Skip to main content

/ Govern

ISO 27001 Consulting and Implementation Australia

Build an information security management system your team can run and your customers can examine. Aegentra helps Australian organisations define scope, assess risks, implement agreed controls and organise operating evidence for ISO/IEC 27001:2022. Start with discovery, then receive an implementation proposal with a fixed fee, clear responsibilities and a proposed timetable.

Get the brochure by emailCall 03 9956 9399

Independent internal audit and certification are separate from our implementation work.

Black-and-white architectural study of a contemporary glass and concrete office building.
Illustrative architecture

Melbourne-based · Australia-wide delivery · Fixed implementation fee agreed after discovery

An ISMS that works beyond the policy folder

One scope. Connected responsibilities.

Your agreed ISMS scope

People
Processes
Information
and services
Technology
Suppliers
Risk decisionsOwnershipReview

Illustrative ISMS model, tailored to your organisation.

ISO 27001 implementation means establishing how your organisation manages information-security risk: what is in scope, who makes decisions, which controls are needed and how their operation is checked. The work includes people, processes, suppliers and technology, not just an IT configuration or a set of templates.

Aegentra works with your leadership, internal teams and existing IT provider to turn that into a working management system with clear responsibilities, records and review. The service can support a first implementation, a stalled programme or a defined readiness gap. We start by identifying what already works and what needs to change.

Delivery
remote across Australia, with onsite work by arrangement.
Commercial model
discovery followed by an agreed fixed implementation fee.
Certification
assessed and decided by an independent accredited certification body.

/ Service brochure

Get the ISO 27001 implementation brochure.

Review the ISMS scope, delivery approach, responsibilities and operating evidence in one document. Receive a copy by email to read or share with your team.

PDF · 2 pages · 383 KB

Where should we email your brochures?

One email: the implementation overview attached, plus a download link for the detailed capability and services brochure.

Use your company email. Gmail, Yahoo and other personal or temporary email addresses are not accepted.

We use your name and work email to send the brochure and keep a copy of your request in our enquiry inbox. Privacy policy.

Additional brochure

ISO 27001 implementation: capability & services

Explore the implementation pathway, Microsoft 365 security hardening, deliverables and responsibilities in our detailed service brochure.

PDF · 13 pages · 39.9 MB · Download link sent by email

Fast-track ISO 27001 · Small business

Less coordination for you. A clear path from implementation to certification support.

Choose Aegentra’s combined implementation and internal-audit engagement with three distinct delivery roles. It is designed for businesses with limited time to manage an ISO 27001 project themselves, but the ability to make decisions and provide the access and evidence the work needs.

5–7 weeksTarget implementation period

Fewer than 10 peopleSuitably scoped small businesses

This accelerated option is assessed at discovery. It requires a manageable ISMS scope, timely client decisions and no major remediation blockers. It is not a guaranteed certification date; the written proposal confirms the plan and dependencies.

Implementation consultant
Builds the agreed ISMS with your team, coordinates the in-scope controls and prepares the documentation and operating evidence.
Separate internal auditor
A different competent consultant, independent of the implementation work, plans and conducts the Clause 9.2 internal audit and reports their own findings.
Dedicated project manager
A third consultant coordinates milestones, responsibilities and certification-body arrangements, keeping the project moving without directing audit judgements.
Illustrative monochrome project workspace with three seats, a laptop and organised documents.
Illustrative workspace · AI-generated

Support through Stage 1 and Stage 2

We help you arrange an independent accredited certification body, prepare for its Stage 1 and Stage 2 audits, and respond to findings within the agreed engagement. You have a coordinated point of contact through the certification process; the certification body conducts those audits and independently decides whether to issue your certificate.

Certification-body fees are separate. Audit availability, evidence readiness and corrective actions affect the certificate timeline. Your proposal defines the support, fees and responsibilities.

Client participation and audit safeguards

Your team still provides access and evidence, approves the scope and risk decisions, assigns control owners and participates in management review. A shorter programme reduces coordination work; it does not remove these responsibilities.

The internal auditor must not audit their own work. Documented conflict-of-interest and impartiality checks confirm whether separate Aegentra consultants can perform the roles. If objectivity cannot be protected, a separate provider is required.

How our internal audits work

What your ISO 27001 implementation produces

Your written scope identifies the deliverables, acceptance points and responsible people. The programme is built around the following outputs, tailored to the services, information and locations included in your ISMS.

WorkstreamWhat we help produceWhat your organisation contributes
Scope and baselineA defined ISMS boundary, relevant business context, interested-party requirements and prioritised gaps.Leadership decisions about the services, sites, systems and obligations in scope.
Risk assessment and treatmentAgreed risk criteria, an information-security risk register, treatment decisions and accountable action owners.Knowledge of the business, assets, suppliers, existing controls and acceptable risk.
Statement of ApplicabilityA traceable explanation of necessary controls, implementation status and inclusion or exclusion rationale, checked against the 93 Annex A reference controls.Approval of treatment decisions and accurate information about how controls operate.
Documentation and responsibilitiesRequired documented information, practical procedures, security objectives, assigned responsibilities and agreed competence/awareness arrangements.Review, approval and adoption of the arrangements by the people who will use them.
Implementation and evidenceAgreed control work, an evidence register and records showing what has been implemented and checked.System access, operational participation and completion of client-owned actions.
Review and handoverManagement-review preparation, an open-action record and an organised handover for independent assurance.Management review, risk acceptance, corrective action and appointment of the separate internal auditor and certification body.

Technical work is defined before it starts. Your proposal states which configurations Aegentra will implement, which actions remain with your team or IT provider, and which remediation or licences need a separate quote. Where appropriate, Microsoft 365 changes can be scoped through Aegentra Harden.

/ Watch

Why prepare before a customer asks for proof?

A policy describes what should happen. Operating evidence shows what actually happened. This short Aegentra video explains why that distinction matters when customers assess your security, and why certification is not a guarantee of security, insurance cover or legal compliance.

AI-presented educational video by Aegentra · 4:06

Watch on YouTube

Loading the player connects to YouTube. You can read the transcript without loading it.

Read the video transcript

0:00 — Can you show how security works?

Your next customer may ask for proof. Are you ready? Imagine you're about to win a contract. Then the buyer asks how you protect their information.

You have security software, an IT provider, and a folder of policies. But can you show who checks the controls, when they were tested, and what happens if something fails? That is why ISO 27001 readiness matters.

0:28 — More than installing controls

Think of your business like a building. Installing locks is one step. Knowing who holds the keys, checking the alarms, practising an evacuation, and fixing weaknesses is an ongoing system.

Information security works the same way. The standard helps organise that work around your business risks.

0:49 — Customer trust and certification scope

For customers, this turns a promise into something they can examine. If you handle sensitive information or support a larger organisation, the buyer needs a way to assess your security.

Certification can provide independent assurance within its defined scope. It does not mean a business cannot be breached. And a certificate only covers what its scope actually includes.

1:14 — Insurance and operating evidence

Now consider insurance. An insurer may ask whether multifactor authentication protects your systems, how you manage security updates, and how you protect backups. Those answers need to reflect reality.

A policy saying backups are tested is different from a dated record showing a successful restore. The useful question is: could you support your answers with evidence?

ISO certification does not guarantee insurance cover, cheaper premiums or a successful claim. Your policy terms, disclosures, conditions, and the incident itself still matter. Readiness helps you organise the controls and evidence behind those conversations.

Think back to the building. An inspection record can show what was checked. It does not replace the terms of your insurance policy.

2:06 — Australian privacy obligations

In Australia, this also connects to obligations already in force. If your organisation is covered by the Privacy Act, you must take reasonable steps to protect personal information using technical and organisational measures. Some organisations are exempt and exceptions apply, so check your coverage.

Certification is not a substitute for meeting the legal obligations that apply to your business.

2:32 — Ransomware-payment reporting

Ransomware-payment reporting is another example. Since May 2025, organisations covered by these rules must report a ransom payment within 72 hours of making it or becoming aware of a payment made on their behalf.

That clock concerns the payment, not simply discovering an attack. Knowing your obligations, contacts, and escalation process before an incident is part of being prepared.

2:58 — Why prepare, and where does Essential Eight fit?

Here is the distinction. These obligations do not create a blanket ISO certification requirement for every Australian company. The reason to prepare is that your risks, customer expectations, and responsibilities need an organised response.

Australia's Essential Eight can help with technical protections. ISO 27001 provides the broader management system. They can complement each other.

3:24 — Where to start

So where do you start? Identify the information and services that matter most. Define the scope. Assess the risks. Assign an owner to each action.

Then test the controls you rely on: access, backups, supply arrangements, and incident response. Keep the evidence and review what changes. Build a system that people use. Then decide whether certification supports your business goals.

Your next customer asks for proof. You should be able to show how security works in your business. That is the value of readiness.

Next in Australian cyber readiness: what the Essential Eight actually covers.

A clear result at every stage.

Aegentra may target an approximately 12-week implementation programme for an appropriately scoped, Microsoft 365-first organisation with sufficient leadership availability and no major remediation blockers. This is a planning assumption, not a guarantee. Timing depends on the ISMS boundary, starting maturity, technical complexity, evidence availability, client decisions, remediation, internal-audit arrangements and the certification body’s schedule. The written proposal records the actual delivery plan and dependencies.

Scroll to explore all six stages.

  1. Weeks 1–2

    Discovery

    Tenant baseline + scoping doc

    Where Aeges is included in the agreed scope, read-only access supports the tenant posture snapshot. Establish the asset register and agree the ISMS scope with your senior stakeholder.

  2. Weeks 3–5

    Gap analysis

    Risk and applicability map + remediation plan

    Risk-selected controls are recorded in the Statement of Applicability, with Annex A used as the completeness cross-check. Gaps are prioritised and agreed with accountable owners.

  3. Weeks 6–9

    Build

    Policies + tenant configuration + evidence

    The assigned implementation team configures the controls included in the written scope, which may include conditional access, data-loss prevention, device management, sensitivity labels and access reviews. Policies and evidence are recorded in the agreed client environment.

  4. Week 10

    Internal audit coordination

    Separate audit plan + corrective actions

    A different competent Aegentra consultant, independent of the implementation work, completes the Clause 9.2 audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. The implementation consultant can support the client in addressing findings.

  5. Week 11

    Management review

    ISMS management review minutes

    Leadership reviews ISMS performance, risks, audit findings and improvement actions. Decisions, responsibilities and follow-up actions are recorded in the management-review minutes.

  6. Week 12

    Auditor handover

    Certification-readiness handover

    Organise the agreed evidence pack, open actions and handover for the independent certification body. The proposal confirms document access, platform terms and any support after handover; certification timing remains the certification body’s responsibility.

Certification remains an independent decision. Stage 1 and Stage 2 timing is also subject to the selected certification body’s calendar.

Connect the ISMS to the way your Microsoft 365 environment operates

For Microsoft 365-based organisations, we connect the risk treatment plan to agreed work in the tenant and the records needed to review it. That might involve identity and access, device management, email protection or information handling, depending on your risks, existing configuration and licences.

You do not have to use Microsoft 365. The implementation scope can include other technology and evidence sources; Aeges support is limited to the capabilities agreed for your environment.

Aeges can support the collection and organisation of agreed Microsoft 365 technical evidence. Those records still need context and review. A configuration snapshot does not prove that a business process worked, that every relevant system is covered or that the organisation conforms to ISO 27001.

Where ongoing monitoring is agreed, supported technical-control changes can be identified for review. This is separate from the initial implementation scope unless your proposal includes it.

Illustrative evidence trailAn employee leaves.
What needs checking?
Illustrative scene of a person returning a closed company laptop and access badge.
Evidence to review
  • Completed leaver record
  • Account and access records
  • Exceptions and follow-up
  1. RequestNotification and approval
  2. Check accessIdentity, devices and apps
  3. ReviewProcess owner follows up

Illustrative image and workflow, not a client record or a product screenshot. Actions and evidence depend on the agreed scope.

Example: removing access when someone leaves

Illustrative implementation example, not a client result

Decision or actionWhat the example shows
Identify the riskA departing employee could retain access to customer information or business systems.
Agree the treatmentDefine a leaver process covering notification, approval, account access, devices and relevant third-party services.
Implement the agreed changesYour responsible team or scoped specialist carries out the approved actions, including the systems outside Microsoft 365.
Check operating evidenceReview a completed leaver record, relevant account/access records and documented exceptions. A written policy alone is not evidence of completion.
Assign ownership and reviewThe process owner checks unresolved actions and uses the agreed review cycle to identify recurring failures.

The same reasoning applies to other controls: identify the risk, agree the action, assign ownership and keep enough evidence to evaluate whether it works. Microsoft’s certification of its cloud services does not certify your organisation or your use of them.

Who will deliver your ISO 27001 implementation?

Your proposal identifies the accountable engagement lead and the consultants assigned to your scope. It records their responsibilities, relevant competence, specialist support and the separation required for independent assurance. Before work begins, you know who is responsible for each part of the engagement and how their experience fits the role.

Aegentra’s delivery team combines senior experience in IT audit, cybersecurity governance, enterprise risk, internal controls and management systems. The team’s qualifications support both the governance work and the technical implementation required by your scope.

Team members bring more than two decades of professional experience, including 2,000+ hours of ISO, ASD ISM and GRC audit work across 70+ organisations. This experience spans their professional careers, including work delivered outside Aegentra engagements.

Team qualifications and credentials

Qualifications, professional credentials and formal training held across Aegentra’s delivery team.

Management systems and audit

  • ISO/IEC 27001 Lead Implementer
  • PECB ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor
  • CISA — Certified Information Systems Auditor
  • ISM Auditor

Cybersecurity and cloud

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • Certificate of Cloud Security Knowledge (CCSK)
  • OSCP+ — OffSec Certified Professional Plus

Service delivery and specialist training

  • ITIL Expert
  • PRINCE2
  • Mastering Generative AI for Cybersecurity Certificate
  • Essential Eight Assessment Course certificate — TAFEcyber

Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.

Personnel security clearance

NV1 Security Clearance

NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.

Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.

ISO/IEC 27001:2022 ISMS implementation illustrative composite report cover

ISO/IEC 27001 · ISMS implementation

August 2026

Illustrative composite

The Enterprise Deal That Exposed a Security Governance Gap

An illustrative composite scenario showing how a 68-person Australian B2B SaaS provider could turn fragmented controls into a working ISO/IEC 27001:2022 information security management system.

Illustrative composite, not a single client engagement. This worked scenario shows the implementation method, evidence trail and certification-body boundary; it is not a claim about a customer outcome.

Read the full case study

What will it cost, and how long will it take?

Indicative packages, with a fixed implementation fee agreed after discovery

For suitably scoped companies with fewer than 10 people, the following ranges are a starting point for budgeting. We confirm your fixed fee after reviewing the ISMS scope and starting position. Your proposal records the inclusions, exclusions, responsibilities and payment terms before work begins.

Both ranges exclude GST. Including 10% Australian GST, the indicative totals are A$13,200–16,500 for implementation and A$16,500–19,800 for fast-track. The main cost drivers are the services and locations in scope, organisational complexity, existing documentation and controls, technical remediation, available internal capacity and the evidence already in operation.

ImplementationStarts fromA$12,000–15,000 + GST
Typical indicative range for end-to-end implementation consultation: from discovery and ISMS planning through the agreed implementation work, readiness preparation and support through the certification process. Internal audit is separately scoped unless included in your proposal.
Fast-track implementation + internal auditStarts fromA$15,000–18,000 + GST
Typical indicative range for the combined small-business package: an implementation consultant, a different internal auditor and a dedicated project manager, plus assistance with certification-body booking and its Stage 1 and Stage 2 process. Audit objectivity and impartiality must be protected; the certification body’s own fees are not included.
Technical remediation and licences
included only where expressly scoped; additional work is separately identified.
Independent internal audit
included in the fast-track package, with a different competent auditor and documented impartiality checks; otherwise separately scoped. If objectivity cannot be protected, a separate provider is required.
Certification-body fees
separate from Aegentra’s implementation fee.
Continuing support and platforms
access periods, subscriptions and any post-readiness assistance confirmed in writing.

A timetable based on evidence, not a certificate promise

The staged programme above is an indicative example, not a universal delivery period. The fast-track option targets implementation in 5–7 weeks for suitably scoped companies with fewer than 10 people, timely client decisions and no major remediation blockers. Your proposal confirms the milestones, client responsibilities and audit arrangements. Certification-body availability, audit findings and corrective actions affect when a certificate can be issued; the implementation target is not a guaranteed certification date.

Your team remains part of the work

Nominate a sponsor who can make decisions and control owners who can provide information, operate the arrangements and resolve actions. Leadership approves scope and risk decisions; IT or your service provider supports technical work; other process owners contribute the records relevant to their responsibilities. We agree the required participation during scoping rather than promise a fixed workload for every client.

Implementation, internal audit and certification have different jobs

Aegentra helps you establish the agreed ISMS and prepare it for independent assurance. A different competent Aegentra consultant, independent of the implementation work, performs the Clause 9.2 internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required.

The independent accredited certification body conducts its certification assessment, including Stage 1 and Stage 2, and makes the certification decision. Aegentra can support an agreed handover; neither our consultancy nor our software issues the certificate or guarantees the outcome.

Aegentra
scoped implementation and agreed readiness support.
Your organisation
decisions, resources, operation and management review.
Aegentra — different consultant
objective evaluation and internal-audit conclusions, independent of the implementation work and subject to impartiality checks.
Certification body
independent assessment and certification decision.

Explore our separately scoped ISO 27001 internal-audit service for an operating ISMS, whether implemented by Aegentra, another provider or your own team. Auditor competence, prior involvement, conflicts and impartiality are checked before acceptance.

Questions to settle before you start

Is ISO 27001 suitable for a small business?

Yes. The ISMS should reflect the information you handle, the services you deliver and your risks. A smaller organisation can use proportionate processes and clear ownership without copying the bureaucracy of a large enterprise. The important question is whether the arrangements are appropriate and operate effectively, not how many policy documents you have.

We already have an IT provider. What does an implementation consultant add?

Your IT provider may already manage important technical controls. ISO 27001 implementation connects those controls with business scope, risk decisions, people and supplier responsibilities, documented information and review. We agree who performs each action so existing services are not duplicated or assumed to cover work outside their contract.

Can we reuse our policies, tools and existing evidence?

Existing material is a starting point, not something to discard automatically. We review whether it fits the proposed scope, reflects current practice and supports the required decisions. Your proposal identifies the systems to be used and confirms access, storage, export and handover arrangements. No replacement platform or migration is implied without agreement.

Do we have to implement all 93 Annex A controls?

Not automatically. Controls are selected to address your risks and applicable requirements, and the Annex A reference set is checked so necessary controls are not overlooked. The Statement of Applicability records the relevant decisions and implementation status. Controls from outside Annex A may also be necessary.

Can we start without committing to certification?

Yes. Defining scope, understanding gaps and improving risk management can be useful before you decide on certification. Tell us whether the driver is a customer requirement, a tender, an internal improvement programme or an existing deadline so the proposed work supports that decision.

Which edition does this work address?

ISO/IEC 27001:2022, including its applicable 2024 climate-action amendment. The context review considers whether climate change is relevant to the ISMS and whether interested parties have related requirements. This does not turn the engagement into a separate environmental-management certification programme.

Can ISO 27001 be coordinated with ISO 42001 or Essential Eight?

Related work can be coordinated where it makes sense, but the frameworks are not interchangeable. Essential Eight focuses on selected technical mitigation strategies; ISO 27001 establishes an information-security management system. ISO 42001 addresses AI management and introduces distinct AI-related responsibilities and assessments. Any combined scope is agreed separately; one certificate does not establish conformity with the others.

Regulatory obligations such as APRA CPS 234, where applicable, require their own assessment. ISO 27001 certification does not automatically establish compliance with those obligations.

What happens after the implementation engagement?

Your organisation continues to operate and improve the ISMS: reviewing risks, maintaining evidence, responding to changes and resolving issues. The handover identifies outstanding actions and responsibilities. Any ongoing assistance, platform access or support for certification findings is defined in the proposal, rather than assumed to be unlimited or automatically included.

Insights

Read the background before you commit.

All insights

Teams building internal audit capability can explore ISO 27001 Lead Auditor training, with audit competence and independence considered separately from implementation responsibilities.

Standard references: ISO/IEC 27001:2022 and Amendment 1:2024. The information on this page is general guidance; the agreed scope and contract define the services provided.

Let’s talk.

Tell us what is driving your ISO 27001 project, which services and systems need to be in scope, and any customer or certification deadline. We will discuss your starting point, the work your team can support and the information needed to prepare a fixed-fee implementation proposal.

Book discovery call

Melbourne-based, delivered across Australia

Discovery, document review, interviews and delivery meetings can be conducted remotely across Australia. Where the scope needs onsite work, location, availability and travel costs are agreed in advance. New Zealand and other APAC engagements can be considered by arrangement.

For local delivery arrangements and scoped options, explore our ISO 27001 consulting services in Melbourne.

Also explore ISO 27001 support for Sydney businesses, delivered remotely with onsite work by arrangement.

Australia
03 9956 9399
Calling from overseas
+61 3 9956 9399

Typical enquiry response: 1–3 business hours.