First-year certification starts at A$30,000 ex GST for an Australian organisation under 20 staff on a single cloud platform, and reaches A$95,000 at 100 staff with offices and on-premises systems. The figure covers readiness and implementation (A$15,000–55,000), a compliance platform (A$7,000–20,000 a year) and the certification audit (A$8,000–20,000). Years two and three cost less, with surveillance audits at A$2,500–15,000 a year. Across the full three-year cycle that is A$57,000–180,000, or under A$1,600 a month at the bottom of the range.
Most figures on this page represent three separate bills: a consultant to run the process, a compliance platform to track it, and the security operations your auditor expects to find running underneath. Secure60 collapses all three into one engagement on one platform, which removes the duplicate tool spend, most of the process effort, and the audit preparation that adds more to a first-year quote than the audit fee itself.
Secure60 holds ISO 27001:2022 certification, so what you buy is a system we already operate rather than a to-do list you still have to action. The ranges below are the Australian market rather than our pricing — book a readiness call and we’ll scope a number against them.
Every quote breaks down into four line items, whatever the proposal calls them.
| Component | What it covers | AU market range (2026, ex GST) |
|---|---|---|
| Readiness & implementation | Gap assessment, risk assessment, policies, control implementation, internal audit, audit prep | A$15,000 – 55,000 |
| Compliance platform | Control tracking, evidence collection, policy management | A$7,000 – 20,000 per year |
| Certification audit (Stage 1 + 2) | Independent audit by an accredited certification body | A$8,000 – 20,000 (larger or multi-site to A$25,000+) |
| Ongoing surveillance | Annual surveillance audit in years 2 and 3 | A$2,500 – 15,000 per year |
These are published Australian market ranges rather than Secure60 pricing. Two factors set your position within them: how many people and systems are in scope, and how much security you already run. A 15-person SaaS company operating entirely in one cloud sits near the bottom of each range, which sums to about A$30,000 for year one. A 100-person company with an office network, on-premises servers and three acquisitions’ worth of tooling sits near the top.
The Australian market also offers a packaged option: compliance-as-a-service at around A$3,750 a month (A$45,000 a year, ex GST) to reach certification, dropping to about A$2,450 a month (A$29,400 a year) for ongoing maintenance, typically capped at 50 employees and excluding the external audit fee. It serves as a benchmark for the market rate of a fully delivered service.
Headcount drives the audit quote, the number of controls in scope, and the implementation effort, which makes it the largest single cost variable.
| Company size | Where you land in the market ranges |
|---|---|
| Under 20 staff | Bottom of every range — about A$30,000–45,000 for year one. Implementation near A$15,000–25,000, audit near A$8,000–12,000. Small scope, few systems, fast interviews. |
| 20–50 staff | Middle of the ranges. This is the band the packaged A$45,000-a-year market offerings target. |
| 50–100 staff | Upper half. More departments in scope produces more interviews, more evidence and more audit days. |
| 100+ staff | Top of the ranges and beyond — multi-site audits exceed A$25,000, and implementation cost depends heavily on how standardised the environment is. |
The certificate runs on a three-year cycle, so the budget covers the cycle rather than year one alone.
| Year | What happens | Market cost (sum of ranges above, ex GST) |
|---|---|---|
| Year 1 | Implementation + platform + Stage 1 and Stage 2 audit | A$30,000 – 95,000 |
| Year 2 | Platform + first surveillance audit + keeping controls and evidence current | A$9,500 – 35,000 |
| Year 3 | Platform + second surveillance audit, then recertification (A$8,000–15,000) at the end of the cycle | A$17,500 – 50,000 |
| Three-year cycle | The full certification cycle | A$57,000 – 180,000 (about A$1,600 – 5,000 a month) |
Internal effort in years 2 and 3 appears on no invoice and is the line most budgets omit. Surveillance audits check that the system still runs: access reviews happened, logs were monitored, incidents were handled, evidence exists. Where nobody owns that work, the gap surfaces at the surveillance audit, and restoring a lapsed ISMS costs more than maintaining one.
ISO 27001 certifies a management system, which runs continuously. The standard requires ongoing risk assessment, internal audits, management reviews and evidence that controls operate.
Organisations that budget A$50,000 for the certificate and nothing for running it reach one of two outcomes: paying a consultant again each year to reconstruct evidence before each surveillance audit, or allowing the ISMS to decay until a large customer’s security review identifies it. In the tables above, year one buys the certificate and the operating cost retains it.
Secure60 delivers the certification and operates the security behind it as a single engagement on one platform, so the consultant fee, the platform subscription and the security operations your auditor expects to see running — log retention, monitoring, vulnerability management — arrive as one cost rather than three. Governance, log management and vulnerability management share the same context. Secure60 holds ISO 27001:2022 certification, so we run the same system we build for you. We do not publish pricing, because every engagement is scoped to the organisation. A readiness call produces a number for your size, systems and deadline, alongside the market figures above for comparison.
What's the cheapest way to get ISO 27001 certified in Australia?
Doing the implementation work internally and buying only the audit (A$8,000–20,000 at market rates) produces the lowest invoice. The cost moves rather than disappearing: consultant fees are exchanged for months of your own team’s time, and a failed Stage 2 audit adds the re-audit fee and the delay.
Does the certification audit cost extra on top of implementation?
Yes, in every case. The audit must be performed by an accredited certification body, independent of whoever helped you prepare. Budget A$8,000–20,000 for Stage 1 and Stage 2 at market rates, and more for larger or multi-site organisations.
What are the ongoing costs after certification?
Surveillance audits run A$2,500–15,000 a year at market rates, plus your platform subscription and the internal effort of keeping controls and evidence current. Recertification every three years runs A$8,000–15,000.
Is a compliance platform like Vanta or Drata enough on its own?
No. A platform tracks controls and collects some evidence automatically. Implementing the controls, running the risk assessment, writing the policies and fronting the auditor remain with a consultant, your own team, or a provider that does both.
Does a 15-person startup pay the same as a 100-person company?
No. Headcount drives the audit quote, the number of controls in scope and the implementation effort, which makes it the largest single cost variable. Under 20 staff on a single cloud platform, year one lands near A$30,000–45,000 at market rates. At 100 staff with an office network, on-premises servers and several acquisitions’ worth of tooling, the same year reaches A$95,000.
How much does Secure60 charge for ISO 27001?
We do not publish pricing, because each engagement is scoped to the organisation — size, systems, existing controls, deadline. A readiness call produces a scoped number rather than a range.
Why do published ISO 27001 cost estimates vary so much?
Most quote a single number without stating what it contains. Some count only the audit, some count implementation but not the platform, and few separate year one from the ongoing cost. Priced component by component, as above, the market is more consistent than the headline figures suggest.