The short version
- Organisational ISO 27001 certification and personal PECB certification are separate processes. This guide concerns the individual auditor pathway.
- Learning, examination success, credential application and credential award are separate stages. Provisional Auditor still requires an application and PECB approval.
- Professional experience and qualifying audit hours are separate requirements: Auditor needs 200 hours, Lead Auditor 300 and Senior Lead Auditor 1,000.
- Choose Self-Study (A$829 + GST), PECB eLearning (A$849 + GST) or private online training (A$2,799 + GST, by enquiry).
First, clear up the confusion: your company vs you
“ISO 27001 certification” means two completely different things depending on who is asking. Sort this out first — it decides which path you are on.
Path A
Certifying your company
Organisational certification concerns an organisation’s ISMS and a certification body’s decision following its assessment. The outcome is an organisational certificate — covered in our certification guide.
Path B · this guide
Certifying yourself
You earn a personal professional credential — PECB Certified ISO 27001 Lead Auditor — after PECB approves the examination, application and experience requirements for that tier. This is the path this guide covers.
What an ISO 27001 Lead Auditor actually does
An ISO 27001 auditor evaluates an ISMS against defined criteria, including the applicable management-system requirements. The work includes planning, reviewing the Statement of Applicability and supporting evidence, interviewing process owners, selecting samples, evaluating findings and reporting conclusions. Internal, supplier and certification audits have different purposes and commissioning organisations.
Building the ISMS is the other career track — covered in our companion guide, how to become a certified ISO 27001 Lead Implementer. Choose the pathway that fits the work you need to perform.
The step-by-step pathway
- 01
Prepare and complete your learning
PECB expects a fundamental understanding of ISO/IEC 27001 and comprehensive knowledge of audit principles. Foundation can help with unfamiliar terminology; Foundation and Lead Implementer are not mandatory prior credentials. Study how to plan, conduct, report and follow up an ISMS audit.
- 02
Pass the PECB examination
The current English PECB examination has 80 multiple-choice questions, including stand-alone and scenario-based questions, across seven competency domains. It lasts three hours, is open book under the permitted-reference rules and has a 70% pass mark. Check the current examination record and assigned candidate handbook in myPECB before booking, particularly for another language.
- 03
Apply with evidence for the eligible tier
Review the experience table and keep an audit log. Submit the credential application and required evidence, and meet PECB’s examination and Code of Ethics requirements. Provisional Auditor does not require professional experience or audit hours, but the application is still assessed.
- 04
Receive PECB’s credential decision
PECB evaluates your application and awards the tier supported by the evidence. Passing the examination alone does not award Provisional Auditor or the full Lead Auditor credential. Check the current maintenance requirements, applicable fees and CPD obligations for the tier awarded.
- 05
Meet the requirements for an audit assignment
A personal credential does not appoint you to conduct certification audits. A certification body separately evaluates your competence, relevant experience, technical knowledge and impartiality for its assignments. Employers and clients also set their own requirements for internal and supplier audit roles.
Credential tiers & the audit hours each one needs
The same examination supports all four tiers. Your professional experience and qualifying audit activity determine which tier you can apply for. PECB evaluates the application and supporting evidence; additional hours do not automatically upgrade a credential.
| Credential tier | Total experience | In infosec mgmt | Audit hours |
|---|---|---|---|
| Provisional Auditor | None | — | 0 |
| Auditor | 2 years | 1 yr | 200 |
| Lead Auditorthe target | 5 years | 2 yrs | 300 |
| Senior Lead Auditor | 10 years | 7 yrs | 1,000 |
Audit activity hours required, by tier
Requirements are set by PECB — see the official ISO/IEC 27001 Lead Auditor credential page. Every tier also requires signing the PECB Code of Ethics.
The audit hours that actually count
Two things are counted separately. Professional experience is your years working — with a minimum in information security management (one year for Auditor, two for Lead, seven for Senior Lead). Audit activity hours are hands-on hours doing audit work itself.
PECB lists audit planning and programme management, interviews, document review, working papers, onsite audit activity, audit and nonconformity reports, follow-up and leading audit teams as relevant activities. Record the date, audit scope, your role, activities, hours and supporting references. PECB decides whether the evidence meets its requirements; course exercises do not replace qualifying audit activity.
Roles and career pathways in Australia
A personal credential does not appoint you to conduct certification audits. A certification body separately evaluates your competence, relevant experience, technical knowledge and impartiality for its assignments. Employers and clients also set their own requirements for internal and supplier audit roles.
The credential may support progression into risk, governance, implementation, audit and consulting roles. Actual eligibility, remuneration and engagement requirements depend on experience, sector, location and employer or client requirements.
Where ISO 27001 audit work is used
Match the audit method, scope and competence to the purpose of the assignment:
- Internal audits evaluate the organisation’s own ISMS against its audit criteria, with objectivity and impartiality protected.
- Supplier audits evaluate another party against agreed requirements; the scope and reporting recipient depend on the commissioning organisation.
- Certification audits support a certification body’s decision. An individual course certificate or credential does not certify an organisation.
- Implementation and audit responsibilities need clear boundaries. Holding both credentials does not remove an independence problem when auditing work for which you are responsible.
For a separately scoped engagement, see Aegentra’s independent ISO 27001 internal-audit service. Assignment suitability and independence are assessed separately from training.
Course costs, study time and examination arrangements
Aegentra Academy offers Self-Study for A$829 + GST, PECB eLearning for A$849 + GST and private one-to-one online training for A$2,799 + GST per learner. Each includes the official PECB examination pathway. Australian billing addresses attract 10% GST; review supported currencies and the total payable on the course page before payment. Private training is arranged by enquiry, with the timetable, trainer, access, examination arrangements and terms confirmed in writing before payment.
One free retake is included within the applicable PECB cycle. For Self-Study and eLearning, the current 12-month cycle starts at purchase; for instructor-led training, it starts at course completion. Waiting periods and booking rules apply. Failing does not restart the cycle. The written private-training confirmation must identify which cycle applies to the blended package.
PECB ISO 27001 Lead Auditor course and exam · ISO 27001 learning pathway · Lead Auditor exam guide
FAQs
What is the difference between certifying my company and certifying myself?
Organisational certification concerns an organisation’s ISMS and a certification body’s decision following its assessment. Personal certification concerns the PECB credential tier approved for an individual after examination and application. An individual credential does not certify an organisation or appoint its holder to a certification-body audit team.
Do I need experience to start?
Course entry knowledge and credential experience are separate. PECB expects understanding of ISO/IEC 27001 and audit principles. Provisional Auditor has no professional-experience or audit-hour threshold, but passing alone does not award it: you must apply and receive PECB approval. The Lead Auditor tier requires five years of professional experience, including two in information security management, and 300 qualifying audit hours.
What counts as audit activity hours?
PECB lists audit planning and programme management, interviews, document review, working papers, onsite audit activity, audit and nonconformity reports, follow-up and leading audit teams as relevant activities. Record the date, audit scope, your role, activities, hours and supporting references. PECB decides whether the evidence meets its requirements; course exercises do not replace qualifying audit activity.
Lead Implementer or Lead Auditor — which should I take?
Choose Lead Implementer for establishing, operating and improving an ISMS, or Lead Auditor for evaluating it through audit planning, evidence collection, findings and reporting. Each has its own examination and experience pathway. Holding both credentials does not remove the need for objectivity when auditing work you helped implement.
How much does it cost and how long does it take?
Aegentra Academy offers Self-Study for A$829 + GST, PECB eLearning for A$849 + GST and private one-to-one online training for A$2,799 + GST per learner. Each includes the official PECB examination pathway. Australian billing addresses attract 10% GST; review supported currencies and the total payable on the course page before payment. Private training is arranged by enquiry, with the timetable, trainer, access, examination arrangements and terms confirmed in writing before payment. Aegentra estimates 30–40 hours of self-paced learning effort; this is not video runtime or a completion guarantee. Private teaching comprises 24 hours across four six-hour or eight three-hour sessions, plus a separate one-hour consultant session. The three-hour examination is arranged separately. No public group cohort or classroom venue is currently advertised.
Can a Lead Auditor certify a company to ISO 27001?
A personal credential does not appoint you to conduct certification audits. A certification body separately evaluates your competence, relevant experience, technical knowledge and impartiality for its assignments. Employers and clients also set their own requirements for internal and supplier audit roles.
Sources and factual checks
PECB course, examination and credential sources checked 13 September 2026. Check your assigned myPECB examination record and current booking terms before enrolling.
Official PECB course and credential requirements · Current candidate handbook · PECB examination and retake rules

