ISO 27001 consultant · Gap analysis · Certification readiness

ISO 27001 consultant · a senior security lead to take you to certification

An ISO 27001 consultant builds and runs the information security management system (ISMS) the standard requires: the scope, the risk assessment, the Statement of Applicability, the controls, the internal audit and the management review. We place a senior practitioner, a fractional or interim CISO, who runs that work inside your business until the certification audit.

We are not a certification body and we do not certify. An independent certification body audits you. To hire an ISO 27001 consultant through us, brief us on the scope; we send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after five-stage vetting.

How a brief runswhat we undertake

  1. 01Brief30-MINUTE SCOPING CALLDay 0
  2. 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
  3. 03InterviewsYOU MEET THE SHORTLISTYour diary
  4. 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
  5. 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief

Shortlist3–5

3–5
Shortlist · with pay or day rate, availability and IR35 set out
5
Vetting · stages before a candidate reaches you

15 minutes · video or phone

Book 15 minutes to hire an ISO 27001 consultant

Tell us the scope and the days a week. We come back with ISO 27001 Consultant candidates, their day rates and availability.

  1. 0115 minutes, video or phone
  2. 02We scope the role and the days a week
  3. 03A shortlist of 3–5 after the call
  4. 04Fractional, interim and permanent briefs
Prefer email? Use the booking page →

Pick a day that suits · live availability

Live security leadership roles

Fractional recruitment works differently from a permanent search — shorter, scoped by days a week, and priced on the engagement. Send a ISO 27001 Consultant brief and we come back with a shortlist of three to five vetted candidates.

01/ the role

ISO 27001 consultant: what the security lead does

ISO/IEC 27001 sets the requirements for an information security management system: a way of running security as a managed process rather than a set of tools. An ISO 27001 consultant does the work of building that system with your people, then keeps it running until an auditor can test it. On our briefs that consultant is a senior security lead, usually a fractional or interim CISO, who owns the programme rather than handing you templates.

Scope and context

The lead agrees what the ISMS covers: which parts of the business, which sites, which systems and which data. A scope that matches what your customers are asking about is easier to certify and more useful afterwards. They also record the interested parties and their requirements, such as customer contracts and the law.

Risk assessment and treatment

The core of the standard is a risk assessment: what could go wrong with the confidentiality, integrity and availability of your information, how likely it is, and how much it would hurt. Each risk gets an owner and a treatment. The same thinking sits behind the UK GDPR security principle, which the ICO describes as appropriate technical and organisational measures based on an analysis of risk.

Statement of Applicability and controls

The Statement of Applicability lists the Annex A controls, says whether each one applies, and gives the reason. In the 2022 edition the controls are grouped as organisational, people, physical and technological. The lead writes the policies that matter, puts the controls in place with the teams who operate them, and keeps the evidence an auditor will ask to see.

Internal audit and management review

Before a certification body arrives, the ISMS has to show it checks itself. The lead arranges an internal audit by someone independent of the work audited, then takes the results to a management review, where the leadership team looks at performance, risks and improvements and records its decisions. The NCSC’s Cyber Security Toolkit for Boards is a useful companion for that board-level conversation.

02/ scope

ISO 27001 certification: how it works

ISO 27001 certification is a written assurance, from an independent certification body, that your ISMS meets the standard. ISO writes the standard; it does not perform certification or issue certificates. The current version is ISO/IEC 27001:2022.

The certification body audits in two stages

Certification bodies work to ISO/IEC 17021-1, which sets requirements for their competence and impartiality. The audit comes in two stages. Stage 1 reviews your documentation and readiness: the scope, the risk assessment, the Statement of Applicability. Stage 2 tests whether the ISMS actually runs as written, by interviewing people and sampling evidence. After certification the body returns for surveillance audits, and the certificate is renewed by a recertification audit.

Accreditation: check the certification body

In the UK, certification bodies are accredited by UKAS, the national accreditation body appointed by government. Accreditation is independent confirmation that the certification body is competent. You can search UKAS accredited organisations before you choose one. ISO’s own guidance is to evaluate several certification bodies and check their accreditation.

Who does what

Your security lead builds and runs the ISMS and prepares you for the audit. The certification body audits it and decides. The two roles are kept apart: the certification body is independent of you and of anyone who helped build your system. We are not a certification body, we do not certify, and we do not promise an outcome or a date.

How to hire an ISO 27001 consultant

Write down why you want certification (a customer contract, a tender, a board decision), the scope you have in mind, and who will own security once the lead steps back. Decide whether you need someone for part of the week over a longer run, which is fractional, or full-time for a fixed period, which is interim. Take references from people the candidate has taken through certification before. We send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after our five-stage vetting.

03/ vetting

How we vet ISO 27001 consultants

What we undertake on every brief, before a candidate reaches you.

  1. 01

    Qualification screen

    Verify ISO 27001 Consultant tenure, sector context and stage fit.

    SOURCING
  2. 02

    Mandate fit

    Match to your situation — stage, board dynamics, timing.

    MATCHING
  3. 03

    Reference deep-dive

    We take references ourselves, from recent past clients — real outcomes, not titles.

    VERIFY
  4. 04

    Shortlist

    Three to five candidates with day rate, availability and IR35 position set out.

    SHORTLIST OF 3–5

04/ iso 27001 gap analysis

ISO 27001 gap analysis: where you are against the standard

An ISO 27001 gap analysis compares how you run security today with what the standard requires. The lead works through the management system requirements (context, leadership, planning, support, operation, performance evaluation and improvement) and then the Annex A controls, and records for each one whether you meet it, partly meet it, or do not.

The output is a list of gaps, each with an owner, an order of work and the evidence that will close it. A good gap analysis also tells you which gaps matter for your scope and which do not, so you do not build controls you will then exclude in the Statement of Applicability.

It is also the best way to test a candidate. Ask them how they would run your gap analysis, who they would interview and what they would want to see. The answer tells you more than a list of past certifications. If a customer is asking for a lighter baseline first, the government-backed Cyber Essentials scheme is a separate certification; our cyber security assessment page covers the difference.

05/ fractional CISO for ISO 27001

Fractional CISO for ISO 27001: a security lead who stays after the audit

A fractional CISO for ISO 27001 leads the programme for part of the week, then stays on to run the ISMS once you are certified. That matters because certification is not the end: the surveillance audits test whether the system is still working. See our hub to hire a fractional CISO, or read what a CISO does to set the scope.

If you would rather have a remote, part-time security lead, the model is often called a virtual CISO. If the deadline is close and the work needs someone full-time, an interim CISO is the better fit. Either way, the same person should not also audit their own work; the internal audit needs someone independent of it.

If the lead works through their own company, the off-payroll working rules (IR35) may apply. Status is decided by how the engagement runs, and a medium or large client makes the determination. Our IR35 guide sets out the tests.

06/ questions

ISO 27001 consultant FAQ

The questions people ask before bringing in an ISO 27001 consultant.

Builds and runs the information security management system the standard requires: agrees the scope, runs the risk assessment, writes the Statement of Applicability, puts controls in place with your teams, arranges the internal audit and takes the results to management review. On our briefs this is a senior security lead, usually a fractional or interim CISO.

An independent certification body audits your ISMS in two stages: stage 1 reviews documentation and readiness, stage 2 tests whether the system runs as written. In the UK, check the certification body is accredited by UKAS. The current version of the standard is ISO/IEC 27001:2022.

No. We are not a certification body and we do not certify. We place the senior practitioner who prepares you; an independent, accredited certification body audits you and decides. ISO itself does not certify either.

A comparison of how you run security today with the requirements of the standard and its Annex A controls. The output is a list of gaps, each with an owner and the evidence that will close it. It is usually the first piece of work a security lead does.

A fractional CISO suits a business that needs senior security leadership for part of the week and wants the same person to run the ISMS after certification. See how to hire a fractional CISO, or a virtual CISO for remote cover.

Write down why you need certification, the scope and who will own security afterwards. Decide between fractional and interim. Take references from people the candidate has taken through certification. We send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after five-stage vetting.

It depends on the scope, the days a week and how long the work runs. We set out each candidate’s pay or day rate on every shortlist. Our fractional CISO cost page sets out sourced day-rate bands for the seat. The certification body’s audit is a separate cost, agreed with them.

No. ISO 27001 is an international standard for a whole management system. Cyber Essentials is a UK government-backed certification scheme focused on a small set of technical controls. Many businesses do both.

Book 15 minutes · shortlist of 3–5

Bring the brief. We architect the team.

A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.

Fractional Quest logo — how to hire an ISO 27001 consultant, iso 27001 consultant