Reviewed by the Aegentra Security Team — NV1-cleared ISO 27001 practitioners · Updated May 2026
Three ISO 27001 working documents, published in full and free to use — no email, no form, no account. These are the artefacts an auditor asks for first, each shipping as an editable CSV and a formatted PDF.
Three official PECB certifications against ISO/IEC 27001:2022. What separates them is what you will do with an ISMS — understand it, build it, or audit it. Every price includes the official PECB examination voucher and two exam attempts — the initial sit plus one free resit within 12 months — with no separate exam fee later.
| Course | What it qualifies you to do | Exam & attempts | Price (+ GST) |
|---|---|---|---|
| ISO 27001 Foundation | Understand the documents — describe the standard, the four Annex A themes, and how an ISMS runs day to day. The right starting point if you have been handed a Statement of Applicability and need to know what you are reading. | Voucher included · 2 attempts · 1 hour, closed-book | $399 + GST |
| ISO 27001 Lead Implementer | Write the documents — scope an ISMS, run the risk assessment, and write the Statement of Applicability and risk treatment plan from a blank sheet. This is the method every template on this page came out of. | Voucher included · 2 attempts · 3 hours, open-book, scenario-based | $849 + GST |
| ISO 27001 Lead Auditor | Test the documents — plan and lead internal, supplier and certification audits against ISO 19011, including how a Statement of Applicability and a risk register get sampled and what makes an exclusion defensible. | Voucher included · 2 attempts · 3 hours, open-book, scenario-based | $849 + GST |
Foundation is recommended but is not a prerequisite. Every course is available as flexible Self-Study, a live Online Class, or in-person Classroom in Melbourne and Sydney on request — the credential issued is identical in each case. Aegentra Academy is an official PECB authorised training partner. See the full course catalogue.
Every file below is the real artefact, complete. Nothing is truncated to make you ask for the rest, and nothing sits behind a form. Open the CSV in Excel, Google Sheets or Numbers and start editing. All three are written against ISO/IEC 27001:2022 including Amendment 1:2024 — the current 93-control Annex A across four themes, not the superseded 114-control 2013 edition.
The Statement of Applicability is the most-examined document in a Stage 1 audit, and the one most often got wrong. Clause 6.1.3d requires it to address every one of the 93 Annex A controls — including the ones you exclude, each with a justification. A partial SoA listing only what you implemented is the single most common finding.
This template carries all 93, each with an applicability decision, a written justification, and the implementation status. It is worked through for a 100-staff Australian B2B SaaS business, and includes two genuine exclusions — A.7.10 storage media and A.8.30 outsourced development — argued from scope rather than convenience, which is the distinction an assessor is testing. For the control catalogue on its own, see the full list of all 93 Annex A controls.
Eighteen worked risks, each scored twice — inherent, then residual after treatment. The gap between those two numbers is the evidence that a control is doing something, and it is why a register carrying a single score cannot demonstrate risk acceptance under clause 6.1.3f.
Each row carries a named owner, a treatment decision — modify, retain, avoid or share — and the Annex A controls that treat it, so the register and the Statement of Applicability reconcile against each other. Auditors cross-check exactly that: a control marked applicable with no risk driving it, or a risk with no control treating it, is where the questions start.
Seventeen obligations from APRA CPS 234 and the Defence Industry Security Program, each mapped to the ISO 27001 clause or Annex A control that satisfies it, with the evidence a practitioner would actually produce. This is the Australian-specific piece generic templates omit. If you are an APRA-regulated entity or sit in a Defence supply chain, the question is never "are we ISO 27001 certified" — it is "which control answers this obligation, and what do we show the assessor".
The three documents above are what you produce to build an ISMS. These four are what you produce to verify one — the working papers a Clause 9.2 internal audit generates, and what a certification body reads as evidence that the audit happened properly. All seven describe the same worked organisation, so you can follow one company end to end: Statement of Applicability, risk register, audit plan, checklist, nonconformity, report.
The audit checklist covers Clauses 4 to 10 only, and that is deliberate. Those clauses are mandatory for everyone. Annex A is sampled risk-based against your Statement of Applicability, so a fixed Annex A checklist cannot be correct for two different organisations — anyone selling one is selling a shape, not an audit.
If you would rather have the audit run for you, we deliver independent Clause 9.2 internal audits. To run them yourself, the ISO 27001 Lead Auditor course teaches the method these papers came out of.
Use the structure. Write your own content. The columns, the justification wording and the way exclusions are argued are transferable; the asset list, the scope and the risk scores are not.
For the wider sequence these documents sit inside, see the ISO 27001 implementation checklist and the ISO 27001 certification guide for Australia.
Documents are not the hard part of ISO 27001. Most organisations that slip do so on three things a template cannot supply: an audit slot booked late — certification bodies want six to ten weeks of lead time — an internal audit and management review that had to happen before Stage 2 and did not, and controls that exist on paper but produce no evidence when sampled.
The other constraint is ownership. Programmes succeed when one named person owns the ISMS and has the authority to get evidence out of other teams. Only 34 of the 93 controls are technical: HR owns screening and offboarding, legal owns supplier clauses, management owns the review. If the internal audit is the gap, we run independent Clause 9.2 audits. If you want to own it yourself, the PECB ISO 27001 Lead Implementer course teaches the method these documents came out of.