Cybersecurity

ISO 27001 certification in Australia

ISO 27001 certifies a management system, not a checklist, which is why it takes longer and lasts longer than the alternatives. This page covers what the standard actually requires, what it costs in effort and money in Australia, where projects stall, and how to tell whether your buyers genuinely need it.

What it is

Four things to understand before you commit to ISO 27001

Most failed ISO 27001 projects fail for the same reason: the organisation treated it as a control implementation exercise when the certificate is awarded for running a system.

01

It certifies the system, not the controls

The auditor is checking that you assess risk, document decisions, assign ownership, audit yourself internally and improve continually. Annex A controls matter, and they are selected because your risk assessment justified them. A business that implements every control without the management system around it will still fail the audit.

02

Certification comes from an accredited body

You are audited in two stages by a certification body, not by a consultant. Stage one reviews documentation, stage two tests that the system operates. Anyone offering to certify you without that separation is not offering ISO 27001.

03

Six to twelve months is realistic

The internal audit and management review have to have happened before certification, and they need evidence covering a period. That timing is the reason this cannot be compressed below a few months regardless of budget.

04

It is a three year cycle, not an event

Certification runs three years with surveillance audits in between, then recertification. Budget for the ongoing obligation at the start, because the cost of maintaining it is what organisations forget when they compare it against a one-off assessment.

Fit

When ISO 27001 is worth it, and when it is oversized

ISO 27001 is the right answer for a specific commercial reason. Adopting it without that reason is the most expensive way to improve security.

It suits you when

Enterprise or overseas customers name it in procurement, you are losing deals for want of it, or you handle other organisations data at scale. It carries weight internationally in a way no Australian standard does, and once you hold it the same evidence answers most other security questionnaires.

Enterprise and overseas sales

Look elsewhere when

Nobody has asked for it by name. If the driver is an Australian client questionnaire or an insurer, SMB1001 certifies for a business under two hundred people at a fraction of the effort. If the driver is government work, the Essential Eight and IRAP are the relevant pathway. If your customers are American, they probably mean SOC 2.

When something smaller answers it

How we help

Getting to certification without a stalled project

We are vendor funded, so the service costs your business nothing. We are not an auditor and we do not certify you, which is exactly why we can tell you when you do not need this.

01

Confirm the requirement is genuinely ISO 27001

Read the procurement wording. A meaningful share of businesses scoping ISO 27001 have been asked for something smaller, and the difference is six months and a large number.

02

Set the scope deliberately

Scope decides the size of everything after it. Certifying one product line or one office is legitimate and far faster than certifying the whole organisation. Over-scoping at the start is the single most common cause of a project that never finishes.

03

Assess the gap against the system, not the controls

Risk assessment method, statement of applicability, policy set, ownership, internal audit and management review. Most organisations have some controls and none of the system.

04

Close the control gaps with what you own

A large share of Annex A is configuration inside Microsoft 365 or Google Workspace. We do this before recommending purchases, which usually shortens the shopping list.

05

Run the system, then certify

Internal audit and management review have to have happened. We put continuous evidence collection in place so stage two and the surveillance audits are reports rather than scrambles.

Due diligence

What to check before you start on ISO 27001

These are the items that decide whether certification arrives on time or at all.

Whether your buyers accept an alternative

Some procurement teams accept SOC 2, SMB1001 or a completed questionnaire in place of ISO 27001. Ask before committing to the largest option.

The scope statement

Which entities, sites, systems and services are inside the boundary. This appears on the certificate, so a scope that is too narrow will not satisfy the buyer who asked, and one that is too wide costs months.

Consultant and certification body are separate

The body that audits you cannot be the party that built your system. Any offer that blends the two is a problem you will discover at audit.

The internal audit and management review timing

Both must have run before certification. Projects that leave these to the end lose a quarter to sequencing that could have been planned.

The three year cost, not the first year

Surveillance audits, recertification, and the internal effort to keep evidence current. Ask for the full cycle when comparing quotes, because first year pricing hides most of it.

What already counts

If you hold SOC 2 or have done Essential Eight work, a substantial part of the control evidence carries across. Establish that before scoping from zero.

Common questions

Questions about ISO 27001

What Australian businesses ask us

How much does ISO 27001 certification cost in Australia?

Three costs, and the audit is usually the smallest. There is the certification body fee, which scales with the size and scope of your organisation, any consulting to build the management system, and internal time, which is normally the largest of the three. Ask for the three year figure rather than the first year, because surveillance audits and maintenance are where the ongoing cost sits.

How long does ISO 27001 take?

Six to twelve months for most organisations. The floor is set by process rather than budget: the internal audit and management review must have happened, and stage two tests that the system has been operating. Tight scope shortens it, and an organisation that already runs documented processes will be at the faster end.

Do we need ISO 27001 or SOC 2?

It depends on where your customers are. ISO 27001 is an international certification of a management system and is the common language in Europe, Asia and Australian enterprise procurement. SOC 2 is an American audit report expected by United States customers and software buyers. Businesses selling into both markets often do both, and the underlying control work overlaps heavily.

Is ISO 27001 worth it for a small business?

Usually not unless a named customer requires it. For a business under two hundred people with an Australian client base, SMB1001 produces a certificate at a fraction of the effort. The exception is a small business selling into enterprise or overseas, where ISO 27001 is the entry ticket and the cost is a cost of sale.

Can we get certified without a consultant?

Yes, and it takes longer. The standard is readable and the work is mostly discipline. What a consultant buys you is scope decisions made correctly the first time and a shorter path to internal audit. What a consultant cannot do is certify you, since that must come from an accredited body.

Do you provide ISO 27001 certification?

No, and nobody advising you should. Certification comes from an accredited body that must be independent of whoever built your system. We help you decide whether you need it, set the scope, use what you already own, and put the evidence tooling in place. We are vendor funded, so the service costs your business nothing.

We are vendor funded and completely free to your business. Always focused on the right outcome.

Check whether ISO 27001 is what you were actually asked for.

A meaningful share of the businesses that call us about ISO 27001 have been asked for something smaller. Answer six questions about the request and your current position, and we will tell you which standard it means and what already counts towards it.

Book a Call

Independent guidance at no cost to your business.

Read further on this

The pages and articles that answer the next question a buyer usually asks.