ISO 27001 consultant vs certification body: what you pay for what
Two separate bills people constantly confuse. What a readiness consultant charges, what the certification body charges, and why you need both.
By Kellwick Team · July 13, 2026 · 2 min read
There are two separate costs in getting ISO 27001, and they go to two different organisations that are not allowed to be the same one. A readiness consultant (like Kellwick) prepares you: finds the gaps, builds the evidence, gets you audit-ready. A certification body runs the actual Stage 1 and Stage 2 audit and issues the certificate. You pay both, and confusing the two is how budgets go wrong.
Here is what each side does and roughly what it costs.
Who charges you for what
| Readiness consultant | Certification body | |
|---|---|---|
| Role | Prepares you for the audit | Runs the audit, issues the certificate |
| Example work | Gap analysis, evidence, risk register, SoA, remediation | Stage 1 and Stage 2 audit, surveillance |
| Typical cost | Readiness from $4,500; retainer from $2,000/mo | Set by the CB, scales with size and scope |
| Can they also certify you? | No | Yes - that is their only job |
Why they have to be different
Accredited certification bodies cannot audit an ISMS they built themselves - that independence is the whole point of the certificate. So a consultant who prepares you cannot also be the body that certifies you, and any firm claiming to do both is not describing accredited certification. This is a feature, not a hassle: it is what makes the certificate mean something to your customers.
Kellwick sits firmly on the preparation side. We are an independent advisory practice, not a certification body, and we never issue certificates or guarantee outcomes.
What you pay a consultant for
The readiness assessment (from $4,500), any remediation to close the gaps, and often an ongoing retainer to keep the ISMS alive between audits. See the full picture on the pricing page.
What you pay the certification body for
Their Stage 1 and Stage 2 audit fee, then an annual surveillance audit, and a recertification audit every three years. The CB sets these fees and they scale with your headcount and scope, so ask any body you shortlist for a quote early - it belongs in your budget from the start.
Budgeting for both
A realistic first-year ISO 27001 budget has three parts: preparation (consultant), the certification audit (CB), and maintenance so it does not go stale before surveillance. The pricing calculator will size the preparation side for you in five questions; the CB quotes the rest.
Figures here are indicative and not a binding quote.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.