ISO27K

How to get ISO 27001 clients

The largest single source of ISO 27001 consulting work in Canada is a certification body that is forbidden from doing the work itself. Most consultants never ask for it. This page is about that channel and the four others worth running.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

ISO 27001 consulting is not sold the way security services generally are, and firms that market it like penetration testing struggle. The buyer is almost never shopping. They have been handed a requirement by a customer or a tender, they have a date attached to it, and they are looking for someone who can tell them what it will cost and how long it will take. Whoever answers those two questions credibly first usually wins, and the firms that win most often are the ones that were already standing where the requirement lands.

We run this directory and sell listings on it, so read the section about directories with the scepticism that deserves. The rest is what we would say to a consultant who asked. If you are still deciding whether to sell advisory work at all, the prior question is consultancy or accredited certification body, which are two different businesses.

What makes ISO 27001 work different to sell

The trigger is external and dated
Nobody wakes up wanting an ISMS. A European customer asked, a tender required it, or a renewal added a clause. That means demand is not created by your marketing, it is discovered by it, and the job is to be findable at the moment the requirement arrives rather than to persuade anyone of anything.
A whole category of firm is banned from competing with you
ISO/IEC 17021-1 forbids a certification body from consulting for an organization it certifies. The bodies see every unprepared company in the country and cannot help any of them. That is the referral channel, and it is discussed below because it is the most underused one in this market.
The engagement has a visible finish line
A certificate either gets issued or it does not, on a date a third party controls. That makes the work easier to sell than an open-ended security retainer and much harder to deliver late without consequence.
Buyers can compare you on a real number
Audit days are published in the standards bodies work from, so a buyer who has read what an audit actually costs arrives knowing roughly what the certification body half is worth. A consultant who cannot explain why their own number is what it is looks worse against that reading than they used to.

The five channels, and what each is worth

ISO 27001 client acquisition by channel, Canadian practices, 2026
ChannelCost per signed client (CAD)Lead timeCeiling
Certification body referralNear zero, plus the effort to build the relationship3 to 9 months to first referralReal, but the highest quality work in this list
Past client and partner referralNear zero, or a 10 to 20 per cent revenue shareImmediate once it existsLags your delivery volume by two quarters
Tender and RFP monitoring$2,000 to $8,000 in time per win1 to 4 monthsHigh, and most firms ignore it entirely
Your own writing and searchHigh upfront, near zero afterwards6 to 18 monthsHighest, and the slowest to start
Directory listing$600 to $4,000WeeksCapped by the directory's own traffic
The patternThe cheapest channels do not scale and the scalable ones are slow. Nothing here is both fast and cheap.

Those ranges assume engagements between $20,000 and $80,000 CAD, which covers most first ISMS builds. Below about $15,000 CAD an engagement, paid search stops making arithmetic sense before anything else does, and that is usually a signal to look at how the work is packaged rather than at the channel.

The certification body referral, which most firms never ask for

A certification body cannot consult for a client it certifies. It also cannot certify a client it consulted for, generally for two years afterwards depending on the accreditation body's rules. So every body in this country has a steady flow of enquiries from companies that are nowhere near auditable, and the only thing it can do with them is send them somewhere else.

Most bodies keep an informal list of consultants they are willing to name. Getting onto it is not a sales conversation and treating it as one is why most attempts fail. What gets a firm onto that list, in the order the body cares about:

  1. Your clients pass stage 2 without major nonconformities. This is the entire test. A body that names you and then audits a shambles has spent its own credibility. If you have not sent anyone through yet, say so rather than implying otherwise.
  2. You understand the boundary and respect it in front of the client. A consultant who tells a client the auditor is being unreasonable creates work for the body. A consultant who explains why the finding is correct saves it.
  3. You never ask the auditor for advice on a live engagement. The body's auditors are prohibited from giving it, and asking puts them in an awkward position they will remember.
  4. You are reachable and you scope honestly. Bodies refer work they will have to audit later. A consultant who talks a client into a scope four times larger than the requirement is creating a problem the auditor inherits.
  5. You ask. Once, plainly, of the scheme manager rather than the sales team, after you have a completed engagement to point at. Most consultants never do this step.

The reverse referral matters as much

Send work the other way. When your client is ready to book an audit, give them three bodies and an honest description of the differences rather than one name. Bodies notice which consultants bring them prepared clients and which bring them arguments, and the ones who do it well end up on more lists than the ones who do it exclusively. Naming three also keeps you clear of anything that looks like a kickback arrangement, which is the fastest way to lose the relationship permanently.

Tender monitoring, the channel nobody runs

Public sector and broader public sector procurement in Canada publishes its requirements, and a meaningful share of ISO 27001 demand originates there: either the buying organization needs the certificate itself, or it is imposing it on suppliers. Both produce consulting work and neither is visible to a firm that only markets to inbound search.

What to watch, and what to do with it:

  • Solicitations that name ISO 27001 as a mandatory or rated requirement. Every bidder who lacks it is a prospect with a hard date. The bid documents are public, and so, usually, is the list of who attended the bidders' conference.
  • Awards to suppliers who will now have to comply. A three-year contract with a security schedule in it creates a certification project six months later.
  • Provincial and municipal buyers specifically. Federal procurement tends to name its own control frameworks. Provincial health, education and municipal buyers are more likely to name ISO 27001 by name because it is the thing they can score against.

The approach that works here is not a pitch. It is one short message naming the specific solicitation, what the certification requirement in it actually demands, and roughly what it will cost the bidder in time and money to meet. That is genuinely useful to somebody in the middle of writing a bid, and it arrives from the only person who has read their tender.

Writing, and what to write about

Content works in this market for one reason: the buyer's first three questions are cost, duration and whether the thing they were asked for is even ISO 27001, and almost nothing published answers them with a number. A practice that publishes real Canadian figures ranks against firms publishing nothing but adjectives.

The pieces that generate enquiries, in rough order:

  1. What it cost, in CAD, with the audit day count behind the figure. Nobody publishes this and everybody searches for it.
  2. The scope statement decision, because it is the one choice that changes every other number and clients get it wrong before they call anyone.
  3. What a stage 2 finding actually looks like, written up from real engagements with the client details removed. This does more to establish that you have done the work than any credential list.
  4. The standard your buyer probably meant. A large share of enquiries begin with somebody having been asked for the wrong thing.

Write about the engagement you actually run rather than about the standard. The standard is documented; your delivery is not, and it is the only thing a prospect cannot get elsewhere.

Directories, including this one

A directory listing is a capped channel. It cannot produce more enquiries than the directory receives, and any directory telling you otherwise is selling. What it does well is catch the buyer who has decided to hire someone and wants three names in their own province, which is a later and better qualified moment than most channels reach.

The honest comparison: a listing costs less than a single conference booth and produces fewer leads, but the leads arrive with a project and a date attached. Against cold outbound it is cheaper per signed client and much lower volume. Against your own writing it is faster to start and has a lower ceiling. Run it as one line in a pipeline, never as the pipeline. If you want to be in ours, the listing page carries both tiers and the prices, and claiming an existing listing is free.

What to actually do, in order

  1. Finish two engagements you can describe in detail without naming the client. Everything below depends on having them, and they matter more than any credential, though two of the credentials are worth holding.
  2. Ask two certification bodies to be on their referral list, of the scheme manager, once.
  3. Set up tender alerts for ISO 27001 across the provincial procurement portals you can actually serve. This is an afternoon of setup.
  4. Publish your own pricing with the arithmetic behind it. This is the single highest-return thing a small practice can do and the one most refuse.
  5. Ask every finished client for one introduction, at the point the certificate arrives, which is the only moment they are unambiguously pleased.
  6. List where buyers already look, and treat it as a line rather than a plan.

Be findable when the requirement lands

Listing your firm here puts you in front of Canadian companies who have already decided to certify. Claiming an existing listing is free.

List your firm

Common questions

Can a certification body refer work to a consultant?

Yes, and it is normal practice. What ISO/IEC 17021-1 prohibits is the body consulting for a client it certifies, and offering consultancy and certification as a package. Naming several consultants without a financial interest in the outcome is a different thing and most bodies do it, because the alternative is turning enquiries away. Ask for the list rather than assuming it does not exist.

Should I pay a certification body for referrals?

No, and offering to is how a consultant gets removed from a list. A financial arrangement between a body and a consultant working on the same client is exactly what the independence rules exist to prevent, and an accreditation body auditing the certification body will look for it. Refer work in both directions and keep money out of it.

How long before a new ISO 27001 practice has steady pipeline?

Referrals cannot start until you have finished clients, which means the first year runs on outbound, tenders and whatever network you brought with you. Firms that get through the first year usually did it on two or three engagements from prior relationships. Anyone promising a faster route is selling the route.

Is it worth specialising by industry?

Usually yes, and by trigger rather than by sector. The company being asked for ISO 27001 by a European customer has a different problem from the one answering a Canadian public sector tender, and the second is easier to find. Specialising narrowly on a sector with few Canadian buyers is how small practices run out of market.