What Is ISO 27001?
ISO 27001 is the world's leading standard for managing information security. It sets out how an organisation should protect the information it holds — not through a fixed checklist of technology, but by building a proper system for identifying risks and managing them. That system is called an ISMS (information security management system).
What makes ISO 27001 powerful is that it's certifiable. An independent, accredited body can audit you against the standard and, if you meet it, issue an internationally recognised certificate — a credible, third-party stamp that says your security is genuinely managed, not just claimed.
ISO 27001 (formally ISO/IEC 27001) is the international standard for an information security management system. It requires you to understand your information security risks and put a structured, risk-based system in place to manage them — covering people, processes, and technology. You can be independently audited and certified against it, which is why it's so widely used to prove security to customers, regulators, and partners. The current version is ISO/IEC 27001:2022.
A quick clarification that trips people up: ISO 27001 and ISO 27002 are not the same. ISO 27001 is the standard you get certified against — it contains the requirements and the list of controls. ISO 27002 is a companion guidebook that explains, in detail, how to implement those controls. You certify to 27001; you use 27002 as a how-to reference.
Why Get ISO 27001 Certified?
For most Australian organisations, the decision to certify comes down to two things: winning business and proving trust. The security benefits are real, but it's commercial pressure that usually starts the conversation.
- It wins and protects contracts. ISO 27001 is increasingly written into enterprise and government tenders as a requirement, or a strong preference. Without it, you can be filtered out before anyone reads your proposal.
- It shortcuts the security questionnaire. Large customers send long due-diligence questionnaires before they'll buy. A certificate answers many of those questions at a stroke and speeds up the sale.
- It builds genuine trust. An independent certificate is far more persuasive than telling a customer "we take security seriously." It's evidence, not a claim.
- It gives you a real security program. Beyond the badge, the process forces you to understand your risks and manage them systematically — which is valuable in its own right.
According to the ISO Survey, the number of valid ISO 27001 certificates worldwide nearly doubled in 2024 to around 100,000, and is growing roughly 20–25% a year. As more of your competitors and peers certify, ISO 27001 is shifting from a differentiator to an expectation — which means not having it increasingly stands out for the wrong reasons.
What ISO 27001 Actually Involves
ISO 27001 has two parts that work together: the management system requirements (the mandatory clauses) and the controls (Annex A). Here's what that means without the jargon.
Part 1: The management system (the mandatory bit)
These are the core requirements every certified organisation must meet — the "system" in ISMS. In plain terms, you must:
Part 2: The Annex A controls (the security measures)
Annex A is the menu of security controls you draw on to treat your risks. In the 2022 version there are 93 controls, grouped under four themes:
Importantly, you don't blindly apply all 93. You apply the controls that your risk assessment says you need, and justify the rest — which is what keeps ISO 27001 risk-based and proportionate rather than a tick-box exercise.
ISO 27001:2022 vs 2013 — What Changed
If you read older guidance online, you'll see references to 114 controls. That's the previous, 2013 version — and it matters that you work from the current one.
The 2022 update made three headline changes:
- Fewer, reorganised controls. Annex A went from 114 controls to 93, regrouped from 14 categories into the four clear themes above (organisational, people, physical, technological).
- 11 new controls for modern risks. The update added controls covering things that barely existed in 2013 — including threat intelligence, information security for cloud services, secure coding, data leakage prevention, and monitoring activities.
- A broader title. The standard's name was updated to reference "cybersecurity and privacy protection," reflecting its wider modern scope.
The transition period for moving from ISO 27001:2013 to ISO 27001:2022 ended on 31 October 2025. Certificates against the old 2013 version are no longer valid, so every current certification is to the 2022 standard. If you're starting now, you start on 2022 — and if anyone offers to certify you against 2013, that's a clear warning sign.
The ISO 27001 Certification Process, Step by Step
Certification follows a well-worn path. Knowing the steps up front makes the whole thing far less daunting.
-
Gap analysisStart by measuring where you are against the standard. This shows you the gaps to close and gives you a realistic plan and timeline before you commit.
-
Define your scope and engage leadershipAgree what the ISMS will cover and get senior management genuinely on board. A scope that's too broad makes the project harder; too narrow and the certificate won't satisfy your customers.
-
Risk assessment and treatmentIdentify your information security risks and decide how to treat each — the foundation everything else is built on.
-
Build the ISMS: policies and Statement of ApplicabilityDocument the controls you'll apply (and why), and put the supporting policies and procedures in place.
-
Implement the controlsPut the controls and processes into day-to-day practice, and train your people. This is where the standard becomes real rather than paper.
-
Internal audit and management reviewCheck your own ISMS works — and fix what doesn't — before the certification body looks at it. Leadership formally reviews the system.
-
Stage 1 audit (readiness)An accredited certification body reviews your documentation and confirms you're ready for the main audit.
-
Stage 2 audit (certification)The certification body assesses whether your ISMS is genuinely implemented and effective — testing evidence, not just reading policies.
-
Certification grantedPass, and you're issued an ISO 27001 certificate, valid for three years.
-
Surveillance and recertificationAnnual surveillance audits keep your certificate live, and a full recertification at the end of the three-year cycle renews it. ISO 27001 is an ongoing commitment, not a one-off.
How Long Does ISO 27001 Take — and What Does It Cost?
Timeline: for most organisations, reaching certification takes somewhere between three and twelve months. A smaller business with a tight scope and reasonable existing practices can move quickly; a larger or more complex organisation starting from a low base will take longer.
Cost: there's no single price, because it depends on several moving parts. Rather than a misleading flat figure, it's more useful to understand what you're paying for:
The biggest cost drivers are your size, the scope of the ISMS, and how much remediation you need to reach the standard. The most reliable way to get a real number is a short scoping conversation — anyone quoting a flat fee sight-unseen is guessing.
ISO 27001 vs SOC 2 vs Essential Eight
These three come up together constantly, and they're often confused. They're not competitors so much as different tools for different jobs.
| ISO 27001 | SOC 2 | Essential Eight | |
|---|---|---|---|
| What it is | An international, certifiable security management system | An auditor's report on your controls (a US framework) | Australia's eight prescriptive technical mitigations |
| You end up with | A recognised certificate | A report you share (often under NDA) | A maturity level (1–3) |
| Best for | Proving managed security to customers and tenders, globally | Reassuring US and SaaS customers about specific controls | Aligning with Australian government expectations |
| Approach | Risk-based management system | Attestation against trust criteria | Prescriptive control baseline |
In practice they complement each other: ISO 27001 gives you the overarching management system, the Essential Eight provides a strong set of prescriptive technical controls, and SOC 2 serves customers (often US-based) who specifically ask for it. And while ISO 27001 is a strong foundation for APRA CPS 234, it doesn't replace it — CPS 234 has its own specific obligations on top.
Choosing an ISO 27001 Partner: Red Flags to Avoid
Plenty of providers will offer to "get you certified fast." Some are excellent; some will leave you with a fragile certificate and a system no one uses. Here's what to watch for.
5 Myths About ISO 27001
How Cyber Ethos Helps With ISO 27001
Cyber Ethos is led by Dr. Kiran Kewalramani — a PhD-qualified cybersecurity specialist with CISSP, CISA, and GAICD credentials and over 20 years of experience across security and governance. We get organisations ready for ISO 27001 and keep them there — in plain language, scoped to what your customers actually need. That includes:
- Gap analysis. A clear picture of where you stand against the standard, and a realistic plan and timeline.
- ISMS design and documentation. Setting the right scope, and building your risk assessment, Statement of Applicability, and supporting policies.
- Risk assessment and treatment. The risk-based core done properly, so your controls fit your business rather than a generic template.
- Implementation support and internal audit. Helping you put controls into practice and checking the ISMS genuinely works before the certification body sees it.
- Certification readiness. Preparing you for the Stage 1 and Stage 2 audits with an independent accredited certification body — we get you ready; the accredited body issues the certificate, as independence requires.
- Ongoing maintenance. Through a Cyber Ethos virtual CISO, we can keep the ISMS live, manage your surveillance audits, and drive continual improvement — so certification stays an asset, not a scramble.
Thinking about ISO 27001?
Talk to Dr. Kiran Kewalramani directly. We'll start with a gap analysis, show you exactly what certification will take for your business, and map the most efficient path to get there. No jargon, no pressure.
Start with a gap analysis →📞 1800 CETHOS (1800-238-467) · cyberethos.com.au