Some things genuinely do. Most day-to-day compliance management does not. Here is how to tell the difference — and how to avoid paying for work you could do yourself.
Where you need a consultant
These are not suggestions to use Fortify instead. They are situations where a qualified third party is legally required or where the stakes are high enough that self-service is the wrong tool.
The Stage 2 technical assessment must be conducted by an accredited certifying body. You cannot self-certify CE+. Fortify prepares you for it; a certifying body delivers it.
Certification requires an independent accredited audit body. You can build your ISMS without a consultant — but the certification audits themselves must be conducted by a third party.
Determining your lawful basis for complex processing scenarios, responding to enforcement action, or drafting contractual clauses for novel data processing arrangements. These require a solicitor or regulated IG consultant.
CE+ external vulnerability scanning and penetration testing must be conducted by a qualified tester. This is a technical service, not a compliance assessment.
If the ICO contacts you formally, get legal advice before you respond. This is not the moment for a self-service tool.
Where you do not need a consultant
These are common consultant engagements that a structured platform handles better — faster, cheaper, and with live ongoing visibility rather than a point-in-time report.
A structured self-assessment — even a 10-minute one — gives you a scored baseline and a prioritised gap list. A consultant does the same thing, at significantly higher cost, with a lag of days or weeks.
Mapping your data, documenting lawful basis, and building a record of processing activities is systematic work, not specialist work. A structured tool guides you through it in the right order.
The preparation work — gap assessment, control implementation, policy documentation, internal audit — can all be done without a consultant. Many organisations hire one for the preparation, then discover they have paid for work they could have done themselves.
Maintaining your risk register, tracking roadmap progress, logging incidents, managing vendor questionnaires, and generating quarterly reports. These are operational activities — a portal is more effective than a consultant for ongoing use.
Security awareness training, policy acknowledgement, and onboarding processes for new starters. A consultant cannot be present for every new hire; a platform can.
Side by side
| What you need | Consultant | Fortify |
|---|---|---|
| Speed to baseline assessment | Days to weeks (scoping, engagement, report delivery) | 10 minutes (AI-guided, instant scored report) |
| Cost | £1,500–£10,000+ for an initial engagement | Free assessment; portal plans from £149/month |
| Ongoing visibility | Snapshot — accurate at point of assessment, stale immediately after | Live — score and findings update as you work through actions |
| Availability | Subject to scheduling and retainer | Always available; no booking required |
| CE+ Stage 2 assessment | ✓ Required — must use accredited body | ✗ Not provided — Fortify prepares you; certifying body delivers the audit |
| ISO 27001 certification audit | ✓ Required — must use accredited body | ✗ Not provided — Fortify builds your ISMS; certifying body audits it |
| Legal advice on GDPR | ✓ Required for complex scenarios and enforcement | ✗ Not provided — Fortify is informational, not legal advice |
| Risk register and roadmap | ✓ Can build one for you (charged per engagement) | ✓ Built-in, maintained live, exportable |
| Policy library | ✓ Can draft policies (charged per document) | ✓ AI-generated drafts, editable, stored in portal |
| Vendor risk management | ✓ Can assess vendors (charged per engagement) | ✓ Questionnaires, tiering, register — all in portal |
| Incident management | ✗ Typically not included in scope | ✓ Log, investigate, track corrective actions, generate reports |
| White-label reports for your clients | ✓ Consultancy report (no advisor portal) | ✓ Available through the Fortify Advisor Programme |
Decision guide
Stage
Before you start
Use
FortifyRun a free assessment first. It takes 10 minutes and gives you a scored baseline — so if you do engage a consultant, you come to that conversation knowing your position and can focus their time on the specific gaps that need specialist input.
Stage
During preparation
Use
FortifyBuild your documentation, implement controls, manage your roadmap, and maintain your evidence trail. A consultant's time is expensive; use it on things that genuinely require expertise, not on building a policy library.
Stage
At certification time
Use
BothA consultant or accredited body is required for CE+ Stage 2 and ISO 27001 certification audits. Fortify prepares you; the certifying body delivers the assessment. Some organisations also engage a pre-assessment consultant to validate readiness before the formal audit.
Stage
Ongoing management
Use
FortifyAfter certification, ongoing compliance — tracking controls, managing risks, handling incidents, preparing for surveillance audits — is operational work. A portal is more cost-effective and more consistent than repeated consultant engagements.
Stage
When you receive ICO contact or legal challenge
Use
ConsultantGet qualified legal advice before responding. This is a regulated situation requiring professional judgment, not a self-service tool.
Before engaging anyone — consultant or platform — know where you stand. The free Digital Resilience Assessment takes 10 minutes and gives you a scored baseline, a gap list, and a 30/60/90-day plan. No account required.