Annex A controls across four themes — organizational, people, physical and technological. A common misconception is that you must implement all 93. You do not. You must consider all 93 and justify which apply.
| Theme | Controls | Typical burden |
|---|---|---|
| Organizational | 37 | Policy, supplier management, incident process |
| People | 8 | Screening, training, disciplinary process |
| Physical | 14 | Often largely inherited from a cloud provider |
| Technological | 34 | Where most implementation effort lands |
The Statement of Applicability is the document that makes this defensible. A control excluded with a clear justification is fine. A control excluded because nobody looked at it is a nonconformity. This is where a first-time ISMS most often falls down, and it is cheap to get right at the start and expensive to fix at Stage 2.
Consultant vs Compliance Platform vs In-House
| Automation platform | In-house | Avantcert | |
|---|---|---|---|
| Who does the work | Your team | Your team | Our consultants |
| Scope definition | Not covered | Often too broad | Stage 1 of the engagement |
| Risk assessment | Templates | You build it | Built with you |
| Statement of Applicability | Template | You justify all 93 | Written and defensible |
| Internal audit | Not covered | Hard to do independently | Run for you |
| Stage 1 / Stage 2 | Not present | You are alone | With you |
If you already run a platform, keep it — continuous evidence collection is genuinely useful and we work with what you have. Compare approaches in our Vanta alternative and Drata alternative guides.
What ISO 27001 Consulting Costs
Avantcert engagement ranges by company size, already discounted 30–50% below typical market rates.
| Tier | Employees | Avantcert engagement | Certification body fee | Max duration |
|---|---|---|---|---|
| Startup | 5–50 | from $4,000 | Separate | 60 days |
| Mid-Market | 51–200 | around $9,500 | Separate | 60 days |
| Large Enterprise | 201–500 | up to $15,000 | Separate | 60 days |
The accredited certification body's Stage 1 and Stage 2 audit fee is separate and paid directly to them, because the organization that prepares you cannot also audit you.
Scope is the lever. A tightly defined ISMS reduces implementation effort, audit days and every surveillance audit for the full three-year cycle. Full breakdown in ISO 27001 certification cost.
Get a Scoped ISO 27001 Quote
Tell us your headcount and what sits inside the ISMS. Scoped estimate and an implementation roadmap within 24 hours.
Our form could not load. Email your headcount and ISMS scope and you'll get the same estimate within 24 hours.
Email your requirements Open the full quote formHow to Compare ISO 27001 Consultants
Ask who defines the scope. A consultant who accepts whatever scope you propose is not saving you money. Scope is the single largest cost driver across three years and it should be argued about in week one.
Ask whether the internal audit is included. It is a mandatory clause. Some quotes leave it out and it reappears as a change order.
Ask who attends Stage 2. "Audit support" sometimes means a document review and sometimes means someone in the room. Those are different products.
Ask about the certification body relationship. A consultancy that works regularly with accredited bodies can tell you realistic scheduling. One that has never dealt with them will discover the queue at the same time you do.
Be wary of anyone who says they can certify you. They cannot. It is the clearest disqualifying signal available.
ISO 27001 Consultant FAQs
What does an ISO 27001 consultant do?
An ISO 27001 consultant defines your ISMS scope, runs the risk assessment and treatment plan, builds the Statement of Applicability, implements the Annex A controls that apply, writes the policy set, runs the internal audit and management review, and supports you through the certification body's Stage 1 and Stage 2 audits.
Can a consultant certify me to ISO 27001?
No. Certification is issued only by an accredited certification body, and a consultancy cannot audit the ISMS it built. Avantcert prepares you and works alongside accredited bodies who perform the audit. Any firm claiming to issue the certificate itself is not describing accredited certification.
How long does ISO 27001 certification take with a consultant?
Avantcert scopes ISO 27001 engagements to a 60-day maximum and most finish sooner. The variables are your starting maturity, the size of the ISMS scope, and certification body scheduling for Stage 1 and Stage 2.
How much does an ISO 27001 consultant cost?
Avantcert ISO 27001 engagements run from $4,000 for a 5–50 employee company, around $9,500 at 51–200, and up to $15,000 at 201–500 or multi-site scope. Scope, not headcount, is the largest driver.
Do I need a consultant or can I do ISO 27001 in-house?
You can do it in-house if you have someone who owns security as a real part of their job and can absorb several months of ISMS work. The constraint is rarely knowledge; it is capacity, and the risk to manage is scoping the ISMS too broadly at the start, which raises every audit fee for the next three years.
Should I do ISO 27001 or SOC 2 first?
Whichever your customers are asking for. ISO 27001 is the international certification and is generally the lower-cost route at comparable scope, starting around $4,000 against $7,000 for SOC 2 readiness, and its certificate lasts three years where a SOC 2 report repeats annually. If both are on the roadmap, running them together shares the risk assessment, policies and evidence. See ISO 27001 vs SOC 2.
Related Services
Start with an a gap analysis against the standard, see the numbers in certification cost, read the ISO 27001 overview, or compare against SOC 2 compliance.
Official reference: ISO/IEC 27001.
Talk to an ISO 27001 consultant
Thirty minutes to scope your ISMS and tell you what it will cost.