Organisations approaching ISO 27001 certification face an early decision: buy a compliance platform, engage a consultancy, or both. The short answer is that platforms suit organisations with straightforward structures and spare internal capacity, while consultancies suit complex, accountable organisations where judgement, context and audit outcomes matter most. Many organisations sensibly use both. This guide sets out what each option actually does, when each is the right choice, and the questions to ask before committing.
What does a compliance platform actually do?
A compliance platform is software that structures your ISO 27001 programme. It provides document templates, control checklists, task tracking and a central place to collect evidence for audit. Good platforms reduce administration significantly. What a platform cannot do is make judgement calls about your organisation.
Platforms are strongest at the mechanical layer of an information security management system (ISMS): policy templates mapped to the standard, automated reminders for reviews, dashboards showing completion status, and evidence repositories that keep auditors supplied. For a security lead running a programme alone, that structure has real value, and subscription pricing is typically far below consultancy fees.
The limitation is that ISO 27001 is not a form-filling exercise. The standard requires decisions: what is in scope, which risks matter, which Annex A controls apply and why, and what “acceptable risk” means for your organisation. A platform presents the questions. It cannot answer them for you, and it cannot tell you when your answer would concern an auditor.
What does an ISO 27001 consultancy actually do?
A consultancy supplies the judgement layer: scoping the management system correctly, leading risk assessment, making defensible decisions about control applicability, preparing your team for audit, and building a framework your own people can run. The output is not documents. It is an ISMS that stands up to external scrutiny.
In practice, consultancy work concentrates where organisations most often go wrong on their own. Scope drawn too wide makes certification unmanageable; drawn too narrow, it fails to cover what your clients care about. Risk assessment done mechanically produces a register nobody uses. The Statement of Applicability, the document auditors examine most closely, requires reasoning for every included and excluded control.
A good consultancy also transfers knowledge as it goes. The test of the engagement is whether your internal team understands the system well enough to own it, with the consultancy providing continuity, assurance and senior capacity rather than doing everything indefinitely.
When is a platform the right choice?
A platform alone is a reasonable choice when your organisation is structurally simple, when you have a capable person with genuine time allocated to the programme, when your risk environment is conventional, and when your certification deadline allows for learning as you go.
Honest criteria, not marketing criteria, look like this: a single-site or cloud-native business with one core product; an internal lead who has implemented a management system before, or has senior support and time to learn; customers asking for certification as a checkbox rather than probing how security actually operates; and tolerance for a longer runway while the internal team works through the standard for the first time.
If those conditions hold, a platform subscription is an economical route, and nothing in this article should talk you out of it.
When is a consultancy the right choice?
Engage a consultancy when the organisation is complex or heavily accountable, when the audit outcome carries commercial weight, when no internal person can give the programme sustained senior attention, or when a previous audit went badly. In these situations, judgement and experience determine the result more than tooling does.
Complexity takes many forms: multiple entities or sites, regulated sectors, layered supply chains, legacy infrastructure alongside cloud services, or client contracts that impose specific security obligations. Accountability raises the stakes further. When a major client, regulator or board is watching the outcome, a first-attempt certification with a clean audit matters.
Evidence is the fairest way to weigh this. Across all Secure Step Forward client audits, external auditors have raised zero major nonconformities. Behind that sits an effectiveness discipline: more than 1,400 requirements and controls assessed at internal audit, each scored on how well it is working rather than whether it merely exists, with an average score of 92 across active engagements. One client relationship, with Colliers, has run for more than four years and produced zero findings at the most recent recertification. Outcomes of that kind are a function of senior people applying judgement inside a framework over time, which is precisely what tooling alone does not provide.
Can you use both?
Yes, and the combination is often the strongest arrangement. The platform handles structure, evidence and workflow; the consultancy handles scoping, risk judgement, audit preparation and assurance. The practical requirement is a consultancy that is fluent in your chosen platform without being dependent on any one of them.
Platform-fluent rather than platform-dependent matters for a simple reason: your tooling should be chosen for your organisation, not for your adviser’s convenience. A consultancy tied to a single platform has an incentive to fit your programme to its software. An independent consultancy can work inside whatever tooling you already run, or none, and advise on tooling selection without a stake in the answer.
What should you ask any provider before choosing?
Whichever route you take, five questions separate credible providers from confident websites. First, what were your clients’ results at their last external audits? Second, who exactly will work on our programme, and for how long? Third, how do you measure whether controls are working, not just documented? Fourth, what happens at the end of the engagement, and could our team run the system without you? Fifth, how do you handle changes to the standard, such as the transition to ISO 27001:2022?
The first question is the sharpest. Audit results are the one outcome that cannot be dressed up, and any provider doing good work will answer it directly with numbers. The fourth question tests for dependency: the right answer describes knowledge transfer to your internal team built in from the start. The fifth tests proactivity, because standards change on the standard’s schedule, not yours, and a partner should assess the impact and act without being asked.
Frequently asked questions
Is a compliance platform enough to get ISO 27001 certified?
Yes, organisations do certify using platforms alone. Success depends on internal capacity and complexity. The certification body audits your management system, not your software, so the judgement calls embedded in scoping, risk assessment and the Statement of Applicability still have to be made well by someone.
Is a consultancy more expensive than a platform?
Usually, over the same period, yes. The fair comparison is against outcomes and internal time. A platform is cheaper per month but consumes more internal hours and carries more first-attempt risk in complex organisations. Weigh total cost, including your team’s time and the commercial cost of a failed or delayed audit.
How long does ISO 27001 certification take?
Typically six to twelve months from a standing start, depending on scope, complexity and internal availability. Organisations with strong existing security practice move faster. The certification audit itself is conducted in two stages by an accredited certification body listed with UKAS or an equivalent national body.
Do we still need internal effort if we hire a consultancy?
Yes. A management system describes how your organisation actually operates, so your people must be involved in building and running it. A consultancy that offers to do everything without your team is building dependency, not capability.
Where does your organisation stand today?
The free self-assessed Readiness Check shows how your current arrangements measure against ISO 27001, in your own time and without obligation. Start the Readiness Check, or see how we approach ISO 27001.