No law requires it. But enterprise procurement increasingly treats ISO 27001 as a pass/fail filter, and the alternative — a full security review on every deal — costs more founder time than certification once enterprise is a real part of your pipeline. Defer it while enterprise deals are occasional; commit before they become the plan.
Nobody will fine you for selling to a bank without ISO 27001. The pressure is commercial: large organisations run supplier-security policies, and those policies need a cheap way to sort hundreds of vendors into “acceptable risk” and “more work required”. A current ISO 27001 certificate is that sorting mechanism — independent, internationally recognised, checkable in one line of an RFP response.
That’s why the requirement keeps showing up in three escalating forms:
| Where it appears | How hard the requirement is |
|---|---|
| A security questionnaire row: “Are you ISO 27001 certified?” | Soft. Evidence of running controls plus a committed date often passes. |
| Supplier security policy: “vendors handling our data must hold ISO 27001 or equivalent” | Firm, but “or equivalent” and “within an agreed period” are frequently negotiable with the security team. |
| RFP mandatory criteria: certification as a pass/fail field | Hard. No certificate, no shortlist — nobody you meet has authority to waive it. |
The trend line matters more than any single deal: the same enterprise that negotiated last year moves the requirement into the mandatory column next year, because pass/fail is cheaper for them to administer than judgement. So the honest answer to the H1 is: not legally, not yet universally — but increasingly, and one deal at a time.
Without a certificate, each enterprise deal triggers the full treatment: a long security questionnaire, evidence assembly, calls with their security team, a contract security schedule negotiated line by line. Most of that lands on you or your CTO, because nobody else can answer accurately — and it repeats, in a different template, for every new logo. Deals slow, and the same objections get re-litigated from scratch each time.
Certification front-loads the work once. The implementation effort, the audit and the running of the system are real costs — priced honestly here — but they’re incurred once and then amortised across every deal that follows. Reviews shrink from “prove everything” to “certificate number, scope, and a handful of specifics”. The founder-hours stop scaling with deal count.
The crossover is a pipeline question. One enterprise logo a year, and review-per-deal is probably cheaper. Enterprise as the growth plan — the position most SaaS startups heading upmarket are in — and review-per-deal becomes the most expensive way to buy the same outcome repeatedly.
You can defer when your buyers are mid-market or SMB and nobody upstream requires flow-down; enterprise deals are occasional and champion-led, so evidence plus a dated plan gets you through; or you’re still proving the product and a certification program would displace the work that keeps the company alive.
You can’t defer when target RFPs list certification as mandatory criteria; you handle data sensitive enough that supplier policies won’t flex — financial, health, government-adjacent; a signed customer’s contract commits you to certify within a period; or the same deal-blocking review keeps repeating and each one costs you a quarter’s selling time.
Watch for flow-down clauses in the deals you’ve already signed. When your customer holds certifications or regulatory obligations of their own, their contract often obliges their suppliers — you — to meet a named security standard or “equivalent controls”. Founders discover these clauses at renewal, when the customer’s own auditor asks about supplier assurance. Read the security schedule before deciding you’re free to defer.
One more input: deferring certification is not deferring security. The controls procurement asks about — logging, monitoring, vulnerability management, incident response — are worth running regardless, and running them early makes eventual certification an evidence exercise rather than a build.
Waiting for the deal that requires it before starting. It feels prudent — why spend before the revenue justifies it? — but the timing never works. Certification means implementing the system, then passing a Stage 1 and Stage 2 audit with an accredited certification body; the timeline is measured in months. An enterprise procurement window is not. When the mandatory-criteria RFP lands, the choice isn’t “certify or not” — it’s “lose this one and certify for the next one”.
Make the decision on your pipeline’s shape, twelve months out, not on the deal in your inbox.
Secure60 builds and runs the ISMS: risk assessment, controls, policies, and the governance and evidence layer that keeps you audit-ready — with the logging, monitoring and vulnerability management underneath run by us rather than added to your team’s list. We’re ISO 27001:2022 certified ourselves; the certificate itself comes from an accredited certification body, and our job is getting you through their audit and keeping you through every surveillance audit after it. Commercials are scoped to the engagement — a readiness call gets you a straight answer on whether certification pays for itself yet.
Is ISO 27001 a legal requirement for selling to enterprise in Australia?
No. No Australian law requires ISO 27001 to sell software or services. The requirement comes from your customers’ procurement and supplier-security policies — which makes it commercial, not legal, and negotiable in some accounts and non-negotiable in others.
Would SOC 2 do instead of ISO 27001?
Depends on who’s buying. SOC 2 is the US-market attestation; ISO 27001 is the international certification, and it’s what Australian and Asia-Pacific enterprise procurement most often names. Secure60 focuses on ISO 27001 — the trade-off has its own page.
Can we pass enterprise security reviews without any certification?
Yes, sometimes — with strong evidence of running controls and a committed certification date. It works best when the security team has discretion and the deal has an internal champion. It stops working when the RFP makes certification a pass/fail field. See what to do when a customer asks directly.
How far ahead of an enterprise push should we start?
Before the deal that demands it exists. Certification runs through implementation, then a Stage 1 and Stage 2 audit — the timeline page sets out the stages — and enterprise procurement windows are rarely long enough to certify inside one.
Does ISO 27001 mean no more security questionnaires?
No — most enterprises still send one. But the certificate answers the hardest rows in one line, shortens the review, and moves you from ‘prove everything’ to ‘confirm specifics’.
What does certification actually cost?
At Australian market rates it’s a five-figure exercise in year one across implementation, platform and audit — the component-by-component breakdown is in our cost guide.