Cyber security · Governance and compliance

ISO 27001 consulting and certification readiness in Australia

Gap assessment, ISMS design, control implementation and audit preparation for organisations that need ISO/IEC 27001:2022 certification to win or keep enterprise and government work. Led by consultants who have run security functions themselves, with an offshore team that carries the documentation and evidence work at a sensible cost.

Book a 30-minute callHow certification works

What ISO 27001 is

The standard, in plain terms

ISO/IEC 27001 is the international standard for an information security management system, usually shortened to ISMS. Certification means an accredited third party has audited your organisation and confirmed that you have a working system for identifying information security risks, deciding how to treat them, applying controls, and checking that those controls keep working. It is a certificate about the management system, and about the controls the system says you operate.

The current version is ISO/IEC 27001:2022. It has ten clauses, of which clauses 4 to 10 set the mandatory requirements: understanding the organisation and its context, leadership, planning, support, operation, performance evaluation and improvement. Annex A lists 93 reference controls in four themes: organisational (37), people (8), physical (14) and technological (34). You select the Annex A controls that apply to your risks and record the decision, with justification for anything excluded, in a Statement of Applicability. Certificates issued against the 2013 edition expired at the end of the transition period in October 2025, so any new certification is against 2022.

Certification is issued by a certification body, and in Australia the bodies you should use are accredited by JAS-ANZ. Coder Trove is a consultancy, and we prepare you for the audit and support you through it; we do not issue certificates, and no consultancy should claim to.

Who needs it in Australia

Organisations pursue ISO 27001 because a customer or market requires it. The usual trigger is commercial: an enterprise customer's procurement team will not proceed without it, a government panel or tender lists it as a requirement, a bank's third-party risk process scores it, or a target market overseas expects it. SaaS and technology companies selling to large organisations meet it earliest. Professional services firms, managed service providers, health and data businesses, and suppliers to APRA-regulated entities under CPS 230 and CPS 234 meet it next. If you have been asked for it, the deadline attached to the request will shape the programme more than the standard does.

How certification works

From first gap assessment to certificate, and what happens after

Gap assessment

We compare what you have against clauses 4 to 10 and the Annex A controls relevant to your risks, and produce a costed, sequenced plan. Two to four weeks. This is also the point to fix the scope, because a scope that is too wide is the most common reason programmes run long.

ISMS design

Context, interested parties, scope statement, information security policy, risk assessment method, risk register, risk treatment plan and Statement of Applicability. Written for your organisation, in the words your people use, with a named owner for each document.

Control implementation

The technical controls, most of which sit in Microsoft 365, Intune, Defender, Entra and your cloud platform: access control, logging, patching, backup, endpoint protection, secure configuration. Our engineers deliver these, or your team does with our specifications.

Operate and evidence

Certification bodies expect to see the system running, typically for three months before Stage 2. Awareness training, supplier reviews, access reviews, incident handling and metrics all generate the records the auditor will sample.

Internal audit and management review

Both are mandatory before certification. We run the internal audit independently of the people who built the system, and facilitate the management review so leadership's decisions are recorded the way the standard requires.

Stage 1 and Stage 2 audits

Stage 1 reviews documentation and readiness; Stage 2 tests implementation. We attend both, manage findings and corrective actions, and stay through surveillance audits in years one and two and recertification in year three.

Talk through your timelineThirty minutes with our cyber security practice manager. A scoped proposal follows within a few business days.

Timeline and cost

How long ISO 27001 takes and what it costs in Australia

For a mid-sized organisation starting from reasonable practice, nine to twelve months from gap assessment to certificate is realistic. Six months is achievable when scope is tight, leadership treats it as an operating change, and the technical controls are already largely in place, for example after an Essential Eight uplift. Eighteen months or more usually means the scope was too broad, ownership was unclear, or the programme was run by one person alongside a day job.

Costs fall into three parts, and the ranges below are market ranges for Australian organisations of 50 to 500 people, so that you can sanity-check any proposal, including ours.

Cost lineTypical Australian rangeWhat moves it
Consulting: gap assessment, ISMS build, internal audit, audit support$30,000 to $120,000Scope, number of sites and entities, how much documentation and control work exists, how much your own team can carry
Certification body: Stage 1, Stage 2, then annual surveillance$8,000 to $25,000 for initial certification; $5,000 to $12,000 per surveillance yearHeadcount and sites in scope, which determine audit days; choice of certification body
Technical remediationNil to $80,000 or moreGaps found in logging, identity, endpoint, backup and cloud configuration; often reduced substantially where Microsoft 365 E3 or E5 licensing is already held
Compliance tooling (optional)$10,000 to $40,000 per yearPlatforms that automate evidence collection; useful for SaaS companies with several frameworks, unnecessary for many others
Internal timeRoughly 0.3 to 0.5 of a full-time person for the programmeWho owns the ISMS after certification, and whether that role exists before you start

Ranges are indicative as at September 2026, exclusive of GST, and drawn from published Australian pricing and our own engagements. A fixed-price proposal follows a gap assessment or a scoping conversation.

Our approach

How Coder Trove runs an ISO 27001 programme

Led by practitioners

Consultants who have owned the risk

The practice is led by our Chief Information Security Officer and run by our Cyber Security Practice Manager. Our governance consultants have led cyber consulting practices, held CISO and CTO roles in government and the private sector, and hold CISM and OSCP certifications. They have presented to audit and risk committees and been audited themselves, and they build the ISMS with both in mind.

Documentation at the right cost

Senior judgement, offshore effort

An ISMS involves a large amount of structured writing, evidence collection and register maintenance. Our delivery centre in Ho Chi Minh City does that work under the direction of the Australian lead, which is how we keep the consulting line in the lower half of the range above without thinning out the senior time where it matters.

Controls, not just policies

Engineers on the same team

Where the gap assessment finds technical control weaknesses, our cloud and security engineers fix them: conditional access, privileged access, logging and alerting in Defender and Sentinel, device compliance in Intune, backup and recovery testing. The written policy then matches the configuration an auditor will see.

Related frameworks

ISO 27001, the Essential Eight, SOC 2 and NIST CSF

Australian organisations rarely face one framework at a time, and the work overlaps more than the acronyms suggest.

Essential Eight and ISO 27001

The Essential Eight is a set of eight technical mitigation strategies with three maturity levels, defined by the Australian Signals Directorate. ISO 27001 is a management system standard with a much broader control set. The eight strategies map directly onto Annex A technological controls, so an organisation that has reached Essential Eight Maturity Level 2 has already implemented a good share of the technical controls ISO 27001 will test. For most Australian organisations the efficient order is Essential Eight first, then ISO 27001 built on top of it. Insurers and Australian customers tend to ask for the Essential Eight; international customers and enterprise procurement tend to ask for ISO 27001.

SOC 2

SOC 2 is an attestation report under the American AICPA framework, common when selling software to US customers. It shares most of its control substance with ISO 27001, and an ISMS built properly provides most of the evidence a SOC 2 Type II examination needs. If your customers are split between Australia and North America, plan both from the start and collect evidence once.

NIST Cybersecurity Framework

NIST CSF 2.0 is a risk management framework rather than a certifiable standard. It is useful for structuring a board-level security programme and is often expected by US-parented organisations. ISO 27001 clauses and Annex A controls map cleanly to its six functions, so organisations that need both usually run them together.

Common questions

ISO 27001 questions we are asked most

How long does ISO 27001 certification take in Australia?
Nine to twelve months is typical for a mid-sized organisation starting from reasonable practice, including the operating period the certification body wants to see before Stage 2. Six months is possible with a tight scope and existing technical controls. The gap assessment gives you a dated plan.
How much does ISO 27001 cost?
Consulting typically runs $30,000 to $120,000 for Australian organisations of 50 to 500 people, plus certification body fees of $8,000 to $25,000 for initial certification and $5,000 to $12,000 for each surveillance year, plus any technical remediation. We quote a fixed price after the gap assessment; the table above shows what moves each line.
Can we scope certification to part of the business?
Yes, and you usually should. The scope can be a product, a business unit, a set of locations or a set of services, as long as the boundary is defensible and the interfaces to the rest of the organisation are managed. Customers will read the scope statement on your certificate, so it needs to cover the services they buy.
Do we need compliance software like Vanta or Drata?
Not for ISO 27001 alone. These platforms automate evidence collection and are worth it for SaaS companies maintaining several frameworks at once. For a single certification, a well-organised document set and a task calendar do the job at a fraction of the cost. We will tell you which applies to you at the gap assessment.
Who issues the certificate?
A certification body, which for Australian organisations should be accredited by JAS-ANZ. We help you choose one, prepare for its Stage 1 and Stage 2 audits, and manage findings. Consultancies do not issue ISO 27001 certificates.
What happens after certification?
The certificate is valid for three years, with a surveillance audit in each of the first two years and recertification in the third. The ISMS has to keep operating: risk reviews, internal audits, management reviews, training and supplier checks on a calendar. Many clients keep us on a light retainer to run the internal audit and prepare surveillance evidence; others take it in-house once the first cycle is done.
We already do the Essential Eight. How much of ISO 27001 is left?
A meaningful share of the technical controls is done. What remains is the management system: risk assessment, policies, ownership, supplier management, awareness, incident process, internal audit and the records that show it all operating. That is most of the documentation effort and roughly half the calendar time.

Start here

Tell us who is asking for the certificate, and when they need it

Thirty minutes with Ben Jones, our Cyber Security Practice Manager, to confirm scope, timeline and the shape of the programme. A scoped proposal follows within a few business days. If you would rather write first, use the contact page.