Skip to main content
Aegentra
Guide · Updated

ISO 27001 certification in Australia: cost, process and timeline

ISO 27001 organisational certification confirms that an independent accredited certification body has assessed an organisation’s information security management system against ISO/IEC 27001. The organisation first defines and operates the ISMS, completes internal audit and management review, addresses relevant corrective actions and then proceeds through Stage 1 and Stage 2 certification audits. Implementation support, internal audit and certification are separate roles.

By Harry Sidhu — Director and Principal Consultant, Aegentra9 min readLast reviewed

The organisational certification process

The usual organisational certification path is to define the ISMS scope; assess and treat information-security risk; establish the Statement of Applicability; implement and operate the selected controls; retain objective evidence; complete internal audit and management review; close relevant corrective actions; and proceed to Stage 1 and Stage 2 with an independent accredited certification body. The certification body alone decides whether to issue, maintain, suspend or withdraw certification.

Implementation, internal audit and certification roles

RoleResponsibility
Organisation and implementation supportDefine, implement, operate and improve the ISMS and retain evidence.
Internal auditorEvaluate the ISMS under Clause 9.2 while protecting competence, objectivity and impartiality.
Accredited certification bodyPerform Stage 1 and Stage 2 and make the certification decision.

ISO 27001 certification cost in Australia

Implementation and certification are separate costs. Aegentra confirms its implementation fee after discovery. The certification body quotes Stage 1, Stage 2 and ongoing surveillance separately based on the certified scope, headcount, sites and audit duration. Internal audit and any remediation are also separately scoped. Obtain current written quotations rather than relying on a universal market range.

For itemised planning allowances, scope qualifications and a worked three-year budget, read the detailed ISO 27001 cost guide for Australia.

For the current visible starting price and scope factors for Aegentra’s standalone service, review the independent ISO 27001 internal-audit service.

Which accreditation will your customer accept?

ANAB and IAS accredit certification bodies; the certification body audits the organisation and issues its ISO 27001 certificate. They are not two grades of ISO 27001 or the only accreditation options. JASANZ and other relevant accreditors may also meet the buyer’s requirements.

Start with the customer’s contract or tender. Check any named accreditor, equivalent-accreditation provision, the certification body’s current scope and status, and the legal entity, services and locations the certificate must cover. Geography alone does not decide acceptance; obtain written buyer clarification where necessary.

Aegentra provides scoped implementation and internal-audit services. The independent certification body makes the certification decision and quotes its fees separately. Academy individual credentials follow a separate issuer and program-specific accreditation pathway.

Certificate-scope check — illustrative worksheet
Buyer requirementRelevant scopeEvidence to inspectGap or questionConfirmation owner
The service and legal entity named in the tenderEntity, activities, systems and locations that deliver itCurrent certificate, scope statement and certification-body accreditation scope/statusIs the requested service included, and is the accreditor or equivalent accepted?Your procurement owner and the buyer; certification body for certificate details

A genuine certificate may cover a different entity, service or location. Record the gap and obtain written clarification. A certificate does not guarantee tender acceptance, breach immunity, insurance cover, regulatory compliance or the safety of an AI product.

Download the editable certificate-scope worksheet (CSV)

Compare accreditation, scope and certification-body costs

Sources for the accreditation distinction

General distinction checked 3 October 2026. Verify the proposed certification body and your buyer’s acceptance for each engagement.

Timeline factors

Aegentra may target an approximately 12-week implementation programme for an appropriately scoped, Microsoft 365-first organisation with sufficient leadership availability and no major remediation blockers. This is a planning assumption, not a guarantee. Timing depends on the ISMS boundary, starting maturity, technical complexity, evidence availability, client decisions, remediation, internal-audit arrangements and the certification body’s schedule. The written proposal records the actual delivery plan and dependencies.

Internal audit at planned intervals

ISO/IEC 27001 requires internal audits at planned intervals. A competent internal employee or external auditor may perform the audit where objectivity and impartiality are protected. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. The service is also available for systems implemented in-house or by another provider, subject to the same scope, prior-involvement and conflict checks.

Many organisations use an annual internal-audit cycle because it fits their management and certification calendar, but ISO/IEC 27001 does not prescribe one universal complete audit every calendar year. Frequency and coverage should be justified using process importance, information-security risk, significant changes and previous audit results.

Stage 1 and Stage 2

Stage 1 examines documented readiness and whether the organisation is prepared for the effectiveness assessment. Stage 2 samples implementation and operating evidence across the agreed certification scope. The certification body controls its audit programme, records findings and makes the decision.

Need implementation support before those audits? Review the ISO 27001 consulting and implementation service.

Individual training is not organisational certification

Professional training may help an internal owner build knowledge and competence, but no particular personal training credential is mandatory for an organisation to obtain ISO 27001 certification. Individual PECB credentials and organisational ISO 27001 certification are separate outcomes. Current individual course information belongs on the relevant Aegentra Academy course page.

New to the standard? The PECB ISO 27001 Foundation course is the entry-level individual pathway; preview the concepts with the free Clauses 4–10 study map and ISO 27001 terminology glossary. Compare the full course family through the Aegentra Academy ISO 27001 pathway. For audit training specifically, review the official PECB ISO 27001 Lead Auditor course and examination.

Surveillance and recertification

Certification is not a one-off project. The organisation must continue operating and improving the ISMS, retain objective evidence, complete its planned audit programme and management reviews, address nonconformities and prepare for the certification body’s surveillance and recertification activity.

FAQs

Organisational certification

Start with scope, risk and responsibility.

Aegentra can support implementation and readiness. Internal audit and the certification decision remain separately assigned.