Roles explained

Certification body vs consultant vs platform

Three different vendors, three different jobs. Confusing them is the most expensive mistake in the ISO 27001 market.

Certification bodyConsultantCompliance platform
JobAudits your ISMS and issues the certificateHelps you build the ISMSAutomates evidence collection and documentation
Can issue a certificate?Yes — the only one that canNoNo
Credential to checkAccreditation (UKAS, ANAB, DAkkS, RvA)Lead Auditor / Lead Implementer experienceCustomer references, integrations
Typical cost$8K–$25K+ audit fees (published ranges)Varies widely; £2k–£8k for small-org gap work (published UK data)$5k–$30k/yr (published ranges)
Independence ruleCannot consult on the ISMS it certifiesCannot certify what it builtN/A

The rule that matters

Accreditation rules forbid a certification body from consulting on the ISMS it certifies. If one company offers to "do it all" — build your ISMS and issue the certificate — that certificate's independence is compromised, and sophisticated buyers will treat it that way. Hire the consultant to build, the CB to judge.

What most companies actually buy

  1. Platform or templates for policies, evidence, and the SoA — the documentation grind.
  2. Consultant (optional) for gap assessment, risk assessment, and internal audit — the expertise gap.
  3. Certification body for Stage 1, Stage 2, surveillance, and recertification — the certificate.
Beware the bundled pitch. Some vendors sell "certification included" packages where the certifying entity is obscure or unaccredited. Always verify the CB's accreditation separately — that's the part that makes the certificate real.

Talk to the certifiers

Get scoped quotes from accredited CBs — free, 2 minutes.

Get a free quote