They’re different purchases. A consultant implements the ISMS and fronts the auditor. A platform — Vanta and Drata are the well-known ones — tracks controls and collects evidence through integrations. Neither runs the security operations underneath: logging, monitoring, vulnerability management. You’re really deciding whether to buy two or three things separately, or one provider that does all of it.
Start with what’s true about the tools. Vanta and Drata are good software. They connect to your cloud, your identity provider and your device fleet, collect evidence automatically through those integrations, track your controls against the standard, ship usable policy templates, and give your auditor a dashboard instead of a shared drive full of screenshots. Companies that run them well genuinely spend less time on evidence wrangling. None of that is the question.
The question is what’s left over — because a platform tracks, a consultant implements, and neither runs the security operations underneath.
| Consultant | Compliance platform | One provider doing both | |
|---|---|---|---|
| What it’s good at | Judgement: scoping, risk assessment, policies that match your reality, internal audit, preparing you for and sitting with you through Stage 1 and Stage 2 | Automation: evidence collection via integrations, continuous control tracking, policy templates, an auditor-readable dashboard | The judgement and the automation as one engagement, plus operating the controls themselves |
| What it leaves with you | Day-to-day control operation, and everything between engagements — evidence keeps needing to exist after the consultant leaves | Implementing the controls, fixing what the dashboard flags, and answering the auditor | The audit itself, which always belongs to an accredited certification body |
| Who runs security operations (log retention, monitoring, vulnerability management) | You | You — the platform reports on whether they’re running | The provider |
| Cost shape (AU market rates, ex GST) | A$15,000–55,000 for readiness and implementation | A$7,000–20,000 a year | Scoped to the engagement |
| After certification | Re-engage before each surveillance audit, or carry it internally | Keeps tracking — useful exactly as long as someone keeps doing the tracked work | Keeps running |
Note what the table implies about the market ranges: they stack. The platform doesn’t remove the need for the consultant’s judgement, and the consultant doesn’t remove the need for ongoing tracking, so most companies pricing this properly are pricing both — and then discovering a third line item below.
Annex A’s technological controls expect things to be operating, not documented: logs retained somewhere useful, systems monitored for anomalous behaviour, vulnerabilities found and fixed on a cadence. At Stage 2 the auditor samples the records those activities produce.
Here’s how that plays out in each model. The consultant writes you a monitoring policy — a good one — and leaves. The platform puts a tile on the dashboard that stays red until monitoring evidence starts arriving. Neither of them is watching your logs. So the work lands on your engineers, which is a real cost paid in roadmap time, or it becomes a third purchase from a security operations provider, at which point you’re managing three vendors to earn one certificate.
That’s the honest frame for the decision. Not “consultant or platform” — they’re complements, not substitutes — but how many separate things you want to buy and coordinate: two, three, or one.
Already have Vanta or Drata? Then keep it — the objection “we’ve already paid for a platform” is usually an argument for the combined model, not against it. The platform is doing its job; the red tiles are the jobs nobody bought. We make them work and run the security they don’t: our operations feed the integrations you’ve already configured, evidence arrives on its own, and the dashboard goes green for reasons that are true.
Buying the tracker and budgeting nothing for the work being tracked. To be fair to the platforms, they don’t claim otherwise — automated evidence collection means evidence of what’s running gets collected automatically, and the vendors say so. The buyer error is reading “compliance automation” as “compliance done”, then discovering at the gap between purchase and Stage 2 that a monitoring tile turns green when monitoring runs, and monitoring runs when someone runs it. The dashboard was never going to be that someone. Decide who is before you sign anything, because that decision — not the software — sets your real cost and your real timeline.
Tools hand you a to-do list. We do the list — and run the security behind it. One engagement covers what the table above splits across columns: the ISMS build and evidence work, preparation for Stage 1 and Stage 2 with your accredited certification body, and the operations underneath — log retention, monitoring, vulnerability management — running on our platform. We hold ISO 27001:2022 certification ourselves, so the system we run for you is the one we run for us. Commercials are scoped to the engagement on a readiness call, with the market ranges above as your benchmark.
Do we still need a consultant if we buy Vanta or Drata?
Usually, yes — or someone playing that role. The platform tracks controls and collects evidence through integrations; it doesn’t run your risk assessment, scope your ISMS, write policies that match reality, or sit with you through Stage 1 and Stage 2. That judgement work is what consultants are for.
Can a compliance platform get us ISO 27001 certified on its own?
No. Certification requires an audit by an accredited certification body, and the audit examines whether controls actually operate. A platform makes tracking and evidence collection far easier — it doesn’t implement the controls or answer the auditor’s questions.
Is Secure60 a Vanta or Drata alternative?
Not exactly — we replace the combination, not the tool. Instead of buying a platform, hiring a consultant and finding someone to run security operations, you get one provider doing all three for ISO 27001. If you already run one of those platforms, we work with it rather than rip it out.
What does each option cost?
At Australian market rates: readiness and implementation consulting runs A$15,000–55,000, and a compliance platform A$7,000–20,000 a year, ex GST. Those two stack — most companies buying one end up buying the other. Secure60 engagements are scoped individually; see the full ISO 27001 cost breakdown for how the pieces add up.
Who deals with the auditor in each model?
The audit is always performed by an accredited certification body — nobody’s dashboard replaces that. A consultant prepares you and sits with you through it; a platform gives the auditor organised evidence to sample; a combined provider does both of those at once.
Who runs monitoring and log retention in each model?
In the consultant model: you. In the platform model: also you — the platform checks whether it’s happening and collects the evidence. Only in the combined model does the provider actually operate the monitoring, log retention and vulnerability management the auditor expects to see running.