ISO 27001 is the international standard for information security, and in Australia it has quietly become the shorthand for "you can trust this supplier with your data." If a big customer's procurement or security team has started asking about it, this is what it means and what achieving it involves.
What ISO 27001 actually certifies
Certification is independent proof that your business runs an information security management system (ISMS): a documented, risk-based way of protecting the information you hold, which an accredited certification body audits against the ISO 27001 standard.
It is not a firewall or a piece of software. It is a management system, how you assess risk, choose controls, assign responsibility and keep improving, so security holds up as your business changes rather than depending on one person remembering to do the right thing.
Why Australian buyers keep asking for it
In Australia, ISO 27001 turns up wherever information security has to be proven to someone else:
- Vendor security questionnaires, enterprise and government buyers send long security assessments before they sign; a 27001 certificate answers most of those questions at once.
- APRA CPS 234, regulated finance entities must manage information security across their suppliers, so they push the requirement down to the vendors they work with.
- The SOCI Act, critical-infrastructure obligations are making security posture a board-level issue for a widening set of industries.
- Essential Eight alignment, 27001 gives you the management wrapper that the ACSC Essential Eight technical controls sit inside.
The practical effect is that 27001 stops being a "nice to have" the moment a large customer, insurer or regulator gets involved, and having it can be the difference between reaching the shortlist and being filtered out.
What the certification involves
The path follows the same shape as any ISO system, applied to information security:
- Scope and risk assessment, define which information and systems are in scope, and assess the risks to them.
- Select controls, choose the Annex A controls that address those risks and record the reasoning in a Statement of Applicability.
- Build and implement the ISMS, policies, access control, supplier management, incident response and the records that prove they actually run.
- Internal audit and management review, check the system yourself and have leadership review it before the external audit.
- Certification audit, an accredited certification body audits in two stages and, if satisfied, issues your certificate, then confirms it at periodic surveillance audits.
Two ways to get there
You can do it yourself, which means someone learning the standard, running a risk assessment and writing the documentation on top of their day job. Or you can have it done for you: this is what IMSM does, a dedicated Australian consultant runs the risk assessment, builds the ISMS around how you actually operate, and manages you through to the certification audit for a single fixed fee agreed upfront.
What it costs and how long it takes
Both depend on the same things: the size of your organisation, how many sites and systems are in scope, and how much you already do formally. Rather than quote a generic number, we scope both against your actual situation, see what drives the cost of ISO certification for the detail.
Need ISO 27001 to close a deal or satisfy a customer?
Get my fixed-fee quote →Tell us what you do and how many staff you have, and we'll send a fixed-fee quote for ISO 27001 certification within 24 hours.