Cybersecurity
ISO 27001 certification in Australia
ISO 27001 certifies a management system, not a checklist, which is why it takes longer and lasts longer than the alternatives. This page covers what the standard actually requires, what it costs in effort and money in Australia, where projects stall, and how to tell whether your buyers genuinely need it.
What it is
Four things to understand before you commit to ISO 27001
Most failed ISO 27001 projects fail for the same reason: the organisation treated it as a control implementation exercise when the certificate is awarded for running a system.
Fit
When ISO 27001 is worth it, and when it is oversized
ISO 27001 is the right answer for a specific commercial reason. Adopting it without that reason is the most expensive way to improve security.
It suits you when
Enterprise or overseas customers name it in procurement, you are losing deals for want of it, or you handle other organisations data at scale. It carries weight internationally in a way no Australian standard does, and once you hold it the same evidence answers most other security questionnaires.
Enterprise and overseas sales
Look elsewhere when
Nobody has asked for it by name. If the driver is an Australian client questionnaire or an insurer, SMB1001 certifies for a business under two hundred people at a fraction of the effort. If the driver is government work, the Essential Eight and IRAP are the relevant pathway. If your customers are American, they probably mean SOC 2.
When something smaller answers it
How we help
Getting to certification without a stalled project
We are vendor funded, so the service costs your business nothing. We are not an auditor and we do not certify you, which is exactly why we can tell you when you do not need this.
Confirm the requirement is genuinely ISO 27001
Read the procurement wording. A meaningful share of businesses scoping ISO 27001 have been asked for something smaller, and the difference is six months and a large number.
Set the scope deliberately
Scope decides the size of everything after it. Certifying one product line or one office is legitimate and far faster than certifying the whole organisation. Over-scoping at the start is the single most common cause of a project that never finishes.
Assess the gap against the system, not the controls
Risk assessment method, statement of applicability, policy set, ownership, internal audit and management review. Most organisations have some controls and none of the system.
Close the control gaps with what you own
A large share of Annex A is configuration inside Microsoft 365 or Google Workspace. We do this before recommending purchases, which usually shortens the shopping list.
Run the system, then certify
Internal audit and management review have to have happened. We put continuous evidence collection in place so stage two and the surveillance audits are reports rather than scrambles.
Due diligence
What to check before you start on ISO 27001
These are the items that decide whether certification arrives on time or at all.
Whether your buyers accept an alternative
Some procurement teams accept SOC 2, SMB1001 or a completed questionnaire in place of ISO 27001. Ask before committing to the largest option.
The scope statement
Which entities, sites, systems and services are inside the boundary. This appears on the certificate, so a scope that is too narrow will not satisfy the buyer who asked, and one that is too wide costs months.
Consultant and certification body are separate
The body that audits you cannot be the party that built your system. Any offer that blends the two is a problem you will discover at audit.
The internal audit and management review timing
Both must have run before certification. Projects that leave these to the end lose a quarter to sequencing that could have been planned.
The three year cost, not the first year
Surveillance audits, recertification, and the internal effort to keep evidence current. Ask for the full cycle when comparing quotes, because first year pricing hides most of it.
What already counts
If you hold SOC 2 or have done Essential Eight work, a substantial part of the control evidence carries across. Establish that before scoping from zero.
Common questions
Questions about ISO 27001
What Australian businesses ask us
How much does ISO 27001 certification cost in Australia?
Three costs, and the audit is usually the smallest. There is the certification body fee, which scales with the size and scope of your organisation, any consulting to build the management system, and internal time, which is normally the largest of the three. Ask for the three year figure rather than the first year, because surveillance audits and maintenance are where the ongoing cost sits.
How long does ISO 27001 take?
Six to twelve months for most organisations. The floor is set by process rather than budget: the internal audit and management review must have happened, and stage two tests that the system has been operating. Tight scope shortens it, and an organisation that already runs documented processes will be at the faster end.
Do we need ISO 27001 or SOC 2?
It depends on where your customers are. ISO 27001 is an international certification of a management system and is the common language in Europe, Asia and Australian enterprise procurement. SOC 2 is an American audit report expected by United States customers and software buyers. Businesses selling into both markets often do both, and the underlying control work overlaps heavily.
Is ISO 27001 worth it for a small business?
Usually not unless a named customer requires it. For a business under two hundred people with an Australian client base, SMB1001 produces a certificate at a fraction of the effort. The exception is a small business selling into enterprise or overseas, where ISO 27001 is the entry ticket and the cost is a cost of sale.
Can we get certified without a consultant?
Yes, and it takes longer. The standard is readable and the work is mostly discipline. What a consultant buys you is scope decisions made correctly the first time and a shorter path to internal audit. What a consultant cannot do is certify you, since that must come from an accredited body.
Do you provide ISO 27001 certification?
No, and nobody advising you should. Certification comes from an accredited body that must be independent of whoever built your system. We help you decide whether you need it, set the scope, use what you already own, and put the evidence tooling in place. We are vendor funded, so the service costs your business nothing.
We are vendor funded and completely free to your business. Always focused on the right outcome.
Check whether ISO 27001 is what you were actually asked for.
A meaningful share of the businesses that call us about ISO 27001 have been asked for something smaller. Answer six questions about the request and your current position, and we will tell you which standard it means and what already counts towards it.
Book a Call
Independent guidance at no cost to your business.
Read further on this
The pages and articles that answer the next question a buyer usually asks.
- Our advice on cybersecurity advisory
- Check where you stand
- Cyber security services Brisbane
- Cyber security services Melbourne
- Cyber security services Sydney
- essential-eight
- mdr
- penetration-testing
- security-services-explained
- security-standards-compared
- smb1001-certification
- virtual-ciso
- the incident response pack, free download
- the IT continuity pack, free download
- connectivity and SD-WAN
- advice for IT leaders
- advice for finance leaders
- ACMA’s 2026-27 priorities, and the SMS deadline

