Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

ISO 27001 consultant cost: engagement models and scope of work

Consultants do not publish rates, so we do not print a rate table. The rate is also the wrong thing to compare. What decides your cost is the scope of work, who carries the risk when it takes longer than planned, and whether you are buying knowledge you lack or time you do not have.

Updated July 2026

Why this page carries no day rates

ISO 27001 consulting has no published price list. Consultants price per engagement, against your scope and your maturity, and a rate table would therefore be assembled rather than reported.

It would also mislead you. A day rate is meaningless without a day count, and the day count is the part that varies: a lower rate across more days costs more. When you have two proposals, the question that decides the money is not whose rate is lower but whether both are quoting for the same work. Usually they are not, and that is what to fix first.

What you are actually buying

Consultants and platforms get compared as alternatives. They are not: they solve different problems, and only one of them has a published price.

A consultant sells judgement

  • What your scope should be, and what to leave out of it
  • Whether a control is genuinely applicable to you
  • What evidence an auditor will actually accept
  • Whether your risk methodology will survive Stage 1
  • Where you are over-engineering and can stop

Priced per engagement. Nothing published, so you source it by asking more than one.

A platform sells collection

  • Automated evidence gathering from your systems
  • A control framework to work against
  • Monitoring that shows drift between audits
  • Somewhere for the auditor to look

This layer is genuinely published. Lowest published dimension on each vendor's AWS Marketplace listing, 12-month contract, checked July 2026:

A platform will not tell you your scope is wrong, and a consultant will not collect your evidence every night. The common mistake is buying the platform and assuming the judgement comes with it. The three routes compared.

Engagement models, and who carries the risk

The model matters more than the rate, because it decides what happens when the work takes longer than anyone planned. It usually does.

Fixed fee for a defined scope

Budget certainty: HighOverrun risk: Consultant

The consultant quotes a total for a named set of deliverables. You know the number before you start and the consultant absorbs overrun.

Watch: Only as good as the scope definition. A fixed fee against a vague scope is a fixed fee for an argument later. The consultant prices their risk into the number, and that is rational rather than sharp practice.

Time and materials

Budget certainty: LowOverrun risk: You

You pay for the time used. Flexible, and sensible when the work genuinely cannot be specified up front.

Watch: You carry the overrun. Cap it, agree a burn-rate review, and make sure someone internal is actually managing the engagement. Unmanaged time and materials is how a gap analysis becomes a programme.

Milestone or outcome based

Budget certainty: MediumOverrun risk: Shared

Fees attach to defined milestones: scope agreed, risk assessment complete, ISMS documented, internal audit run.

Watch: Define each milestone as a deliverable someone could inspect, not as a stage name. Never tie a fee to the certification decision itself, which the consultant does not control and should not be incentivised to influence.

Advisory retainer alongside a platform

Budget certainty: MediumOverrun risk: Shared

You run the programme with a platform for evidence and control mapping, and buy a limited amount of expert time for the decisions: scope, applicability, risk methodology, audit readiness.

Watch: Requires someone internal who can actually run it. The failure mode is buying the retainer and never using it, then arriving at Stage 1 with a platform full of evidence for a scope that was wrong.

The scope of work is the contract

Go through every line with every consultant you are considering, and make them answer in writing. Two proposals that answer these differently are not competing quotes, whatever their totals say. This is also the exercise that tells you which consultant has done this before.

Scope definitionWho decides what is in the ISMS, and does the consultant advise or just record your decision?
Risk assessmentWho runs it, who owns the output, and does it use your risk methodology or theirs?
Statement of ApplicabilityWho drafts it and who justifies each exclusion? This is the document your auditor reads first.
Policies and proceduresWritten for you, or templates tailored? Ask to see one that has been through a Stage 2.
Control implementationDoes the consultant advise on controls or implement them? Almost always the former. Your team does the work.
Internal auditThe standard requires one, and it must be independent of the work being audited. Can this consultant run it given what else they have done for you?
Management reviewFacilitated or your own? It is a requirement of the standard, not a formality before the audit.
Audit supportWill they be present at Stage 1 and Stage 2, and is that inside the fee or extra?
Non-conformity remediationIf the audit raises findings, is closing them in scope, or does a new engagement start?

Ask about impartiality before you engage anyone

Certification bodies operate under impartiality requirements, and a body that has consulted on your ISMS may be unable to certify it. The order in which you buy things therefore matters: hire the consultant first and you may find the certification body you wanted is ruled out.

Put it to the certification body in writing before you engage a consultant. Ask what its impartiality rules mean for the consultant you are considering, and confirm on the accreditation body's own register that it is accredited for ISO/IEC 27001 rather than for another scheme. Both questions are free at this stage and expensive later. Checking accreditation properly.

What drives the size of the engagement

More work

  • No existing policies, asset inventory or risk register
  • A broad scope, or a scope nobody has agreed yet
  • Evidence that exists only in people's heads
  • No internal owner, so the consultant chases decisions
  • Legacy or hybrid infrastructure with unclear boundaries
  • A first certification with no comparable framework in place

Less work

  • A tightly drawn scope, decided before the consultant arrives
  • An existing framework with overlapping evidence
  • A named internal owner with the authority to decide
  • Evidence already collected by a platform
  • A single environment with clear boundaries
  • Documented processes, even imperfect ones

Scope sits at the top of both lists deliberately. It is the one lever you fully control, and it moves the consultant engagement, the audit time under ISO/IEC 27006-1:2024, and the internal hours together.

Red flags

  • Guarantees certification. The certification body decides, independently, and no consultant controls that. A guarantee is either a misunderstanding of how certification works or a claim about a relationship with a certification body that should worry you more.
  • A proposal with no scope of work. If nobody could tell from the document whether a deliverable had been delivered, you have not bought anything you can enforce.
  • Templates presented as an ISMS. A policy set is a starting point. Auditors have read the same templates, and a management system nobody follows fails Stage 2 with full documentation.
  • Cannot describe evidence for a specific control. Pick an Annex A control relevant to you and ask what an auditor would accept. Hesitation here is the tell.
  • Never advises narrowing scope. Scope is the buyer's biggest lever and a broad scope is the consultant's biggest engagement. Someone who has never argued a client out of scope is selling.
  • Vague about impartiality. Ask directly whether their involvement affects which bodies can certify you, and confirm the answer with the certification body rather than the consultant.

Frequently asked questions

How much does an ISO 27001 consultant charge per day?
Consultants do not publish day rates, so any rate table you find has been assembled from assumptions rather than read off a price list. Consulting is priced per engagement against your scope, your maturity and the work you want done. The rate is also the wrong thing to compare: a cheaper day rate across more days is not cheaper, and two proposals quoting different amounts of work are not comparable at all. Compare scopes of work first, then compare the totals of proposals that cover the same scope.
Do I need a consultant for ISO 27001?
It depends on whether you have the knowledge and the attention, which are two separate constraints. A consultant supplies knowledge of what the standard requires and what auditors accept as evidence, and that shortens the path considerably for a first certification. A consultant does not supply attention: your people still have to make the decisions, own the risks and be interviewed. If the binding constraint is that nobody has time, a consultant helps less than you expect, because the work that cannot be delegated is the work that takes the time.
What is the difference between a consultant and a compliance platform?
They solve different problems and are not substitutes. A platform automates evidence collection and gives you a control framework to work against; its cost is genuinely published, since several vendors list prices on AWS Marketplace. A consultant supplies judgement: what your scope should be, whether a control is applicable, whether your evidence will satisfy an auditor. A platform will not tell you that your scope is wrong. Many organisations use both, and use the consultant for the decisions rather than the documentation.
What should I look for when hiring an ISO 27001 consultant?
A scope of work specific enough to argue about. It should name the deliverables, say who produces each one, say what your people have to supply and by when, and state what happens if the work takes longer than planned. Ask for recent clients you can speak to and for anonymised examples of a Statement of Applicability they have produced. Ask them to describe a scope they advised a client to narrow, because a consultant who has never argued a client out of scope has been selling rather than advising.
Can my consultant also be my certification body?
Ask the certification body, and ask before you engage either. Certification bodies operate under impartiality requirements, and a body that has consulted on your ISMS may be unable to certify it. This is a genuine trap: organisations have hired a consultant and later found that the certification body they wanted was ruled out, or that the certificate they were offered was not accredited for ISO/IEC 27001. Put the question to the certification body in writing at the start, when the answer is free.
What are the red flags when hiring an ISO 27001 consultant?
A guarantee of certification is the clearest one, because the certification body decides independently and no consultant controls that outcome. Others: a proposal with no scope of work you could hold anyone to; an inability to describe what evidence auditors accept for a specific Annex A control; no willingness to name the scope they would recommend; and templates presented as a finished ISMS. A generic policy set is a starting point, not a management system, and auditors have read the same templates you have.

Updated July 2026