ISO 27001 consultant cost: engagement models and scope of work
Consultants do not publish rates, so we do not print a rate table. The rate is also the wrong thing to compare. What decides your cost is the scope of work, who carries the risk when it takes longer than planned, and whether you are buying knowledge you lack or time you do not have.
Updated July 2026
Why this page carries no day rates
ISO 27001 consulting has no published price list. Consultants price per engagement, against your scope and your maturity, and a rate table would therefore be assembled rather than reported.
It would also mislead you. A day rate is meaningless without a day count, and the day count is the part that varies: a lower rate across more days costs more. When you have two proposals, the question that decides the money is not whose rate is lower but whether both are quoting for the same work. Usually they are not, and that is what to fix first.
What you are actually buying
Consultants and platforms get compared as alternatives. They are not: they solve different problems, and only one of them has a published price.
A consultant sells judgement
- What your scope should be, and what to leave out of it
- Whether a control is genuinely applicable to you
- What evidence an auditor will actually accept
- Whether your risk methodology will survive Stage 1
- Where you are over-engineering and can stop
Priced per engagement. Nothing published, so you source it by asking more than one.
A platform sells collection
- Automated evidence gathering from your systems
- A control framework to work against
- Monitoring that shows drift between audits
- Somewhere for the auditor to look
This layer is genuinely published. Lowest published dimension on each vendor's AWS Marketplace listing, 12-month contract, checked July 2026:
- Vantafrom $6,000
- Drata$7,500
- Secureframe$7,500
- Sprintofrom $2,000
- Scytalefrom $2,100
A platform will not tell you your scope is wrong, and a consultant will not collect your evidence every night. The common mistake is buying the platform and assuming the judgement comes with it. The three routes compared.
Engagement models, and who carries the risk
The model matters more than the rate, because it decides what happens when the work takes longer than anyone planned. It usually does.
Fixed fee for a defined scope
The consultant quotes a total for a named set of deliverables. You know the number before you start and the consultant absorbs overrun.
Watch: Only as good as the scope definition. A fixed fee against a vague scope is a fixed fee for an argument later. The consultant prices their risk into the number, and that is rational rather than sharp practice.
Time and materials
You pay for the time used. Flexible, and sensible when the work genuinely cannot be specified up front.
Watch: You carry the overrun. Cap it, agree a burn-rate review, and make sure someone internal is actually managing the engagement. Unmanaged time and materials is how a gap analysis becomes a programme.
Milestone or outcome based
Fees attach to defined milestones: scope agreed, risk assessment complete, ISMS documented, internal audit run.
Watch: Define each milestone as a deliverable someone could inspect, not as a stage name. Never tie a fee to the certification decision itself, which the consultant does not control and should not be incentivised to influence.
Advisory retainer alongside a platform
You run the programme with a platform for evidence and control mapping, and buy a limited amount of expert time for the decisions: scope, applicability, risk methodology, audit readiness.
Watch: Requires someone internal who can actually run it. The failure mode is buying the retainer and never using it, then arriving at Stage 1 with a platform full of evidence for a scope that was wrong.
The scope of work is the contract
Go through every line with every consultant you are considering, and make them answer in writing. Two proposals that answer these differently are not competing quotes, whatever their totals say. This is also the exercise that tells you which consultant has done this before.
Ask about impartiality before you engage anyone
Certification bodies operate under impartiality requirements, and a body that has consulted on your ISMS may be unable to certify it. The order in which you buy things therefore matters: hire the consultant first and you may find the certification body you wanted is ruled out.
Put it to the certification body in writing before you engage a consultant. Ask what its impartiality rules mean for the consultant you are considering, and confirm on the accreditation body's own register that it is accredited for ISO/IEC 27001 rather than for another scheme. Both questions are free at this stage and expensive later. Checking accreditation properly.
What drives the size of the engagement
More work
- No existing policies, asset inventory or risk register
- A broad scope, or a scope nobody has agreed yet
- Evidence that exists only in people's heads
- No internal owner, so the consultant chases decisions
- Legacy or hybrid infrastructure with unclear boundaries
- A first certification with no comparable framework in place
Less work
- A tightly drawn scope, decided before the consultant arrives
- An existing framework with overlapping evidence
- A named internal owner with the authority to decide
- Evidence already collected by a platform
- A single environment with clear boundaries
- Documented processes, even imperfect ones
Scope sits at the top of both lists deliberately. It is the one lever you fully control, and it moves the consultant engagement, the audit time under ISO/IEC 27006-1:2024, and the internal hours together.
Red flags
- Guarantees certification. The certification body decides, independently, and no consultant controls that. A guarantee is either a misunderstanding of how certification works or a claim about a relationship with a certification body that should worry you more.
- A proposal with no scope of work. If nobody could tell from the document whether a deliverable had been delivered, you have not bought anything you can enforce.
- Templates presented as an ISMS. A policy set is a starting point. Auditors have read the same templates, and a management system nobody follows fails Stage 2 with full documentation.
- Cannot describe evidence for a specific control. Pick an Annex A control relevant to you and ask what an auditor would accept. Hesitation here is the tell.
- Never advises narrowing scope. Scope is the buyer's biggest lever and a broad scope is the consultant's biggest engagement. Someone who has never argued a client out of scope is selling.
- Vague about impartiality. Ask directly whether their involvement affects which bodies can certify you, and confirm the answer with the certification body rather than the consultant.