The buying decision
ISO 27001 certification in Australia means an independent certification body has assessed your organisation’s information security management system against the standard, within a defined scope. The work involves more than buying policies or passing a technical security test. You need a management system that operates, evidence to support it and a plan to maintain it.
Before requesting prices, separate three decisions: what needs to be certified, who will help prepare your business, and who will carry out the independent certification audit.
This guide is for business owners, operations leaders and IT managers comparing requirements, costs and delivery options. For implementation support, see Stanfield IT’s ISO 27001 services.
What does ISO 27001 certification actually prove?
ISO/IEC 27001 sets requirements for an information security management system, usually shortened to ISMS. Its purpose is to manage risks to the confidentiality, integrity and availability of information. The current edition is ISO/IEC 27001:2022, with a 2024 amendment covering climate-action considerations in the organisation’s context. [1] [2]
An ISMS is the way your business makes, implements and checks information security decisions. Certification is independent assurance about that system. It is not a guarantee that no incident will occur, and a certificate for one service or business unit should not be presented as covering everything the organisation does.
Our recommendation: start with the commercial requirement. Ask the customer or procurement team which legal entity, services and locations they expect the certificate to cover. A cheaper, narrower scope is not good value when it excludes the service your customer is buying.
What does your business need before certification?
Use the following as a readiness checklist, not a replacement for the standard or your certification body’s requirements. It is designed to help you test whether a proposal includes the work your business will actually need.
A clear boundary
Identify the services, people, locations, information and supporting systems in scope. Record dependencies on suppliers and shared business functions.
Accountable leadership
Nominate an executive sponsor, a day-to-day ISMS owner and people authorised to approve expenditure, accept risks and resolve overdue actions.
Risk-based decisions
Connect important information risks to treatment decisions, control owners and priorities. Avoid a disconnected policy library.
Evidence and review
Be ready to show how work is performed, checked and improved—not only what the policy says should happen.
The management system needs to fit the organisation. Do not let an implementation proposal treat every business as though it has the same workforce, systems, suppliers and risks. [1]
How much does ISO 27001 certification cost in Australia?
There is no useful all-in price without a scope and a view of your starting point. Ask for separate costs for preparation, technical improvements, independent certification and ongoing operation. Otherwise, a low audit fee can be mistaken for the budget for the whole project.
For context, Citation Group’s published Australian guide describes costs from about A$6,000 for smaller businesses to more than A$40,000 for large organisations, discussing certification, surveillance and implementation. This is one provider’s broad guide—not a national tariff, a complete budget for your business or a Stanfield IT quote. Confirm scope, inclusions, tax treatment and the period covered before relying on any figure. [6]
| Budget category | Ask the supplier to specify | Watch for |
|---|---|---|
| Readiness and ISMS implementation | Gap assessment, scope, risk work, documentation, workshops, evidence preparation and internal review support. | A template package presented as a completed implementation. |
| Technical improvements | Agreed changes to identity, devices, cloud, backups, monitoring and other relevant controls. | Licences, project work or remediation excluded from the headline fee. |
| Independent certification | Stage 1, Stage 2, audit days, travel, follow-up work, surveillance and renewal arrangements. | An initial-audit price being compared with a multi-year package. |
| Keeping the ISMS operating | Internal ownership, evidence collection, reviews, corrective actions, training and recurring support. | No budget or responsible person after the first certificate. |
For your internal business case, calculate:
External implementation + technical uplift + certification fees + internal staff time + ongoing maintenance.
Give each item an owner and identify which costs recur. Record GST consistently. Ask for the assumptions behind any fixed fee, including staff numbers, locations, systems, workshop time and the amount of remediation included. A fixed price without a fixed scope is difficult to compare.
The ISO 27001 certification process in Australia
Keep implementation and independent assessment distinct. SGS describes a certification pathway that includes preparation, Stage 1, Stage 2, a certification decision and subsequent surveillance. The practical checkpoints below help you manage the work around those assessment stages. [5]
1. Agree the scope and business outcome
Write down why you are pursuing certification and what must be covered. Check customer wording before finalising the scope. Name the executive sponsor and the person who will run the project.
2. Assess gaps and approve a delivery plan
Ask for a gap register that separates missing processes, missing evidence and technical weaknesses. Each action should have an owner, effort estimate and dependency. Use that register to agree the budget and schedule.
3. Build and operate the ISMS
Turn risk decisions into working procedures and controls. Start collecting evidence while the work happens. For example, a staff departure should produce a record of the access removed and who checked it—not an unsupported statement that access is always removed promptly.
4. Check the system before the external assessment
Plan internal audit and management review, record findings and deal with corrective actions. Make sure internal auditing is sufficiently objective rather than asking someone simply to approve their own work. BSI’s internal-auditor training covers planning, conducting, reporting and following up an ISMS audit. [9]
5. Complete Stage 1 and Stage 2
Stage 1 examines readiness for the certification process. Stage 2 assesses the implemented management system and its effectiveness. Agree the assessment arrangements with the certification body, address findings and allow time for its certification decision. Booking an audit does not guarantee a certificate. [5]
6. Maintain the system after certification
Keep ownership and review activity in place. Certification normally follows a three-year cycle with surveillance audits between certification and renewal; confirm the precise schedule and fees with your body. [6]
How long does ISO 27001 certification take?
Set the schedule after the gap assessment, not before it. Ask the implementation partner to separate the time needed to become ready from the certification body’s availability, assessment process and decision.
As a starting point, use this illustrative 90-day readiness work plan to organise the first phase. It is not a promise of certification in 90 days or an industry-average timeline. Extend phases where your scope, resources or remediation work require it.
- Days 1–30: establish the baseline.Confirm the business requirement, scope, sponsor, gap register and cost assumptions. Discuss audit availability without treating a tentative booking as proof of readiness.
- Days 31–60: implement and collect evidence.Work through agreed priorities, assign control owners and capture operating records. Escalate dependencies that could delay the project.
- Days 61–90: test readiness and revise the schedule.Review evidence quality, complete planned internal checks and management review, and reassess unresolved gaps before committing to the next audit milestone.
A useful provider proposal should explain what would move the dates: unavailable decision-makers, a major system change, missing records, supplier dependencies or unresolved findings. It should also distinguish your responsibilities from the provider’s.
What documents and evidence should you prepare?
Our recommended approach is to organise evidence around decisions and activities, rather than collecting screenshots without context. Stanfield IT’s ISMS service connects registers, policies, control ownership and review cycles with operational evidence. [11]
For each important control, ask: what risk does it address, who operates it, what record shows it happened, and who checked the result?
| Activity | Useful evidence example | Question to resolve |
|---|---|---|
| Access review | Dated review, reviewer, exceptions and completed removal actions. | Was access checked or merely exported? |
| Backup recovery | Restore-test record, outcome and follow-up actions. | Was recovery tested or only backup-job completion? |
| Supplier assessment | Assessment, scope checks, approval and review date. | Who accepted any remaining risk? |
| Management review | Recorded decisions, assigned actions and resource approvals. | Did leadership make decisions or just receive a report? |
These examples are not an exhaustive mandatory-document list. Agree evidence requirements for your particular scope. Use controlled access for audit material and redact information that the reviewer does not need.
How do Annex A and the Statement of Applicability fit?
Annex A provides reference controls across organisational, people, physical and technological themes. The Statement of Applicability records necessary controls, reasons for inclusion, implementation status and justification for excluded Annex A controls. It should reflect risk-treatment decisions, not an arbitrary selection of convenient controls. PECB explains its role and the need to keep it current. [8]
When comparing implementation proposals, ask who will develop and maintain this document. A useful handover should let your team explain the decisions behind it without relying on a consultant to interpret every row.
How to choose an ISO 27001 consultant and certification body
Your organisation owns the ISMS. An implementation partner helps you prepare it. A certification body independently assesses it. ISO develops standards but does not issue certificates. Accreditation is not compulsory, although it provides an additional level of confidence in a certification body. Check what your customer requires rather than assuming every certificate meets the same procurement conditions. [3]
For a body claiming JASANZ accreditation, use the JASANZ register to check its accreditation and relevant scope. Verify the certificate’s legal entity, covered services, locations and current status with the issuer or appropriate register. A logo on a proposal is not the whole check. [4]
Use these five questions when shortlisting implementation partners:
- What will we actually receive? Ask for deliverables, acceptance criteria and a clear division of responsibilities.
- Who handles technical gaps? Establish whether the engagement includes implementation, advice only or coordination with your IT provider.
- How will audit objectivity be protected? Clarify roles for implementation, internal auditing and independent certification.
- What happens when findings arise? Confirm the remediation allowance, response responsibilities and additional charges.
- What do we keep at the end? Confirm access to editable documents, registers, evidence and agreed platform exports.
Ask for anonymised examples of a roadmap and evidence register, plus relevant references that the provider has permission to share. Be cautious about guaranteed certification dates before anyone has examined your environment.
Avoid turning certification into an annual scramble
Our recommendation is to set the operating calendar before the implementation project closes. Assign owners for risk updates, supplier reviews, evidence checks, staff awareness, internal audits, management review and corrective actions.
For example, introduce a short monthly action review and use it to escalate blocked work. Align more detailed reviews with your risks and certification arrangements, rather than relying on the next audit reminder to restart the programme. This is a suggested management rhythm, not a claim that the standard prescribes monthly meetings.
Stanfield IT provides ISMS implementation and ongoing management, including evidence workflows, review coordination, register updates and remediation tracking. Agree the service scope and what your internal team will continue to own. [11]
How Stanfield IT helps you prepare
Stanfield IT’s ISO 27001 readiness and implementation support can cover gap analysis, ISMS planning, risk treatment, Statement of Applicability support, policies, technical improvements and audit preparation. It connects the management-system work with the systems your business actually operates. [10]
Stanfield IT does not issue ISO 27001 certificates. Independent certification is a separate engagement with a certification body.
For an initial discussion, bring the customer requirement, intended scope, approximate staff numbers, key systems, target date and any existing assessment. The next step should establish what is already in place, what needs work and who will be responsible—not simply sell you a bundle of documents. You can discuss your ISO 27001 readiness with Stanfield IT.
Frequently asked questions
What are the main ISO 27001 certification requirements?
Your organisation needs an ISMS that meets the standard within its defined scope and evidence that it is operating effectively. Use the actual standard and the certification body’s requirements, not a generic online checklist, to establish readiness. [1]
Is an ISMS the same as ISO 27001 certification?
No. The ISMS is your management system. Certification is the independent assessment outcome. You can implement a management system without seeking certification immediately. [3]
Is ISO 27001 certification compulsory?
ISO does not require every organisation using its management-system standards to obtain certification. Check the requirements that apply to your customer contracts, tenders and organisation before deciding whether certification is necessary. [3]
Who can issue an ISO 27001 certificate?
A certification body makes the certification decision. ISO itself and Stanfield IT do not issue the certificate. Confirm the body’s credentials, independence and suitability for the assurance your customer requires. [3] [10]
Does an audit quote cover the full project cost?
Do not assume so. Ask for a written breakdown covering implementation, technical remediation, internal time, independent audits and ongoing support. Compare the same scope and cost period across suppliers.
Can we guarantee certification by a customer’s deadline?
Do not promise an outcome before checking gaps, delivery capacity and certification-body availability. Ask for a readiness plan with dependencies and contingency, and confirm what evidence the customer will accept while the work proceeds.
Does Essential Eight compliance replace ISO 27001?
No. Essential Eight is a set of technical mitigation strategies. ISO 27001 addresses an information security management system. Relevant Essential Eight work can support controls within that system, but does not replace certification. [7] [1]
Is this the same as an individual auditor qualification?
No. This guide concerns certification of an organisation’s ISMS. A training course or auditor qualification develops an individual’s skills; completing one does not certify their employer’s management system. [9]
Sources and further reading
The planning checklists and illustrative readiness schedule are recommendations, not quotations from the standard. Use the current standard and your certification body’s requirements for your engagement.
- ISO: ISO/IEC 27001:2022 — information security management systems
- ISO: ISO/IEC 27001:2022/Amd 1:2024 — climate action changes
- ISO: certification and accreditation
- JASANZ: accredited bodies register; certified organisations register
- SGS Australia: ISO/IEC 27001 certification process
- Citation Group: published Australian cost guide — provider guidance, not a Stanfield IT price or independent market survey.
- ASD’s Australian Cyber Security Centre: Essential Eight
- PECB: the Statement of Applicability
- BSI: ISO/IEC 27001 internal-auditor training
- Stanfield IT: ISO 27001 services
- Stanfield IT: ISMS implementation and management