Cyber Ethos

ISO 27001 Certification in Australia: Process, Cost & Requirements (2026) | Cyber Ethos
ISO 27001 Guide · Australia 2026

ISO 27001 Certification in Australia: Stop Losing Deals Over Security

ISO 27001 is becoming the entry requirement for enterprise contracts, government tenders, and international markets. Here's exactly what it takes to get certified, the process, timeline, cost, and what's changed in 2026.

KK
Dr. Kiran Kewalramani · PhD · CISSP · CISA · GAICD
Founder, Cyber Ethos · 20+ years in cybersecurity · Queensland, Australia
93
Annex A controls in ISO 27001:2022 (across 4 themes)
~100K
Valid certificates worldwide — growing ~20–25% a year (ISO Survey)
3 years
How long a certificate lasts, with annual surveillance audits
2022
Current version — the 2013 edition retired 31 Oct 2025

What Is ISO 27001?

ISO 27001 is the world's leading standard for managing information security. It sets out how an organisation should protect the information it holds — not through a fixed checklist of technology, but by building a proper system for identifying risks and managing them. That system is called an ISMS (information security management system).

What makes ISO 27001 powerful is that it's certifiable. An independent, accredited body can audit you against the standard and, if you meet it, issue an internationally recognised certificate — a credible, third-party stamp that says your security is genuinely managed, not just claimed.

The one-paragraph answer

ISO 27001 (formally ISO/IEC 27001) is the international standard for an information security management system. It requires you to understand your information security risks and put a structured, risk-based system in place to manage them — covering people, processes, and technology. You can be independently audited and certified against it, which is why it's so widely used to prove security to customers, regulators, and partners. The current version is ISO/IEC 27001:2022.

A quick clarification that trips people up: ISO 27001 and ISO 27002 are not the same. ISO 27001 is the standard you get certified against — it contains the requirements and the list of controls. ISO 27002 is a companion guidebook that explains, in detail, how to implement those controls. You certify to 27001; you use 27002 as a how-to reference.

Why Get ISO 27001 Certified?

For most Australian organisations, the decision to certify comes down to two things: winning business and proving trust. The security benefits are real, but it's commercial pressure that usually starts the conversation.

  • It wins and protects contracts. ISO 27001 is increasingly written into enterprise and government tenders as a requirement, or a strong preference. Without it, you can be filtered out before anyone reads your proposal.
  • It shortcuts the security questionnaire. Large customers send long due-diligence questionnaires before they'll buy. A certificate answers many of those questions at a stroke and speeds up the sale.
  • It builds genuine trust. An independent certificate is far more persuasive than telling a customer "we take security seriously." It's evidence, not a claim.
  • It gives you a real security program. Beyond the badge, the process forces you to understand your risks and manage them systematically — which is valuable in its own right.
Why it's becoming a baseline, not a bonus

According to the ISO Survey, the number of valid ISO 27001 certificates worldwide nearly doubled in 2024 to around 100,000, and is growing roughly 20–25% a year. As more of your competitors and peers certify, ISO 27001 is shifting from a differentiator to an expectation — which means not having it increasingly stands out for the wrong reasons.

What ISO 27001 Actually Involves

ISO 27001 has two parts that work together: the management system requirements (the mandatory clauses) and the controls (Annex A). Here's what that means without the jargon.

Part 1: The management system (the mandatory bit)

These are the core requirements every certified organisation must meet — the "system" in ISMS. In plain terms, you must:

🎯
Set the scope and get leadership behind it
Decide what the ISMS covers (which parts of the business, which systems and information) and secure genuine commitment from top management — ISO 27001 explicitly requires leadership involvement, not just an IT sign-off.
⚖️
Assess and treat your risks
Identify the information security risks you actually face and decide how to handle each one. This risk assessment is the engine of the whole standard — everything else flows from it.
📄
Document your Statement of Applicability
The SoA records which Annex A controls you apply, justifies any you leave out, and links them back to your risks. It's one of the most important documents in your ISMS, and auditors lean on it heavily.
🔁
Monitor, audit, and improve
Run internal audits, hold management reviews, and continually improve. ISO 27001 is built on a cycle of doing, checking, and improving — it's designed to keep working over time, not pass once.

Part 2: The Annex A controls (the security measures)

Annex A is the menu of security controls you draw on to treat your risks. In the 2022 version there are 93 controls, grouped under four themes:

🏢
Organisational (37)
Policies, roles, supplier and cloud security, access management rules, incident management — the "how we run security" controls.
👥
People (8)
Screening, security awareness and training, responsibilities, and what happens when people join, move, or leave.
🏬
Physical (14)
Secure areas, equipment protection, clear-desk practices, and physical monitoring — security in the real world, not just online.
💻
Technological (34)
Access control, encryption, logging and monitoring, secure development, backups — the technical safeguards.

Importantly, you don't blindly apply all 93. You apply the controls that your risk assessment says you need, and justify the rest — which is what keeps ISO 27001 risk-based and proportionate rather than a tick-box exercise.

ISO 27001:2022 vs 2013 — What Changed

If you read older guidance online, you'll see references to 114 controls. That's the previous, 2013 version — and it matters that you work from the current one.

The 2022 update made three headline changes:

  • Fewer, reorganised controls. Annex A went from 114 controls to 93, regrouped from 14 categories into the four clear themes above (organisational, people, physical, technological).
  • 11 new controls for modern risks. The update added controls covering things that barely existed in 2013 — including threat intelligence, information security for cloud services, secure coding, data leakage prevention, and monitoring activities.
  • A broader title. The standard's name was updated to reference "cybersecurity and privacy protection," reflecting its wider modern scope.
The 2013 version is gone

The transition period for moving from ISO 27001:2013 to ISO 27001:2022 ended on 31 October 2025. Certificates against the old 2013 version are no longer valid, so every current certification is to the 2022 standard. If you're starting now, you start on 2022 — and if anyone offers to certify you against 2013, that's a clear warning sign.

The ISO 27001 Certification Process, Step by Step

Certification follows a well-worn path. Knowing the steps up front makes the whole thing far less daunting.

  1. Gap analysis
    Start by measuring where you are against the standard. This shows you the gaps to close and gives you a realistic plan and timeline before you commit.
  2. Define your scope and engage leadership
    Agree what the ISMS will cover and get senior management genuinely on board. A scope that's too broad makes the project harder; too narrow and the certificate won't satisfy your customers.
  3. Risk assessment and treatment
    Identify your information security risks and decide how to treat each — the foundation everything else is built on.
  4. Build the ISMS: policies and Statement of Applicability
    Document the controls you'll apply (and why), and put the supporting policies and procedures in place.
  5. Implement the controls
    Put the controls and processes into day-to-day practice, and train your people. This is where the standard becomes real rather than paper.
  6. Internal audit and management review
    Check your own ISMS works — and fix what doesn't — before the certification body looks at it. Leadership formally reviews the system.
  7. Stage 1 audit (readiness)
    An accredited certification body reviews your documentation and confirms you're ready for the main audit.
  8. Stage 2 audit (certification)
    The certification body assesses whether your ISMS is genuinely implemented and effective — testing evidence, not just reading policies.
  9. Certification granted
    Pass, and you're issued an ISO 27001 certificate, valid for three years.
  10. Surveillance and recertification
    Annual surveillance audits keep your certificate live, and a full recertification at the end of the three-year cycle renews it. ISO 27001 is an ongoing commitment, not a one-off.

How Long Does ISO 27001 Take — and What Does It Cost?

Timeline: for most organisations, reaching certification takes somewhere between three and twelve months. A smaller business with a tight scope and reasonable existing practices can move quickly; a larger or more complex organisation starting from a low base will take longer.

Cost: there's no single price, because it depends on several moving parts. Rather than a misleading flat figure, it's more useful to understand what you're paying for:

Getting ready
Scope-based
The work to build your ISMS, run the risk assessment, and close gaps — done in-house, with support, or a mix. Driven by your size and starting maturity.
Certification audit
Separate fee
The accredited certification body's Stage 1 and Stage 2 audit fees — separate from any consulting, and based largely on your organisation's size and scope.
Keeping it
Ongoing
Annual surveillance audits and the effort to maintain the ISMS, plus recertification every three years.

The biggest cost drivers are your size, the scope of the ISMS, and how much remediation you need to reach the standard. The most reliable way to get a real number is a short scoping conversation — anyone quoting a flat fee sight-unseen is guessing.

ISO 27001 vs SOC 2 vs Essential Eight

These three come up together constantly, and they're often confused. They're not competitors so much as different tools for different jobs.

  ISO 27001 SOC 2 Essential Eight
What it is An international, certifiable security management system An auditor's report on your controls (a US framework) Australia's eight prescriptive technical mitigations
You end up with A recognised certificate A report you share (often under NDA) A maturity level (1–3)
Best for Proving managed security to customers and tenders, globally Reassuring US and SaaS customers about specific controls Aligning with Australian government expectations
Approach Risk-based management system Attestation against trust criteria Prescriptive control baseline

In practice they complement each other: ISO 27001 gives you the overarching management system, the Essential Eight provides a strong set of prescriptive technical controls, and SOC 2 serves customers (often US-based) who specifically ask for it. And while ISO 27001 is a strong foundation for APRA CPS 234, it doesn't replace it — CPS 234 has its own specific obligations on top.

Choosing an ISO 27001 Partner: Red Flags to Avoid

Plenty of providers will offer to "get you certified fast." Some are excellent; some will leave you with a fragile certificate and a system no one uses. Here's what to watch for.

🚩
One company offering to both consult and certify you
For certification to mean anything, the body that issues it must be independent of the people who helped you prepare. A provider claiming to do both is a serious red flag — and a sign the certificate may not be properly accredited.
✅ Look for: a consultant who prepares you, and a separate, accredited certification body that audits and certifies you.
🚩
A "certificate in 2 weeks" promise
A genuine ISMS takes time to build and operate, and auditors expect to see evidence it's actually running. Unrealistically fast promises usually mean shortcuts that won't survive scrutiny — or a certificate that isn't worth much.
✅ Look for: a realistic timeline based on your scope and starting point, not a one-size-fits-all promise.
🚩
A box of templates and no risk thinking
ISO 27001 is risk-based. A provider who just hands you generic policy templates without understanding your actual risks gives you shelfware — documents for the auditor that no one in the business follows.
✅ Look for: a real risk assessment tailored to your business that drives which controls you apply.
🚩
Pushing the widest possible scope
A scope that's larger than you need inflates cost and effort; one that's too narrow won't satisfy your customers. Getting scope wrong is one of the most expensive early mistakes.
✅ Look for: help setting a scope that matches what your customers and tenders actually require.
🚩
Disappearing after the certificate
Certification is the start, not the finish — surveillance audits and continual improvement follow. A partner who vanishes once you pass leaves you to maintain it alone.
✅ Look for: support for the ongoing surveillance cycle, ideally as part of broader security leadership.
KK
Practitioner's advice
"The organisations that get the most out of ISO 27001 treat it as a way to genuinely run security better, and the certificate follows. The ones that struggle treat it as a document-writing exercise to win one deal — they pass the audit, then the binder gathers dust until the next surveillance visit causes a panic. Build an ISMS your team actually uses day to day, scope it to what your customers really need, and certification becomes the easy part."
— Dr. Kiran Kewalramani, PhD, CISSP · Founder, Cyber Ethos

5 Myths About ISO 27001

Myth 1: "ISO 27001 is just about paperwork."
Reality: Documentation matters, but certification requires the controls to be genuinely implemented and working. Auditors test evidence and effectiveness — a policy that no one follows won't get you through a Stage 2 audit.
Myth 2: "ISO 27001 is only for big companies."
Reality: Organisations of every size certify, and the scope can be sized to a small business. In fact, it's increasingly expected of small SaaS and service providers, because their enterprise customers demand it.
Myth 3: "Once you're certified, you're done."
Reality: A certificate lasts three years but depends on passing annual surveillance audits and continually improving. ISO 27001 is an ongoing management system, not a one-off badge you hang on the wall.
Myth 4: "ISO 27001 means we're CPS 234 compliant."
Reality: It's a strong foundation, but it doesn't satisfy APRA CPS 234's specific obligations — things like the 72-hour notification rule and the Board's ultimate accountability still need to be addressed separately.
Myth 5: "Our IT team can get us certified on their own."
Reality: ISO 27001 is a management system that needs leadership commitment, risk-based decisions, and organisation-wide processes — including people, physical, and supplier controls. It's far more than a set of IT tasks.

How Cyber Ethos Helps With ISO 27001

Cyber Ethos is led by Dr. Kiran Kewalramani — a PhD-qualified cybersecurity specialist with CISSP, CISA, and GAICD credentials and over 20 years of experience across security and governance. We get organisations ready for ISO 27001 and keep them there — in plain language, scoped to what your customers actually need. That includes:

  • Gap analysis. A clear picture of where you stand against the standard, and a realistic plan and timeline.
  • ISMS design and documentation. Setting the right scope, and building your risk assessment, Statement of Applicability, and supporting policies.
  • Risk assessment and treatment. The risk-based core done properly, so your controls fit your business rather than a generic template.
  • Implementation support and internal audit. Helping you put controls into practice and checking the ISMS genuinely works before the certification body sees it.
  • Certification readiness. Preparing you for the Stage 1 and Stage 2 audits with an independent accredited certification body — we get you ready; the accredited body issues the certificate, as independence requires.
  • Ongoing maintenance. Through a Cyber Ethos virtual CISO, we can keep the ISMS live, manage your surveillance audits, and drive continual improvement — so certification stays an asset, not a scramble.

Thinking about ISO 27001?

Talk to Dr. Kiran Kewalramani directly. We'll start with a gap analysis, show you exactly what certification will take for your business, and map the most efficient path to get there. No jargon, no pressure.

Start with a gap analysis →
📞 1800 CETHOS (1800-238-467) · cyberethos.com.au

Common Questions About ISO 27001 Certification

What is ISO 27001 in simple terms? +
ISO 27001 (formally ISO/IEC 27001) is the international standard for an information security management system, or ISMS — a structured, risk-based way of managing the security of the information your organisation holds, across people, processes, and technology. It's certifiable, meaning an independent accredited body can audit you and issue a recognised certificate. The current version is ISO/IEC 27001:2022.
What's the difference between ISO 27001 and ISO 27002? +
ISO 27001 is the certifiable standard — it sets the requirements for your management system and includes Annex A, the list of controls. ISO 27002 is a companion guidance document that explains in detail how to implement those controls. You get certified against ISO 27001; you use ISO 27002 as a how-to reference. You can't be "certified to ISO 27002".
Why should my business get ISO 27001 certified? +
Mostly to win business and prove trust. ISO 27001 is increasingly required in enterprise and government tenders and in customer security questionnaires, so it opens doors and speeds up due diligence. It also gives you a structured, risk-based security program and supports other obligations such as APRA CPS 234. With global adoption growing around 20–25% a year, it's becoming a baseline expectation rather than a nice-to-have.
How long does ISO 27001 certification take? +
For most organisations, around three to twelve months to reach certification — depending on your size, your scope, how mature your existing controls are, and how much time you can dedicate. A small, focused scope with reasonable practices already in place is faster; a large or complex environment starting from scratch takes longer. The two-stage certification audit is then scheduled once you're ready.
How much does ISO 27001 certification cost? +
There's no single figure. Cost depends on the size and complexity of your organisation, the scope of the ISMS, how much remediation you need, and the certification body's audit fees (separate from any consulting support). Budget for the work to get ready, the independent certification audit, and ongoing annual surveillance. A scoping conversation is the only reliable way to get an accurate estimate — be wary of flat quotes given without understanding your situation.
What is the Statement of Applicability (SoA)? +
The Statement of Applicability is a central ISO 27001 document that lists the Annex A controls, states which ones you apply, justifies any you exclude, and records their status. It connects your risk assessment to the specific controls you've chosen. Auditors rely on it heavily, which makes it one of the most important documents in your ISMS.
What changed in ISO 27001:2022? +
The 2022 version reorganised Annex A from 114 controls into 93, grouped under four themes — organisational, people, physical, and technological — and added 11 new controls covering modern risks such as threat intelligence, cloud security, and secure coding. The title was also broadened to reference cybersecurity and privacy protection. The previous 2013 version was retired after a transition period that ended on 31 October 2025, so all current certifications are to the 2022 standard.
ISO 27001 vs SOC 2 — which do we need? +
It depends on your customers. ISO 27001 is an internationally recognised, certifiable management system — strong for tenders and customers worldwide, and it results in a certificate. SOC 2 is a US attestation report on specific controls, often requested by US-based or SaaS customers, and it results in a report you share (usually under NDA) rather than a certificate. Many growing companies pursue ISO 27001 first as the broader, globally recognised baseline, and add SOC 2 if specific customers require it.
How long does an ISO 27001 certificate last? +
An ISO 27001 certificate is valid for three years. To keep it, you must pass annual surveillance audits during that period, and then complete a full recertification audit at the end of the three-year cycle to renew it. It reflects an ongoing management system, so it has to be maintained rather than achieved once and forgotten.
Does Cyber Ethos issue the ISO 27001 certificate? +
No — and no consultancy should. To keep certification independent, the formal certification audit must be carried out by a separate accredited certification body, which issues the certificate. Cyber Ethos prepares you for that audit — gap analysis, building your ISMS, risk assessment, internal audit, and readiness — so you walk into the certification audit with confidence. Call 1800 CETHOS (1800-238-467) or visit cyberethos.com.au/contact to start.