Skip to content

Resources/Working in ISO/7 min read

How much do ISO consultants charge?

The short answer

UK ISO 27001 consultants typically charge £800 to £1,500 per day, with total project fees ranging from around £5,000 for a micro company to £80,000 or more for a mid-sized organisation. The exact figure depends on company size, scope complexity, and the consultant's experience.

  • Gautham SenthilnathanCEO & Co-Founder
  • Dimitar YotovHead of Compliance

Last updated

In the UK, most ISO 27001 consultants charge between £800 and £1,500 per day. A handful of the larger firms push past £1,800. For a small tech company with 10 to 50 staff, the total consultancy bill for a full implementation usually lands between £8,000 and £25,000, spread over three to six months. That is the single biggest line item in most certification budgets, bigger than the certification body's own fees.

We have seen founders spend nothing on consultancy (they wrote everything themselves over evenings and weekends) and we have seen a 40-person fintech spend £55,000 on a Big Four advisory firm that delivered a 200-page risk register nobody ever opened again. Neither extreme is necessarily wrong, but the second one usually is.

Day rates vs project fees

Consultants price in one of two ways, and the choice matters more than you think.

Day-rate engagements bill for each day of work. You get flexibility: if your team moves fast, you use fewer days. If you stall, the meter keeps running. Rates in 2026 sit roughly here:

Consultant typeTypical UK day rateNotes
Independent / sole trader£800 - £1,100Often ex-auditors or former heads of InfoSec. Lean overhead.
Boutique consultancy (2-10 people)£1,000 - £1,400Usually the best value for startups and SMEs.
Mid-tier consultancy£1,200 - £1,500More structured delivery, sometimes more process.
Big Four / large advisory£1,500 - £2,000+Enterprise clients, regulated industries, complex scopes.

These figures come from market surveys by High Table and Iseo Blue, cross-checked against published rate cards from several UK consultancies in 2026 [1][2]. They are market estimates, not official benchmarks.

Fixed-fee projects quote a single price for the full implementation, from gap analysis to Stage 2 readiness. The advantage is predictability. The risk is that fixed-fee providers sometimes template heavily, handing you a set of generic policies that technically satisfy the standard but do not describe what your organisation actually does. We have audited companies whose "information classification policy" still referenced a previous client's name in the headers. That is a real thing that happens.

Total project cost by company size

The table below covers the consultancy portion only, not your certification body fees, tooling, or internal staff time. For the full picture, see how much ISO 27001 costs in the UK.

Company sizeTypical consultant daysEstimated total consultancy fee
Micro (1-10 staff)5 - 12£5,000 - £15,000
Small (11-50 staff)10 - 25£10,000 - £30,000
Medium (51-250 staff)20 - 50£25,000 - £65,000
Large (251+ staff)40 - 80+£50,000 - £120,000+

These ranges assume a single-site, primarily digital scope. If you have physical manufacturing, multiple offices, or heavily regulated data (healthcare, payments), add 20 to 40 percent.

Cost drivers

Three things move the number more than anything else.

Scope complexity. A 15-person SaaS company running everything in AWS with one product is a straightforward scope. A 15-person company that also handles payment card data, stores health records, and has staff in three countries is not. The standard requires you to define your scope under Clause 4.3 [3], and the broader and messier the scope, the more consultant days you consume.

Your starting point. If you already have decent access controls, an asset inventory, and some form of incident response, a good consultant can get you from there to certification-ready in half the time. If you are starting from a shared Google Drive with no access controls and passwords on sticky notes, budget for the upper end.

The consultant's approach. Some consultants hand you a stack of templates and tell you to fill them in. Others sit with your engineering team and build policies that reflect your actual infrastructure. The second approach costs more per day but usually results in fewer audit findings and less rework. We would rather pay £1,200 a day for someone who writes a 10-page ISMS manual that your team will actually read than £800 a day for someone who delivers 60 pages of boilerplate.

The impartiality rule

Here is something that catches people out. Under ISO/IEC 17021-1, Clause 5.2, a certification body cannot audit an ISMS that it helped build [4]. If the same organisation that advises you on your policies also conducts your Stage 1 and Stage 2 audits, that is an impartiality breach, and your certificate is worthless.

This means your consultant and your CB must be separate organisations. It sounds obvious, but several large firms offer both "advisory" and "certification" arms under the same parent company, separated by an internal Chinese wall. Technically permissible if the accreditation body is satisfied with the separation, but we have seen it challenged, and it makes auditors uncomfortable.

At Calibre, we only do the certification side. We will never write your policies, build your risk register, or tell you how to implement a control, because the moment we do, we cannot objectively audit it. If you want consultancy recommendations, we can point you to independents we trust, but we keep the two roles cleanly apart.

Going without a consultant

Not every company needs one. If you have someone internally who understands the standard (perhaps they have done this at a previous company), a good compliance platform like Vanta, Drata, or Sprinto, and 20 to 40 hours of focused time, you can build your own ISMS. The standard itself costs about £115 to £125 from the BSI or ISO web store [5], and ISO 27002:2022 (the implementation guidance) is another £150 or so.

The risk of going solo is that you miss things an experienced consultant would catch in an hour. A misunderstood Clause 6.1.2 risk methodology, an SoA that lists 114 controls instead of the 93 in the 2022 revision, a scope statement so broad it doubles your audit days. These mistakes cost time and money at the audit stage. If you are uncertain, a two-day gap analysis (£1,600 to £3,000) from an independent consultant will tell you exactly where you stand and whether you need further help.

Choosing a consultant

Ask three questions before you sign anything:

  1. Have you worked with companies of my size and sector? Ask for two references you can actually call.
  2. What will I own at the end? You should own every document, every policy, every record. If the consultant keeps them on a proprietary platform you lose access to when the contract ends, walk away.
  3. Are you connected to a certification body? If the answer involves phrases like "preferred partner" or "we can fast-track your audit", check whether that relationship compromises the independence required by ISO 17021-1 [4].

FAQ

Yes, and for small companies it is often the smarter move. An independent consultant with 10 years of audit experience and low overheads will usually charge £800 to £1,100 a day and give you more direct attention than a junior consultant from a larger firm billing at the same rate.

No reputable consultant guarantees certification, because the decision sits with the certification body's auditor, not with them. If someone guarantees a pass, that is a red flag. What they can reasonably promise is that you will be "audit-ready", meaning your documentation and implementation should withstand scrutiny.

A five-day ISO 27001 Lead Implementer course costs roughly £1,500 to £2,500 in the UK [6]. If you have someone with the right aptitude and you are willing to wait while they learn, this can work out cheaper than hiring a consultant, particularly if you plan to maintain the ISMS long-term. The trade-off is speed: an experienced consultant gets you there in three months; a first-timer might take six to nine.

Before. A good consultant will help you define your scope and build your project plan, and you will want those settled before you ask a CB to quote audit days. Once your scope is clear, approach two or three accredited CBs for quotes. See how to get ISO 27001 certification in the UK for the full process.

Sources

  1. 1.High Table. (2026). "ISO 27001 Certification Cost Guide 2026". https://hightable.io
  2. 2.Iseo Blue. (2026). "UK ISO 27001 Consultancy Market Report". https://iseoblue.com
  3. 3.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements". https://www.iso.org/standard/27001
  4. 4.ISO/IEC. (2015). "ISO/IEC 17021-1:2015 Conformity assessment - Requirements for bodies providing audit and certification of management systems". https://www.iso.org/standard/61651.html
  5. 5.BSI Group. (2022). "BS EN ISO/IEC 27001:2022". https://www.bsigroup.com
  6. 6.CQI/IRCA and various UK training providers. (2026). Lead Implementer course pricing from published schedules.

Found this useful? Pass it on.

Certification, without the drag.

A process built for how modern teams actually work, run by tech-first auditors, and honest about what you do and don't need.