Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

ISO 27001: Should You Get a Readiness Assessment or Hire a Consultant?

ISO Certifications | Audit Readiness

Published: May 31, 2022

Last Updated: Jan 7, 2026

Organizations pursue ISO 27001 certification for many reasons: internal security initiatives, customer pressure, or market expectations. One of the most common questions companies face early on is when to involve a certification body and whether they should first complete a readiness assessment or work with a consultant. 

Ryan Mackie, Principal at Schellman, breaks down how to navigate these early decisions. 

When to Contact a Certification Body 

Typically, a certification body doesn’t need to be engaged until your organization is about 60–70% through your Information Security Management System (ISMS) development and implementation.  

At that point, your organization will have: 

  • Defined the scope of the ISMS  
  • Begun implementing controls  
  • Documented core policies and processes  
  • Started establishing governance around monitoring and continual improvement 

Reaching this level of maturity gives the certification body enough information to properly estimate audit timing, plan resources, and help you map backwards from your desired certification date.  

Should You Get a Readiness Assessment? 

Many organizations wonder if a readiness assessment is the right next step. A readiness assessment, performed by a certification body, evaluates the design of your ISMS at a specific moment in time. This is most beneficial when you have already begun implementing some controls or documentation in your ISMS and want to understand potential gaps before beginning your formal audit. 

During this assessment, auditors can identify where your system aligns to ISO 27001 requirements and where additional work is needed, though it does not include any gap remediation on your behalf.  

When a Consultant May Be the Better Option 

If you have not started designing, developing, or implementing your ISMS yet, a readiness assessment likely isn’t the right tool as certification bodies are strictly prohibited from providing consulting or advisory services. They can tell you what the standard requires, but they cannot tell you how to fix gaps or help you build your ISMS.  

In these cases, hiring a consultant might be the better option as they can provide hands-on guidance, helping you design policies, map controls, and build your ISMS. 

Moving Forward with Your ISO 27001 Certification Journey 

Determining when to engage a certification body and whether to conduct a readiness assessment can significantly streamline your ISO 27001 journey. If you've already started implementing your ISMS, a readiness assessment may help pinpoint any remaining work. If you're just beginning, a consultant is likely the more efficient route. 

Whichever stage you're in, early conversations can help set realistic expectations and better position your team for certification success. Contact us today to discuss your ISO 27001 certification objectives and roadmap. 

In the meantime, discover additional ISO 27001 preparation insights in these helpful resources:  

About Ryan Mackie

Ryan Mackie is a Managing Principal at Schellman, and has been with the firm since 2005. Ryan supports the regional Florida market and manages SOC, PCI-DSS, ISO, HIPAA, and Cloud Security Alliance (CSA) STAR Certification and Attestation service delivery. He also oversees the firm-wide methodology and execution for the ISO certification services, including ISO 27001, ISO 9001, ISO 20000-1, and ISO 22301 as well as CSA STAR certification services. He has over 25 years of experience. Ryan also is an active member of the CSA and co-chairs the Open Control Framework committee which is responsible for the CSA STAR Program methodology and execution.