ISO 27001 certification services cover two separate jobs, and one firm is not allowed to do both. An accredited certification body runs the audit and issues the certificate. An implementation partner builds and operates the information security management system that gets audited. Consilien does the second job. We scope the system, close the control gaps, run the internal audit, and stay in the room through Stage 2.
Two very different companies show up when you search for this
A customer sent you a security questionnaire. Or an insurer did. Or a European partner asked for a certificate before renewal, and now a contract everyone assumed was closed is sitting on someone's desk.
So you searched. And what came back was two entirely different industries wearing the same label.
One group is accredited certification bodies. Firms like A-LIGN, Schellman, NQA, SGS, and Intertek, accredited in the US by ANAB or IAS. They audit you. They issue the certificate. That is the entire product.
The other group builds the thing that gets audited. Consultancies, managed IT and security firms, and platform vendors. Consilien sits here.
Here is the part almost nobody puts on their website. Those two groups are legally separated. ISO/IEC 17021-1, the standard every accredited certification body has to operate under, says in clause 5.2.5 that "the certification body and any part of the same legal entity and any entity under the organizational control of the certification body shall not offer or provide management system consultancy."
Read that again if you skimmed it. Your auditor cannot build your program. Not will not. Cannot.

