The organisational certification process
The usual organisational certification path is to define the ISMS scope; assess and treat information-security risk; establish the Statement of Applicability; implement and operate the selected controls; retain objective evidence; complete internal audit and management review; close relevant corrective actions; and proceed to Stage 1 and Stage 2 with an independent accredited certification body. The certification body alone decides whether to issue, maintain, suspend or withdraw certification.
Implementation, internal audit and certification roles
| Role | Responsibility |
|---|---|
| Organisation and implementation support | Define, implement, operate and improve the ISMS and retain evidence. |
| Internal auditor | Evaluate the ISMS under Clause 9.2 while protecting competence, objectivity and impartiality. |
| Accredited certification body | Perform Stage 1 and Stage 2 and make the certification decision. |
ISO 27001 certification cost in Australia
Implementation and certification are separate costs. Aegentra confirms its implementation fee after discovery. The certification body quotes Stage 1, Stage 2 and ongoing surveillance separately based on the certified scope, headcount, sites and audit duration. Internal audit and any remediation are also separately scoped. Obtain current written quotations rather than relying on a universal market range.
For itemised planning allowances, scope qualifications and a worked three-year budget, read the detailed ISO 27001 cost guide for Australia.
For the current visible starting price and scope factors for Aegentra’s standalone service, review the independent ISO 27001 internal-audit service.
Which accreditation will your customer accept?
ANAB and IAS accredit certification bodies; the certification body audits the organisation and issues its ISO 27001 certificate. They are not two grades of ISO 27001 or the only accreditation options. JASANZ and other relevant accreditors may also meet the buyer’s requirements.
Start with the customer’s contract or tender. Check any named accreditor, equivalent-accreditation provision, the certification body’s current scope and status, and the legal entity, services and locations the certificate must cover. Geography alone does not decide acceptance; obtain written buyer clarification where necessary.
Aegentra provides scoped implementation and internal-audit services. The independent certification body makes the certification decision and quotes its fees separately. Academy individual credentials follow a separate issuer and program-specific accreditation pathway.
| Buyer requirement | Relevant scope | Evidence to inspect | Gap or question | Confirmation owner |
|---|---|---|---|---|
| The service and legal entity named in the tender | Entity, activities, systems and locations that deliver it | Current certificate, scope statement and certification-body accreditation scope/status | Is the requested service included, and is the accreditor or equivalent accepted? | Your procurement owner and the buyer; certification body for certificate details |
A genuine certificate may cover a different entity, service or location. Record the gap and obtain written clarification. A certificate does not guarantee tender acceptance, breach immunity, insurance cover, regulatory compliance or the safety of an AI product.
Download the editable certificate-scope worksheet (CSV)
Compare accreditation, scope and certification-body costs
Sources for the accreditation distinction
- ISO certification guidance
- ANAB ISO 27001 accreditation
- IAS management-system accreditation
- JASANZ accreditation explained
General distinction checked 3 October 2026. Verify the proposed certification body and your buyer’s acceptance for each engagement.
Timeline factors
Aegentra may target an approximately 12-week implementation programme for an appropriately scoped, Microsoft 365-first organisation with sufficient leadership availability and no major remediation blockers. This is a planning assumption, not a guarantee. Timing depends on the ISMS boundary, starting maturity, technical complexity, evidence availability, client decisions, remediation, internal-audit arrangements and the certification body’s schedule. The written proposal records the actual delivery plan and dependencies.
Internal audit at planned intervals
ISO/IEC 27001 requires internal audits at planned intervals. A competent internal employee or external auditor may perform the audit where objectivity and impartiality are protected. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. The service is also available for systems implemented in-house or by another provider, subject to the same scope, prior-involvement and conflict checks.
Many organisations use an annual internal-audit cycle because it fits their management and certification calendar, but ISO/IEC 27001 does not prescribe one universal complete audit every calendar year. Frequency and coverage should be justified using process importance, information-security risk, significant changes and previous audit results.
Stage 1 and Stage 2
Stage 1 examines documented readiness and whether the organisation is prepared for the effectiveness assessment. Stage 2 samples implementation and operating evidence across the agreed certification scope. The certification body controls its audit programme, records findings and makes the decision.
Need implementation support before those audits? Review the ISO 27001 consulting and implementation service.
Individual training is not organisational certification
Professional training may help an internal owner build knowledge and competence, but no particular personal training credential is mandatory for an organisation to obtain ISO 27001 certification. Individual PECB credentials and organisational ISO 27001 certification are separate outcomes. Current individual course information belongs on the relevant Aegentra Academy course page.
New to the standard? The PECB ISO 27001 Foundation course is the entry-level individual pathway; preview the concepts with the free Clauses 4–10 study map and ISO 27001 terminology glossary. Compare the full course family through the Aegentra Academy ISO 27001 pathway. For audit training specifically, review the official PECB ISO 27001 Lead Auditor course and examination.
Surveillance and recertification
Certification is not a one-off project. The organisation must continue operating and improving the ISMS, retain objective evidence, complete its planned audit programme and management reviews, address nonconformities and prepare for the certification body’s surveillance and recertification activity.