Cybersecurity

7 mins

ISO 27001 Consulting Services – Your Step-by-Step Guide to Certification

Last Updated
September 24, 2026
ISO 27001 Consulting Services

Key Takeaways

  • ISO 27001 consulting services help you build an information security management system (ISMS) ready for ISO/IEC 27001:2022 certification, which only an accredited certification body can issue.
  • Annex A lists 93 controls (37 organisational, 8 people, 14 physical, 34 technological), 11 of them new in 2022.
  • ISO 27001:2013 certificates lost validity after 31 October 2025, so a lapsed holder now needs a full initial audit.
  • Certification runs on a three-year cycle: Stage 1 and Stage 2 audits, surveillance audits in years 2 and 3, then recertification.
  • Pivot Point Security's 2024 pricing puts a 100-employee, single-site project at $70,000 to $120,000 including the certification audit, over 6 to 12 months.
  • Microsoft's ISO 27001 certification covers Microsoft's cloud services, not your configuration, so an assessor must still evaluate your own controls.

ISO 27001 consulting services help you build the information security management system (ISMS) that an accredited certification body will certify. Consultants can't certify you, and certification bodies aren't allowed to consult for you, so the two roles always sit with different firms. Hire help for the gap analysis and risk assessment, keep ownership of the ISMS in-house, and plan for 6 to 12 months.

‍

What Is ISO 27001?

ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS), which an accredited certification body can audit and certify. The ISMS is a risk-based way to protect the confidentiality, integrity and availability of your information. ISO publishes the standard as a set of requirements the ISMS must meet, not a list of products to buy.

Annex A theme Controls New in 2022
A.5 Organisational 37 3
A.6 People 8 0
A.7 Physical 14 1
A.8 Technological 34 7
Total 93 11

The control counts come from BSI's ISO/IEC 27001:2022 transition briefing. Clauses 4 to 10 are mandatory for every organisation. Annex A works differently: you can exclude a control, but only with a written justification in your Statement of Applicability (SoA).

Certification is voluntary, but it is a common way to evidence security obligations under the EU General Data Protection Regulation (GDPR).

Two changes since 2022 matter for anyone starting now. Amendment 1:2024 added a requirement to clause 4.1: decide whether climate change is relevant to your ISMS. Under IAF MD 26, certification bodies had to move every certified organisation to the 2022 edition by 31 October 2025. ISO 27001:2013 certificates are no longer valid, and SGS confirms a lapsed holder is treated as a new client needing a full initial audit.

‍

The Role of an ISO 27001 Consultant

An ISO 27001 consultant turns the standard into your working ISMS. That means scoping it, running the risk assessment, writing the Statement of Applicability and policies, guiding implementation, and running the internal audit before the certification body arrives.

Service What you receive When
Scoping ISMS scope statement and context analysis (clauses 4.1 to 4.3) Phase 1, first
Gap analysis Gap report against clauses 4 to 10 and all 93 Annex A controls Phase 1
Risk assessment Risk method, risk register and risk treatment plan (clauses 6.1.2 and 6.1.3) Phase 1
Statement of Applicability A justified include or exclude decision for every Annex A control Phase 1, after risk treatment
Policies and procedures Information security policy (clause 5.2) and supporting procedures Phase 2
Implementation support Guidance on controls and evidence that they operate Phase 2
Awareness training Delivered sessions and training records (clause 7.3) Phase 2
Internal audit Internal audit report and corrective actions (clause 9.2) Phase 2, before Stage 1
Management review Minutes of top management's ISMS review (clause 9.3) Phase 2, before Stage 1
Audit support Stage 1 and Stage 2 readiness, and help closing nonconformities During certification

The two-phase split follows Pivot Point Security's published consulting approach. Phase 1 works out where you stand, and Phase 2 closes the gaps.

If your team has had a technical security assessment in the last year, give it to the consultant on day one. It shortens the gap analysis for the technological controls. The findings only help if they get fixed, so it's worth reading how to turn assessment findings into remediation before Phase 2 starts.

What an ISO 27001 Consultant Can't Do

A consultant advises and builds, but the accountability and the certificate sit elsewhere. A consultant cannot:

  • Issue your certificate. Only an accredited certification body can do that.
  • Own your risks or run your management review. Risk owners approve the treatment plan and accept the risk that remains (clause 6.1.3). Top management conducts the management review (clause 9.3).
  • Act as your certification body. Under ISO/IEC 17021-1 clause 5.2.5, a certification body, and any entity it controls, must not offer management system consultancy. European Accreditation's clause 5.2.5 guidance sets this out.

‍

Step-by-Step Guide to ISO 27001 Certification

Certification takes ten steps, from scoping to the Stage 2 audit. Pivot Point Security puts most projects at 6 to 12 months, depending on size and complexity. After certification come surveillance audits in years 2 and 3, and a recertification audit before the three-year certificate expires.

Step Who leads Output
1. Scope and context You, with the consultant ISMS scope statement
2. Gap analysis Consultant Gap report and remediation plan
3. Risk assessment and treatment Consultant runs the method; your risk owners decide Risk register and treatment plan
4. Statement of Applicability Consultant drafts; you approve Signed SoA
5. Implement controls and policies You Working controls, approved policies, evidence
6. Awareness training You, with consultant support Training records
7. Internal audit Consultant or an independent internal auditor Audit report and corrective actions
8. Management review Top management Review minutes and decisions
9. Stage 1 audit Certification body Readiness findings
10. Stage 2 audit Certification body Certification decision

Steps 1 to 8 stay your responsibility even when a consultant does most of the work. The certification body audits what your organisation runs, not what the consultant wrote.

Certification is a cycle, not a one-off. Between audits, keep running internal audits and management reviews at planned intervals. The surveillance audits in years 2 and 3 check a sample of the ISMS. The recertification audit reviews the whole system again.

Stage 1 vs Stage 2 Audit

Stage 1 checks whether your ISMS is designed correctly. Stage 2 checks whether it works in practice.

Audit What it checks Nonconformities
Stage 1 Documentation and design against clauses 4 to 10, and whether you are ready for Stage 2 Must be addressed before Stage 2 goes ahead
Stage 2 Evidence that the ISMS, including your selected Annex A controls, operates as documented Need corrective action plans the certification body accepts before it issues the certificate

‍

How Much Does ISO 27001 Consulting Cost, and How Long Does It Take?

Pivot Point Security's published 2024 pricing puts a 100-employee, single-site ISO 27001 project at $70,000 to $120,000, including the certification audit. Consulting makes up $50,000 to $90,000 of that, and most projects take 6 to 12 months.

Cost item What it covers Range
Phase 1 consulting Scope, risk assessment, risk treatment plan, gap assessment $30,000 to $40,000
Phase 2 consulting Gap closure, ISMS documents, internal audit, audit support $20,000 to $50,000
Certification audit Stage 1 and Stage 2, by the certification body $20,000 to $30,000
Year 1 total $70,000 to $120,000
Surveillance audit Each of years 2 and 3 $10,000 to $15,000

The figures come from Pivot Point's 2024 cost breakdown, updated in August 2026. They cover a company certifying ISO 27001 alone at one location. The certification audit is only $20,000 to $30,000 of the total, and the rest is preparation.

Adding both surveillance audits brings the three-year cycle to $90,000 to $150,000, before your own staff time. Pivot Point says about 75% of its projects fall inside these ranges. Costs run higher with more locations or more standards in scope. They run lower when your security programme is already mature or your team handles more of the remediation.

These are US prices from a US firm, so treat them as a benchmark. Get quotes from at least three consultants and three accredited certification bodies.

If your ISMS will run on Microsoft 365 and Azure, a security assessment of your Microsoft environment shows which technical controls are already in place before the gap analysis starts.

‍

ISO 27001 on Microsoft 365 and Azure: What Your Stack Already Evidences

Microsoft's ISO 27001 certification covers how Microsoft runs its cloud services, not how you configure them. The tools you already license can still produce evidence for 7 of the 11 controls added in 2022.

What You Can and Can't Inherit From Microsoft's Certificate

You can use Microsoft's certification, but not as your own. Microsoft's cloud services go through regular independent ISO/IEC 27001 audits, and the certificates and reports sit on the Service Trust Portal. Microsoft says you can use them in your assessment, but you must still engage an assessor for your own controls and processes. File them as supplier evidence under controls A.5.19 to A.5.23, which cover suppliers and cloud services. They are not proof of your own compliance.

The 11 New ISO 27001:2022 Controls, Mapped to Microsoft Tools

CyberQuell's mapping: evidence, not certification.

Control Microsoft evidence source Coverage
5.7 Threat intelligence Microsoft Sentinel and Defender XDR threat intelligence Direct
5.23 Cloud services Defender for Cloud Apps cloud discovery, Defender for Cloud Direct
5.30 ICT readiness for business continuity Azure Site Recovery test failover records Partial: tests, not the plan
7.4 Physical security monitoring None None
8.9 Configuration management Intune configuration profiles, Defender Vulnerability Management configuration assessment Direct
8.10 Information deletion Purview Data Lifecycle Management retention and deletion policies Direct
8.11 Data masking Azure SQL dynamic data masking Partial: Azure SQL data only
8.12 Data leakage prevention Purview Data Loss Prevention (DLP) Direct
8.16 Monitoring activities Microsoft Sentinel, Defender XDR Direct
8.23 Web filtering Defender for Endpoint web content filtering Direct
8.28 Secure coding None, outside Microsoft 365 None

That makes 7 direct, 2 partial and 2 with no Microsoft evidence. Microsoft retired standalone Defender Threat Intelligence on 1 August 2026 and moved it into Sentinel and Defender XDR at no extra cost. For 8.9, configuration assessment comes with Defender for Endpoint Plan 2, but security baselines assessment needs the Defender Vulnerability Management add-on. If you harden devices to a benchmark, see how to apply CIS Benchmarks in practice.

Microsoft Learn documents the other sources: 

Each remaining source is a documented Microsoft capability. Cloud discovery identifies the cloud apps your staff actually use (5.23), and Site Recovery test failovers record recovery drills without touching production (5.30). Retention and deletion policies remove content on a schedule (8.10), dynamic data masking hides sensitive columns from non-privileged users (8.11), and web content filtering blocks website categories (8.23).

Monitoring evidence for 8.16 only goes back as far as your logs do, so check how long each Microsoft 365 log source is retained.

Tracking Readiness Inside Microsoft

Two built-in tools track your ISO 27001 readiness. Purview Compliance Manager has an ISO/IEC 27001:2022 assessment template. It's a premium template, and some licences, such as Microsoft 365 E5, include up to three premium templates at no extra cost. Defender for Cloud lists ISO IEC 27001:2022 among its regulatory standards for Azure, AWS and GCP. It needs any Defender for Cloud plan except Defender for Servers Plan 1 or Defender for API Plan 1. Both score technical configuration, not your ISMS, so use them to track evidence.

‍

Choosing the Right ISO 27001 Consultant

Choose a consultant who holds ISO 27001 Lead Implementer or Lead Auditor credentials and has worked at your size and on your technology stack. They should also be independent of your certification body and sign a contract that leaves you owning every document.

Selection Criteria

Criterion What good looks like How to verify
Credentials ISO/IEC 27001 Lead Implementer or Lead Auditor Ask for certificate numbers and check them with the issuing training body
Relevant experience Projects at your headcount and in your sector Ask for two references you can call
Stack experience Has scoped an ISMS on Microsoft 365 and Azure Ask how they collect evidence from Purview and Defender
Independence Not part of, or controlled by, a certification body Get it confirmed in writing
Certification body shortlist Helps you compare accredited bodies without being one Check accreditation by a national body such as UKAS in the UK
Document ownership You own every policy, register and SoA Put an ownership clause in the contract
Post-certification support Internal audits and surveillance-year help are available Get the price in the proposal, not "on request"

Hiring a consultant moves the work, not the accountability. That's the same principle behind what stays yours when you outsource security.

Questions to Ask Before You Sign

  • Which implementations have you completed at our size and in our sector?
  • What method do you use for the gap analysis and the risk assessment?
  • Who writes the Statement of Applicability, and who approves it?
  • How will our team learn to run the ISMS after you leave?
  • Can you share a project plan with milestones?
  • How do you price changes to scope?

Red Flags

Walk away from a consultant who:

  • promises certification or a fixed short timeline before doing a gap analysis
  • offers to certify you, or routes the audit to a certification body they are connected to
  • delivers template policies with only your name added
  • leaves the internal audit out of scope
  • has no support after the Stage 2 audit

‍

ISO 27001 Consultant vs Compliance Software vs vCISO

A consultant builds the ISMS, compliance software automates evidence collection, and a virtual CISO (vCISO) provides ongoing security leadership. For a firm of 50 to 500 people, the practical split is a consultant in year one, then software or a vCISO for the surveillance years.

Option Best for What it doesn't do
Consultant Year one: scope, risk assessment, SoA, internal audit Run your controls day to day after certification, unless contracted
Compliance software Tracking controls and collecting evidence across the surveillance years Make risk decisions or define a scope that fits your business
vCISO Part-time security leadership, risk decisions, management review preparation Implement controls or collect evidence at scale

ISO 27001 requires defined security roles and responsibilities (clause 5.3), not someone with the title of CISO. That's why a vCISO can hold the role. Top management stays accountable for the ISMS under clause 5.1.

If you want the logging and monitoring evidence for controls 8.15 and 8.16 produced continuously, talk to CyberQuell about Microsoft Sentinel monitoring.

‍

Final Thoughts

Good ISO 27001 consulting services speed up scoping, risk assessment and the Statement of Applicability. They don't take ownership of the ISMS away from you. Based on Pivot Point's published ranges, budget $70,000 to $120,000 for a 100-person, single-site project, and 6 to 12 months to get certified. Keep the firm that builds your ISMS separate from the body that certifies it. If you already run on Microsoft 365 and Azure, find out what your tools evidence before the gap analysis starts, so your consultant isn't starting from zero.

Book a call with CyberQuell to scope a security assessment of your Microsoft 365 and Azure environment, so your consultant starts the gap analysis with evidence already in hand.

Last Updated:
September 24, 2026

FAQs

Find answers to commonly asked questions about our cybersecurity solutions and services.

How long does ISO 27001 certification take?

Most projects take 6 to 12 months from scoping to the Stage 2 audit, according to Pivot Point Security. The timeline depends on your size, your scope and how many security controls already work. Organisations with fewer locations and an established security programme tend to finish sooner.

‍

How much does ISO 27001 consulting cost?

Pivot Point Security's 2024 pricing puts consulting at $50,000 to $90,000 for a 100-employee company certifying one site. Adding the certification audit brings year one to $70,000 to $120,000. Surveillance audits then cost $10,000 to $15,000 in each of years 2 and 3.

‍

Can an ISO 27001 consultant certify my company?

No. Only an accredited certification body can issue an ISO 27001 certificate. Under ISO/IEC 17021-1 clause 5.2.5, a certification body, and any entity it controls, cannot consult on your management system. The consultant and the certifier are always different firms.

‍

Is ISO 27001:2013 still valid?

No. Under IAF MD 26, every ISO 27001:2013 certificate had to transition to the 2022 edition by 31 October 2025. Certificates that missed the deadline are no longer valid. Organisations that lapsed now need a full initial audit against ISO/IEC 27001:2022.

‍

Does Microsoft 365's ISO 27001 certificate make us compliant?

No. Microsoft's ISO 27001 certification covers how Microsoft runs its cloud services, not how you configure and use them. You can use it as supplier evidence, but Microsoft states you must still engage an assessor for your own controls and processes.

‍

What's the difference between ISO 27001 and ISO 27701?

ISO 27001 covers information security management. ISO 27701 covers privacy information management for organisations that handle personal data. Since the 2025 edition, ISO/IEC 27701 is a standalone standard, so you can certify to it without holding ISO 27001. If you already hold ISO 27001, the two can share one management system.

‍

What's the difference between ISO 27001 and SOC 2?

ISO 27001 ends in a certificate for your management system, issued by an accredited certification body. SOC 2 ends in an attestation report, in which an independent CPA firm examines your controls against the AICPA's Trust Services Criteria. Which one you need usually depends on what your customers ask for.

‍

Do I need a consultant to get ISO 27001 certified?

No. ISO 27001 does not require outside help, and some organisations build their information security management system entirely in-house. A consultant brings a tested method for scoping, the risk assessment and the Statement of Applicability, which usually shortens year one.

‍

Protect Your Business from Cyber Threats

Get in touch with our cybersecurity experts to discuss your security needs and solutions.