Cyber security · Governance and compliance
ISO 27001 consulting and certification readiness in Australia
Gap assessment, ISMS design, control implementation and audit preparation for organisations that need ISO/IEC 27001:2022 certification to win or keep enterprise and government work. Led by consultants who have run security functions themselves, with an offshore team that carries the documentation and evidence work at a sensible cost.
What ISO 27001 is
The standard, in plain terms
ISO/IEC 27001 is the international standard for an information security management system, usually shortened to ISMS. Certification means an accredited third party has audited your organisation and confirmed that you have a working system for identifying information security risks, deciding how to treat them, applying controls, and checking that those controls keep working. It is a certificate about the management system, and about the controls the system says you operate.
The current version is ISO/IEC 27001:2022. It has ten clauses, of which clauses 4 to 10 set the mandatory requirements: understanding the organisation and its context, leadership, planning, support, operation, performance evaluation and improvement. Annex A lists 93 reference controls in four themes: organisational (37), people (8), physical (14) and technological (34). You select the Annex A controls that apply to your risks and record the decision, with justification for anything excluded, in a Statement of Applicability. Certificates issued against the 2013 edition expired at the end of the transition period in October 2025, so any new certification is against 2022.
Certification is issued by a certification body, and in Australia the bodies you should use are accredited by JAS-ANZ. Coder Trove is a consultancy, and we prepare you for the audit and support you through it; we do not issue certificates, and no consultancy should claim to.
Who needs it in Australia
Organisations pursue ISO 27001 because a customer or market requires it. The usual trigger is commercial: an enterprise customer's procurement team will not proceed without it, a government panel or tender lists it as a requirement, a bank's third-party risk process scores it, or a target market overseas expects it. SaaS and technology companies selling to large organisations meet it earliest. Professional services firms, managed service providers, health and data businesses, and suppliers to APRA-regulated entities under CPS 230 and CPS 234 meet it next. If you have been asked for it, the deadline attached to the request will shape the programme more than the standard does.
How certification works
From first gap assessment to certificate, and what happens after
Gap assessment
We compare what you have against clauses 4 to 10 and the Annex A controls relevant to your risks, and produce a costed, sequenced plan. Two to four weeks. This is also the point to fix the scope, because a scope that is too wide is the most common reason programmes run long.
ISMS design
Context, interested parties, scope statement, information security policy, risk assessment method, risk register, risk treatment plan and Statement of Applicability. Written for your organisation, in the words your people use, with a named owner for each document.
Control implementation
The technical controls, most of which sit in Microsoft 365, Intune, Defender, Entra and your cloud platform: access control, logging, patching, backup, endpoint protection, secure configuration. Our engineers deliver these, or your team does with our specifications.
Operate and evidence
Certification bodies expect to see the system running, typically for three months before Stage 2. Awareness training, supplier reviews, access reviews, incident handling and metrics all generate the records the auditor will sample.
Internal audit and management review
Both are mandatory before certification. We run the internal audit independently of the people who built the system, and facilitate the management review so leadership's decisions are recorded the way the standard requires.
Stage 1 and Stage 2 audits
Stage 1 reviews documentation and readiness; Stage 2 tests implementation. We attend both, manage findings and corrective actions, and stay through surveillance audits in years one and two and recertification in year three.
Timeline and cost
How long ISO 27001 takes and what it costs in Australia
For a mid-sized organisation starting from reasonable practice, nine to twelve months from gap assessment to certificate is realistic. Six months is achievable when scope is tight, leadership treats it as an operating change, and the technical controls are already largely in place, for example after an Essential Eight uplift. Eighteen months or more usually means the scope was too broad, ownership was unclear, or the programme was run by one person alongside a day job.
Costs fall into three parts, and the ranges below are market ranges for Australian organisations of 50 to 500 people, so that you can sanity-check any proposal, including ours.
| Cost line | Typical Australian range | What moves it |
|---|---|---|
| Consulting: gap assessment, ISMS build, internal audit, audit support | $30,000 to $120,000 | Scope, number of sites and entities, how much documentation and control work exists, how much your own team can carry |
| Certification body: Stage 1, Stage 2, then annual surveillance | $8,000 to $25,000 for initial certification; $5,000 to $12,000 per surveillance year | Headcount and sites in scope, which determine audit days; choice of certification body |
| Technical remediation | Nil to $80,000 or more | Gaps found in logging, identity, endpoint, backup and cloud configuration; often reduced substantially where Microsoft 365 E3 or E5 licensing is already held |
| Compliance tooling (optional) | $10,000 to $40,000 per year | Platforms that automate evidence collection; useful for SaaS companies with several frameworks, unnecessary for many others |
| Internal time | Roughly 0.3 to 0.5 of a full-time person for the programme | Who owns the ISMS after certification, and whether that role exists before you start |
Ranges are indicative as at September 2026, exclusive of GST, and drawn from published Australian pricing and our own engagements. A fixed-price proposal follows a gap assessment or a scoping conversation.
Our approach
How Coder Trove runs an ISO 27001 programme
Led by practitioners
Consultants who have owned the risk
The practice is led by our Chief Information Security Officer and run by our Cyber Security Practice Manager. Our governance consultants have led cyber consulting practices, held CISO and CTO roles in government and the private sector, and hold CISM and OSCP certifications. They have presented to audit and risk committees and been audited themselves, and they build the ISMS with both in mind.
Documentation at the right cost
Senior judgement, offshore effort
An ISMS involves a large amount of structured writing, evidence collection and register maintenance. Our delivery centre in Ho Chi Minh City does that work under the direction of the Australian lead, which is how we keep the consulting line in the lower half of the range above without thinning out the senior time where it matters.
Controls, not just policies
Engineers on the same team
Where the gap assessment finds technical control weaknesses, our cloud and security engineers fix them: conditional access, privileged access, logging and alerting in Defender and Sentinel, device compliance in Intune, backup and recovery testing. The written policy then matches the configuration an auditor will see.
Related frameworks
ISO 27001, the Essential Eight, SOC 2 and NIST CSF
Australian organisations rarely face one framework at a time, and the work overlaps more than the acronyms suggest.
Essential Eight and ISO 27001
The Essential Eight is a set of eight technical mitigation strategies with three maturity levels, defined by the Australian Signals Directorate. ISO 27001 is a management system standard with a much broader control set. The eight strategies map directly onto Annex A technological controls, so an organisation that has reached Essential Eight Maturity Level 2 has already implemented a good share of the technical controls ISO 27001 will test. For most Australian organisations the efficient order is Essential Eight first, then ISO 27001 built on top of it. Insurers and Australian customers tend to ask for the Essential Eight; international customers and enterprise procurement tend to ask for ISO 27001.
SOC 2
SOC 2 is an attestation report under the American AICPA framework, common when selling software to US customers. It shares most of its control substance with ISO 27001, and an ISMS built properly provides most of the evidence a SOC 2 Type II examination needs. If your customers are split between Australia and North America, plan both from the start and collect evidence once.
NIST Cybersecurity Framework
NIST CSF 2.0 is a risk management framework rather than a certifiable standard. It is useful for structuring a board-level security programme and is often expected by US-parented organisations. ISO 27001 clauses and Annex A controls map cleanly to its six functions, so organisations that need both usually run them together.
Common questions
ISO 27001 questions we are asked most
How long does ISO 27001 certification take in Australia?
How much does ISO 27001 cost?
Can we scope certification to part of the business?
Do we need compliance software like Vanta or Drata?
Who issues the certificate?
What happens after certification?
We already do the Essential Eight. How much of ISO 27001 is left?
Start here
Tell us who is asking for the certificate, and when they need it
Thirty minutes with Ben Jones, our Cyber Security Practice Manager, to confirm scope, timeline and the shape of the programme. A scoped proposal follows within a few business days. If you would rather write first, use the contact page.