Skip to main content

ISO 27001 · PERTH

ISO 27001 consulting for Perth organisations

Build an information security management system that covers the services you sell, the systems you use and the responsibilities you control.

Aegentra supports Perth and Western Australian organisations with ISO/IEC 27001:2022 implementation, internal audits and certification preparation. We are Melbourne-based and work remotely across Australia. On-site work is available by arrangement, with travel quoted separately.

Discuss your ISO 27001 scope · Check your service boundaries

03 9956 9399
Read Aegentra’s Google reviews

Business-wide feedback, including consulting and Academy training.

Perth skyline and the Swan River viewed from Kings Park

Start with the work your customers buy

  1. Business systems
  2. Customer systems
  3. External providers

Information security can extend beyond your office network to client drawings, project spaces, remote support accounts and subcontractors.

Western Australia's established mining equipment, technology and services sector makes these useful questions for Perth suppliers. The scope still depends on your particular business and customer requirements.

A defined ISMS makes those responsibilities understandable, including dependencies on customer systems, operational environments and external providers.

Read our national ISO 27001 service overview for the broader implementation approach.

Worked example: remote support for a resources customer

Illustrative example, not an Aegentra client case study.

A Perth engineering software supplier supports a customer's site through remote access. Its proposed certification scope covers software development, but the customer contract also includes production support and handling maintenance records.

Resolve that mismatch before buying a certification package. Which support activities belong within the ISMS? Who authorises remote access, holds the records and responds to a compromised subcontractor account?

The output is a scope statement, responsibility map and evidence plan covering the contracted service. Operational technology risks and interfaces need specific attention. An office IT scope does not establish assurance over every connected customer environment.

Use the same scope for certification-body quotes. Compare services, entities, sites and audit coverage alongside accreditation and buyer acceptance. A cheaper quote for narrower coverage may leave the customer's requirement unresolved.

For technical remediation alongside the management system, explore security hardening support.

What WA procurement guidance means for suppliers

The WA Government Cyber Security Policy requires covered entities to consider information security in relevant procurement, conduct supplier due diligence and understand shared responsibilities. It also addresses independent assurance for high-risk managed-service and cloud procurements. Those provisions do not make ISO 27001 mandatory for every supplier or make it interchangeable with IRAP. Read sections 3.4.1–3.4.2.

The WA Procurement Rules require offers to be evaluated against the criteria and process in the Request. Check the actual clause, the service it covers and when the evidence is required. Certification cannot guarantee an award.

Support matched to your starting point

Start with your requirement and available evidence, whether you need implementation, gap closure or assessment preparation.

ISO 27001 implementation

Indicative starting budget: A$12,000–15,000 + GST A$13,200–16,500 including Australian GST.

For suitably scoped organisations with fewer than 10 people. Establish the ISMS scope, risk assessment, treatment plan, Statement of Applicability and agreed operating controls. We organise the implementation work, responsibilities and evidence, with certification-preparation support defined in your proposal. Internal audit is separately scoped unless included.

Explore implementation deliverables

ISO 27001 internal audit

From A$2,300 + GST From A$2,530 including Australian GST.

For a smaller organisation with one clear ISMS scope and straightforward evidence access. A competent auditor reviews documents, interviews control owners and samples operating evidence against the agreed criteria. Deliverables include the audit plan, documented findings and report; any corrective-action follow-up is specified in the scope.

See the internal-audit scope

Fast-track implementation and internal audit

Indicative starting budget: A$15,000–18,000 + GST A$16,500–19,800 including Australian GST.

For suitably scoped organisations with fewer than 10 people. An implementation consultant, a different internal auditor and a project manager coordinate the programme. Auditor assignment is subject to documented competence, conflict-of-interest and impartiality checks. The agreed package includes assistance arranging a certification body and preparing for Stage 1 and Stage 2.

Discuss a coordinated programme

What is—and is not—in the budget?

Your starting point, services, systems, locations, existing evidence and remediation needs determine the final work. We confirm the scope and fixed fee in writing. These starting budgets are not quotes for every organisation; larger or more complex businesses need a separate scope.

Certification-body fees are separate. Your proposal identifies any travel, licences, additional technical work and other exclusions before you commit. Compare the complete implementation and certification budget, not just the first invoice.

Read the Australian certification cost guide

Check the boundaries of your service

Select the activities that apply. This checklist identifies questions to resolve before scoping an engagement; it does not assess certification readiness or tender eligibility.

Private planning controls

No confidential information is needed. Your selections stay in this page and clear when it is closed or refreshed.

Service boundaryQuestion or action
Customer informationIdentify the information you receive, where it is stored, who can access it and how it is returned or deleted.
Remote accessConfirm who approves access, how it is monitored and how customer and supplier responsibilities are documented.
External providersList the providers supporting your service, their responsibilities and the assurance you need from them.
Operational technologyIdentify the operational systems and interfaces involved. Confirm the assessment expertise and scope needed for those environments.
Customer requirementCheck the exact clause, required evidence, covered service and deadline. Resolve unclear wording with the buyer.

Questions for your scope discussion

Select the activities that apply to your service.

Use these questions to start a discussion. Your selections do not confirm compliance, certification readiness or acceptance by a buyer.

Download the project scoping worksheet.

From a defined boundary to an operating system

Agree the activities and decisions your team will own, then plan implementation, evaluation and independent certification preparation as separate stages.

  1. Agree the requirement and boundary

    Confirm what your customer needs, the services and information in scope, existing work, responsibilities and decision dates. Record the agreed deliverables and exclusions before implementation begins.

  2. Build and operate the ISMS

    Work through the risks, necessary controls, Statement of Applicability and operating procedures. Implement the agreed changes and collect evidence from the people and systems that perform the work.

  3. Test and review

    Arrange an objective internal audit, address findings and complete management review. The auditor must not audit their own work; appoint a separate provider if objectivity cannot be protected.

  4. Prepare for independent certification

    Organise the evidence and support agreed preparation for Stage 1 and Stage 2. The certification body controls its audit programme, findings and certification decision. Aegentra does not issue the certificate.

Timing depends on readiness, not just headcount. For an eligible fast-track scope, 5–7 weeks is an implementation planning target, not a promised certificate date. Leadership decisions, remediation, operating evidence, audit findings and certification-body availability can change the schedule. Your written proposal records the actual plan and dependencies.

Client feedback

Medical clinic · ISO 27001

We certified our medical clinic for ISO 27001 through Aegentra, and the entire process was smooth and well managed.

Google review excerpt, reproduced with permission.

Team and evidence

Know who is responsible for the work

Aegentra is based in Melbourne and delivers ISO 27001 services remotely across Australia, with onsite work by arrangement. We confirm the people assigned, their relevant qualifications, responsibilities and availability in your proposal. Travel and any onsite requirements are agreed before booking.

Our delivery-team capability includes ISO/IEC 27001 implementation and audit qualifications, CISA, CISM and cloud-security credentials. These are held across the team—not necessarily by every consultant. The experience and credential evidence relevant to your assigned roles are confirmed before work starts.

If Aegentra provides both implementation and internal audit, a different competent consultant who is independent of the implementation work performs the audit, subject to documented conflict and impartiality checks. If those safeguards cannot protect objectivity, a separate provider is required. Certification remains the responsibility of an independent accredited certification body.

Meet our delivery-team capability · Read an Australian internal-audit engagement

The linked audit case study is a published Australian engagement, not evidence of a client in this location.

Read Aegentra's Google reviews

Business-wide feedback, including consulting and Academy training.

Certification bodies

ANAB, IAS or JASANZ: what are you actually choosing?

ISO/IEC 27001 is the management-system standard. An independent certification body audits your organisation and decides whether to issue a certificate. ANAB—the ANSI National Accreditation Board—IAS, the International Accreditation Service, and JASANZ are accreditation bodies: they assess certification bodies. They are not three different grades of ISO 27001.

Check that the proposed certification body holds current accreditation for ISO/IEC 27001 and that the certificate's scope fits the services, legal entity and locations your buyer needs covered. International recognition can support acceptance, but it does not override a tender's conditions. If a customer specifies an accreditation or permits an equivalent, clarify acceptance in writing before you book.

A certificate does not guarantee a government contract. If certification covering the work being purchased is mandatory, an unsuitable scope may leave your bid non-compliant. Meeting that requirement still does not replace the buyer's other participation conditions or evaluation criteria. Read the specific procurement documents and seek clarification where needed.

Why can the price differ? You buy certification from a certification body, not from an accreditation logo. Audit time, complexity, sites, travel, rates, follow-up work and the ongoing audit programme affect the quote. Compare Stage 1, Stage 2, surveillance and recertification on the same scope. Do not assume ANAB is always dearer, IAS is always cheaper, or that a customer's country alone determines which certificate it will accept.

Compare accreditation and certification costs

Verification references: ISO: certification and accreditation, ANAB: certificate checks, ANAB: certification cost factors, IAS management-system accreditation, Commonwealth procurement evaluation. State-specific guidance is linked in the relevant city sections.

Questions from Perth businesses

Do we need a Perth-based consultant?

Aegentra is Melbourne-based and supports Perth remotely. On-site work can be arranged with separately quoted travel. We agree access to the people and evidence involved.

Does our customer's ISO requirement cover the whole company?

Check the contracting entity, service, locations and systems covered by the wording. Clarify uncertainty with the buyer before assuming a narrow or company-wide scope.

Can you review an ISMS we already operate?

Yes. An ISO 27001 internal audit can assess the defined system and identify findings requiring action. We establish an appropriate audit scope and objectivity arrangements before the engagement.

How should we compare implementation and certification costs?

Separate consulting, internal effort, technical remediation and certification-body charges. Compare quotes against the same scope and ongoing obligations. Our Australian certification cost guide explains the main cost components.

LET'S TALK

Bring the requirement. We will help define the work.

Tell us what your business delivers, why you need ISO 27001 and any deadline. We will help establish the scope and next step.

Call 03 9956 9399, or use the enquiry form below. Please summarise your requirement without including confidential customer information.

03 9956 9399
Overseas: +61 3 9956 9399
Contact@aegentra.com.au

We typically respond within 1–3 business hours.

Your project details

Tell us your approximate team size, the service you want covered and any customer deadline. Please do not send passwords, sensitive personal information or confidential tender documents through this form.

We use these details to respond to your enquiry. Read our Privacy Policy.