For most Australian organisations under 100 staff, first-year certification runs A$30,000–95,000 ex GST at market rates: readiness and implementation (A$15,000–55,000), a compliance platform (A$7,000–20,000 a year) and the certification audit (A$8,000–20,000). Years two and three cost less — surveillance audits run A$2,500–15,000 a year.
Four line items. Everything you’ll be quoted is one of these, whatever it’s called on the proposal.
| Component | What it covers | AU market range (2026, ex GST) |
|---|---|---|
| Readiness & implementation | Gap assessment, risk assessment, policies, control implementation, internal audit, audit prep | A$15,000 – 55,000 |
| Compliance platform | Control tracking, evidence collection, policy management | A$7,000 – 20,000 per year |
| Certification audit (Stage 1 + 2) | Independent audit by an accredited certification body | A$8,000 – 20,000 (larger or multi-site to A$25,000+) |
| Ongoing surveillance | Annual surveillance audit in years 2 and 3 | A$2,500 – 15,000 per year |
These are published Australian market ranges, not Secure60 pricing. Two things move you within them: how many people and systems are in scope, and how much security you already run. A 15-person SaaS company with everything in one cloud sits near the bottom of each range. A 100-person company with an office network, on-premises servers and three acquisitions’ worth of tooling does not.
There’s also a packaged option in the Australian market: compliance-as-a-service at around A$3,750 a month (A$45,000 a year, ex GST) to reach certification, dropping to about A$2,450 a month (A$29,400 a year) for ongoing maintenance, typically capped at 50 employees and excluding the external audit fee. Useful as a benchmark for what “done for you” costs at market rates.
Headcount is the single biggest cost driver — it drives the audit quote, the number of controls in scope, and the implementation effort.
| Company size | Where you land in the market ranges |
|---|---|
| Under 20 staff | Bottom of every range. Implementation near A$15,000–25,000, audit near A$8,000–12,000. Small scope, few systems, fast interviews. |
| 20–50 staff | Middle of the ranges. This is where the packaged A$45,000-a-year market offerings are aimed. |
| 50–100 staff | Upper half. More departments in scope means more interviews, more evidence, more audit days. |
| 100+ staff | Top of the ranges and beyond — multi-site audits push past A$25,000, and implementation depends heavily on how standardised your environment is. |
Almost every published figure quotes year one and stops. The certificate runs on a three-year cycle, so budget for the cycle.
| Year | What happens | Market cost (sum of ranges above, ex GST) |
|---|---|---|
| Year 1 | Implementation + platform + Stage 1 and Stage 2 audit | A$30,000 – 95,000 |
| Year 2 | Platform + first surveillance audit + keeping controls and evidence current | A$9,500 – 35,000 |
| Year 3 | Platform + second surveillance audit, then recertification (A$8,000–15,000) at the end of the cycle | A$17,500 – 50,000 |
The line most budgets miss isn’t on the invoice at all: internal effort in years 2 and 3. Surveillance audits check that the system still runs — that access reviews happened, logs were monitored, incidents were handled, evidence exists. If nobody owns that work, you find out at the surveillance audit, and fixing a lapsed ISMS costs more than maintaining one.
The mistake isn’t underestimating year one. It’s treating certification as the finish line.
ISO 27001 certifies a management system — a thing that runs continuously, not a project that ends. The standard requires ongoing risk assessment, internal audits, management reviews and evidence that your controls actually operate. Buyers who budget A$50,000 for the certificate and A$0 for running it end up in one of two places: paying a consultant again every year to reconstruct evidence before each surveillance audit, or quietly letting the ISMS decay until a big customer’s security review notices. The honest way to read the tables above: year one buys the certificate; the operating cost keeps it.
Tools hand you a to-do list. We do the list — and run the security behind it. That’s the cost structure difference: instead of paying separately for a consultant, a platform, and the security operations your auditor expects to see running (log retention, monitoring, vulnerability management), it’s one engagement on one platform — governance, log management and vulnerability management in the same context. Secure60 is ISO 27001:2022 certified ourselves, so we run the same system we build for you. We don’t publish pricing — every engagement is scoped to the organisation. What we’ll give you on a readiness call is a real number for your size, systems and deadline, alongside the market figures above so you can judge it.
What's the cheapest way to get ISO 27001 certified in Australia?
Do the implementation work internally and buy only the audit (A$8,000–20,000 at market rates). It’s the cheapest on paper and the most expensive in practice — you’re trading consultant fees for months of your own team’s time, and a failed Stage 2 audit costs you the re-audit and the delay.
Does the certification audit cost extra on top of implementation?
Yes, always. The audit must be performed by an accredited certification body, which is independent of whoever helped you prepare. Budget A$8,000–20,000 for Stage 1 and Stage 2 at market rates, more for larger or multi-site organisations.
What are the ongoing costs after certification?
Surveillance audits run A$2,500–15,000 a year at market rates, plus your platform subscription and the internal effort of keeping controls and evidence current. Recertification every three years runs A$8,000–15,000.
Is a compliance platform like Vanta or Drata enough on its own?
No. A platform tracks controls and collects some evidence automatically, but someone still has to implement the controls, run the risk assessment, write the policies and front the auditor. That someone is a consultant, your own team, or a provider that does both.
How much does Secure60 charge for ISO 27001?
We don’t publish pricing, because we scope each engagement to the organisation — size, systems, existing controls, deadline. Book a readiness call and you’ll get a scoped number, not a range.
Why do published ISO 27001 cost estimates vary so much?
Because most quote a single number without saying what’s in it. Some count only the audit, some count implementation but not the platform, and almost none separate year one from the ongoing cost. Priced component by component, as above, the market is more consistent than it looks.