An ISO 27001 consultant helps an organisation build, implement, and maintain an information security management system (ISMS) that satisfies ISO/IEC 27001:2022 [1]. In practice, that means running the gap analysis, facilitating the risk assessment, drafting policies the team will actually follow, and preparing the organisation for its Stage 1 and Stage 2 certification audits. The role sits between advisor and project manager, and a good consultant does both without crossing into the certification body's territory.
That last point matters more than most job descriptions acknowledge.
The role
If you read ten consultant job adverts, eight of them will list "implement ISO 27001" as though it were a single task. It is not. Here is what a consultant's engagement typically looks like, roughly in order.
Gap analysis. The consultant reviews what the organisation already has (access controls, an HR onboarding checklist, a password policy somebody wrote in 2019) and maps it against the requirements of Clauses 4 to 10 and the 93 Annex A controls [1]. The output is a gap report: what exists, what is missing, and what needs rewriting. A thorough gap analysis takes two to five days for a company of 20 to 80 people.
Scope and context. Clause 4.3 requires a defined ISMS scope, and Clause 4.1 requires the organisation to understand its context [1]. The consultant helps the leadership team draw the boundary (which services, which offices, which data) and document the internal and external issues that affect information security. This is a conversation, not a document dump.
Risk assessment facilitation. Clause 6.1.2 requires a risk assessment methodology, and 6.1.3 requires a risk treatment plan [1]. The consultant does not write the risk register in a hotel room and email it over. They facilitate workshops with the people who actually know where the risks are: the engineering lead, the head of ops, the person who manages the cloud infrastructure. The methodology itself is usually one or two pages. The register is a living spreadsheet or tool, not a PDF.
Policy and procedure drafting. The mandatory documents for ISO 27001 run to roughly 20 to 25 items depending on how you count. A consultant drafts these, but the key skill is writing policies that are short enough to read and specific enough to audit. We have reviewed policies that ran to 40 pages and said nothing actionable; nobody needs that. A good acceptable use policy is two pages, and a good access control policy is three.
Control implementation guidance. The consultant advises on how to implement the controls the organisation has declared applicable in its Statement of Applicability (SoA). The 2022 standard has 93 controls across four themes: organisational (37), people (8), physical (14), and technological (34) [1]. The consultant does not configure the firewall or write the Terraform module. They tell the engineering team what the control requires, what evidence the auditor will ask for, and what "good enough" looks like.
Internal audit. Clause 9.2 requires at least one internal audit before the certification audit [1]. Many consultants conduct this themselves or bring in a subcontracted auditor. The internal audit is a dry run: it tests whether the ISMS works in practice, not just on paper. The output is an internal audit report with findings categorised as major nonconformities, minor nonconformities, or opportunities for improvement.
Audit preparation. The consultant reviews the evidence pack, runs a mock Stage 1 review of the documentation, coaches staff on what auditors actually ask, and makes sure the management review (Clause 9.3) has been conducted and minuted [1]. At Calibre, we see a clear difference in audit outcomes between organisations that had a consultant do proper preparation and those that winged it.
Required skills
The job adverts get this part roughly right, but they tend to list certifications instead of competencies. Here is what actually matters.
| Skill | Why it matters |
|---|---|
| Deep knowledge of ISO/IEC 27001:2022 and ISO/IEC 27002:2022 | You cannot advise on controls you have not read. The 2022 revision restructured Annex A entirely [1][2] |
| Risk assessment methodology | Facilitation is the core of the engagement. A consultant who cannot run a risk workshop is a policy typist |
| Technical literacy | You do not need to be a developer, but you need to understand cloud infrastructure, identity providers, CI/CD pipelines, and encryption at rest vs in transit |
| Writing | Most of the deliverables are documents. If you write like a compliance textbook, your client's team will not read the policies |
| Project management | A typical engagement runs 3 to 6 months. Somebody has to keep it on track, and that somebody is the consultant |
| Audit experience | Having sat on the auditor side (ISO/IEC 17021-1 [3], lead auditor qualified) makes a material difference. You know what the CB will actually check |
Formal qualifications vary. A Certified Information Security Manager (CISM) or ISO 27001 Lead Implementer certificate is common. A Lead Auditor qualification (CQI/IRCA or Exemplar Global registered) is a stronger signal, because it means the consultant has been trained to assess conformity, not just build systems. Some consultants hold both.
Typical deliverables
A consultant's output is concrete. By the end of an engagement, the organisation should have:
- A defined ISMS scope and context document
- A risk assessment methodology and populated risk register
- A risk treatment plan mapped to Annex A controls
- A Statement of Applicability
- 15 to 25 policies and procedures (information security policy, access control, incident management, supplier security, and the rest)
- An internal audit report
- Minutes of at least one management review
- An evidence pack ready for Stage 1
If the consultant leaves and you do not have these things in a state the team understands and can maintain, the engagement failed regardless of what the invoice said.
The impartiality boundary
Under ISO/IEC 17021-1 [3], a certification body must not audit an ISMS it helped build. This is an impartiality requirement and it is not optional. A consultant who works for the same firm that will certify you is either breaking the rules or relying on a structural separation that most small CBs cannot credibly maintain.
The practical consequence: choose your consultant and your CB separately. If a consultancy offers "end-to-end certification including the audit", ask exactly how the auditor independence works. If the answer is vague, walk away.
For more on how much consultants typically charge, the range in the UK is roughly £800 to £1,500 per day depending on seniority and specialism.
Day-to-day reality
A consultant working with a 30-person SaaS company might spend Monday morning on a risk workshop with the engineering team, Monday afternoon drafting an incident management procedure, Tuesday reviewing access control evidence in AWS IAM, and Wednesday on a call explaining to the CEO why the management review is not optional. Thursday is writing the internal audit report. Friday is answering Slack messages from the ops lead who wants to know whether their current backup schedule satisfies control 8.13.
It is not glamorous. It is detail work with a clear endpoint. The best consultants we have worked alongside are the ones who make themselves unnecessary within six months, leaving a team that can run the ISMS without them.
FAQ
No. Plenty of organisations, especially those with an experienced head of security or compliance, do it in-house. A consultant saves time and reduces the risk of nonconformities at audit. For a company with no prior ISMS experience, the time saved usually justifies the cost of certification.
Not for the same ISMS. ISO/IEC 17021-1 [3] prohibits a CB from providing consultancy and certification to the same client. Your consultant and your certification body must be separate entities with no conflicting interests.
Three to six months for initial certification, depending on the organisation's size and starting maturity. Ongoing support (surveillance audit preparation, continual improvement) is usually a few days per quarter.
A Lead Implementer is trained to build an ISMS. A Lead Auditor is trained to assess whether an ISMS conforms to the standard. Many consultants hold both, and we would argue the auditor qualification is more useful for consultancy because it teaches you what "sufficient evidence" actually looks like. More on this in our guide on how to become an ISO 27001 consultant.
Sources
- 1.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection. Information security management systems. Requirements". https://www.iso.org/standard/27001
- 2.ISO/IEC. (2022). "ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection. Information security controls". https://www.iso.org/standard/75652.html
- 3.ISO/IEC. (2015). "ISO/IEC 17021-1:2015 Conformity assessment. Requirements for bodies providing audit and certification of management systems". https://www.iso.org/standard/61651.html
- 4.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html
- 5.Department for Science, Innovation and Technology. (2026). "Cyber Security Breaches Survey 2025/2026". GOV.UK. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026
- 6.High Table. (2026). "ISO 27001 Certification Cost Guide 2026". https://hightable.io

