All insights
Cyber & risk6 min read

ISO 27001 certification in Australia: the realistic path, cost and timeline

What ISO 27001 certification actually involves for an Australian organisation — scope decisions, the mandatory documents, Stage 1 and Stage 2 audits, realistic cost and timeline, and the mistakes that cause a failed audit.

By FORTE/CYBERx AdvisoryReviewed by FORTE/CYBERx Advisory4 September 2026

Why organisations pursue it here

In Australia, ISO/IEC 27001 is usually bought before it is believed in. An enterprise customer, a government panel, a tender or an insurer asks for it, and the certificate becomes a revenue dependency. That is a legitimate reason to start, but it predicts the two most common outcomes: a scope drawn too narrowly to satisfy the buyer, or a programme run as a documentation exercise that collapses at the first surveillance audit.

The organisations that get value treat the standard as the operating discipline they lacked — a risk register that is reviewed, access that is governed, suppliers that are assessed, incidents that are learned from. The certificate is then a by-product rather than the objective.

Scope: the decision that sets everything else

The scope statement defines which services, locations, people and systems the information security management system (ISMS) covers, and it is printed on the certificate. Buyers read it. A certificate scoped to "the corporate IT function" will not satisfy a customer asking about the platform that processes their data.

Draw the scope around the service the market is asking about, plus the shared functions it genuinely depends on: identity, endpoint management, the development pipeline, the hosting environment, and the people who operate them. Excluding a dependency you rely on is the fastest way to produce a certificate that fails commercial diligence even though it passed audit.

Scope also drives cost. Every additional site, legal entity and product line adds audit days. For most Australian SMEs and scale-ups the right first scope is one product or service, one legal entity, and remote-first working arrangements described honestly.

What the standard actually requires

Clauses 4 to 10 are the mandatory management system: context and interested parties, leadership and policy, risk assessment and treatment, objectives, competence and awareness, documented information, operational control, monitoring, internal audit, management review, and corrective action. These clauses are where audits are passed or failed.

Annex A is the control set — 93 controls across organisational, people, physical and technological themes in the 2022 revision. You do not implement all of them by default; you select them through risk treatment and record the reasoning in the Statement of Applicability, including justified exclusions.

The mandatory documented outputs are a manageable list: scope, information security policy, risk assessment and treatment process, Statement of Applicability, risk treatment plan, security objectives, evidence of competence, operational planning records, monitoring and measurement results, internal audit programme and results, management review minutes, and nonconformity and corrective action records.

The audit sequence

Certification is performed by an accredited certification body — in Australia, accreditation is via JAS-ANZ. Choosing an accredited body matters: an unaccredited certificate is routinely rejected in enterprise procurement.

Stage 1 is a readiness and documentation review, usually remote. The auditor checks that the ISMS exists on paper, the scope is coherent, the risk method is defined and the Statement of Applicability is complete. Findings here are normal and are meant to be fixed before Stage 2.

Stage 2 is the certification audit proper. The auditor samples evidence that the system is operating: access reviews actually performed, risks actually treated, an internal audit actually run, a management review actually held with decisions recorded, incidents actually logged and closed. Nonconformities are raised as minor or major; a major nonconformity must be closed before the certificate issues.

After certification, surveillance audits occur annually and a recertification audit at three years. The recurring cost and effort of surveillance is the part most business cases forget.

Realistic timeline

For a first-time certification with a single-service scope, six to twelve months is the honest range. Under six months is possible only where access governance, logging, supplier assessment and incident handling already function and simply need to be documented and evidenced.

A workable sequence: month one, scope, gap analysis and management commitment. Months two and three, risk assessment, Statement of Applicability and policy set. Months three to six, control implementation and — critically — evidence accumulation, because auditors need to see the system running, not just written. Month six or seven, internal audit and management review. Month seven or eight, Stage 1. Month nine or ten, Stage 2.

The non-negotiable constraint is the evidence period. You cannot show three months of access reviews in a week. Start the recurring activities early even if the documentation is still in draft.

Apply this to your organisation

Want this assessed against your environment?

Send us the specifics and a senior advisor will respond within one business day.

Native secure submission. Your details are never sold or shared.

What it costs

Costs fall into three buckets and vary widely with scope and starting maturity. Certification body fees are the most predictable, priced by audit days across Stage 1, Stage 2 and annual surveillance. Advisory or implementation support is optional but is where the range widens most. Internal effort — usually the largest real cost — is the time of the person coordinating the programme plus the operational teams producing evidence.

Two costs are routinely underestimated: remediation of technical gaps that the risk assessment exposes (multi-factor coverage, logging retention, backup testing, offboarding), and the ongoing annual load of surveillance audits, internal audit and management review. Budget for the operating cost, not just the project.

We do not publish fixed prices for this work because the driver is scope and current state, and any number quoted before a gap analysis is a guess. A short scoping conversation gets you a defensible range.

How it sits with the Essential Eight, ISO 42001 and the Privacy Act

The Essential Eight is a prescriptive technical mitigation set from the ACSC; ISO 27001 is a risk-based management system. They are complements, not alternatives — many Australian organisations use the Essential Eight as the technical baseline inside an ISO 27001 risk treatment plan, and being able to show both is what most enterprise and government buyers actually want.

If you are also adopting AI, ISO/IEC 42001 shares the same clause 4 to 10 management-system structure. Building the ISMS with that in mind means the risk process, internal audit, management review and corrective action machinery serve both standards later, rather than being duplicated.

Certification does not discharge Privacy Act obligations. It provides strong evidence of the "reasonable steps" expected under APP 11, but notifiable data breach duties, collection notices and the handling of personal information remain separate obligations to demonstrate.

Why first-time audits fail

Rarely because a control is missing. Usually because the evidence is thin: a risk register created the month before the audit, an internal audit performed by the person who built the ISMS, a management review with no attendance record or decisions, access reviews that were discussed but not documented, and supplier assessments for one vendor out of forty.

The other recurring cause is a Statement of Applicability that excludes controls without a defensible reason, or that claims controls are implemented when the sampled evidence says otherwise. Auditors sample. Consistency between what the documents claim and what the systems show is the whole test.

The fix is unglamorous: start the recurring rhythms early, keep the records as you go, and have someone independent of the build run the internal audit.

A sensible first 30 days

Week one — decide the scope against the commercial reason you are certifying, and name an accountable owner with executive backing.

Week two — run a gap analysis against clauses 4 to 10 and Annex A, and record findings as risks with owners rather than as a checklist.

Week three — stand up the risk register and the asset and supplier inventories. These three artefacts feed almost everything else.

Week four — start the recurring activities that need history: access reviews, backup restore tests, incident logging and supplier assessment for tier one vendors. Then choose the certification body, because their availability often sets the real timeline.

Sources and further reading

This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.

Related reading

Start a useful conversation

Talk to a senior advisor

Tell us the decision, constraint or opportunity. A senior operator responds within one business day.

Native secure submission. No embedded HubSpot branding.