Can you get ISO 27001 without a consultant?

8 min read · Updated

Yes. ISO 27001 doesn't require a consultant: the certification body assesses your information security management system, not who helped you build it. Plenty of small businesses get certified on their own. What you can't skip is the work itself: deciding your scope, assessing your risks, choosing your controls, writing it down, and then running it for long enough to show the auditor it works.

Doing it yourself saves a consultant fee, often £3,000 to £25,000 for a small UK business (as of 2026), but costs your team time. This guide shows where that time goes, so you can decide with your eyes open.

What the certification body needs to see

At stage 1, the auditor reviews your documentation. At stage 2, they check that the system is working: they look at records, talk to your people and sample evidence. To pass, you need the requirements of clauses 4 to 10 of the standard in place, and a reasoned decision on each of the 93 controls in Annex A.

In plain terms, that means:

  1. Context and scope: what your business does, who cares about your information (customers, regulators, staff), and what's in and out of the ISMS.
  2. Leadership: an information security policy approved by top management, and clear roles.
  3. Risk assessment and treatment: a method, a risk register, and decisions about each risk.
  4. Statement of Applicability (SoA): every Annex A control, whether it applies, why, and whether it's in place.
  5. Supporting policies and procedures for the controls you've chosen.
  6. Operation and evidence: training records, access reviews, supplier checks, backups and restore tests, incident records.
  7. Internal audit and management review before the certification audit.
  8. Corrective action: how you fix what the internal audit finds.

Where people get stuck

  • The blank page. Writing a risk register and SoA from nothing is the slowest part, and it's where generic templates produce documents that don't describe your business.
  • Scope creep. Trying to include everything makes the audit bigger and the work harder.
  • Policies nobody follows. Auditors check practice, not just paperwork. A policy that says "quarterly access reviews" needs four access review records.
  • Running out of steam after certification. Surveillance audits come round every year, and the evidence has to keep building.
  • Internal audit independence. Clause 9.2 needs your internal auditor to be objective and impartial. In a very small team, that often means an external person for this one task.

A do-it-yourself route

  1. Agree the why and the deadline. Who's asking (customer, tender, board) and by when? This decides your scope and your pace.
  2. Set the scope. Start with the services and systems your customers care about.
  3. Get top management on board. They approve the policy and the risk decisions, and they sit in the management review.
  4. Assess your risks. List your information assets, what could go wrong, how likely and how bad, then decide what to do about each.
  5. Write the SoA. Go through all 93 Annex A controls with reasons.
  6. Write only the policies you need, in your own words, matching what you actually do.
  7. Run it for a while. Many certification bodies like to see the system operating for a few months, with real records, before stage 2.
  8. Do an internal audit and a management review. Fix what they find.
  9. Choose a UKAS-accredited certification body and book stage 1 and stage 2.
  10. Keep it running for the surveillance audits.

When a consultant is still worth it

  • You have a hard deadline in weeks, not months.
  • Nobody in the business has time to own it.
  • Your environment is complex (many sites, regulated data, heavy custom software).
  • You want someone to coach you through the first internal audit.

A middle route works for many: do the work yourself, and pay for a few days of expert review or an external internal audit.

How ClearIMS helps

ClearIMS is built for businesses that want to do ISO 27001 themselves without building a compliance team. You describe your business in plain English, and it drafts your scope, risk register, risk treatments, Statement of Applicability, policies and tasks, so you start from a draft about your business rather than a blank template. A named person in your business reviews, changes and approves every record; the AI never approves anything. Then it keeps the system running with owned, dated tasks, internal audits, management reviews and evidence in one place, and gives your external auditor scoped, read-only access to your approved records.

We make the software. Your certificate is awarded by your certification body, and nobody can guarantee it.

Take the 2-minute readiness check, or book a 20-minute call.

SOURCES

  1. ISO/IEC 27001:2022 (ISO)
  2. Find a UKAS-accredited certification body (UKAS)
  3. ISO 27001 certification cost UK (ClauseWise, Mar 2026)
FOUNDING CUSTOMER PROGRAMME · 10 PLACES

Ten organisations get the software at half price. We get to learn from them.

Start with the 30-day free trial. If ClearIMS earns its place, a founding seat locks £150 a month for 24 months, or £1,500 a year upfront. No VAT charged.

Apply for a founding placeBook a 20-minute callWe make the software. Your certification is yours, awarded by your certification body.