You can implement ISO 27001 without a consultant, and companies do it every year. What a good consultant sells is judgement rather than documents, and the audit fee is the same either way: about 7 auditor days for a 20-person company at 1,200 to 1,800 EUR each, set by ISO/IEC 27006 Annex B. Going alone changes your internal cost and the judgement you absorb, so here is the honest split rather than an argument.

What a good consultant is actually selling

Not the documents. Templates are widely available and a generated policy set gets you to roughly the same place. What you are paying for is judgement, in four places:

Scope. Getting this wrong is expensive in both directions. Too wide and you pay for auditor days you did not need. Too narrow and your customer's security team rejects the certificate because it excludes the thing they care about.

Risk assessment that survives contact. Not the register itself, but a methodology an auditor accepts and criteria that hold up when applied consistently.

Knowing what an auditor will actually ask. This is experience and it is difficult to acquire from documentation. It is the difference between passing Stage 2 and being told to come back.

Someone to argue with. An outside view on whether a control is genuinely implemented or merely written down.

What you take on by going alone

The sequencing, mostly. Scope, then context and risk, then the Statement of Applicability, then run the system long enough to have records. Steps taken out of order get redone, and that is where the time goes.

You also take on the internal audit. Clause 9.2 requires one before certification and requires auditor independence: nobody audits their own work. In a small company that is genuinely hard, and it is the most common reason people bring in outside help for a single week rather than a whole programme.

The cost that does not change either way

The audit. Auditor days come from the ISO/IEC 27006 Annex B chart, so a 20-person company is around 7 days at 1,200 to 1,800 EUR each whether a consultant was involved or not. The arithmetic. Doing it yourself changes your internal cost, not the audit fee.

And the recurring half does not change: surveillance audits each year, records for the period, forever. Companies that certify successfully alone are usually the ones that kept records as they went rather than assembling them before each visit.

The honest recommendation

Doing it yourself is a reasonable choice, particularly if someone internal has done it before or the scope is genuinely small. Hiring help for the two hard judgements, scope and internal audit, while doing the rest yourself, is also reasonable and is what a lot of people actually do.

What is not reasonable is deciding based on the software. No tool replaces the judgement above, and any vendor telling you otherwise is selling you the easy half. What a tool should do is make the recurring half survivable: records that exist, dated, when the auditor asks. What ours covers, clause by clause, gaps included.