Key Takeaways
- ISO 27001 consulting services help you build an information security management system (ISMS) ready for ISO/IEC 27001:2022 certification, which only an accredited certification body can issue.
- Annex A lists 93 controls (37 organisational, 8 people, 14 physical, 34 technological), 11 of them new in 2022.
- ISO 27001:2013 certificates lost validity after 31 October 2025, so a lapsed holder now needs a full initial audit.
- Certification runs on a three-year cycle: Stage 1 and Stage 2 audits, surveillance audits in years 2 and 3, then recertification.
- Pivot Point Security's 2024 pricing puts a 100-employee, single-site project at $70,000 to $120,000 including the certification audit, over 6 to 12 months.
- Microsoft's ISO 27001 certification covers Microsoft's cloud services, not your configuration, so an assessor must still evaluate your own controls.
ISO 27001 consulting services help you build the information security management system (ISMS) that an accredited certification body will certify. Consultants can't certify you, and certification bodies aren't allowed to consult for you, so the two roles always sit with different firms. Hire help for the gap analysis and risk assessment, keep ownership of the ISMS in-house, and plan for 6 to 12 months.
What Is ISO 27001?
ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS), which an accredited certification body can audit and certify. The ISMS is a risk-based way to protect the confidentiality, integrity and availability of your information. ISO publishes the standard as a set of requirements the ISMS must meet, not a list of products to buy.
The control counts come from BSI's ISO/IEC 27001:2022 transition briefing. Clauses 4 to 10 are mandatory for every organisation. Annex A works differently: you can exclude a control, but only with a written justification in your Statement of Applicability (SoA).
Certification is voluntary, but it is a common way to evidence security obligations under the EU General Data Protection Regulation (GDPR).
Two changes since 2022 matter for anyone starting now. Amendment 1:2024 added a requirement to clause 4.1: decide whether climate change is relevant to your ISMS. Under IAF MD 26, certification bodies had to move every certified organisation to the 2022 edition by 31 October 2025. ISO 27001:2013 certificates are no longer valid, and SGS confirms a lapsed holder is treated as a new client needing a full initial audit.
The Role of an ISO 27001 Consultant
An ISO 27001 consultant turns the standard into your working ISMS. That means scoping it, running the risk assessment, writing the Statement of Applicability and policies, guiding implementation, and running the internal audit before the certification body arrives.
The two-phase split follows Pivot Point Security's published consulting approach. Phase 1 works out where you stand, and Phase 2 closes the gaps.
If your team has had a technical security assessment in the last year, give it to the consultant on day one. It shortens the gap analysis for the technological controls. The findings only help if they get fixed, so it's worth reading how to turn assessment findings into remediation before Phase 2 starts.
What an ISO 27001 Consultant Can't Do
A consultant advises and builds, but the accountability and the certificate sit elsewhere. A consultant cannot:
- Issue your certificate. Only an accredited certification body can do that.
- Own your risks or run your management review. Risk owners approve the treatment plan and accept the risk that remains (clause 6.1.3). Top management conducts the management review (clause 9.3).
- Act as your certification body. Under ISO/IEC 17021-1 clause 5.2.5, a certification body, and any entity it controls, must not offer management system consultancy. European Accreditation's clause 5.2.5 guidance sets this out.
Step-by-Step Guide to ISO 27001 Certification
Certification takes ten steps, from scoping to the Stage 2 audit. Pivot Point Security puts most projects at 6 to 12 months, depending on size and complexity. After certification come surveillance audits in years 2 and 3, and a recertification audit before the three-year certificate expires.
Steps 1 to 8 stay your responsibility even when a consultant does most of the work. The certification body audits what your organisation runs, not what the consultant wrote.
Certification is a cycle, not a one-off. Between audits, keep running internal audits and management reviews at planned intervals. The surveillance audits in years 2 and 3 check a sample of the ISMS. The recertification audit reviews the whole system again.
Stage 1 vs Stage 2 Audit
Stage 1 checks whether your ISMS is designed correctly. Stage 2 checks whether it works in practice.
How Much Does ISO 27001 Consulting Cost, and How Long Does It Take?
Pivot Point Security's published 2024 pricing puts a 100-employee, single-site ISO 27001 project at $70,000 to $120,000, including the certification audit. Consulting makes up $50,000 to $90,000 of that, and most projects take 6 to 12 months.
The figures come from Pivot Point's 2024 cost breakdown, updated in August 2026. They cover a company certifying ISO 27001 alone at one location. The certification audit is only $20,000 to $30,000 of the total, and the rest is preparation.
Adding both surveillance audits brings the three-year cycle to $90,000 to $150,000, before your own staff time. Pivot Point says about 75% of its projects fall inside these ranges. Costs run higher with more locations or more standards in scope. They run lower when your security programme is already mature or your team handles more of the remediation.
These are US prices from a US firm, so treat them as a benchmark. Get quotes from at least three consultants and three accredited certification bodies.
If your ISMS will run on Microsoft 365 and Azure, a security assessment of your Microsoft environment shows which technical controls are already in place before the gap analysis starts.
ISO 27001 on Microsoft 365 and Azure: What Your Stack Already Evidences
Microsoft's ISO 27001 certification covers how Microsoft runs its cloud services, not how you configure them. The tools you already license can still produce evidence for 7 of the 11 controls added in 2022.
What You Can and Can't Inherit From Microsoft's Certificate
You can use Microsoft's certification, but not as your own. Microsoft's cloud services go through regular independent ISO/IEC 27001 audits, and the certificates and reports sit on the Service Trust Portal. Microsoft says you can use them in your assessment, but you must still engage an assessor for your own controls and processes. File them as supplier evidence under controls A.5.19 to A.5.23, which cover suppliers and cloud services. They are not proof of your own compliance.
The 11 New ISO 27001:2022 Controls, Mapped to Microsoft Tools
CyberQuell's mapping: evidence, not certification.
That makes 7 direct, 2 partial and 2 with no Microsoft evidence. Microsoft retired standalone Defender Threat Intelligence on 1 August 2026 and moved it into Sentinel and Defender XDR at no extra cost. For 8.9, configuration assessment comes with Defender for Endpoint Plan 2, but security baselines assessment needs the Defender Vulnerability Management add-on. If you harden devices to a benchmark, see how to apply CIS Benchmarks in practice.
Microsoft Learn documents the other sources:
Each remaining source is a documented Microsoft capability. Cloud discovery identifies the cloud apps your staff actually use (5.23), and Site Recovery test failovers record recovery drills without touching production (5.30). Retention and deletion policies remove content on a schedule (8.10), dynamic data masking hides sensitive columns from non-privileged users (8.11), and web content filtering blocks website categories (8.23).
Monitoring evidence for 8.16 only goes back as far as your logs do, so check how long each Microsoft 365 log source is retained.
Tracking Readiness Inside Microsoft
Two built-in tools track your ISO 27001 readiness. Purview Compliance Manager has an ISO/IEC 27001:2022 assessment template. It's a premium template, and some licences, such as Microsoft 365 E5, include up to three premium templates at no extra cost. Defender for Cloud lists ISO IEC 27001:2022 among its regulatory standards for Azure, AWS and GCP. It needs any Defender for Cloud plan except Defender for Servers Plan 1 or Defender for API Plan 1. Both score technical configuration, not your ISMS, so use them to track evidence.
Choosing the Right ISO 27001 Consultant
Choose a consultant who holds ISO 27001 Lead Implementer or Lead Auditor credentials and has worked at your size and on your technology stack. They should also be independent of your certification body and sign a contract that leaves you owning every document.
Selection Criteria
Hiring a consultant moves the work, not the accountability. That's the same principle behind what stays yours when you outsource security.
Questions to Ask Before You Sign
- Which implementations have you completed at our size and in our sector?
- What method do you use for the gap analysis and the risk assessment?
- Who writes the Statement of Applicability, and who approves it?
- How will our team learn to run the ISMS after you leave?
- Can you share a project plan with milestones?
- How do you price changes to scope?
Red Flags
Walk away from a consultant who:
- promises certification or a fixed short timeline before doing a gap analysis
- offers to certify you, or routes the audit to a certification body they are connected to
- delivers template policies with only your name added
- leaves the internal audit out of scope
- has no support after the Stage 2 audit
ISO 27001 Consultant vs Compliance Software vs vCISO
A consultant builds the ISMS, compliance software automates evidence collection, and a virtual CISO (vCISO) provides ongoing security leadership. For a firm of 50 to 500 people, the practical split is a consultant in year one, then software or a vCISO for the surveillance years.
ISO 27001 requires defined security roles and responsibilities (clause 5.3), not someone with the title of CISO. That's why a vCISO can hold the role. Top management stays accountable for the ISMS under clause 5.1.
If you want the logging and monitoring evidence for controls 8.15 and 8.16 produced continuously, talk to CyberQuell about Microsoft Sentinel monitoring.
Final Thoughts
Good ISO 27001 consulting services speed up scoping, risk assessment and the Statement of Applicability. They don't take ownership of the ISMS away from you. Based on Pivot Point's published ranges, budget $70,000 to $120,000 for a 100-person, single-site project, and 6 to 12 months to get certified. Keep the firm that builds your ISMS separate from the body that certifies it. If you already run on Microsoft 365 and Azure, find out what your tools evidence before the gap analysis starts, so your consultant isn't starting from zero.
Book a call with CyberQuell to scope a security assessment of your Microsoft 365 and Azure environment, so your consultant starts the gap analysis with evidence already in hand.

%20for%20Microsoft%20365%20(1).png)
.png)
.png)