Skip to main content

ISO 27001 · BRISBANE

ISO 27001 consultants for Brisbane businesses

A customer asks for ISO 27001. Start by finding out what they need the certificate to cover.

Aegentra helps Brisbane organisations implement an information security management system, complete an objective internal audit and prepare for independent ISO/IEC 27001:2022 certification. We connect the buyer's requirement to your services, systems and operating evidence, then agree the work, responsibilities and fee.

Melbourne-based · Remote Brisbane delivery · Onsite by arrangement

Discuss my Brisbane project · Compare services and fees

03 9956 9399
Read Aegentra’s Google reviews

Business-wide feedback, including consulting and Academy training.

Brisbane city skyline and riverside architecture across the Brisbane River

A tender deadline and a certification deadline are different things

  1. Requirement
  2. Scope
  3. Evidence

START WITH THE REQUIREMENT

Before approving a project, establish whether your buyer needs a current accredited certificate at submission, certification before contract commencement, specified security controls, or supporting evidence for a risk assessment. Those are different deliverables. If the wording is unclear, seek written clarification through the procurement contact rather than assuming an implementation plan will substitute for a certificate.

Queensland's QITC framework illustrates the distinction. Its Comprehensive Contract Conditions address security controls and separately require the certifications specified in the contract Details. That is not a blanket rule that every Queensland supplier must be ISO 27001 certified. Read the conditions actually used for your purchase alongside the tender's participation and evaluation requirements.

Queensland QITC framework

Your first scoping conversation should answer four questions

QuestionWhat to bring
What are you supplying?The service description and contracting entity
What must be demonstrated?The exact security, certification and evidence requirements
What supports that service?Relevant systems, people, sites and outsourced providers
When is each item needed?Tender, onboarding, implementation and certification dates—kept separate

Bring those answers into the project-scoping worksheet. It helps organise the conversation; it is not a tender compliance determination.

Choose the work that matches your starting point

An operating ISMS may need an internal audit rather than another implementation project. A business starting from policies and scattered evidence may need a structured build. We establish which applies before recommending the scope.

ISO 27001 implementation

Indicative starting budget: A$12,000–15,000 + GST A$13,200–16,500 including Australian GST.

For suitably scoped organisations with fewer than 10 people. Establish the ISMS scope, risk assessment, treatment plan, Statement of Applicability and agreed operating controls. We organise the implementation work, responsibilities and evidence, with certification-preparation support defined in your proposal. Internal audit is separately scoped unless included.

Explore implementation deliverables

ISO 27001 internal audit

From A$2,300 + GST From A$2,530 including Australian GST.

For a smaller organisation with one clear ISMS scope and straightforward evidence access. A competent auditor reviews documents, interviews control owners and samples operating evidence against the agreed criteria. Deliverables include the audit plan, documented findings and report; any corrective-action follow-up is specified in the scope.

See the internal-audit scope

Fast-track implementation and internal audit

Indicative starting budget: A$15,000–18,000 + GST A$16,500–19,800 including Australian GST.

For suitably scoped organisations with fewer than 10 people. An implementation consultant, a different internal auditor and a project manager coordinate the programme. Auditor assignment is subject to documented competence, conflict-of-interest and impartiality checks. The agreed package includes assistance arranging a certification body and preparing for Stage 1 and Stage 2.

Discuss a coordinated programme

What is—and is not—in the budget?

Your starting point, services, systems, locations, existing evidence and remediation needs determine the final work. We confirm the scope and fixed fee in writing. These starting budgets are not quotes for every organisation; larger or more complex businesses need a separate scope.

Certification-body fees are separate. Your proposal identifies any travel, licences, additional technical work and other exclusions before you commit. Compare the complete implementation and certification budget, not just the first invoice.

Read the Australian certification cost guide

Would your certificate cover the service being bought?

REQUIREMENT → SCOPE → EVIDENCE

A valid certificate can still be the wrong evidence for a particular contract. If the tender requires certification covering the service you will deliver, but your certificate covers a different entity or activity, the bid may not satisfy that condition. The buyer decides acceptance under the procurement documents—not a certification mark alone.

Illustrative example—not a client engagement: a supplier bids to operate a customer's support platform. Its certificate covers only internal corporate administration. The supplier should not assume that this demonstrates certification of the proposed support service. Clarify the required scope and relevant dependencies before paying for an audit or submitting the claim.

Check these six connections

Private planning controls

0 of 6 planning checks marked as considered.

Any uncertainty becomes a question for the buyer or certification body—not a reason to assume acceptance. Aegentra can help define the ISMS work and evidence needed within the agreed engagement.

Discuss my scope · Read the company certification guide

Why buyers ask about the controls behind the certificate

The Queensland Audit Office's March 2026 review examined three public-sector entities. Only two of the 36 contracts reviewed included requirements for third parties to report cyber security incidents and vulnerabilities. This is a finding from that audit sample, not a failure rate for Queensland businesses. It underlines a practical point: responsibilities and reporting arrangements need to be written down and checked.

Queensland Audit Office: managing third-party cyber security risks

An agreed sequence, with clear decision points

We organise the ISMS work around your operating business. Your team remains responsible for business decisions and running the controls; we make the agreed tasks, evidence and dependencies visible.

  1. Agree the requirement and boundary

    Confirm what your customer needs, the services and information in scope, existing work, responsibilities and decision dates. Record the agreed deliverables and exclusions before implementation begins.

  2. Build and operate the ISMS

    Work through the risks, necessary controls, Statement of Applicability and operating procedures. Implement the agreed changes and collect evidence from the people and systems that perform the work.

  3. Test and review

    Arrange an objective internal audit, address findings and complete management review. The auditor must not audit their own work; appoint a separate provider if objectivity cannot be protected.

  4. Prepare for independent certification

    Organise the evidence and support agreed preparation for Stage 1 and Stage 2. The certification body controls its audit programme, findings and certification decision. Aegentra does not issue the certificate.

Timing depends on readiness, not just headcount. For an eligible fast-track scope, 5–7 weeks is an implementation planning target, not a promised certificate date. Leadership decisions, remediation, operating evidence, audit findings and certification-body availability can change the schedule. Your written proposal records the actual plan and dependencies.

Client feedback

Medical clinic · ISO 27001

We certified our medical clinic for ISO 27001 through Aegentra, and the entire process was smooth and well managed.

Google review excerpt, reproduced with permission.

Team and evidence

Know who is responsible for the work

Aegentra is based in Melbourne and delivers ISO 27001 services remotely across Australia, with onsite work by arrangement. We confirm the people assigned, their relevant qualifications, responsibilities and availability in your proposal. Travel and any onsite requirements are agreed before booking.

Our delivery-team capability includes ISO/IEC 27001 implementation and audit qualifications, CISA, CISM and cloud-security credentials. These are held across the team—not necessarily by every consultant. The experience and credential evidence relevant to your assigned roles are confirmed before work starts.

If Aegentra provides both implementation and internal audit, a different competent consultant who is independent of the implementation work performs the audit, subject to documented conflict and impartiality checks. If those safeguards cannot protect objectivity, a separate provider is required. Certification remains the responsibility of an independent accredited certification body.

Meet our delivery-team capability · Read an Australian internal-audit engagement

The linked audit case study is a published Australian engagement, not evidence of a client in this location.

Read Aegentra's Google reviews

Business-wide feedback, including consulting and Academy training.

Certification bodies

ANAB, IAS or JASANZ: what are you actually choosing?

ISO/IEC 27001 is the management-system standard. An independent certification body audits your organisation and decides whether to issue a certificate. ANAB—the ANSI National Accreditation Board—IAS, the International Accreditation Service, and JASANZ are accreditation bodies: they assess certification bodies. They are not three different grades of ISO 27001.

Check that the proposed certification body holds current accreditation for ISO/IEC 27001 and that the certificate's scope fits the services, legal entity and locations your buyer needs covered. International recognition can support acceptance, but it does not override a tender's conditions. If a customer specifies an accreditation or permits an equivalent, clarify acceptance in writing before you book.

A certificate does not guarantee a government contract. If certification covering the work being purchased is mandatory, an unsuitable scope may leave your bid non-compliant. Meeting that requirement still does not replace the buyer's other participation conditions or evaluation criteria. Read the specific procurement documents and seek clarification where needed.

Why can the price differ? You buy certification from a certification body, not from an accreditation logo. Audit time, complexity, sites, travel, rates, follow-up work and the ongoing audit programme affect the quote. Compare Stage 1, Stage 2, surveillance and recertification on the same scope. Do not assume ANAB is always dearer, IAS is always cheaper, or that a customer's country alone determines which certificate it will accept.

Compare accreditation and certification costs

Verification references: ISO: certification and accreditation, ANAB: certificate checks, ANAB: certification cost factors, IAS management-system accreditation, Commonwealth procurement evaluation. State-specific guidance is linked in the relevant city sections.

Questions

Does ISO 27001 certification guarantee a Queensland Government contract?

No. It can address a specified assurance requirement, but procurement also considers the published criteria, capability, risk and value for money. An otherwise valid certificate may not meet a requirement if its scope or accreditation does not match what the buyer asks for. Confirm the exact tender conditions rather than assuming all agencies use the same rule.

Queensland supplier guidance on value for money

Can you audit an ISMS implemented by our existing IT provider?

Yes, subject to an agreed scope, evidence access and auditor competence and impartiality checks. We do not require you to rebuild an existing system simply to buy an audit. The audit tests the agreed criteria through interviews, document review and risk-based sampling, then reports the findings.

Can our Brisbane staff and interstate contractors sit within one ISMS?

They can be considered within an appropriately defined scope. The work they perform, information they access and processes connecting them matter more than their postcode. Multi-site certification arrangements and any sampling are determined with the certification body; do not assume one office's certificate automatically covers every activity.

We have a deadline next month. Can you guarantee certification?

No. First establish what is due and assess your starting point. We can agree achievable implementation and preparation work, but remediation, operating evidence, auditor availability and the certification body's decision remain dependencies. We will not present an implementation plan as an issued certificate.

LET'S TALK

Turn your Brisbane requirement into a clear scope

Tell us what you supply, who is asking for assurance and when the evidence is needed. We will discuss your starting point and the information required for a written implementation or internal-audit proposal.

03 9956 9399
Overseas: +61 3 9956 9399
Contact@aegentra.com.au

We typically respond within 1–3 business hours.

Your project details

Tell us your approximate team size, the service you want covered and any customer deadline. Please do not send passwords, sensitive personal information or confidential tender documents through this form.

We use these details to respond to your enquiry. Read our Privacy Policy.