/ Govern
ISO 27001 Consulting and Implementation Australia
Build an information security management system your team can run and your customers can examine. Aegentra helps Australian organisations define scope, assess risks, implement agreed controls and organise operating evidence for ISO/IEC 27001:2022. Start with discovery, then receive an implementation proposal with a fixed fee, clear responsibilities and a proposed timetable.
Get the brochure by emailCall 03 9956 9399Independent internal audit and certification are separate from our implementation work.

Melbourne-based · Australia-wide delivery · Fixed implementation fee agreed after discovery
On this page Overview
An ISMS that works beyond the policy folder
Your agreed ISMS scope
and services
Illustrative ISMS model, tailored to your organisation.
ISO 27001 implementation means establishing how your organisation manages information-security risk: what is in scope, who makes decisions, which controls are needed and how their operation is checked. The work includes people, processes, suppliers and technology, not just an IT configuration or a set of templates.
Aegentra works with your leadership, internal teams and existing IT provider to turn that into a working management system with clear responsibilities, records and review. The service can support a first implementation, a stalled programme or a defined readiness gap. We start by identifying what already works and what needs to change.
- Delivery
- remote across Australia, with onsite work by arrangement.
- Commercial model
- discovery followed by an agreed fixed implementation fee.
- Certification
- assessed and decided by an independent accredited certification body.

/ Service brochure
Get the ISO 27001 implementation brochure.
Review the ISMS scope, delivery approach, responsibilities and operating evidence in one document. Receive a copy by email to read or share with your team.
Additional brochure
ISO 27001 implementation: capability & services
Explore the implementation pathway, Microsoft 365 security hardening, deliverables and responsibilities in our detailed service brochure.
Fast-track ISO 27001 · Small business
Less coordination for you. A clear path from implementation to certification support.
Choose Aegentra’s combined implementation and internal-audit engagement with three distinct delivery roles. It is designed for businesses with limited time to manage an ISO 27001 project themselves, but the ability to make decisions and provide the access and evidence the work needs.
5–7 weeksTarget implementation period
Fewer than 10 peopleSuitably scoped small businesses
This accelerated option is assessed at discovery. It requires a manageable ISMS scope, timely client decisions and no major remediation blockers. It is not a guaranteed certification date; the written proposal confirms the plan and dependencies.
- Implementation consultant
- Builds the agreed ISMS with your team, coordinates the in-scope controls and prepares the documentation and operating evidence.
- Separate internal auditor
- A different competent consultant, independent of the implementation work, plans and conducts the Clause 9.2 internal audit and reports their own findings.
- Dedicated project manager
- A third consultant coordinates milestones, responsibilities and certification-body arrangements, keeping the project moving without directing audit judgements.

Support through Stage 1 and Stage 2
We help you arrange an independent accredited certification body, prepare for its Stage 1 and Stage 2 audits, and respond to findings within the agreed engagement. You have a coordinated point of contact through the certification process; the certification body conducts those audits and independently decides whether to issue your certificate.
Certification-body fees are separate. Audit availability, evidence readiness and corrective actions affect the certificate timeline. Your proposal defines the support, fees and responsibilities.
Client participation and audit safeguards
Your team still provides access and evidence, approves the scope and risk decisions, assigns control owners and participates in management review. A shorter programme reduces coordination work; it does not remove these responsibilities.
The internal auditor must not audit their own work. Documented conflict-of-interest and impartiality checks confirm whether separate Aegentra consultants can perform the roles. If objectivity cannot be protected, a separate provider is required.
How our internal audits workWhat your ISO 27001 implementation produces
Your written scope identifies the deliverables, acceptance points and responsible people. The programme is built around the following outputs, tailored to the services, information and locations included in your ISMS.
| Workstream | What we help produce | What your organisation contributes |
|---|---|---|
| Scope and baseline | A defined ISMS boundary, relevant business context, interested-party requirements and prioritised gaps. | Leadership decisions about the services, sites, systems and obligations in scope. |
| Risk assessment and treatment | Agreed risk criteria, an information-security risk register, treatment decisions and accountable action owners. | Knowledge of the business, assets, suppliers, existing controls and acceptable risk. |
| Statement of Applicability | A traceable explanation of necessary controls, implementation status and inclusion or exclusion rationale, checked against the 93 Annex A reference controls. | Approval of treatment decisions and accurate information about how controls operate. |
| Documentation and responsibilities | Required documented information, practical procedures, security objectives, assigned responsibilities and agreed competence/awareness arrangements. | Review, approval and adoption of the arrangements by the people who will use them. |
| Implementation and evidence | Agreed control work, an evidence register and records showing what has been implemented and checked. | System access, operational participation and completion of client-owned actions. |
| Review and handover | Management-review preparation, an open-action record and an organised handover for independent assurance. | Management review, risk acceptance, corrective action and appointment of the separate internal auditor and certification body. |
Technical work is defined before it starts. Your proposal states which configurations Aegentra will implement, which actions remain with your team or IT provider, and which remediation or licences need a separate quote. Where appropriate, Microsoft 365 changes can be scoped through Aegentra Harden.
/ Watch
Why prepare before a customer asks for proof?
A policy describes what should happen. Operating evidence shows what actually happened. This short Aegentra video explains why that distinction matters when customers assess your security, and why certification is not a guarantee of security, insurance cover or legal compliance.
AI-presented educational video by Aegentra · 4:06
Watch on YouTube ↗Loading the player connects to YouTube. You can read the transcript without loading it.
Read the video transcript
0:00 — Can you show how security works?
Your next customer may ask for proof. Are you ready? Imagine you're about to win a contract. Then the buyer asks how you protect their information.
You have security software, an IT provider, and a folder of policies. But can you show who checks the controls, when they were tested, and what happens if something fails? That is why ISO 27001 readiness matters.
0:28 — More than installing controls
Think of your business like a building. Installing locks is one step. Knowing who holds the keys, checking the alarms, practising an evacuation, and fixing weaknesses is an ongoing system.
Information security works the same way. The standard helps organise that work around your business risks.
0:49 — Customer trust and certification scope
For customers, this turns a promise into something they can examine. If you handle sensitive information or support a larger organisation, the buyer needs a way to assess your security.
Certification can provide independent assurance within its defined scope. It does not mean a business cannot be breached. And a certificate only covers what its scope actually includes.
1:14 — Insurance and operating evidence
Now consider insurance. An insurer may ask whether multifactor authentication protects your systems, how you manage security updates, and how you protect backups. Those answers need to reflect reality.
A policy saying backups are tested is different from a dated record showing a successful restore. The useful question is: could you support your answers with evidence?
ISO certification does not guarantee insurance cover, cheaper premiums or a successful claim. Your policy terms, disclosures, conditions, and the incident itself still matter. Readiness helps you organise the controls and evidence behind those conversations.
Think back to the building. An inspection record can show what was checked. It does not replace the terms of your insurance policy.
2:06 — Australian privacy obligations
In Australia, this also connects to obligations already in force. If your organisation is covered by the Privacy Act, you must take reasonable steps to protect personal information using technical and organisational measures. Some organisations are exempt and exceptions apply, so check your coverage.
Certification is not a substitute for meeting the legal obligations that apply to your business.
2:32 — Ransomware-payment reporting
Ransomware-payment reporting is another example. Since May 2025, organisations covered by these rules must report a ransom payment within 72 hours of making it or becoming aware of a payment made on their behalf.
That clock concerns the payment, not simply discovering an attack. Knowing your obligations, contacts, and escalation process before an incident is part of being prepared.
2:58 — Why prepare, and where does Essential Eight fit?
Here is the distinction. These obligations do not create a blanket ISO certification requirement for every Australian company. The reason to prepare is that your risks, customer expectations, and responsibilities need an organised response.
Australia's Essential Eight can help with technical protections. ISO 27001 provides the broader management system. They can complement each other.
3:24 — Where to start
So where do you start? Identify the information and services that matter most. Define the scope. Assess the risks. Assign an owner to each action.
Then test the controls you rely on: access, backups, supply arrangements, and incident response. Keep the evidence and review what changes. Build a system that people use. Then decide whether certification supports your business goals.
Your next customer asks for proof. You should be able to show how security works in your business. That is the value of readiness.
Next in Australian cyber readiness: what the Essential Eight actually covers.
A clear result at every stage.
Aegentra may target an approximately 12-week implementation programme for an appropriately scoped, Microsoft 365-first organisation with sufficient leadership availability and no major remediation blockers. This is a planning assumption, not a guarantee. Timing depends on the ISMS boundary, starting maturity, technical complexity, evidence availability, client decisions, remediation, internal-audit arrangements and the certification body’s schedule. The written proposal records the actual delivery plan and dependencies.
Scroll to explore all six stages.
Weeks 1–2
Discovery
Tenant baseline + scoping doc
Where Aeges is included in the agreed scope, read-only access supports the tenant posture snapshot. Establish the asset register and agree the ISMS scope with your senior stakeholder.

Weeks 3–5
Gap analysis
Risk and applicability map + remediation plan
Risk-selected controls are recorded in the Statement of Applicability, with Annex A used as the completeness cross-check. Gaps are prioritised and agreed with accountable owners.

Weeks 6–9
Build
Policies + tenant configuration + evidence
The assigned implementation team configures the controls included in the written scope, which may include conditional access, data-loss prevention, device management, sensitivity labels and access reviews. Policies and evidence are recorded in the agreed client environment.

Week 10
Internal audit coordination
Separate audit plan + corrective actions
A different competent Aegentra consultant, independent of the implementation work, completes the Clause 9.2 audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. The implementation consultant can support the client in addressing findings.

Week 11
Management review
ISMS management review minutes
Leadership reviews ISMS performance, risks, audit findings and improvement actions. Decisions, responsibilities and follow-up actions are recorded in the management-review minutes.

Week 12
Auditor handover
Certification-readiness handover
Organise the agreed evidence pack, open actions and handover for the independent certification body. The proposal confirms document access, platform terms and any support after handover; certification timing remains the certification body’s responsibility.

Certification remains an independent decision. Stage 1 and Stage 2 timing is also subject to the selected certification body’s calendar.
Connect the ISMS to the way your Microsoft 365 environment operates
For Microsoft 365-based organisations, we connect the risk treatment plan to agreed work in the tenant and the records needed to review it. That might involve identity and access, device management, email protection or information handling, depending on your risks, existing configuration and licences.
You do not have to use Microsoft 365. The implementation scope can include other technology and evidence sources; Aeges support is limited to the capabilities agreed for your environment.
Aeges can support the collection and organisation of agreed Microsoft 365 technical evidence. Those records still need context and review. A configuration snapshot does not prove that a business process worked, that every relevant system is covered or that the organisation conforms to ISO 27001.
Where ongoing monitoring is agreed, supported technical-control changes can be identified for review. This is separate from the initial implementation scope unless your proposal includes it.
What needs checking?

- Completed leaver record
- Account and access records
- Exceptions and follow-up
- RequestNotification and approval
- Check accessIdentity, devices and apps
- ReviewProcess owner follows up
Illustrative image and workflow, not a client record or a product screenshot. Actions and evidence depend on the agreed scope.
Example: removing access when someone leaves
Illustrative implementation example, not a client result
| Decision or action | What the example shows |
|---|---|
| Identify the risk | A departing employee could retain access to customer information or business systems. |
| Agree the treatment | Define a leaver process covering notification, approval, account access, devices and relevant third-party services. |
| Implement the agreed changes | Your responsible team or scoped specialist carries out the approved actions, including the systems outside Microsoft 365. |
| Check operating evidence | Review a completed leaver record, relevant account/access records and documented exceptions. A written policy alone is not evidence of completion. |
| Assign ownership and review | The process owner checks unresolved actions and uses the agreed review cycle to identify recurring failures. |
The same reasoning applies to other controls: identify the risk, agree the action, assign ownership and keep enough evidence to evaluate whether it works. Microsoft’s certification of its cloud services does not certify your organisation or your use of them.
Who will deliver your ISO 27001 implementation?
Your proposal identifies the accountable engagement lead and the consultants assigned to your scope. It records their responsibilities, relevant competence, specialist support and the separation required for independent assurance. Before work begins, you know who is responsible for each part of the engagement and how their experience fits the role.
Aegentra’s delivery team combines senior experience in IT audit, cybersecurity governance, enterprise risk, internal controls and management systems. The team’s qualifications support both the governance work and the technical implementation required by your scope.
Team members bring more than two decades of professional experience, including 2,000+ hours of ISO, ASD ISM and GRC audit work across 70+ organisations. This experience spans their professional careers, including work delivered outside Aegentra engagements.
Team qualifications and credentials
Qualifications, professional credentials and formal training held across Aegentra’s delivery team.
Management systems and audit
- ISO/IEC 27001 Lead Implementer
- PECB ISO/IEC 27001 Lead Auditor
- ISO/IEC 42001 Lead Auditor
- CISA — Certified Information Systems Auditor
- ISM Auditor
Cybersecurity and cloud
- CISSP — Certified Information Systems Security Professional
- CISM — Certified Information Security Manager
- Certificate of Cloud Security Knowledge (CCSK)
- OSCP+ — OffSec Certified Professional Plus
Service delivery and specialist training
- ITIL Expert
- PRINCE2
- Mastering Generative AI for Cybersecurity Certificate
- Essential Eight Assessment Course certificate — TAFEcyber
Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.
Personnel security clearance
NV1 Security ClearanceNV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.
Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.

Illustrative composite
The Enterprise Deal That Exposed a Security Governance Gap
An illustrative composite scenario showing how a 68-person Australian B2B SaaS provider could turn fragmented controls into a working ISO/IEC 27001:2022 information security management system.
Illustrative composite, not a single client engagement. This worked scenario shows the implementation method, evidence trail and certification-body boundary; it is not a claim about a customer outcome.
Read the full case studyWhat will it cost, and how long will it take?
Indicative packages, with a fixed implementation fee agreed after discovery
For suitably scoped companies with fewer than 10 people, the following ranges are a starting point for budgeting. We confirm your fixed fee after reviewing the ISMS scope and starting position. Your proposal records the inclusions, exclusions, responsibilities and payment terms before work begins.
Both ranges exclude GST. Including 10% Australian GST, the indicative totals are A$13,200–16,500 for implementation and A$16,500–19,800 for fast-track. The main cost drivers are the services and locations in scope, organisational complexity, existing documentation and controls, technical remediation, available internal capacity and the evidence already in operation.
- ImplementationStarts fromA$12,000–15,000 + GST
- Typical indicative range for end-to-end implementation consultation: from discovery and ISMS planning through the agreed implementation work, readiness preparation and support through the certification process. Internal audit is separately scoped unless included in your proposal.
- Fast-track implementation + internal auditStarts fromA$15,000–18,000 + GST
- Typical indicative range for the combined small-business package: an implementation consultant, a different internal auditor and a dedicated project manager, plus assistance with certification-body booking and its Stage 1 and Stage 2 process. Audit objectivity and impartiality must be protected; the certification body’s own fees are not included.
- Technical remediation and licences
- included only where expressly scoped; additional work is separately identified.
- Independent internal audit
- included in the fast-track package, with a different competent auditor and documented impartiality checks; otherwise separately scoped. If objectivity cannot be protected, a separate provider is required.
- Certification-body fees
- separate from Aegentra’s implementation fee.
- Continuing support and platforms
- access periods, subscriptions and any post-readiness assistance confirmed in writing.
A timetable based on evidence, not a certificate promise
The staged programme above is an indicative example, not a universal delivery period. The fast-track option targets implementation in 5–7 weeks for suitably scoped companies with fewer than 10 people, timely client decisions and no major remediation blockers. Your proposal confirms the milestones, client responsibilities and audit arrangements. Certification-body availability, audit findings and corrective actions affect when a certificate can be issued; the implementation target is not a guaranteed certification date.
Your team remains part of the work
Nominate a sponsor who can make decisions and control owners who can provide information, operate the arrangements and resolve actions. Leadership approves scope and risk decisions; IT or your service provider supports technical work; other process owners contribute the records relevant to their responsibilities. We agree the required participation during scoping rather than promise a fixed workload for every client.
Implementation, internal audit and certification have different jobs
Aegentra helps you establish the agreed ISMS and prepare it for independent assurance. A different competent Aegentra consultant, independent of the implementation work, performs the Clause 9.2 internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required.
The independent accredited certification body conducts its certification assessment, including Stage 1 and Stage 2, and makes the certification decision. Aegentra can support an agreed handover; neither our consultancy nor our software issues the certificate or guarantees the outcome.
- Aegentra
- scoped implementation and agreed readiness support.
- Your organisation
- decisions, resources, operation and management review.
- Aegentra — different consultant
- objective evaluation and internal-audit conclusions, independent of the implementation work and subject to impartiality checks.
- Certification body
- independent assessment and certification decision.
Explore our separately scoped ISO 27001 internal-audit service for an operating ISMS, whether implemented by Aegentra, another provider or your own team. Auditor competence, prior involvement, conflicts and impartiality are checked before acceptance.
Questions to settle before you start
Is ISO 27001 suitable for a small business?
Yes. The ISMS should reflect the information you handle, the services you deliver and your risks. A smaller organisation can use proportionate processes and clear ownership without copying the bureaucracy of a large enterprise. The important question is whether the arrangements are appropriate and operate effectively, not how many policy documents you have.
We already have an IT provider. What does an implementation consultant add?
Your IT provider may already manage important technical controls. ISO 27001 implementation connects those controls with business scope, risk decisions, people and supplier responsibilities, documented information and review. We agree who performs each action so existing services are not duplicated or assumed to cover work outside their contract.
Can we reuse our policies, tools and existing evidence?
Existing material is a starting point, not something to discard automatically. We review whether it fits the proposed scope, reflects current practice and supports the required decisions. Your proposal identifies the systems to be used and confirms access, storage, export and handover arrangements. No replacement platform or migration is implied without agreement.
Do we have to implement all 93 Annex A controls?
Not automatically. Controls are selected to address your risks and applicable requirements, and the Annex A reference set is checked so necessary controls are not overlooked. The Statement of Applicability records the relevant decisions and implementation status. Controls from outside Annex A may also be necessary.
Can we start without committing to certification?
Yes. Defining scope, understanding gaps and improving risk management can be useful before you decide on certification. Tell us whether the driver is a customer requirement, a tender, an internal improvement programme or an existing deadline so the proposed work supports that decision.
Which edition does this work address?
ISO/IEC 27001:2022, including its applicable 2024 climate-action amendment. The context review considers whether climate change is relevant to the ISMS and whether interested parties have related requirements. This does not turn the engagement into a separate environmental-management certification programme.
Can ISO 27001 be coordinated with ISO 42001 or Essential Eight?
Related work can be coordinated where it makes sense, but the frameworks are not interchangeable. Essential Eight focuses on selected technical mitigation strategies; ISO 27001 establishes an information-security management system. ISO 42001 addresses AI management and introduces distinct AI-related responsibilities and assessments. Any combined scope is agreed separately; one certificate does not establish conformity with the others.
Regulatory obligations such as APRA CPS 234, where applicable, require their own assessment. ISO 27001 certification does not automatically establish compliance with those obligations.
What happens after the implementation engagement?
Your organisation continues to operate and improve the ISMS: reviewing risks, maintaining evidence, responding to changes and resolving issues. The handover identifies outstanding actions and responsibilities. Any ongoing assistance, platform access or support for certification findings is defined in the proposal, rather than assumed to be unlimited or automatically included.
Insights
Read the background before you commit.

ISO 27001 implementation
How ISO 27001 implementation actually works
The process from scope and risk assessment through the Statement of Applicability, risk-selected controls, evidence, internal audit and certification handover.
Read the process
ISO 27001 certification
How to get my company ISO 27001 certified
A step-by-step checklist from scope and risk treatment through internal audit, management review, Stage 1 and Stage 2.
Read the how-to guide- ISO 27001 readiness checklist
questions to organise your starting position.
- Free ISO 27001 templates
practical starting documents to adapt to your scope.
- Company certification guide
how implementation, independent assessment, timing and costs fit together.
- Detailed ISO 27001 cost guide for Australia
itemised planning allowances, scope qualifications and a worked three-year budget, with implementation, internal audit and certification costs kept separate.
Train your internal implementation leadISO 27001 Foundation course
Teams building internal audit capability can explore ISO 27001 Lead Auditor training, with audit competence and independence considered separately from implementation responsibilities.
Standard references: ISO/IEC 27001:2022 and Amendment 1:2024. The information on this page is general guidance; the agreed scope and contract define the services provided.
Let’s talk.
Tell us what is driving your ISO 27001 project, which services and systems need to be in scope, and any customer or certification deadline. We will discuss your starting point, the work your team can support and the information needed to prepare a fixed-fee implementation proposal.
Book discovery callMelbourne-based, delivered across Australia
Discovery, document review, interviews and delivery meetings can be conducted remotely across Australia. Where the scope needs onsite work, location, availability and travel costs are agreed in advance. New Zealand and other APAC engagements can be considered by arrangement.
For local delivery arrangements and scoped options, explore our ISO 27001 consulting services in Melbourne.
Also explore ISO 27001 support for Sydney businesses, delivered remotely with onsite work by arrangement.
- Australia
- 03 9956 9399
- Calling from overseas
- +61 3 9956 9399
Typical enquiry response: 1–3 business hours.
