ISO27K

ISO 27001 consulting: scoping the work

Choosing a consultant is the easy half. The half that decides whether the project works is the statement of work: which deliverables are named, who does what, and what you are still holding when the engagement ends.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

The difference between a $25,000 CAD ISO 27001 consulting engagement and a $70,000 CAD one is almost never the quality of the firm. It is how much of the work each side agreed to do, and that agreement usually exists only as an implication in a proposal. This page is about writing it down: the deliverables a statement of work should name, the division of labour, the payment structure, and the terms that matter when something goes wrong.

If you are still choosing a firm, the consultant guide covers selection and what to ask, and the cost breakdown covers where this line sits in the wider budget. This page assumes you have picked someone and are about to sign.

The deliverable list, named

A statement of work that says "support your ISO 27001 implementation" is not a statement of work. Name the artefacts. If a deliverable is not on this list and not explicitly assigned to your team, it will be discovered as a gap somewhere around week twenty.

Artefacts a first certification requires, and who normally produces each
DeliverableUsually produced byNote
Scope statementBoth, in a workshopEnds up on the certificate. Do not let this be drafted without you.
Information security policy and topic policiesConsultant, reviewed by youThey must describe what you actually do, not what a template says.
Asset, data and supplier inventoryYouThe single most expensive thing to outsource, because they build it by interviewing your people.
Risk assessment method documentConsultantShort. Auditors ask for it by name.
Risk register and treatment planBoth, in workshopsDelivered as a finished spreadsheet, it will not survive an auditor's questions.
Statement of ApplicabilityConsultant, decided by youAll 93 Annex A controls with justifications derived from the register.
Control implementationYou, mostlyEngineering and IT work. A consultant advises, procures nothing and configures nothing.
Awareness training and recordsEitherCheap to buy, and frequently forgotten until stage 2.
Internal auditA third partyCannot be whoever built the system. Budget it separately.
Management review pack and minutesConsultant prepares, you hold the meetingClause 9.3 lists the required inputs. Structure the agenda to match.
Audit supportConsultantSpecify whether they attend stage 1 and stage 2, and for how many days.
Nonconformity closureSpecify explicitlyThe most commonly omitted line, and the one that generates a change order.

The division of labour, agreed up front

Three things should stay in house on almost every engagement, and firms that offer to take them are selling you a worse project at a higher price.

The inventory stays with you because your people already hold the information and paying someone to extract it by interview is the slowest route to a document you could have written in a week. The risk register stays with you in the sense that the scenarios and the scoring decisions are yours, even if the consultant facilitates and writes; a register handed over finished cannot be defended by anyone in your organization when an auditor asks why a risk was accepted. And control operation stays with you permanently, because the management system has to keep running after the engagement ends and a certificate is a three-year commitment, not a purchase.

What is genuinely worth buying is the judgement about what an auditor accepts. That is the thing you cannot read out of the standard, and it is what you are paying a day rate for.

Nobody can guarantee certification

A consultant does not issue the certificate and has no authority over the body that does. A guarantee of certification is therefore a guarantee of someone else's decision, which is worth exactly nothing. What can be guaranteed, and what a good firm will put in writing, is remediation at no additional fee if a major nonconformity is raised against a deliverable they produced. Ask for that instead, because it is a promise they can actually keep.

How the engagement is priced

Consulting pricing models, Canadian market, CAD
ModelTypical (CAD)Risk sits with
Fixed fee for a named deliverable set$25,000 to $70,000The firm, which is why the deliverable list has to be exact.
Day rate against an estimate$1,400 to $2,600 per dayYou. Cap it, and require notice before the cap is reached.
Monthly retainer for the project duration$4,000 to $15,000 per monthShared. Watch the end date, since these run long.
Fractional CISO carrying the system$3,000 to $12,000 per monthOngoing ownership rather than a project. Covers clause 5 accountability.

Fixed fee is the right default for a first certification, because it forces the deliverable conversation you need to have anyway. Day rate suits a company with a capable internal owner buying targeted review. A retainer suits an organization that knows it needs the ownership to continue past the certificate, and at that point a fractional CISO arrangement is often the better shape.

Structure payment against milestones rather than months: scope and gap assessment complete, risk assessment and Statement of Applicability signed off, controls implemented, internal audit and management review held, stage 2 passed. Hold ten to twenty percent to the last milestone. A firm that objects to holding a portion until after stage 2 is telling you something about its confidence.

Terms worth reading before you sign

  • Ownership of documents. You should own the output outright, with no restriction on use after the engagement. Some firms grant only a licence to their template set rather than transferring it, which becomes a problem when you want a different consultant to amend a policy.
  • Named personnel. Name the individual who does the work, and require your consent to substitute. Firms sell with a principal and staff with a junior more often than they should.
  • Independence for the internal audit. Write down that the internal audit will be performed by someone independent of the build. If the same firm proposes to do both, ask which of their people did which, and whether the auditor had any part in producing the documents.
  • Certification body separation. Confirm the firm has no relationship with your intended certification body that could compromise the body's independence, since ISO/IEC 17021-1 makes that the body's problem and therefore eventually yours. The role separation is set out on the certification bodies page.
  • Change control. Scope grows. Agree in advance what a change order looks like and what triggers one, rather than discovering the answer during the stage 1 gap closure period.
  • Data handling. They will hold your risk register, network detail and often personal information. That makes them a supplier inside your own scope, subject to your supplier security control and to PIPEDA or the equivalent provincial statute. Put a confidentiality and data handling schedule in the contract, and then, having done so, actually add them to your supplier register. Auditors have been known to ask.

Warning signs in a proposal

  • A fixed price quoted before anyone has seen your environment. Either it is padded or it will become a change order.
  • A deliverable list consisting of document names with no mention of workshops, interviews or your team's time. That is a template pack with a covering letter.
  • A timeline under four months from a standing start, which ignores the operating period that stage 2 depends on. See why records take calendar time.
  • An offer to also perform your certification audit, or a claim to be an accredited body as well as a consultancy.
  • Pricing tied to a compliance platform subscription the firm resells, with no discussion of whether you need one. Under roughly thirty people with a single cloud environment, you often do not in year one.

Get consulting proposals you can compare

Tell us your scope, headcount and target date and we will put it in front of Canadian firms that do ISO 27001 implementation work.

Get matched

Common questions

How much does ISO 27001 consulting cost in Canada?

$25,000 to $70,000 CAD for a fixed fee engagement taking a first-time company to stage 2, or $1,400 to $2,600 CAD a day on a day rate. The spread depends far more on how much of the work your team does than on the size of your company, which is why the deliverable list matters more than the headline number.

What should be in an ISO 27001 statement of work?

Named artefacts rather than activities: scope statement, policy set, risk method, risk register, treatment plan, Statement of Applicability, training records, management review pack, and audit attendance in days. Alongside each, who produces it. And an explicit line on whether nonconformity closure after stage 1 or stage 2 is included, because that is the omission that generates the argument.

Can a consultant guarantee we pass the audit?

No, and an offer to do so should reduce your confidence rather than raise it, because the certificate is issued by an independent accredited body the consultant has no authority over. What a good firm will commit to in writing is fixing, at no extra fee, any major nonconformity raised against work they produced.

Should we pay monthly or on milestones?

Milestones, with a portion held until after stage 2. Monthly billing on a project with no fixed end date is how a nine-month engagement becomes a fifteen-month one. Tie payments to signed-off artefacts, since those are unambiguous in a way that "progress" is not.

Do we own the policies the consultant writes?

Only if the contract says so. Some firms grant only a licence to a template set rather than transferring ownership, which limits what you can do with the documents later and makes changing supplier awkward. Ask for outright ownership of all deliverables and put it in the agreement before the first invoice.