Braucht man für die ISO 27001-Zertifizierung einen externen Berater?
No, an external consultant is not mandatory. ISO 27001 does not prescribe who builds the Information Security Management System (ISMS). You can achieve certification entirely with internal resources. Consulting and implementation may be carried out by your own team or by external consultants. The external certification audit, by contrast, must always be performed by an independent, accredited certification body, which for reasons of independence is not allowed to also act as your consultant.
The internal audit carries one further restriction. You can outsource it, but not to the same person who built the ISMS, because auditors must not audit their own work. For the full process, read the complete guide to ISO 27001 certification. For proof that certifying in-house works, see how Bliro did it.
Do it yourself or get support?
| Approach | Advantages | Challenges |
|---|---|---|
| Fully in-house | Lower external costs, full build-up of internal knowledge, full control | High time investment, requires knowledge of the standard, mistakes often extend the project |
| External consultant | Experience, faster implementation, avoidance of typical mistakes | Cost, dependency, knowledge may leave the company once the project ends |
| Hybrid (platform plus experts) | Automation of routine work, expert knowledge where it counts, knowledge stays in-house | Ongoing licence costs, your team still has to invest time, requires choosing the right provider |
When external support is worth it
External support is particularly worthwhile when one or more of the following apply:
- Limited time: an upcoming customer contract or audit date calls for speed.
- Lack of experience with the standard: no one on the team has built an ISMS before.
- Limited internal capacity: the team cannot take on the work on top of day-to-day operations.
- First-time certification: the requirements are hardest to gauge the first time around.
A purely in-house approach works well when sufficient time, existing security maturity, and internal knowledge of the standard come together. If one of these is missing, experience shows the project tends to take considerably longer. What ISO 27001 requires in detail is what determines the actual effort.
How Kertos combines platform and experts
Kertos combines the two approaches from the table above. A compliance platform with AI support (KAIA) handles the routine work, and certified in-house experts work alongside your team:
- Platform for the routine work: gap analysis, risk assessment, the SoA, and evidence collection are automated rather than created manually.
- Experts where it counts: the Kertos specialists support questions of interpretation, the internal audit, and preparation for the external audit, including external CISO mandates.
- Knowledge stays with you: instead of dependency on a consultant, you end up with a lasting, lived ISMS you can keep using.
- Independence preserved: Kertos prepares you for the audit, while the external certification audit is still carried out by an independent body.
The outcome is reflected in Kertos's track record: a 100% audit pass rate, roughly 80% less manual compliance effort, a customer satisfaction of 98%, and customers like AskUI reaching ISO 27001 certification in just 8 to 10 weeks. This keeps control in-house without you having to shoulder the entire effort alone.
When Kertos is not the right choice
If you deliberately want pure self-service with no expert contact and your team already knows the standard well, a lean tool-only solution will be cheaper. If you need a one-off, clearly bounded project with no ongoing operation afterwards, traditional consulting may fit better. Kertos pays off where the ISMS has to be lived day to day and maintained through annual surveillance audits.
Frequently asked questions
Can the certification body also provide consulting?
No. The accredited certification body that performs your external audit is not allowed to advise you at the same time. That separation is what makes the audit independent, and therefore what makes the certificate valid.
How much does an ISO 27001 consultant cost?
The range is wide and depends mainly on three things: the maturity of your existing security measures, the scope you define, and whether the engagement includes the internal audit. Always ask for effort to be broken down by project phase rather than quoted as a lump sum, otherwise proposals cannot be compared.
How long does ISO 27001 certification take without a consultant?
Without external support, expect considerably more internal time, especially for a first certification. The decisive factor is less whether you use a consultant and more whether anyone on the team already knows the standard.
How do I find the right ISO 27001 consultant?
Look at whether the provider has experience in your industry and at your company size, whether they also offer the internal audit, and how they ensure knowledge transfer to your team. Clarify early who runs the ISMS day to day once certification is achieved.
Next step
In a 5-minute compliance check we'll work out together which of the three approaches fits your starting position.
Discover our Resources
Find useful whitepapers, videos, and practical tools to help you efficiently achieve your compliance goals.

