Roles explained
Certification body vs consultant vs platform
Three different vendors, three different jobs. Confusing them is the most expensive mistake in the ISO 27001 market.
| Certification body | Consultant | Compliance platform | |
|---|---|---|---|
| Job | Audits your ISMS and issues the certificate | Helps you build the ISMS | Automates evidence collection and documentation |
| Can issue a certificate? | Yes — the only one that can | No | No |
| Credential to check | Accreditation (UKAS, ANAB, DAkkS, RvA) | Lead Auditor / Lead Implementer experience | Customer references, integrations |
| Typical cost | $8K–$25K+ audit fees (published ranges) | Varies widely; £2k–£8k for small-org gap work (published UK data) | $5k–$30k/yr (published ranges) |
| Independence rule | Cannot consult on the ISMS it certifies | Cannot certify what it built | N/A |
The rule that matters
Accreditation rules forbid a certification body from consulting on the ISMS it certifies. If one company offers to "do it all" — build your ISMS and issue the certificate — that certificate's independence is compromised, and sophisticated buyers will treat it that way. Hire the consultant to build, the CB to judge.
What most companies actually buy
- Platform or templates for policies, evidence, and the SoA — the documentation grind.
- Consultant (optional) for gap assessment, risk assessment, and internal audit — the expertise gap.
- Certification body for Stage 1, Stage 2, surveillance, and recertification — the certificate.
Beware the bundled pitch. Some vendors sell "certification included" packages where the certifying entity is obscure or unaccredited. Always verify the CB's accreditation separately — that's the part that makes the certificate real.
Talk to the certifiers
Get scoped quotes from accredited CBs — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.