ISO27K

Consultant or certification body: which business should you be in?

You can build management systems or you can certify them. ISO/IEC 17021-1 means you cannot do both for the same client, and in practice the two are different businesses with different capital requirements, different margins and different failure modes.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

For almost every firm reading this the answer is consultant, and the reason is capital rather than capability. Becoming an accredited certification body means building a conformity assessment organization that satisfies ISO/IEC 17021-1, submitting it to the Standards Council of Canada, funding witnessed audits, and carrying the cost of impartiality controls forever. That is a multi-year, six-figure program before the first certificate is issued. Consulting needs a laptop and two finished engagements. The interesting question is not which is easier, it is what each business actually earns and what it forbids you from doing.

2 years Typical cooling-off before you may certify a client you consulted for

$2,000 to $3,200 Certification body day rate in Canada, CAD

$1,400 to $2,400 Consultant day rate for ISMS work in Canada, CAD

What ISO 17021-1 actually forbids

The rule is narrower than the folklore around it, and getting it precisely right is worth doing because most of the market repeats a version that is wrong.

A certification body may not provide management system consultancy to a client it certifies
This is the core prohibition. Building the ISMS and then auditing it is auditing your own work, which is what the whole accreditation structure exists to prevent.
It may not certify a client it consulted for, for a defined period
Commonly two years from the end of the consultancy. The exact period is set by the scheme and the accreditation body, so check rather than assume.
It may not offer certification and consultancy as a package, or imply certification is faster or cheaper if you use its consultancy
This one catches marketing rather than delivery, and it is where bodies most often get findings raised against them.
Training is allowed, with a boundary
A body may deliver training on the standard. It may not, in doing so, provide specific solutions to the client's own management system, which is where a training day quietly turns into a consulting day.
An auditor may say what is wrong, never what to do about it
This is the rule your clients find most frustrating and it is not negotiable. An auditor who tells a client to adopt a particular control has consulted, and the finding lands on the body at its next accreditation assessment.

What this means if you already sell both

A firm that does readiness consulting and also wants to certify has to choose per client, forever, and keep the record that shows it chose. The practical arrangement in Canada is that firms pick one side and refer the other. A CPA firm that issues SOC 2 opinions and also holds certification body accreditation faces the same structure twice over, which is why the ones that do it separate the practices organizationally rather than by policy.

The two businesses, side by side

ISO 27001 consultancy against accredited certification, as businesses
 ConsultancyAccredited certification body
What you sellAn outcome, on a dateAn opinion, repeatedly, on a cycle
Cost to startEffectively nothing beyond your timeMulti-year accreditation program, six figures CAD before first revenue
Revenue shapeLumpy project revenue, ends at the certificateAnnuity. Surveillance in years one and two, recertification at three
Typical day rate, CAD$1,400 to $2,400$2,000 to $3,200
Utilisation ceilingHigh, and you are the productLower. Auditors need scheme competence per sector
Who regulates youNobody. There is no licence to consultYour accreditation body, continuously, with witnessed audits
How you lose the businessA client fails stage 2 and talks about itSuspension of accreditation, which invalidates your customers' certificates
Client relationship after the certificateEnds, unless you sell upkeepContinues for three years by contract

The annuity is the real difference, and it is smaller than it looks

A certification body's appeal is the recurring revenue: the certificate is a three-year contract with a surveillance visit in each of the intervening years and a recertification at the end. On the published day tables a surveillance is roughly a third of the initial audit and a recertification roughly two thirds, so a client worth ten initial days is worth about another ten days across the rest of the cycle without any new sale.

What that misses is that the same annuity is available to a consultancy and almost nobody sells it. The management system needs an internal audit every year, which the client cannot run independently at small scale, and a management review that most organizations conduct badly without help, plus the clause 10 improvement record that is empty at almost every first surveillance visit. That is a recurring engagement of $8,000 to $25,000 CAD a year, sold to a client who already trusts you, with no accreditation required. Firms that only sell the build spend every year replacing all of their revenue.

Three-year revenue per client, one 30-person Canadian client, CAD
YearConsultancy, build onlyConsultancy with upkeepCertification body
Year one$35,000$35,000$18,000
Year twoNil$14,000$6,000
Year threeNil$14,000$12,000
Three-year total$35,000$63,000$36,000

The figures are illustrative bands for one mid-sized client rather than a market average, and the point is the shape rather than the totals. A consultancy that sells the annual upkeep out-earns a certification body on the same client across the cycle, with none of the accreditation cost. That is the strongest argument against trying to become a certification body, and it is available starting this quarter.

If you still want to be a certification body

It is a legitimate business and Canada has room in it, particularly for ISO/IEC 42001 where the accredited pool is very small. Understand what you are signing up for.

  1. Build the organization ISO/IEC 17021-1 describes before you apply. Impartiality committee, competence criteria per scheme and sector, auditor qualification and monitoring, appeals and complaints, certification decision separated from the audit team. This is a management system of your own and it is assessed as one.
  2. Apply to an accreditation body. In Canada that is the Standards Council of Canada. UKAS and ANAB accredit Canadian operations too, and all three sit under the IAF multilateral arrangement, so the certificates travel. Which one to choose is a market question about where your clients' buyers are.
  3. Fund the assessment program. Office assessment, witnessed audits of your auditors on real client sites, and then surveillance of your own accreditation on a cycle. You need paying clients before you are accredited, which is the chicken-and-egg problem at the centre of this business.
  4. Staff for scheme competence, not headcount. An auditor qualified for ISO 27001 is not automatically qualified for ISO 42001, and accreditation scopes are granted per standard. This is why the utilisation ceiling is lower than a consultancy's.
  5. Accept that you can never help. Your auditors will spend their careers watching clients make avoidable mistakes and being forbidden from saying what to do. Firms whose culture is built on solving problems find this harder than they expect.

The unaccredited shortcut, and why it is a trap

Nothing stops a firm issuing an ISO 27001 certificate without accreditation. It is not illegal and there are firms doing it. What happens is that the certificate fails the check a serious buyer runs, and that check is documented publicly, so your customers discover the problem at the moment they most needed the certificate to work. A business built on that has one bad quarter in it.

The third option most firms should take

Be a consultancy that is unusually good at the audit relationship. You are allowed to attend the audit with your client, you are allowed to explain a finding, and you are allowed to know which bodies quote how many days for what. None of that requires accreditation and all of it is scarce. The firms that get named by certification bodies are the ones whose clients arrive prepared, and that referral channel is worth more than an accreditation program most small firms could not finance anyway.

List the side of the work you actually do

Buyers arriving here are trying to tell a consultant from a certification body. Saying plainly which one you are gets you the enquiries you can serve.

List your firm

Common questions

Can one firm consult and certify, for different clients?

Yes, with real separation. The prohibition is per client, not per firm, so a body may certify company A and consult for company B. In practice accreditation bodies scrutinise the arrangement closely, because the risk is that the sales conversation blurs the two, and most firms that hold accreditation keep the consulting practice in a separate legal entity with separate staff.

How long does certification body accreditation take in Canada?

Plan on two years or more from a standing start, and understand that the time is consumed by building an organization that meets ISO/IEC 17021-1 and then having it assessed, including witnessed audits on live client work. The application itself is not the long part.

Do consultants need any accreditation to sell ISO 27001 work?

None. There is no licence, no register and no legal requirement to hold a credential to advise on ISO 27001 in Canada. What buyers check instead is finished engagements and individual certifications, and which of those are worth holding is a separate question with a short answer.

Is there room for another certification body in Canada?

For ISO 27001, the market is well served and you would be competing on price against global bodies with better day rates than a new entrant can reach. For ISO/IEC 42001 the accredited pool in Canada is small enough that scheduling is a genuine constraint for buyers, which is a real opening for a body already accredited for other schemes and adding one.