No law requires it. Enterprise procurement increasingly treats ISO 27001 as a pass/fail filter, and the alternative — a full security review on every deal — costs more founder time than certification once enterprise is a material part of your pipeline. Certification can be deferred while enterprise deals are occasional, and needs committing before they become the plan.
The pressure is commercial rather than legal. Large organisations run supplier-security policies, and those policies need an inexpensive way to sort hundreds of vendors into acceptable risk and further work required. A current ISO 27001 certificate serves as that sorting mechanism: independent, internationally recognised, and checkable in one line of an RFP response.
The requirement appears in three escalating forms.
| Where it appears | How hard the requirement is |
|---|---|
| A security questionnaire row: “Are you ISO 27001 certified?” | Soft. Evidence of running controls plus a committed date often passes. |
| Supplier security policy: “vendors handling our data must hold ISO 27001 or equivalent” | Firm, though “or equivalent” and “within an agreed period” are frequently negotiable with the security team. |
| RFP mandatory criteria: certification as a pass/fail field | Hard. Without a certificate there is no shortlist, and the people you meet have no authority to waive it. |
The direction of travel is the material input. The enterprise that negotiated last year moves the requirement into the mandatory column the following year, because a pass/fail field is cheaper to administer than case-by-case judgement. Certification is therefore not universally required today and is required by a growing share of the market.
Without a certificate, each enterprise deal triggers a long security questionnaire, evidence assembly, calls with the buyer’s security team, and a contract security schedule negotiated line by line. That work lands on the founder or CTO, because nobody else can answer accurately, and it repeats in a different template for every new logo. Deals slow, and the same objections are re-litigated each time.
Certification front-loads the work once. The implementation effort, the audit and the running of the system are real costs — priced by component here — incurred once and then amortised across every deal that follows. Reviews shrink from proving everything to supplying a certificate number, a scope statement and a handful of specifics. Founder hours stop scaling with deal count.
The crossover point is a pipeline question. At one enterprise logo a year, review-per-deal is usually cheaper. Where enterprise is the growth plan — the position most SaaS startups heading upmarket occupy — review-per-deal becomes the most expensive way to buy the same outcome repeatedly.
Deferral works where your buyers are mid-market or SMB with no flow-down requirement upstream; enterprise deals are occasional and champion-led, so evidence plus a dated plan clears the review; or the product is still being proven and a certification program would displace the work that sustains the company.
Deferral stops working where target RFPs list certification as mandatory criteria; the data you handle is sensitive enough that supplier policies do not flex — financial, health, government-adjacent; a signed customer’s contract commits you to certify within a period; or the same deal-blocking review repeats and each one consumes a quarter of selling time.
Flow-down clauses in deals already signed are worth checking against this decision. Where a customer holds certifications or regulatory obligations of their own, their contract often obliges their suppliers to meet a named security standard or equivalent controls. These clauses commonly surface at renewal, when the customer’s own auditor asks about supplier assurance, so the security schedule is the document that determines whether deferral is available.
Deferring certification is separate from deferring security. The controls procurement asks about — logging, monitoring, vulnerability management, incident response — are worth running regardless, and running them early makes eventual certification an evidence exercise rather than a build.
Certification requires implementing the system, then passing a Stage 1 and Stage 2 audit with an accredited certification body. The timeline is measured in months, and an enterprise procurement window is not. Once a mandatory-criteria RFP arrives, the available options are losing that deal and certifying for the next one.
The decision is therefore made against the shape of the pipeline twelve months out.
Secure60 builds and runs the ISMS: risk assessment, controls, policies, and the governance and evidence layer that keeps you audit-ready, with the logging, monitoring and vulnerability management underneath run by us rather than added to your team’s list. Secure60 holds ISO 27001:2022 certification. The certificate itself comes from an accredited certification body, and our work is getting you through their audit and keeping you through every surveillance audit after it. Commercials are scoped to the engagement, and a readiness call gives you a direct answer on whether certification pays for itself yet.
Is ISO 27001 a legal requirement for selling to enterprise in Australia?
No. No Australian law requires ISO 27001 to sell software or services. The requirement comes from customers’ procurement and supplier-security policies, which makes it commercial rather than legal — negotiable in some accounts and non-negotiable in others.
Would SOC 2 do instead of ISO 27001?
It depends on the buyer. SOC 2 is the US-market attestation; ISO 27001 is the international certification, and it is what Australian and Asia-Pacific enterprise procurement most often names. Secure60 focuses on ISO 27001 — the trade-off has its own page.
Can we pass enterprise security reviews without any certification?
Sometimes, with strong evidence of running controls and a committed certification date. That approach works where the security team has discretion and the deal has an internal champion, and stops working where the RFP makes certification a pass/fail field. See what to do when a customer asks directly.
How far ahead of an enterprise push should we start?
Before the deal that requires it exists. Certification runs through implementation, then a Stage 1 and Stage 2 audit — the timeline page sets out the stages — and enterprise procurement windows are rarely long enough to certify inside one.
Does ISO 27001 mean no more security questionnaires?
No. Most enterprises still send one. The certificate answers the hardest rows in one line and shortens the review from proving everything to confirming specifics.
What does certification cost?
At Australian market rates it is a five-figure exercise in year one across implementation, platform and audit. The component-by-component breakdown is in our cost guide.