Skip to main content
PECB · 27001Lead Implementer

PECB ISO/IEC 27001 Lead Implementer Course & Exam Australia

Lead an ISO 27001 implementation from scoping to certification. Choose flexible Self-Study, with a live Online Class or in-person Classroom in Melbourne & Sydney available on request — from $849 + GST, with official PECB examination access and a free exam resit included.

Available Australia-wide, in New Zealand and across Asia Pacific — and, because self-study and eLearning are delivered online through the myPECB platform, from anywhere in the world. Live online classes run in Australian time zones; in-person classroom delivery in Melbourne and Sydney is available on request. Base prices are published in AUD, and every course page supports available local currencies including NZD. An Australian billing address adds 10% GST; a non-Australian billing address has no Australian GST.

The PECB ISO 27001 Lead Implementer training course costs $849 + GST through Aegentra Academy, an official PECB authorised training partner in Australia. That price includes the official PECB examination voucher, the full course materials, 12 months of myPECB access, and one free exam resit within 12 months. The eLearning format is $928 + GST.

Official course provider
PECB
Edition recorded in catalogue
ISO 27001:2022
Self-Study · eLearning
12 months access
Initial attempt and one free retake
2 exam attempts included
/ Purchase order

ISO 27001 Lead Implementer course price and enrolment options

Live online class

Online classes are arranged through the Aegentra Academy team for individual learners and groups.

Contact us for online class

Learn · Practise · Implement

More than the course: learn, practise and implement

Aegentra combines official PECB training with free exam-preparation resources, practical ISO 27001 implementation tools and optional full exam practice through Aegentra Labs.

Learn

Included with course

Official PECB training + exam

  • Official PECB ISO 27001 Lead Implementer training
  • Official PECB examination voucher
  • Initial exam attempt plus one free resit
  • 12 months myPECB access
  • Official course materials
  • PECB credential application pathway

This is what the $849 + GST Self-Study price covers, or $928 + GST with PECB eLearning.

Choose your course

Practise

Free + optional paid

Prepare with Aegentra Labs

Free

Try before you buy

  • 5 free ISO 27001 Lead Implementer practice questions
  • Answer explanations
  • Why the alternative answers are incorrect
  • Sourced ISO 27001 Lead Implementer exam guide
  • Exam format and competency-domain guidance
  • No paid Labs access required
Optional

Want more practice?

$89 + GST for Academy learners

Regular price: $99 + GST · Save $10

  • Full question bank
  • Casual practice mode
  • Timed exam simulation
  • Detailed answer explanations
  • Saved results
  • Domain-level performance feedback
  • 12 months access
  • One payment, no automatic renewal
Add full Labs access — $89

Aegentra Labs is independently authored supplementary exam preparation. It is not official PECB course content and does not guarantee an examination result.

Implement

Free · No email required

Free ISO 27001 practitioner resources

Go beyond passing the exam. Practical resources built around the work itself — the documents you will actually have to produce.

Explore free ISO 27001 resources

How much does the ISO 27001 Lead Implementer exam cost?

Nothing extra. The official PECB examination voucher for the PECB Certified ISO/IEC 27001 Lead Implementer credential is included in the course price, so there is no separate exam fee to pay later. The ISO 27001 Lead Implementer course costs $849 + GST through Aegentra Academy as flexible Self-Study, or $928 + GST as guided eLearning delivered by PECB master trainers. Both include two exam attempts — the initial sit plus one free resit within 12 months — 12 months of myPECB access, and the full course materials.

What you are paying forAegentra Academy
Course — Self-Study$849 + GST
Course — eLearning (PECB master-trainer video)$928 + GST
Official PECB exam voucherIncluded — no separate exam fee
Exam attemptsTwo — initial sit plus one free resit within 12 months
myPECB platform access12 months
Live Online Class or Classroom (Melbourne & Sydney)Available on request
Tax invoice with GST and ABNIssued automatically at checkout

Every ISO 27001 course listed here is official PECB certification training, and all ISO 27001 training is priced the same way: the ISO 27001 exam cost is bundled in with two attempts, so the number you see is the number you pay — there is no separate examination fee at any level.

The optional $89 + GST Aegentra Labs add-on offered on this page is supplementary exam preparation, not a fee for the official PECB examination. The PECB exam voucher is already included in the course price.

How ISO 27001 Foundation, Lead Implementer and Lead Auditor compare

All three are official PECB certifications against ISO/IEC 27001:2022. What separates them is what you will actually do with an ISMS — describe it, build it, or audit it.

CourseWhat it qualifies you to doExamPrice (+ GST)
ISO 27001 FoundationDescribe the standard, the four Annex A themes, and how an ISMS runs day to day1 hour, closed-book$399 + GST
ISO 27001 Lead ImplementerScope, build and operate an ISMS from a blank sheet — risk assessment, Statement of Applicability, the 93 Annex A controls, and Stage 1 / Stage 2 readiness3 hours, open-book, scenario-based$849 + GST
ISO 27001 Lead AuditorPlan and lead internal, supplier and certification audits in line with ISO 190113 hours, open-book, scenario-based$849 + GST

Foundation is recommended but is not a prerequisite. Take Lead Implementer if you will be the person who gets an organisation audit-ready; take Lead Auditor if you will be the person who checks that work.

How hard is the ISO 27001 Lead Implementer exam, and what format is it?

The examination tests whether you can meet the requirements of an information security management system based on ISO/IEC 27001. It runs three hours, open book, with a 70% pass mark, across seven competency domains — ISMS fundamentals, information security controls, planning an implementation, implementing the ISMS, monitoring and measurement, continual improvement, and preparing for the certification audit.

There are two exam formats, and providers routinely quote only one. PECB publishes a separate candidate handbook for each. The essay-type exam is 12 questions worth 75 points. The multiple-choice exam is 80 questions, mixing stand-alone and scenario-based items. Both are open book at 70%. PECB is progressively transitioning this examination from essay to multiple-choice, which is why both handbooks are current — ask which format your sitting uses rather than assuming the figure you read elsewhere. Domain weightings and sample questions for both are in the PECB ISO/IEC 27001 Lead Implementer candidate handbook.

Open book does not mean easy. The questions are scenario-based: you are given an implementation situation and asked what a competent lead implementer would do next, so the materials only help if you already know where to find things in them. The most common failure is treating it as a lookup exercise rather than a judgement one.

Every enrolment includes two attempts — the initial sit plus one free retake within 12 months. PECB requires a 15-day wait between a failed first attempt and the retake, so allow three weeks if you are working to a deadline. Passing without prior ISMS project experience awards Provisional Implementer; the full Lead Implementer credential follows once you attest to the professional experience and project hours PECB requires. What the credential attests is specific: that you can support an organisation in effectively planning, implementing, managing, monitoring and maintaining an ISMS — not that you have memorised the standard.

Sample ISO 27001 artefacts you can download now

Every authorised PECB course teaches the same syllabus. What differs is whether you leave able to produce the documents an auditor asks for. These are the real artefacts from the course, published in full and free to use — no email required.

  • Statement of Applicability (CSV) or PDF — all 93 Annex A controls with a written justification for each, worked through for a 100-staff Australian B2B SaaS. Includes two exclusions with the scope-based reasoning an assessor will accept.
  • Risk register (CSV) or PDF — 18 worked risks with inherent and residual scoring, treatment decisions, and the Annex A controls that treat each one.
  • APRA CPS 234 and DISP mapping (CSV) or PDF — every obligation mapped to the ISO 27001 clause or Annex A control that satisfies it, and the evidence a practitioner would produce.

How to choose an ISO 27001 Lead Implementer course in Australia

Every authorised PECB course leads to the identical credential — the certificate is the same wherever you buy it. What differs is price, format, and what is actually bundled. Five things to verify before you pay:

  • Is the official PECB exam voucher in the price? It is here. Confirm it is not billed separately after enrolment.
  • How many exam attempts do you get? Two — the initial sit plus one free resit within 12 months of purchase.
  • Can you verify the partner? Aegentra Academy is an official PECB authorised training partner in Australia, listed in the PECB partner directory.
  • Which edition of the standard? Confirm ISO/IEC 27001:2022 with the current 93 Annex A controls across four themes — not the superseded 114-control 2013 edition. Our full Annex A control list sets out all 93.
  • Can you train the way you work? Self-Study, a live Online Class, or an in-person Classroom in Melbourne and Sydney, available on request.
/ What you get

What's included in the ISO 27001 Lead Implementer course fee

The official PECB course and exam package starts at $849 + GST — with no separate exam fee after enrolment. Optional Aegentra Labs exam preparation is clearly priced separately.

Course materials
  • PECB ISO/IEC 27001 Lead Implementer slide deck (digital)
  • 12 months access via myPECB
  • Module quizzes, practice scenarios, and exam-style cases
  • Editable ISMS templates — risk register, SoA, policy set
Exam package
  • Official PECB Lead Implementer exam voucher
  • Three-hour open-book exam, remotely proctored
  • Two exam attempts (initial + one free resit)
  • PECB Implementer / Lead Implementer credential on pass
Practitioner extras
  • Aegentra implementation playbook (Australian context)
  • Sample Statement of Applicability for a 100-staff SaaS
  • APRA CPS 234 and DISP mapping reference sheets
  • Pathway discount toward Lead Auditor
/ Exam requirements & credential

ISO 27001 Lead Implementer exam format, duration and pass mark

The exam voucher is included in your enrolment, and so is one free resit if you don't pass first time. Both the exam and the credential are issued directly by PECB.

Format
Open-book, mixed multiple-choice and scenario-based questions
Duration
3 hours
Questions
Two formats are current while PECB transitions: essay-type (12 questions, 75 points) or multiple-choice (80 questions). Both cover 7 competency domains
Pass mark
70%
Language
English (other PECB languages available on request)
Credential experience requirements

PECB credential hierarchy: Provisional → Implementer/Auditor → Lead Implementer/Lead Auditor → Senior Lead, based on professional experience and project hours. Maintained through continuing professional development (CPD) credits.

Official training + independent exam preparation

How can I prepare for the ISO 27001 Lead Implementer exam after training?

Aegentra Academy provides the official PECB course, learning materials and examination pathway. Aegentra Labs is the separate practice workspace for a sourced exam guide, original PECB-style questions, timed exam mode, answer review and domain-level results for this exact qualification.

Labs practice is supplementary, independently authored and not official PECB course content or an examination guarantee.

/ Before you enrol

Clear answers about price, tax, exams, and certification.

These answers use this course's current catalogue record and PECB's published exam, certification, and maintenance policies.

What is included in the ISO 27001 Lead Implementer course fee?

The published price is A$849 for Self-Study or A$928 for eLearning, before tax. It includes the official PECB course materials, 12 months of access, the first exam attempt, one free retake, and the certification application fee. PECB’s partner-course policy also includes the first year of the Annual Maintenance Fee where maintenance applies; Foundation and Provisional credentials are maintenance-exempt. There is no separate first-exam or certification-application charge after enrolment.

What will PECB charge to maintain the ISO 27001 Lead Implementer credential?

PECB’s current maintenance policy lists no maintenance fee for Foundation, Provisional, or Transition credentials. For all other PECB certifications, the published fee is $390 per three-year certification cycle, together with the applicable CPD requirements and continued adherence to the PECB Code of Ethics. PECB sets this fee and may change it, so check the linked policy before renewal.

Can I pay in NZD or another currency, and when is Australian GST added?

Yes. Every Academy course supports AUD and multiple local currencies, including NZD, USD, SGD, GBP, EUR, INR, AED, MYR, PHP, IDR, and VND when a live quote is available. Currency and tax are separate: an Australian billing address adds 10% GST, while a non-Australian billing address has no Australian GST. For example, an Australian working in New Zealand may pay in NZD and use an Australian billing address, but 10% GST will still be added because the billing address is Australian.

What is the difference between Self-Study and eLearning for ISO 27001 Lead Implementer?

Self-Study costs A$849 before tax and uses the official PECB slide-based materials. eLearning costs A$928 before tax — A$79 more — and adds recorded trainer-led lessons and interactive learning activities. Both routes lead to the same PECB exam and credential, and both include the same exam package. Choose eLearning if explanations and video guidance help you learn; choose Self-Study if you are comfortable working through standards-based material independently and want the lowest price.

Can I sit the ISO 27001 Lead Implementer exam remotely from New Zealand or another time zone?

Yes. PECB publishes remote online exam sessions that candidates can take from home or another suitable location through the PECB Exams application. The published course record lists these exam facts: duration — 3 hours; format — Open-book, mixed multiple-choice and scenario-based questions; assessment — Two formats are current while PECB transitions: essay-type (12 questions, 75 points) or multiple-choice (80 questions). Both cover 7 competency domains; pass mark — 70%; language — English (other PECB languages available on request). New Zealand candidates should choose a published session that suits their local time, meet PECB’s identity and technical requirements, and complete the system check before exam day. PECB’s general exam policy does not publish a New Zealand restriction.

Which credential tier will I receive after the ISO 27001 Lead Implementer exam, and who assesses it?

PECB credential hierarchy: Provisional → Implementer/Auditor → Lead Implementer/Lead Auditor → Senior Lead, based on professional experience and project hours. Maintained through continuing professional development (CPD) credits. Passing the exam does not by itself guarantee the highest experience-based credential tier. PECB requires an online certification application and reference contact details, and its Certification Department decides whether the education, professional experience, and implementation or consulting activity requirements are met.

What evidence does PECB accept for the experience or project hours for ISO 27001 Lead Implementer?

PECB’s public certification-process page does not publish a closed list of documents that automatically proves project hours. It requires the online application and contact details for references who may be contacted to validate your experience. Keep a dated activity log showing the organisation or client, your role, the implementation or consulting activity, dates, responsibilities, and hours; retain employer or client confirmations, statements of work, timesheets, or similar records in case PECB asks for support. The PECB Certification Department assesses the application and makes the final decision.

Can I become both a Lead Implementer and a Lead Auditor?

Yes. You can hold both the ISO 27001 Lead Implementer and ISO 27001 Lead Auditor credentials. They are separate, complementary certifications: Lead Implementer demonstrates that you can build and operate the management system, while Lead Auditor demonstrates that you can audit and verify it. To earn both, complete each course, pass each exam, and apply for each credential. PECB assesses implementation-project experience for the Implementer tier and audit experience for the Auditor tier separately. If you pass an exam before meeting its full experience requirements, you can receive the applicable Provisional credential and upgrade later when those requirements are met; you do not need to retake that exam. Neither credential automatically grants the other.

/ Training prerequisites

What you should know before starting ISO 27001 Lead Implementer

  • Working knowledge of information security concepts.
  • ISO 27001 Foundation or equivalent experience recommended (not required).
/ Who this course is for

Who should take the ISO 27001 Lead Implementer course

  • Security managers, consultants, and prospective ISMS owners
  • Practitioners deploying ISO 27001 from scratch inside their organisation
  • Internal auditors moving into implementation roles
/ What you'll learn

By the end of this course you'll be able to:

  • Plan, scope, and stand up an ISO/IEC 27001:2022 ISMS from a blank sheet of paper.
  • Conduct a defensible information security risk assessment and treatment plan.
  • Produce a Statement of Applicability tailored to the organisation's context.
  • Operationalise the 93 Annex A controls — including which to apply, which to exclude, and why.
  • Prepare the organisation for the Stage 1 and Stage 2 certification audit.
/ Curriculum

What does the ISO 27001 Lead Implementer course cover?

6 modules, fully on-demand. Click any module to see the topics inside.

01How an ISO 27001 implementation project is structured
  • Recap of ISO 27001 structure
  • The PECB implementation methodology
  • Building the implementation project plan
  • Stakeholder mapping and executive buy-in
02How to define ISMS scope, context, and leadership commitment
  • Determining internal and external context
  • Interested parties and their requirements
  • Defining the ISMS scope
  • Information security policy and objectives
03How to run the risk assessment and write the Statement of Applicability
  • Asset, threat, and vulnerability approach
  • Likelihood and impact scoring
  • Risk acceptance criteria
  • Selecting controls and writing the Statement of Applicability
04How to implement the 93 Annex A controls
  • Organizational and People controls
  • Physical and Technological controls
  • Mapping controls to existing processes
  • Evidence design and recording
05How to operate the ISMS — internal audit, management review, and KPIs
  • Awareness, training, and communication
  • Internal audit programme
  • Management review
  • Monitoring, measurement, and KPIs
06How to pass the Stage 1 and Stage 2 certification audit
  • Selecting a certification body
  • Stage 1 and Stage 2 audits explained
  • Nonconformity classification and corrective action
  • Surveillance and recertification cycles
/ Your trainers

Who teaches this course.

Named trainers are shown only where their role and public credentials can be verified. Delivery mode varies by course and selected cohort.

Carl Carpenter

Carl Carpenter

Cybersecurity Professional & Penetration Tester

11 competencies44 modules
ISO/IEC 27001 Senior Lead AuditorCISACISMPCI-QSA

A highly experienced cybersecurity professional and penetration tester with deep expertise across regulated environments — CMMC, HIPAA, PCI, FFIEC, CCPA, and GDPR. A certified auditor and instructor holding ISO/IEC 27001 Senior Lead Auditor, CISA, CISM, and PCI-QSA, and a Cisco, Microsoft, CompTIA, and PECB-certified specialist.

Graeme Parker

Graeme Parker

Cybersecurity & Information Security Expert

13 competencies15 modules
PECB Certified TrainerISO 27001ISO 22301ISO 42001

A Security, Technology, Risk, and Compliance professional with vast experience across private and public sector roles spanning financial services, government, manufacturing, healthcare, and retail. A certified PECB trainer delivering ISO/IEC 27001, ISO 22301, ISO/IEC 42001, CISSP, CISM, and CISA courses globally across the UK, USA, Canada, and Europe.

Nathalie Claes

Nathalie Claes

Security Governance Expert & Management Consultant

8 competencies32 modules
CISO-as-a-ServiceCompliance & RiskDPO

A Security Governance expert and management consultant with over a decade of international experience leading complex security projects. She delivers CISO-as-a-service, senior compliance and risk management, and DPO services, and coaches organisations through growth and restructuring to build resilient, future-ready teams.

/ Career signal

What does an ISO 27001 Lead Implementer do?

The credential that says you can build the system

Lead Implementer is the certification a hiring manager looks for when the job is to stand up an ISMS — scope it, run the risk assessment, write the Statement of Applicability, operationalise the 93 Annex A controls, and walk an external auditor through stage 1 and stage 2 without surprises. It is the difference between "I have heard of ISO 27001" and "I have implemented ISO 27001 from a blank sheet of paper."

Where it shows up in Australian job descriptions

Information Security Manager, ISMS Manager, GRC Lead, Compliance Manager, Security Consultant, vCISO — every one of these roles in the Australian market either requires Lead Implementer or accepts it as a strong substitute for years of equivalent experience. Tier-1 consultancies (Deloitte, PwC, KPMG, EY) and security boutiques use it as a baseline competency check for security-advisory hires. Government-aligned roles (DTA, ATO suppliers, Defence DISP-registered firms) treat it as evidence of implementation capability.

How it pairs with the broader compliance stack

Lead Implementer trains a single core skill — designing and operating a management system to an ISO standard — that transfers directly to ISO 27701 (privacy), ISO 42001 (AI management), ISO 22301 (business continuity), and ISO 9001 (quality). Practitioners who hold Lead Implementer for ISO 27001 are routinely promoted into multi-standard programme roles because the methodology is shared.

The credential most consulting buyers ask for first

When an Australian SMB engages a consultant for ISO 27001 readiness, the procurement question that arrives first is "are your consultants PECB Lead Implementer certified?" Holding the credential is what unlocks billable-day rates in the $1,500-$2,500 AUD range, and it is the only credential that lets you sign off implementation artefacts on behalf of a certification body programme.

/ Where this lands in Australia

ISO 27001 Lead Implementer training in Australia — who hires it

APRA-regulated financial services

APRA CPS 234 obligates regulated entities to maintain information-security capability commensurate with the size and complexity of the organisation, and to test it. Lead Implementer is the credential most often cited when APRA, an internal audit committee, or an external assessor asks "who designed your information-security management system?". Banks, mutuals, super funds, and insurers in Australia almost universally hold Lead Implementer competency in the second line of defence.

Government contractors — DISP, PSPF, IRAP-adjacent work

Defence-industry suppliers under DISP, and Commonwealth tenders at PROTECTED or above, want demonstrable ISMS implementation capability. While IRAP is its own assessment regime focused on ASD ISM controls, the underlying management system that satisfies IRAP looks identical to ISO 27001 — and Lead Implementer is the standard credential for the staff who stand it up. The Protective Security Policy Framework (PSPF) and the ASD Information Security Manual both share their structural DNA with ISO 27001 clauses 4-10.

SaaS, MSPs, and managed-security providers

Any Australian SaaS company targeting enterprise procurement or scaling into the US market will need an organisational ISO 27001 certificate. Lead Implementer is the credential the security lead holds when running that readiness programme — typically as Head of Security, Security Engineering Manager, or vCISO. Managed-service providers running multi-tenant infrastructure use Lead Implementer-credentialled architects to design the shared ISMS that customers inherit.

Healthcare, critical infrastructure, education

Entities captured by the Security of Critical Infrastructure (SOCI) Act and the My Health Records Act both lean on ISO 27001 as the implementation template for their statutory information-security obligations. Public-sector education providers and large hospital networks use the credential as a baseline for security-architect and ISMS-owner roles.

/ Study plan

Is the ISO 27001 exam difficult? How to prepare

The exam is open-book, but the questions reward fluency, not lookup. Plan your study around these checkpoints.

  1. 01Re-read the standard end-to-end at least twice — Lead Implementer is open-book but you cannot afford to be looking up clause numbers during a scenario question. Aim for the point where you can cite clauses 4-10 by number.
  2. 02Build a mock Statement of Applicability for an imagined 100-staff organisation. The exam will throw scenario questions that hinge on whether you can justify a control inclusion or exclusion in writing.
  3. 03Practise mapping a risk-treatment plan against the 93 Annex A controls. Most exam scenarios assume you can land on the right control family within seconds.
  4. 04Walk the implementation methodology twice — context, leadership, risk assessment, SoA, operation, internal audit, management review. The methodology is the spine of every multi-part scenario question.
  5. 05Time-box your practice exam. The official exam is three hours for a multi-domain paper; if you cannot finish the practice in two and a half, your retrieval fluency is the limiting factor — not your knowledge.
  6. 06Schedule the exam 14-21 days after finishing the slides. This is more material than Foundation; rushing the exam window is the single biggest cause of first-attempt failure.

Free learning resources

Put the course concepts into practice.

Use Aegentra’s existing templates, checklists, registers and mappings alongside your course. No account or email is required.

Browse free ISO 27001 resources
/ Practitioner proof

We train what we implement

Aegentra31 July 2026

Case study

Internal

audit

ISO 27001

Transitioning to ISO/IEC 27001: overcoming internal audit bottlenecks

Prepared by

Aegentra Information Security & Compliance Team

Aegentra does not only teach ISO 27001 — we implement and audit it. The engagement record below is a real Clause 9.2 internal audit for an Australian technology company: all of Clauses 4 to 10 and a risk-based sample of 47 Annex A controls, across 73 lines of enquiry. Scope, method, every finding and how each was closed out are published in full.

/ Related reading

Related ISO 27001 resources

Free companion reading for anyone studying or implementing ISO/IEC 27001:2022:

  • ISO 27001 Annex A controls — all 93 controls across the four themes, the 11 that are new in 2022, the ISO 27002 control attributes, and how the Statement of Applicability governs what you implement.
  • ISO 27001 checklist — every mandatory document with its clause number, clause 4–10 readiness checks, Stage 1 and Stage 2 audit lists, and a 12-week readiness timeline.
  • ISO 27001 certification guide for Australia — real costs in AUD, the certification process step by step, and how PECB and JAS-ANZ accreditation fit together.

Compare the family

See where this course fits

The ISO 27001 family page compares current levels, prices, delivery, audiences and exam facts before you choose a pathway.

Compare ISO 27001 pathways

Source and review status

How these course facts are governed

Price, delivery and course content are generated from Aegentra’s authoritative catalogue record. The official PECB course page and exam policy are linked directly below. Source-link checks and substantive human review are tracked separately so one is never presented as the other.

Official PECB sources

Editorial accountability

Harry Sidhu owns publication of this record. A separate course-specific substantive reviewer has not yet been recorded.

Substantive review status

Official source links are checked separately. A course-specific substantive review date will be published when completed.

/ Accreditation

Is the ISO 27001 Lead Implementer certification recognised in Australia?

Yes. PECB certifications are internationally accredited and are accepted on Australian resumes, tender responses and procurement panels. Australia has no separate national licence for ISO 27001 Lead Implementer — the recognition comes from the accreditation behind the credential, which is international.

PECB’s professional certifications are accredited under ISO/IEC 17024 — the international standard for bodies certifying persons — by IAS, UKAS, KAB and COFRAC. Its Foundation certificate programs are separately accredited by ANAB (ANSI National Accreditation Board) under ANSI/ASTM E2659.

Aegentra Academy is an official PECB authorised training partner in Australia, which is what allows this course to include the official PECB examination voucher rather than billing it separately. You can confirm that directly with PECB through the official PECB partner directory.

This official PECB course is sold and supported by Aegentra Academy. PECB supplies the course material, examination and professional credential scheme. Aegentra's wider practice also runs ISO 27001 readiness and GRC engagements and Microsoft 365 hardening for Australian organisations. Named eLearning trainers are credited separately on this page when the course record supplies them.

Courses run online and self-paced through the myPECB platform, so professionals across Melbourne, Sydney, Brisbane, Perth, Adelaide, Canberra and New Zealand enrol online. Instructor-led cohorts and in-person delivery in Melbourne and Sydney are available on request. Multi-seat team pricing is available for five or more seats — email Academy@aegentra.com.au for an enterprise quote. Tax invoices with GST and ABN are issued automatically at checkout.

/ Frequently asked

ISO 27001 Lead Implementer — frequently asked.

Is the ISO 27001 Lead Implementer exam difficult?

It is harder than Foundation but designed to be passed with preparation. The PECB ISO 27001 Lead Implementer exam runs three hours, is open-book, and mixes multiple-choice with scenario-based questions across seven competency domains at a 70% pass mark. Because it is scenario-based it rewards understanding the IMS2 implementation methodology rather than memorising clauses. One free resit is included within 12 months.

How much does the ISO 27001 Lead Implementer course cost in Australia?

The PECB ISO 27001 Lead Implementer course costs $849 + GST through Aegentra Academy, and that price includes the official PECB exam voucher, the full course materials, 12 months of myPECB access, and one free resit within 12 months. Instructor-led equivalents from Australian training providers typically run $2,500 to $3,900 + GST.

What jobs does the ISO 27001 Lead Implementer credential open in Australia?

It is the credential most often named in Australian job ads for ISMS Manager, Information Security Manager, GRC Consultant, Security Compliance Lead, and ISO 27001 readiness consultant roles. In-house it is the qualification for the person who owns the ISMS through stage 1 and stage 2; in consulting it is what lets you bill as the lead on a readiness programme. The credential level you are awarded (Provisional Implementer through Senior Lead Implementer) depends on the professional experience you attest to. For the full pathway — prerequisites, exam, experience attestation, and what employers actually ask for — read aegentra.com.au/insights/how-to-become-iso-27001-lead-implementer

What does the PECB ISO 27001 Lead Implementer course cover?

Six modules covering the entire ISMS lifecycle — from scoping and risk assessment, through the Statement of Applicability, the 93 Annex A controls, day-to-day operation, performance evaluation, and the stage 1 / stage 2 certification audit. Total effort is 30-40 hours of self-paced study.

Is Lead Implementer worth it without Foundation first?

Foundation is recommended but not required. The course assumes a working knowledge of information security concepts. If you have implemented controls in a previous role — even informally — you can go straight to Lead Implementer. If the standard is genuinely new to you, Foundation first is the faster total path because you avoid plateauing on vocabulary during the harder material.

How is the Lead Implementer exam structured?

Three hours, open-book, mixed multiple-choice and scenario-based questions across seven competency domains. Pass mark is 70%. The credential awarded depends on the level of professional implementation experience you can attest to — Provisional Implementer (no experience), Implementer (2 years), Lead Implementer (5 years, with 300 hours on ISMS projects), or Senior Lead Implementer (10 years).

What makes the Aegentra Lead Implementer course different?

Every authorised PECB Lead Implementer course leads to the same credential — the certificate is identical wherever you buy it. The differences are price, format, and who supports you. Aegentra delivers Lead Implementer at $849 + GST (self-study) or $928 + GST (eLearning) — both including the exam voucher and one free resit. Aegentra is also an active Australian ISO consultancy, so the Australian-context artefacts and support come from current management-system practice.

Does Lead Implementer let me certify my organisation?

Lead Implementer credentials the individual — it does not certify the organisation. To get the organisational ISO 27001 certificate you still need a stage 1 and stage 2 audit performed by an accredited certification body (in Australia, typically a JAS-ANZ accredited body). What Lead Implementer does is qualify you to run that readiness programme from the inside, or as the lead consultant.

What is the difference between Lead Implementer and Lead Auditor?

Lead Implementer is the build-side credential — designing and operating an ISMS. Lead Auditor is the verification-side credential — planning and conducting internal, supplier, and certification audits. The two are deliberately separate skill sets, governed by different competency frameworks (PECB Implementer programme vs PECB Auditor programme aligned with ISO 19011). Many practitioners hold both, in sequence — typically Implementer first.

How does Lead Implementer help with APRA CPS 234?

CPS 234 imposes detailed information-security capability obligations on APRA-regulated entities — including an information-asset inventory, classified information-security capability, an incident response capability, and regular testing. The management-system structure that satisfies CPS 234 is, in practice, an ISO 27001 ISMS. Lead Implementer is the credential for the practitioner designing and operating that ISMS. CPS 234 specifically is not a substitute for the ISO 27001 certificate, but the operational artefacts overlap heavily.

Can I use Lead Implementer to consult independently?

Yes. Lead Implementer is the standard credential for independent ISO 27001 readiness consultants in Australia. To use the Lead Implementer title you need to attest to 5 years of professional experience including at least 300 hours on ISMS implementation projects — the credential is awarded at the appropriate level (Provisional Implementer / Implementer / Lead Implementer) based on the experience you attest to.

How long does the Lead Implementer course take?

Typical effort is 30-40 hours of self-paced study spread over four to six weeks. You have 12 months of myPECB access so the pace is yours. Most working professionals complete it in 6-8 weeks of evenings; a focused full-time week is also feasible.

What CPD credits do I earn?

PECB awards 31 CPD credits on completion of the ISO 27001 Lead Implementer course. These count toward CPD requirements at ISACA, (ISC)², AISA, and other professional bodies on submission, and toward maintenance of other PECB credentials.

Can I deliver internal training using the course materials?

The slide deck is licensed for individual study. To deliver structured training to colleagues you should engage Aegentra for a group enrolment — that licenses the material correctly, provides exam vouchers for each attendee, and includes a tailoring session for your organisation's context.

Can my employer pay or reimburse?

Yes, and either direction works. Complete checkout yourself and forward the Stripe tax invoice for reimbursement, or write to Academy@aegentra.com.au and we will invoice your organisation directly with payment terms. Once payment clears we reserve the seats and assign each course to the email addresses you nominate, so your team can start straight away. Groups of five or more are enrolled on a single invoice.

When can I start the course?

Immediately after payment. The Academy team confirms your seat with PECB and you receive login details by email — usually within one business day.

How long do I have access to the course?

You have 12 months of access from enrolment. That window covers the course material, the official PECB exam, and one free resit if you need it.

What if I fail the exam?

One PECB-issued resit is included in your enrolment at no extra cost. Aegentra does not publish a pass-rate claim without an audited cohort dataset.

Questions about invoicing, GST, group bookings, refunds or instructor-led delivery? Read the Academy FAQ.

$849AUD · EXCL. TAX