ISO 27001 is the international, certifiable standard for an information security management system. You assess 93 Annex A controls against your risks, record the decisions in a Statement of Applicability, then pass a Stage 1 and Stage 2 audit by an accredited certification body. First-year cost at Australian market rates: A$30,000–95,000 ex GST.
ISO 27001 is the international standard for an information security management system — an ISMS. Not a checklist of technical settings: a management system, meaning defined scope, assessed risks, chosen controls, and evidence that the whole thing runs continuously. It’s also certifiable, which is why buyers ask for it by name. A certificate from an accredited body is proof a customer can accept without auditing you themselves.
The control catalogue is Annex A: 93 controls in four themes.
| Theme | Controls |
|---|---|
| Organisational | 37 |
| People | 8 |
| Physical | 14 |
| Technological | 34 |
The standard is risk-based. You assess all 93 controls against your actual risks, then document which apply — and justify which don’t — in your Statement of Applicability. Not every control must be implemented; every control must be considered. The control library lists all 93 if you want to see what you’d be assessing.
Two audits get you the certificate. Stage 1 is a documentation review: the auditor checks your ISMS exists on paper — scope, risk assessment, Statement of Applicability, policies. Stage 2 is the real one: interviews and evidence, checking that what’s documented actually operates. Access reviews that happened, logs that were kept and monitored, incidents that were handled.
Both stages are performed by an accredited certification body. That body is independent of whoever helped you prepare — Secure60 included. Anyone offering to both implement and certify you is describing something the accreditation rules don’t allow.
The certificate then runs on a three-year cycle: surveillance audits in years two and three checking the system still operates, then full recertification. The organisations that find surveillance painful are the ones that treated Stage 2 as the finish line.
At Australian market rates, first-year certification runs A$30,000–95,000 ex GST across implementation, a compliance platform and the certification audit — with years two and three costing less. What does ISO 27001 actually cost in Australia? prices every component, by company size, across the full three-year cycle.
On timing: the sequence is fixed — gap assessment, risk assessment, controls and policies, internal audit, Stage 1, Stage 2 — but the calendar depends on your scope, how much security you already run, and how much of your team’s time the project can actually get. How long does ISO 27001 certification take? works through the stages and what compresses or stretches each one.
“We have to implement all 93 controls.” You don’t — and trying to is the most expensive misreading of the standard there is.
You assess all 93 and implement the ones your risks justify, with the reasoning recorded in your Statement of Applicability. The SoA is the document that shapes your audit; auditors read your exclusions as closely as your implementations. And the thing that actually fails Stage 2 audits is rarely a missing control — it’s a control that exists on paper but isn’t operating. A monitoring policy with nothing monitoring, a logging standard with no logs retained. Documentation gets you through Stage 1; operation gets you through Stage 2.
Tools hand you a to-do list. We do the list — and run the security behind it. One engagement covers the ISMS build, the Annex A controls, and the operational layer Stage 2 auditors test hardest: logging, monitoring, vulnerability management, governance and evidence kept live between audits, not reconstructed before them. We hold ISO 27001:2022 certification ourselves — the system we’d build for you is the one we run every day. The certification audit stays with an accredited certification body; our job is making sure you walk into it with nothing to explain away.
Is ISO 27001 legally required in Australia?
No. It’s market-driven: enterprise customers, overseas buyers and security questionnaires ask for it, and contracts increasingly require it. That makes it optional in law and mandatory in practice once a big enough customer asks.
Do we have to implement all 93 Annex A controls?
No. You assess all 93 against your risks and record which apply — and why the rest don’t — in your Statement of Applicability. Auditors read your exclusion justifications as carefully as your implementations.
Who actually certifies us?
An accredited certification body, independent of whoever prepared you. Secure60 builds the ISMS, implements the controls and runs the security behind them — the certification audit itself is always performed by the accredited body.
How long is the certificate valid?
Three years, provided you pass an annual surveillance audit in years two and three. At the end of the cycle you do a full recertification. Budget and staff for the cycle, not just the certificate.
What does ISO 27001 cost?
At Australian market rates, first-year certification runs A$30,000–95,000 ex GST across implementation, platform and audit, with cheaper years two and three. The cost page breaks it down line by line — those are market ranges, not Secure60 pricing.
Should we do SOC 2 instead?
Only if a US buyer specifically demands it. SOC 2 is an AICPA attestation report, dominant in the US market; ISO 27001 is the international certification. We focus on ISO 27001 — the comparison page covers when each applies.