ISO 27001 certifies a management system, not a moment — so the outsourceable work is both the build and the running. The build: scoping the ISMS, the risk assessment and treatment plan, the Statement of Applicability, the Annex A controls, and the policy set.
The running: internal audits, management reviews, corrective actions, evidence upkeep, and the annual surveillance audits that keep the certificate alive through its three-year cycle. A provider can carry all of it; your leadership participates in management reviews, because that seat is genuinely non-delegable.
The standard requires internal audits performed by someone objective and impartial toward the area being audited. In a 20-person company, the engineer who built the ISMS can’t credibly audit it, and certification bodies notice. An outside provider solves this structurally: qualified auditors who didn’t build your controls, with duties separated so the person operating your program isn’t the one auditing it. The certification audit itself always belongs to an independent accredited body — Stage 1, Stage 2, then surveillance. For the startup-sized path see ISO 27001 for startups; the engagement model is on Managed Compliance Services.
No — the standard requires defined responsibilities and visible leadership involvement, not a specific title on payroll. Management review is the piece executives must genuinely attend; the operational roles can be filled externally.
ISO adds a running management system and a three-year certificate with annual surveillance, where SOC 2 re-examines a period each year. Control overlap is large, so one provider running both on shared evidence — as Coalesce did across four frameworks — avoids paying twice.