ISO 27001 consultants in Canada
A readiness consultant builds the management system with you. A certification body audits it. They cannot be the same firm, and understanding why is the first thing that will save you money on this project.
Most Canadian companies pay $25,000 to $70,000 CAD for outside help with a first ISO 27001 certification, on top of the certification body fee. What you get for it varies more than the price does, because the same phrase, ISO 27001 readiness, is used for a set of emailed policy templates and for six months of somebody sitting with your engineers. This page is about telling those apart, what a consultant can and cannot do for you, and when you do not need one at all.
Your consultant cannot be your certification body
This is the rule that surprises people, and it is worth getting straight before you take a single sales call. Certification bodies are themselves accredited against ISO/IEC 17021-1, and that standard requires them to be impartial toward the organizations they certify. It prohibits a certification body from providing management system consultancy, and it prohibits certifying an organization that received management system consultancy from the body, or from a body related to it, within the preceding two years.
The practical consequences are worth spelling out. A firm offering to build your ISMS and issue your certificate is either not accredited, or is describing two legally separate organizations and blurring it, or is going to hand you something that is not an accredited certificate. Buyers who care about ISO 27001 know how to read a certificate, and an unaccredited one answers nothing. Ask any firm you speak to, directly, whether they are quoting to help you get ready or to audit you. A good one will volunteer it.
Certification bodies can and do provide training, and they can run pre-assessments, which are not consultancy because the body tells you what it found without telling you how to fix it. That line is narrower than most readiness projects need. Choosing between bodies is covered on the certification page, and the directory keeps the two categories separate for the same reason.
What a readiness consultant actually does
The useful ones do five things, and a quote that does not cover all five is a quote for part of the job.
Scope and gap assessment. Decide what the management system covers, which entities, products, locations and systems sit inside it, and measure what already exists against the Annex A controls and clauses 4 through 10. Scope is the single biggest lever on cost and everything downstream inherits the decision.
Risk assessment and treatment. Build the risk methodology, run the assessment with your people rather than for them, and produce the risk treatment plan and the Statement of Applicability that follow from it. This is the part that most distinguishes real consulting from template delivery, because a risk register written without your engineers in the room describes a generic company.
Policy and process work. Documentation is where templates genuinely help and where the value is lowest. Policies you did not write and do not follow become findings, so the useful contribution is adapting them to what you actually do and getting them approved.
Control implementation support. Access reviews, logging, vulnerability management, supplier reviews, onboarding and offboarding evidence. Most consultants advise here rather than build, and the gap between advice and implementation is where timelines slip.
Internal audit and management review. Both are mandatory before certification. Internal audit can be outsourced, and often should be in a small company where nobody is independent of the thing they would audit. If your consultant built the ISMS, having the same person also internally audit it weakens the exercise, though it is not prohibited the way certification body consultancy is.
The three ways this gets sold
| Model | Typical range | Fits |
|---|---|---|
| Fixed-fee readiness project | $25,000 to $70,000 | A defined scope and a target audit date. Get the deliverable list and hours in writing. |
| Fractional security leader, monthly | $4,000 to $15,000 per month | Companies with no security owner who will still need one after the certificate. |
| Platform plus light advisory | $8,000 to $30,000 platform, advisory on top | Cloud-native companies with clean infrastructure and someone internal to drive it. |
The third model is oversold. A compliance platform collects evidence and tracks controls well, and it does not make your scope decisions, write your risk assessment, or answer an auditor. Under roughly 30 people with a single product on one cloud account, a platform plus a competent internal owner can genuinely be enough. Above that, or with multiple entities, on-premise systems or a complicated data story, the platform is a tool inside a project rather than a replacement for one. Full numbers are on the cost page.
Where the honest answer is that you need an owner rather than a project, a fractional CISO covers the clause 5 accountability the standard asks for and stays after the audit, which a project consultant does not.
What to ask before you sign
- Who is the named consultant assigned to us, and how many ISO 27001 engagements have they personally run to certificate
- What exactly is delivered, in a list, and how many hours sit behind it
- Who writes the Statement of Applicability, and who runs the internal audit
- Are you also selling us a platform, and what is your commercial relationship with it
- What happens if the certification body raises a major nonconformity, and is remediation inside the fee
- Which certification bodies have you worked alongside recently, and can we speak to a client of similar size
The last one matters more than credentials on a website. A firm that has taken companies your size through stage 2 with bodies operating in Canada knows how those auditors read evidence, and that knowledge is most of what you are buying.
When you do not need a consultant
If you have someone internal who has run an ISO 27001 program before, has the time, and has the authority to make people do things, you can do this without outside help. Buy the standards, buy ISO 27002 for the implementation guidance, and spend the money on the gaps instead. The failure mode is the part-time owner with no authority, because the management system asks for decisions across the whole organization and a person who cannot get a supplier review done will produce a project that stalls three months before the audit.
ISO 27001 consultants by city
Consulting for this standard is almost entirely remote work, so the useful local question is not who has an office near you. It is which privacy statute applies where you operate, since Quebec, British Columbia and Alberta each have their own private-sector law that displaces PIPEDA, and which industries drive the security demands your buyers put in contracts. Each page below covers those for one market.
- Toronto
- Montreal
- Vancouver
- Calgary
- Ottawa
- Edmonton
- Quebec City
- Winnipeg
- Hamilton
- Kitchener-Waterloo
- London
- Halifax
- Victoria
- Windsor
- Oshawa
- Saskatoon
- Regina
- St. John's
- Barrie
- Kelowna
Get quotes from Canadian ISO 27001 consultants
Tell us your scope, headcount and target date, and we will match you with firms that work with companies your size.
Get matchedCommon questions
Can our ISO 27001 consultant also certify us?
No. ISO/IEC 17021-1 prohibits an accredited certification body from providing management system consultancy, and from certifying an organization that received such consultancy from the body or a related body within the previous two years. Use one firm for readiness and a separate accredited body for the audit.
What does an ISO 27001 consultant cost in Canada?
A fixed-fee readiness project for a first certification usually runs $25,000 to $70,000 CAD, and fractional security leadership runs $4,000 to $15,000 CAD a month. The certification body fee is separate and is typically $15,000 to $40,000 CAD in the first year. Scope size, number of entities and how much already exists move all three.
Do we need a consultant based in our city?
Rarely. Almost all readiness work is remote, and the questions that matter are whether the firm knows your industry, your provincial privacy statute and the certification bodies operating in Canada. On-site time matters mainly where physical controls are in scope or where an auditor will visit a facility.
Can a compliance platform replace a consultant?
Sometimes, under about 30 people with a single cloud-hosted product and a capable internal owner. A platform collects evidence and tracks controls. It does not set your scope, write your risk assessment or defend a decision to an auditor. Above that size, or with multiple entities or on-premise systems, treat it as a tool inside the project rather than the project.
How long does a consultant-led certification take?
Nine to fifteen months from a standing start to a certificate is the realistic range, and the constraint is usually having enough operating records for a stage 2 auditor to sample rather than anyone's availability. An organization that already runs documented security controls can move faster, sometimes in six to nine months.