Choosing an ISO 27001 consultant is a harder procurement decision than most buyers expect. The market contains firms with meaningfully different delivery models, pricing structures, and post-certification expectations. A buyer optimising on day rate alone ends up with an open-ended engagement that costs several times the initial estimate. A buyer optimising on brand recognition alone ends up paying Big 4 rates for associate-level delivery. A buyer optimising on speed alone ends up with a certificate and a thin ISMS that fails first surveillance.
This piece is a practical guide to procuring ISO 27001 implementation support. It covers how to scope the engagement correctly, what to look for in a consultancy's delivery model, the commercial questions worth asking up front, the warning signs that predict trouble, and how to evaluate bids from firms with materially different pricing structures.
Scope the engagement before you go to market
The most expensive mistake in ISO 27001 procurement is going to market without scope clarity. Buyers who ask "please quote to implement ISO 27001" get back either inflated quotes from firms pricing risk, or artificially low quotes from firms pricing hope. Neither serves the buyer.
Before approaching firms, establish five things.
The certification scope you actually need. This is driven by your commercial purpose. If a prime contractor is asking for ISO 27001 covering your defence work, the scope is the defence work plus supporting infrastructure. If a regulator is asking for ISO 27001 covering your AI product line, the scope is the AI product line plus supporting infrastructure. Not the whole business unless the whole business is the commercial driver.
Your starting position. Do you hold Cyber Essentials Plus? Do you have existing information security policies? Is there a nominated security lead, or is this greenfield? Be honest about this in diagnostic calls. Firms will scope based on what you tell them, and under-stating maturity leads to under-priced engagements that slip, while over-stating maturity leads to sticker shock at Stage 2 when gaps surface.
Your target timeline. Is there a commercial deadline (a contract renewal, a bid submission, a JOSCAR reassessment) driving this? If so, state it. A firm that cannot deliver against your timeline should decline the work, not quote you for an optimistic one.
Your budget reality. You do not need to disclose a figure, but you need to know what the organisation can genuinely commit to. A Tier 2 defence supplier with twenty staff cannot absorb a six-figure Big 4 engagement without straining the business. Firms pricing appropriately for that scale exist; they are not the Big 4.
Your governance structure. Who owns information security in the business? Who signs off on policies? Who will chair the management review? A firm asking these questions in discovery is signalling they understand ISO 27001 is a management system engagement. A firm not asking is signalling they will treat it as a technical project.
What to look for in delivery model
Consultancies delivering ISO 27001 fall into three broad archetypes, and they serve different buyer needs.
The first archetype is the Big 4 and large tier-one consultancies. They bring brand recognition, deep methodology, and large delivery teams. The typical engagement profile is a senior partner at the opening call, a junior engagement manager running day-to-day delivery, and associate-level consultants doing the documentation work. The pricing reflects the overhead structure, not the practitioner hours. For large enterprise buyers with six- or seven-figure budgets and complex multi-jurisdiction scopes, this is appropriate. For SME and mid-market buyers it typically is not.
The second archetype is the volume cyber consultancy. These firms run standardised implementation playbooks across many clients in parallel. Pricing is aggressive. Delivery quality varies sharply by which consultant you are assigned. Engagements typically run fixed-scope with limited deviation, which is fine if your situation fits the playbook and problematic if it does not. Ideal for organisations with straightforward scope and limited internal bandwidth to direct the engagement.
The third archetype is the boutique practitioner-led firm. Typically one to five senior operators. Lower overhead, no junior hand-off, fixed-scope engagements with practitioners who remain on the work from scope through to certification. Pricing sits between volume and Big 4, but the practitioner seniority is meaningfully higher than either. Right fit for SME and mid-market buyers who want senior hands on the work and do not want to pay Big 4 rates for associate-level delivery.
Each archetype has legitimate use cases. The procurement decision is about matching the archetype to the engagement, not picking the cheapest or the most branded.
The most expensive mistake in ISO 27001 procurement is going to market without scope clarity. Buyers who ask for an open-ended implementation quote get back either inflated quotes pricing risk or artificially low quotes pricing hope.
Commercial questions worth asking
Diagnostic calls are the buyer's main tool for evaluating the firm. The questions worth asking are the ones that reveal how the firm actually operates, not the ones that prompt rehearsed answers.
Ask who will deliver the work on a day-to-day basis. Not who will be at the opening call. Not who the relationship partner is. Who will be in your office, on your calls, writing your policies, attending your management reviews. If the answer is "it depends who is available," that tells you something. If the answer is a specific person with named relevant experience, that tells you something else.
Ask for fixed scope with a fixed price. Not a day rate with an estimated number of days, because those estimates exist to be exceeded. A firm that will not commit to fixed scope is a firm that is not confident it can scope the work, or a firm that benefits commercially from scope creep. Both are warning signs. A firm that says "we will scope it in Phase 1 and commit to fixed price for Phase 2" is appropriate; they are not asking you to commit to a price before the work is understood.
Ask what happens if new scope emerges during implementation. A credible answer is: "We tell you, we re-quote, you decide whether to proceed." An evasive answer ("We'll handle it within the envelope") means either the firm is absorbing cost (unsustainable) or the envelope was inflated to begin with (you overpaid).
Ask about post-certification support. ISO 27001 is a three-year certificate with annual surveillance audits. If the firm's engagement ends at Stage 2 audit pass, you will be building ongoing ISMS operation yourself from cold. If the firm offers an Ongoing Support phase (retainer, advisory, quarterly management review support) that continuity is a meaningful positive for most buyers. Our own three-phase model is structured this way deliberately.
Ask for references from completed engagements in your sector. A defence supplier reference is meaningful if you are a defence supplier. A financial services reference is meaningful if you are financial services. A generic enterprise reference is less meaningful. Any credible firm can provide two or three relevant references.
Ask about failure cases. How many of their engagements have failed Stage 2 audit? How many have had major non-conformities? A firm claiming 100% first-time pass is either very small (so the sample size is misleading) or not telling the truth. A firm with an honest answer ("we have had two minor non-conformities in the last eighteen months, both addressed within thirty days") is a firm that understands the work.
Warning signs that predict trouble
Certain patterns emerge repeatedly in engagements that go wrong.
A proposal that leads with day rates without fixed scope. This is the default commercial structure of firms that benefit from billable hours without accountability to outcome. For a defined engagement with a defined endpoint (certification) there is no good reason not to commit to fixed scope and fixed price after an initial gap assessment.
A proposal that promises certification in four to six weeks from a standing start. ISO 27001 implementation from a low maturity baseline takes three to six months to do properly. A four-to-six week promise either assumes the organisation is already materially more mature than it is, or assumes the consultancy will do thin documentation work that will not stand up at Stage 2.
A proposal that does not engage senior leadership from the organisation. ISO 27001 is a management system standard. If a consultancy proposes an engagement that keeps senior leadership out of the process (no management reviews, no policy sign-off by the board, no executive-level engagement) the ISMS being built is not the ISMS the standard requires.
A proposal that does not mention the Statement of Applicability in any detail. The SoA is the central document of an ISO 27001 ISMS. A consultancy that does not foreground its SoA approach is a consultancy that may treat the SoA as a template exercise, which it is not.
A delivery team where you cannot identify who is accountable for the work. Large teams with unclear accountability structures produce diffused ownership, which produces thin ISMS outputs. A named senior practitioner accountable end-to-end is materially better than a matrixed delivery pod.
Evaluating bids from firms with different pricing structures
Comparing a Big 4 proposal against a boutique practitioner proposal against a volume cyber proposal on price alone is meaningless; the three firms are selling different products.
The comparison that works is total cost of ownership over three years, factoring in implementation cost, ongoing support or retainer, surveillance audit preparation, and time cost on internal leadership.
A Big 4 implementation at £80,000 with no ongoing support plus £25,000/year of internal leadership time to maintain the ISMS is £155,000 over three years. A boutique practitioner implementation at £30,000 with £700/month ongoing support plus £10,000/year of internal leadership time is £85,000 over three years. A volume cyber implementation at £18,000 with no ongoing support and £30,000/year of internal leadership time to rebuild the thin ISMS is £108,000 over three years.
These are illustrative numbers, not quotes, but the shape holds: the headline implementation price is typically a minority of total cost of ownership. A bid that looks cheap at the top often is not cheap after ongoing effort is accounted for. A bid that looks expensive at the top sometimes is genuinely expensive and sometimes is pricing in ongoing continuity that the cheaper bid does not include.
When evaluating bids, ask each firm to quote the three-year profile explicitly: implementation, ongoing support, and expected internal effort. The firms that cannot answer that are the firms selling you only the implementation. The firms that can are the firms thinking about the full engagement.
Closing
ISO 27001 procurement benefits from the same discipline as any other professional services procurement: scope before market, match firm archetype to engagement need, commit to fixed scope and fixed price after gap assessment, insist on practitioner-led delivery continuity, and evaluate on three-year total cost rather than headline implementation price.
Buyers who do this end up with certificates that pass first-time, ISMS operational rhythm that holds up at surveillance, and commercial relationships they would engage again. Buyers who do not typically end up with a certificate, a thin ISMS, and a sense that they paid more than they should have for an outcome less durable than they needed.
If you are scoping an ISO 27001 procurement and want a practitioner-led gap assessment to establish scope and sizing before you go to market, we run Phase 1 Gap Assessments designed exactly for this stage.
