Toolkit, consultant or platform: the three routes, priced
Audit days come from your headcount and complexity under ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21), not from how you prepared. So the entire price difference between these routes sits in getting ready — which is also the part with no published rule behind it.
This comparison is difficult to find anywhere neutral, for a structural reason. The version published by a toolkit vendor finds for the toolkit. The version published by a compliance platform finds for the platform. Both are perfectly honest about their weaknesses in the places where being honest costs them nothing.
We sell none of the three. Consultancies pay us a fixed fee per enquiry, agreed in advance, and it does not change with which route you choose, how large the engagement is, or whether you go ahead at all. If this page persuades you to buy a toolkit and spend nothing else, our revenue is identical.
The same diagram as a table
| Route | Low | High | What is in it |
|---|---|---|---|
| Toolkit | £95 | £1,500 | Your own people do the work |
| Consultant-led | £6,000 | £26,400 | 10–22 days bought in |
| Platform + help | £3,600 | £18,500 | Services only — no subscription |
All three then pay the same certification audit fee, because audit days are set by ISO/IEC 27006-1:2024 Table C.1 and not by how the management system was built.
What each route costs, at four sizes
Single site, no adjusting factors. The last column is the same on every row of a given size, which is the point.
| Scope | Toolkit | Consultant-led | Platform services | Certification audit (all routes) |
|---|---|---|---|---|
| 12 people | £95–£1,500 | £6,000–£26,400 | £3,600–£18,500 | £6,600–£9,000 |
| 25 people | £95–£1,500 | £6,000–£26,400 | £3,600–£18,500 | £7,700–£10,500 |
| 80 people | £95–£1,500 | £12,000–£54,000 | £7,200–£37,800 | £12,100–£16,500 |
| 200 people | £95–£1,500 | £18,000–£78,000 | £10,800–£54,600 | £15,400–£21,000 |
The platform column is professional services only. No major compliance platform publishes a subscription price, so there is no figure to add. Over three years that missing line is frequently the largest in the exercise. How these are calculated.
Good at, weak at
Documentation toolkit
A set of policies, procedures and templates you buy once and adapt. Outlay is the smallest of the three by a wide margin.
Good at
- Cheapest outlay by an order of magnitude
- You keep everything and can reuse it
- Forces your own people to understand the system they will have to operate
- No ongoing licence
Weak at
- Your staff time is the real cost and nobody prices it
- A generic Statement of Applicability is visible to an auditor as a generic Statement of Applicability
- No help when Stage 1 produces a finding you do not understand
- Needs at least one person with the time and the temperament for this
Consultant-led
A consultancy runs the build with you: scope, risk assessment, Statement of Applicability, documentation, internal audit support.
Good at
- Fastest route for a team with no management system experience
- The Statement of Applicability reflects your actual risk, because somebody interviewed you
- Somebody who has sat through Stage 2 before is in the room when you do
- Internal audit can be bought from them — it cannot be bought from your certification body
Weak at
- Most expensive route
- Knowledge can leave with them unless the engagement is structured to prevent it
- Quality varies enormously and there is no register to check anyone against
- An ISMS built for you rather than with you fails its first surveillance audit
Compliance platform
Software that maps controls, collects evidence from your systems automatically and tracks the state of the management system.
Good at
- Evidence collection is genuinely automated, and evidence collection is genuinely tedious
- Continuous rather than annual, which suits the surveillance cycle
- Good when you will also need SOC 2 or other frameworks — controls are reused
- Keeps the ISMS visible between audits, which is when most of them quietly stop
Weak at
- No major platform publishes a price, so it cannot be compared before a sales call
- It cannot decide your scope, write your risk treatment or hold your management review
- A subscription is permanent and usually exceeds the one-off saving within three years
- A platform full of evidence against a scope nobody thought about is still a Stage 1 finding
And what this site is worse at than any of them
We have never implemented a management system, never sat on either side of a Stage 2 audit, and cannot tell you whether a particular control will satisfy a particular auditor. Everything here is read out of published rules and checked against its source, which is a genuine strength for questions about what the rules require and no substitute at all for somebody who has done the work. A toolkit vendor and a consultancy both know things about the texture of this that we do not.
Which route, for which situation
| If this is you | Usually | Why |
|---|---|---|
| Under about 15 people, technical team, time available | Toolkit, plus a few days of review | The work is genuinely doable in-house at this size, and the audit is the smallest band in the table. Buy a day or two of consultant time to review the Statement of Applicability rather than the whole engagement. |
| A tender deadline inside three months | Consultant-led | This is the case where the expensive route is the cheap one. The constraint is clause 9.2 and 9.3 and the certification body's waiting list, and somebody who has done it before sequences around both. |
| You will need SOC 2 or other frameworks as well | Platform, plus services | Control reuse across frameworks is the strongest argument for a platform and the one case where the subscription pays for itself on arithmetic rather than convenience. |
| Already certified, keeping it alive | Toolkit or platform, plus bought-in internal audit | The expensive part of year two onwards is the annual internal audit you cannot get from your certification body. |
| Regulated, or certifying a complex multi-site scope | Consultant-led | Scope design is where the money is made or lost here, the multi-site sampling rule bites, and it is the least suitable decision to take from a template. |
The cost that decides it, and nobody publishes
Comparing a one-off consultancy fee against a platform subscription is comparing two different shapes of number, and the shape matters more than the size.
A consultant-led build at 25 people lands somewhere around £6,000–£26,400 once, and then the knowledge either stays with your people or it does not. A platform is a subscription that renews for as long as you hold the certificate — at minimum three years to the first recertification, and realistically for as long as the customer who asked for the certificate remains a customer.
We cannot tell you where the crossover is, because the input is not published. What we can tell you is what to ask on the sales call: the three-year total, in writing, including renewal uplift. A platform that will not put that in an email before a trial is telling you something.
The question that applies to all three routes
“Who does our internal audit in year two?” Clause 9.2 requires one every year, and BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.6 bars your certification body from doing it. Toolkits do not do it, platforms do not do it, and a consultancy that built your ISMS needs to think about whether it is independent enough of the thing it is auditing. It is the recurring cost that surprises people in year two, and asking about it in year zero costs nothing.
Mixing them is normal
These are archetypes for comparing costs, not products anyone has to buy whole. The shape that turns up most often in practice is a toolkit for the documented information, a small number of consultant days spent on the scope and the risk assessment — the two decisions that are genuinely hard to take from a template and the two that cost the most to get wrong — and bought-in internal audit from year two.
That combination is not in any vendor's comparison table, for the obvious reason.
Where to go next
- Run it for your headcount
- Can we use the tools we already have?
- What a consultant can and cannot do
- The process, end to end
Common questions
Does the route I choose change the audit fee?
No, and this is the most useful thing on this page. Audit days are a function of your headcount, sites and complexity under ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21). They are not a function of how the management system was built or who built it. Everyone pays the same for the audit, so the entire price difference between the three routes is in preparation.
Why is there no price for compliance platforms here?
Because none of them publishes one. We report that as a finding rather than filling it with a guess: the figures in the platform column are the professional services only. It matters more than it sounds, because a subscription is permanent. Over the three years the certificate is valid, the subscription is frequently the largest single line in the whole exercise, and it is the one you cannot compare before booking a sales call.
Can a platform get us certified on its own?
No. A platform cannot decide your scope, cannot write your risk treatment, cannot hold your management review and cannot be your certification body. What it does well is the part that is tedious rather than difficult: collecting evidence from your systems on a schedule and showing you what is missing. That is real value, and it is roughly a third of the work rather than all of it.
Is a toolkit just templates we could write ourselves?
In principle yes, and in practice the value is structure rather than prose — knowing which documents the standard actually expects to exist and which it does not. The risk is shipping the templates as written. An auditor who reads Statements of Applicability for a living recognises an unmodified one immediately, and it invites exactly the questions you least want at Stage 2.
How do we tell a good consultancy from a bad one?
There is no register and no rating that would survive scrutiny, so we do not publish one. Three questions do more work than any badge. First: what will you leave us with that lets our own people run this after you have gone? Second: who will do our internal audit in year two, given our certification body cannot? Third: what is your relationship, if any, with the certification body you are suggesting — because under BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.7, consultancy from a related body can bar that body from certifying you for 2 years.
Can we mix the routes?
Most organisations do, and it is usually the right answer. A common shape is a toolkit for the documentation, a handful of consultant days for scope and the risk assessment, and bought-in internal audit from year two. The routes in this table are archetypes for comparing costs, not packages anyone has to buy whole.
What does this site get paid for each route?
The same fixed amount per enquiry, agreed in advance, whichever route you pick and whichever consultancy receives it. We have no commercial relationship with any toolkit vendor or platform, and no revenue changes if this page persuades you to buy a toolkit and spend nothing else.
Sources cited on this page
- ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
- ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Get all three routes priced for your scope
The last question asks which route you are leaning towards. “Not decided” is the most common answer and the most useful one.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.