Which ISO 27001 course should you buy?
Choose your track by what you will actually do next. Learning the vocabulary and framework? Start with Foundation. Going to build and run your organisation’s ISMS? That is the Lead Implementer track. Auditing an ISMS — internally or as a consultant? Choose Lead Auditor. All three are official PECB certifications, delivered in Australia via Self-Study, a live Online Class, or an in-person Classroom in Melbourne & Sydney (available on request).
| Course level | Primary target role | Duration & formats | Starting price (+ GST) | Main learning objective |
|---|---|---|---|---|
| Foundation | Beginners, IT staff, executives | 1–2 days · Self-Study, Online, Classroom | $399 + GST | Core baseline vocabulary, controls, and the basic structure of an ISMS framework. |
| Lead Implementer | IT managers, compliance officers | 4–5 days · Self-Study, Online, Classroom | $849 + GST | The practical, hands-on skills to build, deploy, and maintain an enterprise ISMS. |
| Lead Auditor | Internal/external auditors, consultants | 4–5 days · Self-Study, Online, Classroom | $849 + GST | Advanced audit methodology to lead 1st-, 2nd-, and 3rd-party compliance audits. |
What organisational certification costs (2026)
Courses certify people. Certifying your company is a separate project with its own budget — the realistic 2026 range for an Australian SMB of 10–250 staff:
| Cost item | Typical range (AUD) | When |
|---|---|---|
| Readiness / implementation (consulting) | $25,000–$55,000 | Weeks 1–12 |
| Stage 1 + Stage 2 certification audit | $8,000–$20,000 | After readiness |
| Annual surveillance audit | Starting at $2,500 | Years 1 and 2 |
| Re-certification audit | $8,000–$15,000 | Year 3 |
Key factors to verify before you buy
- Official exam vouchers. Make sure the course explicitly includes an official PECB examination voucher, with a free exam resit option, in the initial purchase price.
- Delivery format flexibility. Match the format to your schedule — flexible Self-Study modules for independent pacing, or live Online Classes and in-person Classroom courses in Melbourne & Sydney, available on request.
- Current framework versions. Confirm the training is fully updated to the latest ISO/IEC 27001:2022 standard, including all revised Annex A security controls.
What is ISO 27001?
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS) — a documented, audited system for governing information security inside an organisation. It is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The current edition is ISO/IEC 27001:2022, which superseded the 2013 version.
The 2022 revision restructured the Annex A control set into 93 controls across four themes — Organisational (37), People (8), Physical (14), and Technological (34). It also added 11 new controls covering threat intelligence, cloud services, ICT readiness for business continuity, and secure software development.
A certified ISMS is not just a checklist of controls. It is a continuous-improvement loop: define a scope, identify risks, treat those risks with documented controls, audit the system internally, review it at the management level, and feed findings back into the next cycle. The certification audit tests whether that loop is actually running — not whether you own a folder of policies.
Who needs ISO 27001 certification in Australia?
ISO 27001 is not legally mandated in Australia, but it is the de facto security qualifier for serious procurement conversations. If your organisation falls into any of the following categories, expect ISO 27001 to come up in tender questionnaires within 12 months:
- SaaS and technology companies selling to enterprise customers — particularly into financial services, healthcare, government, and ASX-listed buyers.
- Federal and state government suppliers — Australia's Protective Security Policy Framework (PSPF) references ISO 27001 as the recognised information security baseline at Maturity Level 2 and above.
- Health, finance, legal, and education organisations handling personal information that is subject to the Privacy Act 1988, the Notifiable Data Breach (NDB) scheme, or APRA CPS 234.
- Australian SMBs scaling past 20–50 staff — the point at which informal security stops scaling and procurement teams start asking for evidence rather than assurances.
In practice, the question is not whether you will need ISO 27001 — it is whether you will start when you have 12 weeks of runway, or six months later when a deal is on the line and the prospect's procurement team has a 200-question spreadsheet open.
Industries that need ISO 27001 in Australia
Four sectors drive almost all Australian ISO 27001 demand: government, financial services, healthcare, and critical infrastructure. The pressure comes from a different regulator in each, but the answer is the same management-system certificate.
Government contractors and DISP suppliers
Commonwealth and state government tenders almost universally require evidence of a working information-security management system, typically aligned with the Protective Security Policy Framework (PSPF) at maturity level 2 or 3. The PSPF's information-security core requirements map directly onto ISO 27001 clauses 4-10 and the Annex A controls — so a certified ISMS is the fastest defensible answer to a PSPF question. Defence-industry suppliers operating under the Defence Industry Security Program (DISP) face an equivalent expectation; at the Entry Level the assessor wants to see an information-security capability, and ISO 27001 is the most common evidence package.
Financial services under APRA CPS 234
Banks, mutuals, insurers, and superannuation funds in Australia operate under APRA Prudential Standard CPS 234, which imposes specific information-security capability, board-accountability, and testing obligations. CPS 234 is not the same as ISO 27001, but the management-system structure that satisfies CPS 234 is — in practice — an ISO 27001 ISMS. APRA-regulated entities also face CPS 230 (operational risk) and CPG 235 (data risk management), which lean on the same risk-and-control machinery the standard provides. Most CPS 234 board reports cite ISO 27001 as the underlying framework for the second-line capability.
Healthcare and the My Health Records Act
Healthcare providers, pathology labs, and digital-health vendors operating against the My Health Records Act 2012 and the Healthcare Identifiers Act face statutory information-security obligations that ISO 27001 is built to satisfy. The Australian Digital Health Agency's compliance reviews look for evidence of a documented information-security management system; an ISO 27001 certificate (or a credible plan to obtain one) is the standard answer. Private hospital networks and large GP groups use the certificate to satisfy enterprise insurer and government contract requirements.
Critical infrastructure under the SOCI Act
Entities captured by the Security of Critical Infrastructure (SOCI) Act — energy, water, ports, communications, financial-market infrastructure, data-storage and processing — face risk-management programme obligations enforced by the Department of Home Affairs. The Risk Management Program (RMP) Rules require a documented cybersecurity framework; the Department explicitly recognises ISO 27001 as an acceptable framework against which to certify the RMP's cyber obligations. SaaS and managed-service providers hosting workloads for SOCI-captured entities inherit the same expectation through their customer contracts.
Mapping ISO 27001 to Australian regulations
ISO 27001 is not legally mandated in Australia, but most of the country's information-security regulation either maps to it directly or is satisfied by it. The table below summarises the practical relationship between ISO 27001 and the regulations Aegentra is most often asked about.
| Australian regulation | What it requires | How ISO 27001 helps |
|---|---|---|
| APRA CPS 234 | Information-security capability, board accountability, testing, and incident notification for APRA-regulated entities. | Provides the ISMS structure CPS 234 expects — risk register, controls, internal audit, management review. Most CPS 234 board reports cite ISO 27001 as the underlying framework. |
| Protective Security Policy Framework (PSPF) | Government suppliers must demonstrate information security maturity at PSPF level 2 or 3 for most Commonwealth tenders. | PSPF information-security core requirements map directly onto ISO 27001 clauses 4-10 and Annex A. A certified ISMS is the fastest defensible answer. |
| Defence Industry Security Program (DISP) | Defence-industry suppliers must demonstrate information-security capability appropriate to their DISP membership level. | ISO 27001 is the most commonly cited framework for Entry-level DISP information-security evidence and is explicitly recognised in DISP guidance. |
| Security of Critical Infrastructure (SOCI) Act | Risk Management Program (RMP) for captured infrastructure sectors must document cybersecurity framework alignment. | The Department of Home Affairs recognises ISO 27001 as an acceptable framework against which to certify the cyber-hazard component of an RMP. |
| Privacy Act 1988 (APPs) | APP 11 requires entities to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. | The Annex A control set, applied to personal-information handling, is the cleanest documentary answer to APP 11 in an OAIC review or notifiable-breach matter. |
| My Health Records Act 2012 | Healthcare providers and software vendors handling My Health Records data face specific information-security obligations enforced by the Australian Digital Health Agency. | An ISO 27001 ISMS scoped to cover the relevant systems is the standard evidence package presented in ADHA compliance reviews. |
| ASD Essential Eight | Eight prioritised technical mitigations (application control, patching, MFA, etc.) published by the Australian Signals Directorate. | Complementary, not equivalent. The Essential Eight tells you what to do; ISO 27001 governs the system that decides what to do. Most ASD-aligned controls map directly onto Annex A. |
The pattern across all seven regulations is the same: ISO 27001 is rarely a literal requirement, but it is almost always the most efficient documentary answer to a regulator or an enterprise procurement team that asks "show me your information-security management system."
How long does ISO 27001 certification take in Australia?
For a typical Australian SMB on Microsoft 365 with 10–50 staff, 12 weeks from kickoff to audit-ready is the realistic planning number. That covers a single-tenant, single-site environment with a cooperative leadership team and an internal point of contact who can dedicate a few hours a week.
The Stage 1 audit happens immediately after readiness; Stage 2 follows roughly four weeks later. So the realistic kickoff-to-certificate timeline is 16 to 20 weeks. Faster is possible (we have seen 8 weeks) for very small, very clean environments. Slower is common (20–28 weeks) for multi-tenant M365 estates, hybrid on-premise/cloud workloads, or where a parallel SOC 2 is running.
The audit body books up. Most accredited certification bodies in Australia require 6–10 weeks lead time between booking and the Stage 2 audit. We recommend booking the audit slot in week 1 of readiness, not week 11.
How much does ISO 27001 certification cost in Australia?
Two separate buckets are worth understanding: individual training certification, and organisational ISO 27001 certification. They are often confused. Both are required for a serious program.
Individual training certifications (PECB)
PECB is the international training body whose ISO 27001 credentials are most widely recognised in Australian tender evaluations. Pricing is consistent globally; AUD pricing through Aegentra Academy (an official PECB authorised training partner) is:
- ·ISO 27001 Foundation — $399 + GST. Best for IT generalists, project managers, and anyone who needs to understand the standard without operating it.
- ·ISO 27001 Lead Implementer — $849 + GST. The practitioner course. Required reading if you are the person inside the company building the ISMS.
- ·ISO 27001 Lead Auditor — $849 + GST. For internal auditors and people moving into a certification body role.
Every Aegentra Academy enrolment includes the official PECB exam voucher and one free resit within 12 months.
Organisational ISO 27001 certification
These are the costs for actually certifying your company. The ranges below are typical for an Australian SMB of 10–50 staff on Microsoft 365. Larger environments scale up roughly linearly with headcount and tenant complexity.
| Component | Typical AUD | Frequency |
|---|---|---|
| Readiness consulting (gap analysis to audit-ready) | $25,000–$55,000 | Once |
| Stage 1 + Stage 2 certification audit | $8,000–$20,000 | Once (every 3 years) |
| Annual surveillance audit | Starting at $2,500 | Year 1 + Year 2 |
| Three-year re-certification | $8,000–$15,000 | Year 3 |
The readiness range varies more than the audit range because readiness scope varies — some SMBs already have a working ISMS in spreadsheets and just need formalisation; others are starting from a clean slate with no policies, no risk register, and no internal audit capability.
ISO 27001 certification in Melbourne, Sydney and the states
ISO 27001 is an international standard, so the certificate is identical wherever in Australia you are certified. There is no state-based variant, no Victorian version, and no local registration step. What actually changes by location is which certification body has assessor availability near you, whether onsite audit days attract travel cost, and which state and sector obligations sit alongside the standard.
Aegentra is Melbourne-based and works Australia-wide. Readiness work is remote-first, which is why location rarely changes the price — the audit is the part that can, and only when a certification body sends assessors interstate.
Melbourne and Victoria
Most Victorian demand comes from three places: SaaS and technology firms that lost or nearly lost an enterprise deal at security review, health and allied-health providers handling patient data under the Privacy Act, and suppliers into Victorian government procurement. Certification is performed by a JAS-ANZ-accredited body — Aegentra prepares you and audits internally, and never certifies its own clients, because Clause 9.2 requires independence.
Sydney and New South Wales
NSW demand skews to financial services and fintech, where APRA CPS 234 sits alongside ISO 27001, and to firms selling into NSW government. The two frameworks overlap heavily — our free CPS 234 mapping shows which ISO 27001 clause or Annex A control answers each obligation.
Brisbane, Perth, Adelaide and Canberra
Queensland and Western Australia weight toward resources, engineering and critical infrastructure, where the SOCI Act drives the requirement. Canberra is dominated by Defence and federal supply chains, where DISP membership and PSPF alignment usually matter more than the certificate itself. All are served remote-first, and the readiness work is identical.
Does location change the cost?
Rarely, and not by much. Readiness consulting and training are delivered remotely at the same price nationwide. The variable is certification-body travel for onsite audit days — if the nearest accredited assessor is interstate, expect travel to be passed through. Ask for it as a separate line item when you request the audit quote, because it is the one number that genuinely differs by postcode.
Answers by role: CTO, CEO and compliance lead
The same certification looks different depending on what you are accountable for. These are the questions we are actually asked, answered plainly.
As the CTO of an Australian SaaS company, how long does ISO 27001 certification take?
Twelve weeks from kickoff to audit-ready is realistic for a 10–50 staff team already on Microsoft 365 or AWS. Stage 1 follows immediately and Stage 2 lands roughly four weeks later, so kickoff to certificate is typically 16–20 weeks. The constraint is almost never the engineering work — it is that JAS-ANZ-accredited certification bodies want six to ten weeks of lead time. Book the audit slot in week one, not week eleven.
As the CEO of an Australian SaaS company, how much does ISO 27001 cost?
Budget $25,000–$55,000 all-in for a first certification at that size: readiness work, the certification-body audit at $8,000–$20,000, and internal time. If you run it yourself with a trained internal owner, the training is $849 + GST and the audit fee is unavoidable. The genuine variable is how much evidence already exists — a team with access reviews, logging and backups already running is months ahead of one starting from nothing.
As the CEO of an Australian SaaS company, what company should I use to get ISO 27001 certified?
You need two parties, and they cannot be the same one. A certification body accredited by JAS-ANZ issues the certificate — that is who certifies you. A consultant or trainer gets you ready. No legitimate provider does both for the same client, because the accreditation rules forbid it. Anyone offering to certify you themselves is either not accredited or not describing it accurately. Aegentra does readiness, internal audit and training; a JAS-ANZ-accredited body certifies.
As a compliance lead, how do we maintain ISO 27001 once certified?
Certification runs a three-year cycle: surveillance audits in years one and two, full recertification in year three. Between them you must keep the risk assessment current, run an internal audit under Clause 9.2 each year with an auditor independent of the system, and hold a management review with decisions minuted. The most common surveillance finding is not a technical control — it is that the internal audit or the management review did not happen. If independence is the gap, we run independent Clause 9.2 audits.
As a startup founder, do we need ISO 27001 or is SOC 2 enough?
Ask your buyer before spending anything. Australian government, PSPF-aligned, European and most APAC buyers ask for ISO 27001. US buyers more often ask for SOC 2. They overlap 60–80% on controls, so the second one costs far less than the first — but doing the wrong one first is an expensive way to find out. The full comparison is here.
The certification process, step-by-step
The full path from “we should probably do this” to a certified ISMS takes nine concrete steps. The first six are your responsibility (or your implementer's) — if you would rather not run them in-house, our ISO 27001 implementation service exists to run them alongside your team. The last three are the certification body's.
- 01Gap assessment
A read-only review of your current controls against ISO 27001 Annex A. Output: a prioritised list of gaps with effort estimates. We use the Aeges risk engine to do this read-only against your Microsoft 365 tenant. 1 week.
- 02Scope and risk assessment
Define what the ISMS covers (entity, locations, services, data) and identify the risks to those assets. The risks drive the controls — not the other way around. 2 weeks.
- 03ISMS design
Write the Statement of Applicability, the information security policy, and the framework documents. Decide which Annex A controls apply and which are not applicable (with justification). 2 weeks.
- 04Control implementation
Configure the actual controls inside your tenant — Conditional Access, DLP, audit logging, supplier register, incident playbook, business continuity test. This is where engineering meets governance. 4 weeks.
- 05Internal audit
An independent reviewer (not the implementer) audits every applicable control against your evidence. Findings are remediated before Stage 1. 1 week.
- 06Management review
Leadership formally reviews the ISMS performance, residual risks, and improvement opportunities. Minutes go into the audit pack. 1 week.
- 07Stage 1 audit (certification body)
A documentation review by your chosen accredited certification body. Usually remote, 1–2 days. Stage 1 confirms you are ready for the Stage 2 effectiveness audit.
- 08Stage 2 audit (certification body)
The full effectiveness audit. The auditor samples evidence against every applicable control, interviews staff, and walks the implementation. 2–4 days for an SMB.
- 09Certificate issued
Valid for three years. Annual surveillance audits in years one and two. Full re-certification audit in year three.
Training the person who will own your ISMS
If you are going to own the ISMS internally, the PECB ISO 27001 Lead Implementer course is the right starting point. The course covers risk assessment, control selection, the Statement of Applicability, internal audit, and management review — i.e. everything in Steps 02–06 of the process above.
Four things to check when choosing where to enrol:
- Official PECB authorised training partner — the provider should be listed on the PECB partner directory. If they are not listed, the certificate you receive is not the same product.
- Exam voucher included — the official PECB exam is the certificate. A training-only course without the exam is incomplete.
- Free exam resit within 12 months. PECB partners are allowed to bundle this in; reputable ones do.
- Practitioner instructors — the people teaching should have implemented an ISMS recently in an environment that looks like yours. Aegentra trainers are active senior engineers, not full-time trainers.
PECB vs other certification bodies
Two separate things are being “accredited” in the ISO 27001 world and they are easy to confuse.
Individual training (the Lead Implementer and Lead Auditor courses) is offered by training bodies. PECB is the dominant one in Australia and is accredited by ANAB (ANSI National Accreditation Board) under ANSI/ASTM E2659-24 — the international standard for personnel certification bodies. PECB credentials are recognised globally.
Organisational certification (the Stage 1/Stage 2 audit of your company) is offered by accredited certification bodies. The Australian accreditation body is JAS-ANZ. You certify with a JAS-ANZ-accredited certification body — the current accredited bodies, from large international names through to smaller local specialists, are published on the JAS-ANZ public register. Multiple international bodies also operate here under mutual recognition with JAS-ANZ.
For an Australian SMB selling to government or large enterprise, ask the procurement team which body they prefer before you book the audit. Some procurement teams have opinions; most do not.
FAQs
Difficulty depends on the level: Foundation is the most approachable of the three PECB ISO 27001 exams, Lead Implementer is harder, and Lead Auditor is the most demanding. Foundation runs one hour, multiple-choice and closed-book across two competency domains, testing recall — most candidates pass first time after 8–12 hours of study. Lead Implementer and Lead Auditor each run three hours, open-book, mixing multiple-choice with scenario-based questions across seven competency domains. All three require 70% to pass, and every Aegentra Academy enrolment includes one free resit within 12 months.
You get ISO 27001 certification in Australia by building an Information Security Management System and then passing a two-stage audit by a JAS-ANZ accredited certification body. Define the scope, run a gap assessment and risk assessment, write the Statement of Applicability, implement the applicable Annex A controls, then complete an internal audit and management review. Stage 1 reviews your documentation; Stage 2 tests whether the controls actually operate. Book the certification body early — most need 6–10 weeks of lead time. Australian SMBs are typically audit-ready in about 12 weeks.
An ISO 27001 course costs $399 + GST at Foundation level and $849 + GST at Lead Implementer or Lead Auditor level through Aegentra Academy, an official PECB authorised training partner in Australia. Each price includes the official PECB exam voucher, the full course materials, 12 months of myPECB access, and one free resit within 12 months — there is no separate exam fee. Instructor-led equivalents from Australian training providers typically run $1,200–$2,200 + GST at Foundation and $2,500–$3,900 + GST at lead level. This is training for one person, which is a different thing from certifying an organisation.
For an Australian SMB of 10–250 staff, ISO 27001 certification typically costs $25,000–$55,000 for readiness or implementation work, plus $8,000–$20,000 for the Stage 1 and Stage 2 certification audit. Annual surveillance audits start at $2,500 in years one and two, and re-certification at the three-year mark runs $8,000–$15,000. The readiness figure varies the most because scope varies — some organisations only need existing practice formalised and evidenced. Training an individual is a separate and much smaller cost, from $399 + GST.
No — ISO 27001 is not legally mandated in Australia. It is, however, a near-universal requirement for federal and state government tenders (PSPF Maturity Level 2/3), enterprise procurement, and software-as-a-service contracts with large customers. If you sell to government, financial services, healthcare, or any ASX-listed company, you will be asked for evidence of an ISO 27001 certified Information Security Management System (ISMS).
ISO 27001 is an international standard published by ISO/IEC that certifies the existence and operation of an Information Security Management System. SOC 2 is an attestation report issued under the AICPA Trust Services Criteria — predominantly used in North America. ISO 27001 is the dominant standard for Australian, European, and APAC buyers. SOC 2 is the dominant standard for US buyers. Many Australian SaaS companies maintain both.
Yes — but it is rare for an SMB to certify on the first attempt without external guidance. The standard has 93 Annex A controls in the 2022 edition; each control needs a documented policy, evidence of operation, and an internal audit trail. Most Australian SMBs choose to use a senior security engineer (in-house or external) who has implemented an ISMS at least once before. The Aegentra Academy ISO 27001 Lead Implementer course is the most cost-effective way to upskill an internal owner.
The certification audit is run by an accredited certification body — not by your implementer (that would be a conflict of interest). The audit has two stages. Stage 1 is a documentation review, performed remotely, typically 1–2 days. Stage 2 is an effectiveness audit performed onsite or by video, typically 2–4 days for an SMB. The auditor samples evidence against every applicable Annex A control and interviews staff. Major non-conformities must be closed before certification is issued; minor non-conformities are tracked through the surveillance cycle.
An ISO 27001 certificate is valid for three years. During those three years you undergo annual surveillance audits (smaller in scope than the original Stage 2) plus a full re-certification audit at the three-year mark. Failure to meet surveillance commitments can result in suspension or withdrawal of the certificate.
The auditor will issue non-conformities. Major non-conformities prevent the certificate being issued; minor ones do not. You typically have 60–90 days to close findings and submit evidence. Most Australian SMBs who prepare with a senior implementer pass Stage 2 with a small number of minor findings — major non-conformities are usually a sign of a rushed program.
The course certifies you as an individual practitioner — it does not certify your company. To certify your company, you need to actually build the ISMS and pass a Stage 1/Stage 2 audit by an accredited body. The Lead Implementer course teaches you how to do that work; whether you then perform it solo or with a consultancy is a separate decision.
No — they are complementary. The Essential Eight is a technical mitigation strategy from the Australian Cyber Security Centre (ACSC) focused on Windows and Microsoft 365. ISO 27001 is a management system standard covering governance, risk, controls, suppliers, incidents, business continuity, and continual improvement. Many ASD-aligned Essential Eight controls map directly to ISO 27001 Annex A; running both is common practice for Australian SMBs selling to government.