Skip to main content

ISO 27001 · HOBART & TASMANIA

ISO 27001 consulting for Hobart and Tasmania

Turn customer security requirements into a practical management system, with clear responsibilities and evidence your team can maintain.

Aegentra supports organisations in Hobart and across Tasmania with ISO/IEC 27001:2022 implementation, internal audits and certification preparation. We are Melbourne-based and deliver remotely across Australia. On-site work is available by arrangement, with travel quoted separately.

Discuss your ISO 27001 project · Plan your tender evidence

03 9956 9399
Read Aegentra’s Google reviews

Business-wide feedback, including consulting and Academy training.

Fishing boats moored along Hobart’s waterfront beside historic harbour buildings

Make security evidence part of everyday work

  1. Requirement
  2. Evidence
  3. Owner
  4. Due date

A questionnaire, contract renewal or tender can expose scattered security evidence across people, systems and suppliers.

Identify what works, what needs to change and who will maintain it. Policies should describe workable operations; records should show them happening.

Business Tasmania describes local capabilities spanning software, data, integration and cyber security. Customer assurance can involve both these businesses' practices and the providers behind their services.

Our ISO 27001 implementation service brings that work into a defined ISMS with accountable owners.

Worked example: one service, several evidence requests

Illustrative example, not an Aegentra client case study.

A Hobart software business uses a cloud host and external support provider. An enterprise customer and a public-sector opportunity have different assurance requirements.

The team can reuse access reviews, supplier assessments and recovery-test records, mapping each response to the question asked. Its cloud provider's certificate does not establish certification of the software business itself.

If certification is required, check whether its scope covers development, hosting responsibilities and support. Identify subcontracted activities and how those relationships are controlled.

Give certification bodies the same scope and check accreditation and buyer acceptance. A cheaper assessment excluding a contracted service may leave the requirement unresolved.

Use our ISO 27001 checklist to organise an initial review of your current position.

Read the Tasmanian requirement before committing to a solution

Tasmanian procurement documents specify evaluation criteria and any mandatory conditions. Noncompliance with mandatory conditions can eliminate a submission; evaluation can also consider capability, technical merit, risk and value. Certification cannot guarantee an award. See the Government's supplier guidance.

The Government's INFOSEC-3 policy addresses agency security and supply-chain risk, including relevant standards and procurement provisions. It does not make ISO 27001 certification compulsory for every Tasmanian business. Check your buyer's requirements. Read INFOSEC-3, pages 14 and 22–25.

Choose the next piece of work

Choose implementation support, an internal audit or certification preparation according to your existing system and the requirement you need to address.

ISO 27001 implementation

Indicative starting budget: A$12,000–15,000 + GST A$13,200–16,500 including Australian GST.

For suitably scoped organisations with fewer than 10 people. Establish the ISMS scope, risk assessment, treatment plan, Statement of Applicability and agreed operating controls. We organise the implementation work, responsibilities and evidence, with certification-preparation support defined in your proposal. Internal audit is separately scoped unless included.

Explore implementation deliverables

ISO 27001 internal audit

From A$2,300 + GST From A$2,530 including Australian GST.

For a smaller organisation with one clear ISMS scope and straightforward evidence access. A competent auditor reviews documents, interviews control owners and samples operating evidence against the agreed criteria. Deliverables include the audit plan, documented findings and report; any corrective-action follow-up is specified in the scope.

See the internal-audit scope

Fast-track implementation and internal audit

Indicative starting budget: A$15,000–18,000 + GST A$16,500–19,800 including Australian GST.

For suitably scoped organisations with fewer than 10 people. An implementation consultant, a different internal auditor and a project manager coordinate the programme. Auditor assignment is subject to documented competence, conflict-of-interest and impartiality checks. The agreed package includes assistance arranging a certification body and preparing for Stage 1 and Stage 2.

Discuss a coordinated programme

What is—and is not—in the budget?

Your starting point, services, systems, locations, existing evidence and remediation needs determine the final work. We confirm the scope and fixed fee in writing. These starting budgets are not quotes for every organisation; larger or more complex businesses need a separate scope.

Certification-body fees are separate. Your proposal identifies any travel, licences, additional technical work and other exclusions before you commit. Compare the complete implementation and certification budget, not just the first invoice.

Read the Australian certification cost guide

Turn a requirement into an evidence task

Organise a tender or customer assurance request into an action list. This planner does not interpret documents or determine eligibility.

Private planning controls

Use role names and non-confidential summaries. Entries stay in this page, are not saved or sent, and clear when you close or refresh it. Print a copy if you need to keep it.

Your evidence action list

Add a requirement to start your action list.

RequirementTypeTimingEvidence positionEvidence or actionResponsible roleTarget date

This list reflects your entries. Available evidence still needs review against the actual requirement. The list does not confirm compliance or tender eligibility.

For the broader project, download the scoping worksheet.

Build a plan your team can maintain

Separate the work needed to establish the ISMS from the reviews and records needed to keep it operating. Agree who can make decisions and supply evidence before committing to dates.

  1. Agree the requirement and boundary

    Confirm what your customer needs, the services and information in scope, existing work, responsibilities and decision dates. Record the agreed deliverables and exclusions before implementation begins.

  2. Build and operate the ISMS

    Work through the risks, necessary controls, Statement of Applicability and operating procedures. Implement the agreed changes and collect evidence from the people and systems that perform the work.

  3. Test and review

    Arrange an objective internal audit, address findings and complete management review. The auditor must not audit their own work; appoint a separate provider if objectivity cannot be protected.

  4. Prepare for independent certification

    Organise the evidence and support agreed preparation for Stage 1 and Stage 2. The certification body controls its audit programme, findings and certification decision. Aegentra does not issue the certificate.

Timing depends on readiness, not just headcount. For an eligible fast-track scope, 5–7 weeks is an implementation planning target, not a promised certificate date. Leadership decisions, remediation, operating evidence, audit findings and certification-body availability can change the schedule. Your written proposal records the actual plan and dependencies.

Client feedback

Medical clinic · ISO 27001

We certified our medical clinic for ISO 27001 through Aegentra, and the entire process was smooth and well managed.

Google review excerpt, reproduced with permission.

Team and evidence

Know who is responsible for the work

Aegentra is based in Melbourne and delivers ISO 27001 services remotely across Australia, with onsite work by arrangement. We confirm the people assigned, their relevant qualifications, responsibilities and availability in your proposal. Travel and any onsite requirements are agreed before booking.

Our delivery-team capability includes ISO/IEC 27001 implementation and audit qualifications, CISA, CISM and cloud-security credentials. These are held across the team—not necessarily by every consultant. The experience and credential evidence relevant to your assigned roles are confirmed before work starts.

If Aegentra provides both implementation and internal audit, a different competent consultant who is independent of the implementation work performs the audit, subject to documented conflict and impartiality checks. If those safeguards cannot protect objectivity, a separate provider is required. Certification remains the responsibility of an independent accredited certification body.

Meet our delivery-team capability · Read an Australian internal-audit engagement

The linked audit case study is a published Australian engagement, not evidence of a client in this location.

Read Aegentra's Google reviews

Business-wide feedback, including consulting and Academy training.

Certification bodies

ANAB, IAS or JASANZ: what are you actually choosing?

ISO/IEC 27001 is the management-system standard. An independent certification body audits your organisation and decides whether to issue a certificate. ANAB—the ANSI National Accreditation Board—IAS, the International Accreditation Service, and JASANZ are accreditation bodies: they assess certification bodies. They are not three different grades of ISO 27001.

Check that the proposed certification body holds current accreditation for ISO/IEC 27001 and that the certificate's scope fits the services, legal entity and locations your buyer needs covered. International recognition can support acceptance, but it does not override a tender's conditions. If a customer specifies an accreditation or permits an equivalent, clarify acceptance in writing before you book.

A certificate does not guarantee a government contract. If certification covering the work being purchased is mandatory, an unsuitable scope may leave your bid non-compliant. Meeting that requirement still does not replace the buyer's other participation conditions or evaluation criteria. Read the specific procurement documents and seek clarification where needed.

Why can the price differ? You buy certification from a certification body, not from an accreditation logo. Audit time, complexity, sites, travel, rates, follow-up work and the ongoing audit programme affect the quote. Compare Stage 1, Stage 2, surveillance and recertification on the same scope. Do not assume ANAB is always dearer, IAS is always cheaper, or that a customer's country alone determines which certificate it will accept.

Compare accreditation and certification costs

Verification references: ISO: certification and accreditation, ANAB: certificate checks, ANAB: certification cost factors, IAS management-system accreditation, Commonwealth procurement evaluation. State-specific guidance is linked in the relevant city sections.

Questions from Hobart & Tasmania businesses

Do you support organisations outside Hobart?

Yes. We support organisations across Tasmania remotely. Any on-site work and associated travel are agreed and quoted separately; Aegentra is based in Melbourne.

Can a small team maintain an ISMS?

Yes, with clear ownership, workable processes and time for reviews. The design should reflect your services and risks. Management retains accountability when support is outsourced.

Can we start with an internal audit?

Yes, if there is an implemented ISMS to assess. An ISO 27001 internal audit can identify findings and support improvement. It is separate from the certification body's assessment.

What should our budget include?

Allow for internal effort, consulting where needed, technical changes and certification-body fees. Ongoing maintenance and surveillance also need consideration. Our Australian certification cost guide explains the components.

LET'S TALK

Make the next step clear

Tell us what you deliver, the requirement driving your project and any deadline. We will help define the scope and next step.

Call 03 9956 9399, or use the enquiry form below. Please provide a brief summary without confidential customer or tender material.

03 9956 9399
Overseas: +61 3 9956 9399
Contact@aegentra.com.au

We typically respond within 1–3 business hours.

Your project details

Tell us your approximate team size, the service you want covered and any customer deadline. Please do not send passwords, sensitive personal information or confidential tender documents through this form.

We use these details to respond to your enquiry. Read our Privacy Policy.