[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:implement-iso-27001-without-the-help-of-consultants":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","implement-iso-27001-without-the-help-of-consultants","Implementing ISO 27001 without consultants: what you take on, and what they were doing for the money","It is entirely possible to certify without a consultant. It is worth knowing what you are absorbing first, and which parts genuinely benefit from someone who has sat on the other side of an audit.","2026-08-20",{"who":10,"when":11,"do":12},"A company deciding whether to certify ISO 27001 with or without a consultant: the audit fee is the same either way, about 7 auditor days for a 20-person company at 1,200 to 1,800 EUR each, set by ISO\u002FIEC 27006 Annex B; what changes is the internal time and the judgement the company takes on itself.","Before the implementation is planned, since the choice sets who writes the scope and the risk assessment and who answers the auditor's questions at Stage 2, and it is hard to change once the documents exist.","Decide who inside the company owns the judgement calls, the scope, the risk method and the Statement of Applicability, do the recurring work yourselves either way, and bring in outside experience only for the parts where someone who has sat on the other side of an audit changes the outcome.","\nYou can implement ISO 27001 without a consultant, and companies do it every year. What a good consultant sells is judgement rather than documents, and the audit fee is the same either way: about 7 auditor days for a 20-person company at 1,200 to 1,800 EUR each, set by ISO\u002FIEC 27006 Annex B. Going alone changes your internal cost and the judgement you absorb, so here is the honest split rather than an argument.\n\n## What a good consultant is actually selling\n\nNot the documents. Templates are widely available and a generated policy set gets you to roughly the same place. What you are paying for is judgement, in four places:\n\n**Scope.** Getting this wrong is expensive in both directions. Too wide and you pay for auditor days you did not need. Too narrow and your customer's security team rejects the certificate because it excludes the thing they care about.\n\n**Risk assessment that survives contact.** Not the register itself, but a methodology an auditor accepts and criteria that hold up when applied consistently.\n\n**Knowing what an auditor will actually ask.** This is experience and it is difficult to acquire from documentation. It is the difference between passing Stage 2 and being told to come back.\n\n**Someone to argue with.** An outside view on whether a control is genuinely implemented or merely written down.\n\n## What you take on by going alone\n\nThe sequencing, mostly. Scope, then context and risk, then the Statement of Applicability, then run the system long enough to have records. Steps taken out of order get redone, and that is where the time goes.\n\nYou also take on the internal audit. Clause 9.2 requires one before certification and requires auditor independence: nobody audits their own work. In a small company that is genuinely hard, and it is the most common reason people bring in outside help for a single week rather than a whole programme.\n\n## The cost that does not change either way\n\nThe audit. Auditor days come from the ISO\u002FIEC 27006 Annex B chart, so a 20-person company is around 7 days at 1,200 to 1,800 EUR each whether a consultant was involved or not. [The arithmetic](\u002Fiso-27001\u002Fcost). Doing it yourself changes your internal cost, not the audit fee.\n\nAnd the recurring half does not change: surveillance audits each year, records for the period, forever. Companies that certify successfully alone are usually the ones that kept records as they went rather than assembling them before each visit.\n\n## The honest recommendation\n\nDoing it yourself is a reasonable choice, particularly if someone internal has done it before or the scope is genuinely small. Hiring help for the two hard judgements, scope and internal audit, while doing the rest yourself, is also reasonable and is what a lot of people actually do.\n\nWhat is not reasonable is deciding based on the software. No tool replaces the judgement above, and any vendor telling you otherwise is selling you the easy half. What a tool should do is make the recurring half survivable: records that exist, dated, when the auditor asks. [What ours covers, clause by clause, gaps included](\u002Fiso-27001\u002Fcoverage).\n",1789383986455]