Honest comparison

Do you need a security consultant?

Some things genuinely do. Most day-to-day compliance management does not. Here is how to tell the difference — and how to avoid paying for work you could do yourself.

This page is not anti-consultant. Consultants are right for specific situations — we name them. The question is knowing which situation you are in.

Where you need a consultant

Five things that genuinely require specialist input

These are not suggestions to use Fortify instead. They are situations where a qualified third party is legally required or where the stakes are high enough that self-service is the wrong tool.

01

Cyber Essentials Plus Stage 2 assessment

The Stage 2 technical assessment must be conducted by an accredited certifying body. You cannot self-certify CE+. Fortify prepares you for it; a certifying body delivers it.

02

ISO 27001 Stage 1 and Stage 2 audits

Certification requires an independent accredited audit body. You can build your ISMS without a consultant — but the certification audits themselves must be conducted by a third party.

03

Legal advice on GDPR obligations

Determining your lawful basis for complex processing scenarios, responding to enforcement action, or drafting contractual clauses for novel data processing arrangements. These require a solicitor or regulated IG consultant.

04

Penetration testing

CE+ external vulnerability scanning and penetration testing must be conducted by a qualified tester. This is a technical service, not a compliance assessment.

05

ICO investigation response

If the ICO contacts you formally, get legal advice before you respond. This is not the moment for a self-service tool.

Where you do not need a consultant

Five things most organisations pay for and could do themselves

These are common consultant engagements that a structured platform handles better — faster, cheaper, and with live ongoing visibility rather than a point-in-time report.

01

Understanding your current security posture

A structured self-assessment — even a 10-minute one — gives you a scored baseline and a prioritised gap list. A consultant does the same thing, at significantly higher cost, with a lag of days or weeks.

02

Building your ROPA and GDPR documentation

Mapping your data, documenting lawful basis, and building a record of processing activities is systematic work, not specialist work. A structured tool guides you through it in the right order.

03

Preparing for CE+ or ISO 27001

The preparation work — gap assessment, control implementation, policy documentation, internal audit — can all be done without a consultant. Many organisations hire one for the preparation, then discover they have paid for work they could have done themselves.

04

Ongoing compliance management

Maintaining your risk register, tracking roadmap progress, logging incidents, managing vendor questionnaires, and generating quarterly reports. These are operational activities — a portal is more effective than a consultant for ongoing use.

05

Educating your team

Security awareness training, policy acknowledgement, and onboarding processes for new starters. A consultant cannot be present for every new hire; a platform can.

Side by side

Consultant vs Fortify

What you needConsultantFortify
Speed to baseline assessmentDays to weeks (scoping, engagement, report delivery)10 minutes (AI-guided, instant scored report)
Cost£1,500–£10,000+ for an initial engagementFree assessment; portal plans from £149/month
Ongoing visibilitySnapshot — accurate at point of assessment, stale immediately afterLive — score and findings update as you work through actions
AvailabilitySubject to scheduling and retainerAlways available; no booking required
CE+ Stage 2 assessment✓ Required — must use accredited body✗ Not provided — Fortify prepares you; certifying body delivers the audit
ISO 27001 certification audit✓ Required — must use accredited body✗ Not provided — Fortify builds your ISMS; certifying body audits it
Legal advice on GDPR✓ Required for complex scenarios and enforcement✗ Not provided — Fortify is informational, not legal advice
Risk register and roadmap✓ Can build one for you (charged per engagement)✓ Built-in, maintained live, exportable
Policy library✓ Can draft policies (charged per document)✓ AI-generated drafts, editable, stored in portal
Vendor risk management✓ Can assess vendors (charged per engagement)✓ Questionnaires, tiering, register — all in portal
Incident management✗ Typically not included in scope✓ Log, investigate, track corrective actions, generate reports
White-label reports for your clients✓ Consultancy report (no advisor portal)✓ Available through the Fortify Advisor Programme

Decision guide

When to use each approach

Stage

Before you start

Use

Fortify

Run a free assessment first. It takes 10 minutes and gives you a scored baseline — so if you do engage a consultant, you come to that conversation knowing your position and can focus their time on the specific gaps that need specialist input.

Stage

During preparation

Use

Fortify

Build your documentation, implement controls, manage your roadmap, and maintain your evidence trail. A consultant's time is expensive; use it on things that genuinely require expertise, not on building a policy library.

Stage

At certification time

Use

Both

A consultant or accredited body is required for CE+ Stage 2 and ISO 27001 certification audits. Fortify prepares you; the certifying body delivers the assessment. Some organisations also engage a pre-assessment consultant to validate readiness before the formal audit.

Stage

Ongoing management

Use

Fortify

After certification, ongoing compliance — tracking controls, managing risks, handling incidents, preparing for surveillance audits — is operational work. A portal is more cost-effective and more consistent than repeated consultant engagements.

Stage

When you receive ICO contact or legal challenge

Use

Consultant

Get qualified legal advice before responding. This is a regulated situation requiring professional judgment, not a self-service tool.

Start with the free assessment

Before engaging anyone — consultant or platform — know where you stand. The free Digital Resilience Assessment takes 10 minutes and gives you a scored baseline, a gap list, and a 30/60/90-day plan. No account required.