isms.coach
← All guides

Self-led certification

ISO 27001 without a consultant: what it actually takes

Self-led certification is real and common — here's the honest time, skill, and cost tradeoff versus hiring one.

Most ISO 27001 content online is written by consultancies and compliance platforms, so it's not surprising that most of it quietly steers you toward hiring one. It's worth saying plainly: plenty of small companies get certified without a consultant, and it isn't a fringe approach.

What actually determines success

The single biggest factor isn't a security background — it's having one person who can commit real, sustained time to it. Realistically that's 20–40% of a working week, for somewhere between four months and a year and a half depending on how mature your existing practices already are. The people who pull it off are usually IT managers, operations leads, or whoever already owns "how things run" at the company — not dedicated security specialists.

What you're trading against a consultant

  • Cost: a consultant-led implementation for a small org commonly runs $15,000–$50,000 in fees. Self-led, you're trading that fee for your own time instead — not free, just a different currency.
  • Speed: a consultant who's done this dozens of times will usually get you there faster. Self-led takes longer because you're learning the standard as you go.
  • Confidence: the main thing you lose without a consultant is a second set of eyes telling you "this is enough" before the audit. That's the actual gap a structured tool needs to close — not the paperwork itself.

What you actually need in place

Two things matter more than any checklist: visible senior management commitment (an auditor checks for this explicitly), and a documented Statement of Applicability covering all 93 Annex A controls, each with a real justification — not boilerplate copied from a template. Everything else follows from those two.

The realistic path

Start with context and scope, draft your Information Security Policy from that context rather than a generic template, build your risk register, and let each risk you log tell you which Annex A controls actually apply to your business. That's a narrower, more honest path than "read the standard cover to cover and hope."

Ready to actually start? Your Statement of Applicability comes pre-populated with all 93 Annex A controls — no blank page.

Start your ISMS