← All insights

ISO 27001 · Buyer's guide

How to choose an ISO 27001 consultant.

Seven questions that separate genuine specialists from generic compliance shops — and the red flags worth walking away from.

Why this choice matters more than it looks

ISO 27001 certification is now a precondition for most enterprise procurement. The standard itself is stable; the market of people selling help with it is not. Buyers face a spectrum from £400-a-month software tools through to seven-figure transformation programmes, and the differences are not always visible from a website.

The right consultant earns back their fee in audit time saved, scope kept tight, and a management system the business actually operates afterwards. The wrong one leaves a binder, a bill, and an ISMS that frays at the first surveillance visit.

The four profiles you will meet

ISMS.online, Vanta, Drata

The compliance platform

Software-led. Strong for organisations that want a tool and have someone in-house to drive it. Less suited when the bottleneck is judgement rather than documentation.

Zelt, startup blogs

The HR-tech-adjacent listicle

Useful directories, but the recommendations are usually surface-level and skewed toward whoever pays for placement. Treat as a starting point, not a shortlist.

Big-four and mid-tier audit firms

The large generalist consultancy

Deep bench, broad scope, premium price. Often the right fit for regulated enterprises; usually overkill for a 50-person SaaS business.

Independent firms focused on ISO standards

The specialist boutique

Senior practitioners doing the work, fixed scope, narrow focus. The right fit when you want certification delivered, a system you can operate, and a partner you can keep through 27701 and 42001.

Seven questions to ask in the first call

  1. Question 01

    Are they UKAS-aware, and do they understand your certification body?

    UKAS-accredited certificates are the only ones that hold weight in tenders and supply-chain due diligence. A good consultant will tell you which certification body suits your sector, what that body's auditors typically focus on, and how to avoid surprises in Stage 1.

  2. Question 02

    Do the people doing the work hold Lead Auditor and Lead Implementer credentials?

    Firm-level certification is one signal, but the one that actually matters is who sits across the table from you. Insist on named practitioners who hold accredited ISO 27001 Lead Auditor and Lead Implementer qualifications, have built ISMSs end-to-end, and have sat through UKAS Stage 1 and Stage 2 audits on the client side. Credentialled people build defensible programmes; a logo on a website does not.

  3. Question 03

    Can they show evidence of certifications delivered — not just engagements run?

    Ask for the number of clients certified in the last twenty-four months, the certification bodies involved, and references you can speak to. A consultant unwilling to put you in touch with a recent client is telling you something.

  4. Question 04

    Do they understand the standards that sit alongside 27001?

    ISO 27701 (privacy), ISO 42001 (AI), SOC 2, NIST CSF and the EU AI Act increasingly arrive together. A consultant who treats 27001 as an island will build a system you outgrow within a year.

  5. Question 05

    Is the scope fixed, and is the price fixed against it?

    Open-ended day rates are how three-month engagements become nine-month ones. A credible firm will scope the work, fix the price, and tell you in writing what triggers a change request.

  6. Question 06

    Who actually does the work?

    Some firms sell with senior partners and deliver with juniors. Ask who will be on-site, who will draft your policies, and who attends the Stage 2 audit. Insist on names.

  7. Question 07

    Do they leave a system you can operate, or one you depend on them for?

    The point of certification is a working management system, not a binder of documents. A good consultant trains your team, hands over the rhythms, and leaves you able to pass surveillance without them.

Six red flags

  • They offer to act as both your consultant and your certification body. This is a UKAS conflict of interest.
  • They promise certification in under eight weeks for an organisation with no existing security function.
  • Their proposal is dominated by template documents rather than implementation work.
  • They cannot name the auditor or the certification body they recommend.
  • The named delivery lead is not a qualified ISO 27001 Lead Auditor or Lead Implementer.
  • They quote a day rate without a fixed scope or fixed price.

A note on stacked standards

ISO 27001 rarely arrives alone in 2026. Privacy obligations (ISO 27701, UK GDPR), AI governance (ISO 42001, the EU AI Act) and customer-driven frameworks (SOC 2, NIST CSF) usually follow within a year. A consultant who builds a 27001 system that cannot extend to those is selling you rework.

The cheapest path to three certificates is to architect for all three from the start. Ask whether your shortlist has actually delivered that combination.

Next step

Use these questions on us

A short confidential scoping call will tell you, within a week, whether Quaesta is the right fit — and, if we are not, who in the market is.