Skip to content

Resources/Working in ISO/8 min read

How to become an ISO 27001 consultant

The short answer

To become an ISO 27001 consultant you need a few years of hands-on information security or IT experience, a CQI/IRCA-certified ISO 27001 Lead Implementer course, and at least one full ISMS implementation you can point to. Most consultants charge between £800 and £1,500 a day in the UK.

  • Dimitar YotovHead of Compliance

Last updated

You need three things: a few years of practical information security or IT experience, an ISO 27001 Lead Implementer certification from a CQI/IRCA-approved training provider, and at least one full ISMS build you can talk about in detail. Nobody hires a consultant who has only read the standard. The qualification gets you in the door; the implementation experience keeps you there.

I have met consultants who came from IT operations, from legal compliance, from software engineering, and from the military. The common thread is not the starting point, it is whether you have actually built and maintained something resembling an information security management system, even if it was not called that at the time.

Consulting vs auditing

This matters because the two paths look similar from outside but are legally separated.

A consultant helps an organisation build, improve or maintain its ISMS. You might write the risk assessment methodology, draft policies, coach the team through internal audits, and prepare them for certification.

An auditor works for a certification body (CB) and decides whether the ISMS meets the requirements of ISO/IEC 27001:2022 [1]. CBs are accredited by bodies like UKAS in the UK [2] and are bound by ISO/IEC 17021-1, which explicitly prohibits a CB from auditing an ISMS it helped build [3]. That is not a technicality. It is a conflict-of-interest rule that gets enforced.

You can do both in a career, but not for the same client at the same time. Most people start as consultants because the barrier to entry is lower: you do not need to be contracted by an accredited CB, and you can work independently from day one.

Relevant experience

There is no formal minimum, but in practice you need at least three to five years in a role where you touched information security, IT governance, risk management or compliance. Useful backgrounds include:

  • IT operations or infrastructure (you understand access control, patching, backups, and network segmentation because you have done them)
  • Information security analyst or manager roles
  • Software engineering, particularly if you worked with secure development lifecycle practices
  • Data protection or privacy roles (GDPR sits alongside ISO 27001 more often than not, and understanding both is a genuine advantage)
  • Internal audit or compliance in regulated industries (financial services, healthcare, defence)

What matters is that you can walk into a 30-person SaaS company, look at their AWS setup, their onboarding process, and their incident response plan (or lack of one), and tell them what needs to change before a Stage 2 auditor arrives. That judgement comes from doing the work, not from a syllabus.

Qualifications and certifications

The essential one: ISO 27001 Lead Implementer

A CQI/IRCA-certified ISO 27001 Lead Implementer course is the industry standard qualification for consultants [4]. It covers the structure of the standard, risk assessment, the Statement of Applicability, control implementation, and how to run an ISMS programme. Courses run over four to five days, usually with an exam on the final day.

Cost: roughly £1,500 to £2,500 depending on the provider and whether you attend in person or online [5]. BSI, SGS, LRQA, IT Governance, and several smaller providers offer approved courses.

Useful but not essential: ISO 27001 Lead Auditor

The Lead Auditor course teaches you how to plan, conduct and report on audits against ISO 27001. It is required if you want to audit for a CB, but as a consultant it gives you a sharper eye for what auditors will actually look for. I recommend it once you have a couple of implementations behind you, not before.

Cost: similar to the Lead Implementer, £1,500 to £2,500 [5].

Other credentials that help

  • CISSP (Certified Information Systems Security Professional): broad and well-recognised, particularly with US-headquartered clients. Requires five years of paid experience in at least two security domains [6].
  • CISM (Certified Information Security Manager, ISACA): more governance-focused, good fit for ISO 27001 work.
  • ISO 27001 Foundation: a one or two day introduction. Fine as a starting point, but no client hires a consultant on the strength of a Foundation certificate alone.
  • GDPR practitioner qualifications (IAPP CIPP/E, BCS): useful because most UK ISMS implementations overlap with data protection requirements. Understanding the relationship between UK GDPR and ISO 27001 makes you more useful to clients.

Building your first implementations

This is where most aspiring consultants get stuck. You need implementation experience to get hired, but you need to get hired to gain implementation experience.

Three ways around that:

  1. Build one internally. If your current employer does not have ISO 27001, volunteer to lead the project. You will learn more from one real implementation than from five training courses. If they already have it, ask to run the next internal audit cycle (Clause 9.2) or the management review (Clause 9.3).
  1. Subcontract. Established consultancies often need extra hands for larger implementations. You will earn less per day but you will work alongside someone senior, and after two or three projects you will have your own case studies.
  1. Start small. Micro-businesses and startups with 5 to 15 staff are often priced out of the big consultancies. A 10-person fintech that has been asked for ISO 27001 by an enterprise client does not need a £2,000-a-day Big Four consultant. They need someone pragmatic who can get them certified in three to four months without overcomplicating things. That is your market entry point.

The requirements for ISO 27001 are the same regardless of company size, but how you implement them for a five-person startup versus a 500-person bank is completely different. Versatility across scales is what makes a good consultant.

Day rates

UK day rates for ISO 27001 consultants in 2026 vary widely, but the realistic range is:

Experience levelTypical day rate
Junior (1-2 implementations, subcontracting)£500 - £800
Mid-level (3-5 implementations, independent)£800 - £1,200
Senior (10+ implementations, known in the market)£1,200 - £1,800
Specialist (niche sector expertise, integrated audits)£1,500 - £2,500

Sources: High Table's 2026 consulting fee survey and Iseo Blue's market guide [7][8]. These are market surveys, not official figures, and London rates tend to sit at the top of each band.

For context, UKAS-accredited certification body auditor day rates are roughly £1,250 to £1,800 in 2026 [7]. As a consultant you are not competing with that rate; you are a separate line item in the client's budget. A typical small company might spend £4,000 to £8,000 on certification body fees and a further £5,000 to £15,000 on consulting, depending on how much internal capability they have.

Employment vs independence

You do not have to go independent. Many consultancies, managed security service providers, and GRC platforms employ ISO 27001 consultants on salary. Salaries for ISO 27001 / information security consultants in the UK range from roughly £45,000 to £80,000 depending on seniority and location, with senior or principal roles at specialist firms reaching £90,000 or more.

The advantage of employment is steady work and a pipeline you do not have to build yourself. The advantage of independence is higher day rates and the ability to choose your clients. I went independent after my fourth year and have not looked back, but I know plenty of excellent consultants who prefer the structure of a firm.

A realistic timeline

Most people underestimate how long this takes. Here is a rough path:

  • Years 0-3: Build hands-on IT or security experience. Get comfortable with risk registers, access control, incident management, and business continuity in practice, not just theory.
  • Year 3-4: Take the Lead Implementer course. Lead or co-lead your first ISMS implementation, ideally at your employer.
  • Year 4-5: Complete two to three implementations (internal, subcontracted, or as a junior consultant). Take the Lead Auditor course if you want to round out your skills.
  • Year 5+: You now have enough experience to work independently, charge mid-level rates, and build a client base.

Shortcuts exist but they are rarely good ones. I once audited a company whose "consultant" had taken a Lead Implementer course the previous month and had never seen an actual ISMS. They had produced a 200-page policy document copied from a template and a risk register with 47 identical risk ratings. The company failed its Stage 1 and had to start over. The consultant was not invited back.

FAQ

No. There is no formal degree requirement. What matters is demonstrable experience in information security or IT, relevant certifications, and a track record of successful implementations. Some clients and larger consultancies prefer candidates with degrees in computer science, cybersecurity or related fields, but it is not a gatekeeper.

Yes, but not for the same client. ISO/IEC 17021-1 requires certification bodies to maintain impartiality, which means a CB cannot audit work it helped create [3]. You can consult for Company A and audit Company B through a CB, as long as there is no conflict of interest.

The course itself is four to five days, with an exam on the final day. Results typically arrive within four to six weeks. Factor in preparation time if you are new to the standard, perhaps a week of reading ISO/IEC 27001:2022 and the 93 Annex A controls beforehand.

The number of valid ISO 27001 certificates worldwide nearly doubled from 48,671 in 2023 to 96,709 at end-2024 [9]. In the UK, 43% of businesses reported a cyber breach or attack in the past 12 months [10], and supply-chain pressure for certification is increasing. Demand for competent consultants is strong and likely to remain so.

Sources

  1. 1.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection. Information security management systems. Requirements". https://www.iso.org/standard/27001
  2. 2.UKAS. (2026). "UKAS Accreditation". https://www.ukas.com
  3. 3.ISO/IEC. (2015). "ISO/IEC 17021-1:2015 Conformity assessment. Requirements for bodies providing audit and certification of management systems". https://www.iso.org/standard/61651.html
  4. 4.CQI/IRCA. (2026). "Certified Training". https://www.quality.org/certified-training
  5. 5.IT Governance. (2026). "ISO 27001 Training Courses". https://www.itgovernance.co.uk/iso27001-training
  6. 6.ISC2. (2026). "CISSP Certification". https://www.isc2.org/certifications/cissp
  7. 7.High Table. (2026). "ISO 27001 Cost Guide 2026". https://hightable.io
  8. 8.Iseo Blue. (2026). "Information Security Consulting Market Guide". https://www.iseoblue.com
  9. 9.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html
  10. 10.Department for Science, Innovation and Technology. (2026). "Cyber Security Breaches Survey 2025/2026". GOV.UK. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026

Found this useful? Pass it on.

Certification, without the drag.

A process built for how modern teams actually work, run by tech-first auditors, and honest about what you do and don't need.