These are three different purchases. A consultant implements the ISMS and fronts the auditor. A platform — Vanta and Drata are the well-known ones — tracks controls and collects evidence through integrations. Neither runs the security operations underneath: logging, monitoring, vulnerability management. The decision is whether to buy two or three components separately, or one provider that covers all of them.
Vanta and Drata are capable software. They connect to your cloud, your identity provider and your device fleet, collect evidence automatically through those integrations, track controls against the standard, ship usable policy templates, and give your auditor a dashboard rather than a shared drive of screenshots. Companies running them well spend less time assembling evidence.
The decision turns on what sits outside their scope. A platform tracks, a consultant implements, and neither operates the security underneath.
| Consultant | Compliance platform | One provider doing both | |
|---|---|---|---|
| What it covers | Judgement: scoping, risk assessment, policies that match your operations, internal audit, preparing you for and attending Stage 1 and Stage 2 | Automation: evidence collection via integrations, continuous control tracking, policy templates, an auditor-readable dashboard | The judgement and the automation as one engagement, plus operating the controls themselves |
| What it leaves with you | Day-to-day control operation, and everything between engagements — evidence still has to exist after the consultant leaves | Implementing the controls, resolving what the dashboard flags, and answering the auditor | The audit itself, which belongs to an accredited certification body |
| Who runs security operations (log retention, monitoring, vulnerability management) | You | You — the platform reports on whether they are running | The provider |
| Cost shape (AU market rates, ex GST) | A$15,000–55,000 for readiness and implementation | A$7,000–20,000 a year | Scoped to the engagement |
| After certification | Re-engage before each surveillance audit, or carry it internally | Continues tracking, for as long as someone performs the tracked work | Continues running |
The market ranges stack. A platform does not remove the need for the consultant’s judgement, and a consultant does not remove the need for ongoing tracking, so a properly priced plan includes both — and then a third line item.
Annex A’s technological controls require operating capability: logs retained somewhere useful, systems monitored for anomalous behaviour, vulnerabilities found and fixed on a cadence. At Stage 2 the auditor samples the records those activities produce.
In the consultant model, the consultant writes a monitoring policy and the engagement ends. In the platform model, the dashboard shows a control as unmet until monitoring evidence starts arriving. Neither model includes anyone watching the logs. That work goes to your engineers, at a cost paid in roadmap time, or becomes a third purchase from a security operations provider, at which point three vendors are being coordinated to earn one certificate.
Consultant and platform are complements rather than alternatives, so the decision is how many separate components to buy and coordinate: two, three, or one.
Where Vanta or Drata is already in place, keeping it is usually the right call, and an existing platform subscription is an argument for the combined model rather than against it. The platform performs its function; the controls it reports as unmet are the work nobody purchased. Our operations feed the integrations you have already configured, so the evidence arrives without manual collection.
The platforms do not claim otherwise: automated evidence collection collects evidence of what is running, and the vendors say so. The buyer-side error is reading compliance automation as compliance delivered, then finding between purchase and Stage 2 that a monitoring control reports as met once monitoring runs, and monitoring runs once someone operates it.
Establishing who operates it is therefore the decision that sets the real cost and the real timeline, and it precedes the software choice.
Secure60 delivers the certification and operates the security behind it. One engagement covers what the table above splits across columns: the ISMS build and evidence work, preparation for Stage 1 and Stage 2 with your accredited certification body, and the operations underneath — log retention, monitoring, vulnerability management — running on our platform. Secure60 holds ISO 27001:2022 certification, so the system we run for you is the system we run for ourselves. Commercials are scoped to the engagement on a readiness call, with the market ranges above as a benchmark.
Do we still need a consultant if we buy Vanta or Drata?
Usually yes, or someone performing that role. The platform tracks controls and collects evidence through integrations. It does not run your risk assessment, scope your ISMS, write policies that match your operations, or sit with you through Stage 1 and Stage 2. That judgement work is what consultants provide.
Can a compliance platform get us ISO 27001 certified on its own?
No. Certification requires an audit by an accredited certification body, and the audit examines whether controls operate. A platform makes tracking and evidence collection substantially easier. It does not implement the controls or answer the auditor’s questions.
Is Secure60 a Vanta or Drata alternative?
We replace the combination rather than the tool. Instead of buying a platform, hiring a consultant and finding someone to run security operations, you get one provider covering all three for ISO 27001. Where one of those platforms is already in place, we work with it.
What does each option cost?
At Australian market rates: readiness and implementation consulting runs A$15,000–55,000, and a compliance platform A$7,000–20,000 a year, ex GST. The two stack, since most companies buying one also buy the other. Secure60 engagements are scoped individually; see the full ISO 27001 cost breakdown.
Who deals with the auditor in each model?
The audit is performed by an accredited certification body in every model. A consultant prepares you and sits with you through it; a platform gives the auditor organised evidence to sample; a combined provider does both.
Who runs monitoring and log retention in each model?
In the consultant model, you do. In the platform model, you do, and the platform checks whether it is happening and collects the evidence. In the combined model the provider operates the monitoring, log retention and vulnerability management the auditor expects to find running.