You need a compliance consultant when your team is going through its first SOC 2 or ISO 27001 with no internal security experience and wants an expert to make the judgment calls with you. You need only software when you already understand what the framework asks, or have a fractional advisor, and just want a tool that maps controls, collects evidence, and tracks readiness. Many small teams pay for a bundled advisory they will not fully use; others genuinely need the hand-holding. This guide helps you tell which one you are before you sign a year-long engagement.
The choice matters because the price gap is large and the two are easy to conflate. A consultant is people who guide your program and make recommendations; software is a tool that runs the program day to day. Some vendors bundle both, which blurs the line and makes it hard to see what you are actually paying for. Below is what a consultant does, what software does, where they overlap, and a straight test for your situation.
What does a compliance consultant actually do?
A compliance consultant helps you make decisions software cannot make for you. They scope which framework you need and when, interpret ambiguous controls for your specific setup, help you write or tailor policies, advise on the risk assessment, and prepare you for the auditor's questions. A good one has sat through dozens of audits and knows where teams trip. For a first-timer with no security background, that experience compresses months of learning and reduces the odds of a nasty surprise during the audit. The value is judgment: knowing that a given control can be met three ways and which one fits a company your size.
What does compliance software do instead?
Compliance software does the mechanical, ongoing work: it maps controls to the framework, connects to your cloud and identity systems to pull evidence automatically, assigns the rest to owners with due dates, tracks the management-system tasks, and shows a live readiness score so you always know your position. It does not make judgment calls, but for a team that already knows what it needs, it removes almost all of the manual labor a consultant would otherwise bill hours to coordinate. Tools like evidence collection software and control mapping software turn the audit from a document scramble into a maintained system.
Consultant vs software: what each covers
| Need | Compliance consultant | Compliance software |
|---|---|---|
| Choosing which framework and when | Yes, tailored advice | Guidance in content, not personalized |
| Interpreting ambiguous controls | Yes, their core value | No, applies a standard mapping |
| Writing and tailoring policies | Yes | Drafts policies you edit and approve |
| Collecting evidence continuously | Coordinates it, bills hours | Yes, automated plus owners and due dates |
| Tracking readiness day to day | Periodic check-ins | Yes, live score |
| Cost | Often $10,000 and up per engagement | Published, from $79 a month |
How much does a compliance consultant cost?
Consulting is priced by scope and hours, and a first SOC 2 or ISO 27001 engagement commonly runs from several thousand dollars into five figures, separate from both the software and the audit fee. Some compliance vendors fold advisory into the product and sell them together on an annual quote, which is convenient but means you cannot see what the software alone would cost. That bundling is the core difference between a self-serve tool and a done-for-you platform, and it is worth pricing out separately. Our Scytale alternatives page walks through exactly that trade, software plus bundled advisory versus software you run yourself, because Scytale is the clearest example of the bundled model.
When is a consultant worth it?
Hire a consultant when three things are true: this is your first audit, no one on your team has run one before, and the deal or customer waiting on the certificate is worth far more than the engagement fee. In that situation the consultant's judgment is cheap insurance against a failed or delayed audit. It is also worth it when your setup is genuinely unusual, a complex cloud architecture, an uncommon data-handling model, where the standard mapping needs interpretation. The consultant earns their fee in the gray areas, not in the routine work software already handles.
When is software alone enough?
Software alone is enough when you have done this before, or when someone on the team can read a framework and apply common sense, or when you have a fractional advisor for a few hours rather than a full engagement. It is also enough for renewals and surveillance audits: once the program exists and the controls are mapped, keeping it current is maintenance, not interpretation, and that is squarely software's job. Plenty of 5 to 200 person teams get through SOC 2 and ISO 27001 with a tool and a few hours of ad hoc advice, spending a fraction of a full advisory engagement. If your program touches vendors, pairing that with a way to keep vendor certificates of insurance tracked and current closes one of the evidence gaps auditors flag most often.
What about a virtual CISO or fractional advisor?
A fractional or virtual CISO sits between the two extremes and is often the sweet spot for a small team. Instead of a full audit-prep engagement, you buy a few hours a month of senior security judgment: someone to sanity-check your risk decisions, review the AI-drafted policies before you approve them, and be on call for the auditor's harder questions. Paired with software that does the day-to-day tracking, this covers the judgment gap at a fraction of a full engagement. It works because the routine labor, mapping controls, chasing evidence, watching due dates, is handled by the tool, so the human hours go only to the decisions that actually need a human. For most 5 to 200 person teams, a good tool plus a few advisory hours beats either a full consulting contract or going it completely alone.
The honest recommendation
Match the spend to the uncertainty. High uncertainty, first audit, no experience, high stakes, buy the advisory and let software carry the ongoing work underneath it. Low uncertainty, you know the framework or have light advisory access, buy the software and keep the consulting budget. The common mistake is paying for a bundled advisory retainer out of habit when the team already knows what it needs, or skipping expert help entirely on a high-stakes first audit to save money. Decide on your actual level of uncertainty, not on what a vendor packages by default. If you are weighing the two models directly, our guide to choosing compliance software lays out the rest of the decision.
RUN IT, NOT JUST READ IT
Turn this into tracked rows with owners
Everything in this guide becomes obligations, controls, and evidence with owners and due dates inside Complies, with a live readiness score on top. Plans from $79 a month, prices published.