forumNew topic

Major enterprise client asked for ISO 27001 certification, can we handle it ourselves without hiring a consultant?

EEbru O***Member
Job title
Quality control inspector
Sector
IT services
Organization type
8-person team
Joined
Jan 2022
Message
139
#1

We are a Riyadh-based B2B software and integration company with 14 employees. We've reached the annual contract stage worth 420,000 SAR with a major semi-governmental client in Saudi Arabia. However, their procurement department added an ISO 27001 certification requirement to the specs and gave us 6 months to get certified.

We don't have a full-time cybersecurity or compliance specialist on staff; our system infrastructure is managed by our senior DevOps engineer. We got quotes from two different consulting firms: one wants 45,000 SAR for the preparation process while the other is asking 75,000 SAR including the audit.

Even though our team is technically strong we have zero experience when it comes to documentation, risk analysis, and drafting policies. Can we complete this process entirely with internal resources in 6 months or is hiring a consultant an absolute must at these budgets?

LLevent Ö***Veteran
Job title
Production planning
Sector
Textile
Organization type
a company within a holding
Joined
Jan 2023
Message
13
Most Helpful#2

Short answer: With a six-month deadline and a complete lack of in-house experience, trying to handle this without a consultant puts the client contract at serious risk. No matter how solid your technical infrastructure is, ISO 27001 isn't just about IT security; it's a company-wide management and documentation system, which means working with an experienced consultant is necessary.

Here's the roadmap you need to follow to pull this off: 1) In the first month, define the scope and get a GAP analysis done. If your contract only covers the B2B software service, narrow the scope down to just that specific product and its operations rather than the whole company. 2) In months two and three, perform the risk assessment, draft the mandatory policies, and put together the Statement of Applicability (SoA). 3) In month four, implement the controls, complete internal staff training, and actually run the system for at least a month. 4) In month five, conduct the mandatory internal audit and hold your management review meeting. 5) In the final month, bring in an accredited certification body and complete the two-stage external audit.

When choosing a consultant, don't let the 75,000 SAR quote mislead you by bundling the audit fee; the certification body performing the audit and the consultant must remain independent. Hiring a consultant in the 40,000 to 50,000 SAR range solely for prep work and documentation, while selecting the audit body separately, will both reduce costs and guarantee impartiality.

DDamla Y***ExpertCommunity member
Joined
Feb 2025
Message
57
#3

We're an 18-person team in Jeddah, we got certified last year. We paid 38,000 SAR for consulting and 18,000 SAR to the accredited audit firm. The whole process took exactly 5.5 months. If we had tried doing it on our own, our DevOps engineer would've had to stop all dev work for at least 3 months, which would've cost us way more in the end.

CCanMember
Job title
SEO Specialist
Joined
Mar 2024
Message
172
#4

Don't dump this entire burden on your DevOps engineer. ISO 27001 isn't just about firewalls and encryption; HR hiring processes, physical office security, vendor contracts, and asset management make up more than half the standard. An engineer can write the technical controls, but they'll hit a brick wall when it comes to process management.

ÖÖmer N***MemberCommunity member
Joined
Jun 2022
Message
62
#5

Be very careful when hiring a consultant. Most of them just copy-paste generic Word templates floating around the market into your company and pocket 40,000 SAR. When the auditor walks in and asks "Who executes this procedure?" your staff won't even know what they're talking about. Look for someone who will actually sit down and design the processes with you not just sell off-the-shelf templates.

GGökhan D***Member
Job title
Business Owner
Sector
Machinery manufacturing
Organization type
40-person manufacturing company
Joined
Oct 2025
Message
416
#6

we initially thought we'd try it ourselves with templates we found online, but after 2 months we were totally drowning in paperwork. once the external auditor pointed out all the gaps right in our faces during stage 1, we had no choice but to hire a consultant. if you have a hard 6-month deadline, imo don't push your luck.

GGamze K***MemberCommunity member
Joined
Oct 2022
Message
3
#7

Since your client is a semi-governmental entity in Saudi Arabia, did they ask solely for ISO 27001, or are they also expecting NCA ECC (Essential Cybersecurity Controls) compliance? Read the RFP carefully; government tenders often include NCA requirements that are far stricter than the ISO standard, and you need to ask the consultant about this right from the start.

LLeyla Y***ExpertCommunity member
Joined
May 2025
Message
102
#8

An important regulatory reminder: Having the consulting firm and the auditing body be the same entity or sister companies violates accreditation standards. When collecting proposals, make sure to verify the validity of the independent certification body's accreditation (such as IAS, UKAS, or SASO-aligned).

DDilara T***Member
Job title
Social media manager
Sector
Logistics
Organization type
a company within a holding
Joined
Aug 2024
Message
333
#9

The first thing you should do is narrow the scope. Don't scope out the entire company's operations; focus only on the infrastructure of the software you deliver to the client and the dev team behind it. The smaller the scope, the fewer assets there are to audit, which speeds up the timeline and cuts consulting costs.

RRıdvanMember
Job title
Dealer network manager
Organization type
regional distributor
Joined
Mar 2024
Message
92
#10

You're right. If you get three different answers on a topic, the question was asked wrong.

If you post the result here, it will help others too.

DDamla K***MemberCommunity member
Joined
Aug 2025
Message
1
#11

I've been dealing with this for a long time. When we decide without measuring, we always end up in the same place.

If you have questions, write them; I'll answer as best I can.

BBurak B***Veteran
Job title
Software developer
Sector
Printing
Organization type
40-person manufacturing company
Joined
Mar 2023
Message
252
#12

weve heard this a lot but it never happened like that for us. anyway dont hesitate to ask; those who dont ask always pay more.

this is my opinion Im not claaiming its absolute truth.

RRecep Y***Member
Job title
System administrator
Sector
Sports and fitness
Organization type
boutique agency
Joined
Jun 2022
Message
9
#13

Here's how it went for us. Security isn't absolute; it's about making attacks not worth the effort.

I'm also curious if anyone does it differently.

OOsman T***Member
Job title
Technical service technician
Sector
Furniture manufacturing
Organization type
a company within a holding
Joined
Jan 2022
Message
3
#14

Let me share what happened to me; it might be useful. Processes without records never improve, because you don't know what to fix.

Of course, it varies if your situation is different.

DDilara A***Member
Job title
Data entry clerk
Sector
Insurance
Organization type
a company within a holding
Joined
Oct 2024
Message
99
#15

We need to make a distinction here. If you scold false alarms, nobody will report again.

I'm also curious if anyone does it differently.

İİlker G***Member
Job title
Production planning
Sector
Jewelry
Organization type
family business
Joined
Jul 2023
Message
13
#16

We need to make a distinction here. If 2FA is on, a stolen password alone is useless.

Proven by experience.

FFurkan U***MemberCommunity member
Joined
Dec 2024
Message
266
#17

You're right, I've been down that road too. Most incidents start with a leaked password, not a vulnerability.

If I were you, I'd go this route.

KKader K***MemberCommunity member
Joined
Oct 2023
Message
6
#18

There's a common mistake people make when doing this. An automated scan report is not the same as a penetration test.

Correct me if I'm wrong.

FFurkan K***MemberCommunity member
Joined
Nov 2023
Message
141
#19

I have a question. Most incidents start with a leaked password, not a vulnerability.

Solutions that work at a small scale collapse when you grow; I learned this late. Correct me if I'm wrong.

HHakan V***Member
Job title
Software developer
Sector
Law
Organization type
40-person manufacturing company
Joined
Mar 2024
Message
27
#20

Could you elaborate on that? Having backups accessible on the same network and with the same identity makes them part of the target.

Just leaving this note, it might be useful.

Reply