{ "@type": "Article", "@id": "https://www.kertos.io/en/compliance-hub/consultant-iso-27001-certification#article", "headline": "Do you need an external consultant for an ISO 27001 certificate?", "description": "Is an external consultant mandatory for passing ISO 27001, or can you do it yourself? Learn when support is worth it and how Kertos combines a platform with experts so knowledge and control stay in-house.", "url": "https://www.kertos.io/en/compliance-hub/consultant-iso-27001-certification", "mainEntityOfPage": "https://www.kertos.io/en/compliance-hub/consultant-iso-27001-certification", "inLanguage": "en", "dateModified": "2026-08-02", "author": { "@type": "Organization", "name": "Kertos", "url": "https://www.kertos.io" }, "publisher": { "@type": "Organization", "name": "Kertos", "url": "https://www.kertos.io", "logo": { "@type": "ImageObject", "url": "https://cdn.prod.website-files.com/678fa5c02d217f5cd1419991/679b50438fee9f028e99dfb7_Logotype.svg" } }, "about": { "@type": "Thing", "name": "ISO 27001 certification" } }

Braucht man für die ISO 27001-Zertifizierung einen externen Berater?

No, an external consultant is not mandatory. ISO 27001 does not prescribe who builds the Information Security Management System (ISMS). You can achieve certification entirely with internal resources. Consulting and implementation may be carried out by your own team or by external consultants. The external certification audit, by contrast, must always be performed by an independent, accredited certification body, which for reasons of independence is not allowed to also act as your consultant.

The internal audit carries one further restriction. You can outsource it, but not to the same person who built the ISMS, because auditors must not audit their own work. For the full process, read the complete guide to ISO 27001 certification. For proof that certifying in-house works, see how Bliro did it.

Do it yourself or get support?

Approach Advantages Challenges
Fully in-house Lower external costs, full build-up of internal knowledge, full control High time investment, requires knowledge of the standard, mistakes often extend the project
External consultant Experience, faster implementation, avoidance of typical mistakes Cost, dependency, knowledge may leave the company once the project ends
Hybrid (platform plus experts) Automation of routine work, expert knowledge where it counts, knowledge stays in-house Ongoing licence costs, your team still has to invest time, requires choosing the right provider

When external support is worth it

External support is particularly worthwhile when one or more of the following apply:

  • Limited time: an upcoming customer contract or audit date calls for speed.
  • Lack of experience with the standard: no one on the team has built an ISMS before.
  • Limited internal capacity: the team cannot take on the work on top of day-to-day operations.
  • First-time certification: the requirements are hardest to gauge the first time around.

A purely in-house approach works well when sufficient time, existing security maturity, and internal knowledge of the standard come together. If one of these is missing, experience shows the project tends to take considerably longer. What ISO 27001 requires in detail is what determines the actual effort.

How Kertos combines platform and experts

Kertos combines the two approaches from the table above. A compliance platform with AI support (KAIA) handles the routine work, and certified in-house experts work alongside your team:

  • Platform for the routine work: gap analysis, risk assessment, the SoA, and evidence collection are automated rather than created manually.
  • Experts where it counts: the Kertos specialists support questions of interpretation, the internal audit, and preparation for the external audit, including external CISO mandates.
  • Knowledge stays with you: instead of dependency on a consultant, you end up with a lasting, lived ISMS you can keep using.
  • Independence preserved: Kertos prepares you for the audit, while the external certification audit is still carried out by an independent body.

The outcome is reflected in Kertos's track record: a 100% audit pass rate, roughly 80% less manual compliance effort, a customer satisfaction of 98%, and customers like AskUI reaching ISO 27001 certification in just 8 to 10 weeks. This keeps control in-house without you having to shoulder the entire effort alone.

When Kertos is not the right choice

If you deliberately want pure self-service with no expert contact and your team already knows the standard well, a lean tool-only solution will be cheaper. If you need a one-off, clearly bounded project with no ongoing operation afterwards, traditional consulting may fit better. Kertos pays off where the ISMS has to be lived day to day and maintained through annual surveillance audits.

Frequently asked questions

Can the certification body also provide consulting?

No. The accredited certification body that performs your external audit is not allowed to advise you at the same time. That separation is what makes the audit independent, and therefore what makes the certificate valid.

How much does an ISO 27001 consultant cost?

The range is wide and depends mainly on three things: the maturity of your existing security measures, the scope you define, and whether the engagement includes the internal audit. Always ask for effort to be broken down by project phase rather than quoted as a lump sum, otherwise proposals cannot be compared.

How long does ISO 27001 certification take without a consultant?

Without external support, expect considerably more internal time, especially for a first certification. The decisive factor is less whether you use a consultant and more whether anyone on the team already knows the standard.

How do I find the right ISO 27001 consultant?

Look at whether the provider has experience in your industry and at your company size, whether they also offer the internal audit, and how they ensure knowledge transfer to your team. Clarify early who runs the ISMS day to day once certification is achieved.

Next step

In a 5-minute compliance check we'll work out together which of the three approaches fits your starting position.

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check