
Win enterprise deals. Satisfy APRA.Prove Security.
Going it alone takes most businesses 6 months. Our clients certify in as little as 4–8 weeks.
One ISMS satisfies five Australian regulatory obligations at once, the Privacy Act, APRA CPS 234, the Essential Eight, IRAP and SOCI, instead of five separate projects. Done-for-you, fixed fee, dedicated Australian consultant.
- No hidden costs, ever
- Dedicated Australian consultant
- Quick quote in 24 hours
Trusted by Australian businesses
94,000+
cybercrime reports to the ACSC last year
~$71k
average cyber incident cost, small AU business
100%
certification success rate
CPS 234 + E8
maps to APRA & the Essential Eight
One ISMS, the whole Australian regulatory stack
A single evidence base satisfies the regulations Australian buyers and regulators care about.
Privacy Act 1988 & NDB scheme
Evidences the APP 11 'reasonable steps' the OAIC expects, with built-in incident response so eligible breaches are identified and notified within 30 days.
APRA CPS 234
Aligns directly with the information-security control requirements binding on APRA-regulated entities and their third-party providers.
Essential Eight ML2/ML3
Annex A technological controls sit cleanly over the Essential Eight, ideal if you're targeting ACSC Maturity Level 2 or 3.
IRAP & SOCI Act
A recognised baseline for IRAP assessment and support for the CIRMP obligations now in force for critical-infrastructure owners.
Tell us your situation and headcount, we'll scope your fixed fee within 24 hours.
Get my fixed-fee quote →What ISO 27001 certification involves
ISO/IEC 27001:2022 gives your organisation a defensible, risk-based Information Security Management System covering people, processes and technology, the framework Australian regulators, tender panels and enterprise customers ask for by name. It maps cleanly to the Privacy Act 1988, the Notifiable Data Breaches scheme, APRA CPS 234, the Essential Eight and the SOCI Act, so one ISMS satisfies five control sets instead of five separate projects.
Information Security Management System
A documented ISMS scoped to your business, policies, procedures and controls across people, process and technology, not a generic template pack.
Risk assessment & treatment
A risk register and treatment plan auditors ask for first, sized to your actual threat exposure and obligations.
Statement of Applicability
The SoA documents which of the 93 Annex A controls apply to you and why, scoped honestly, not maximally.
Annex A controls (93 across 4 themes)
Organisational (37), People (8), Physical (14) and Technological (34) controls under the 2022 revision.
Internal audit
A full dry run with findings documented, corrected and signed off so the certification audit holds no surprises.
Management review
Leadership review of ISMS performance and corrective actions, evidencing the governance auditors require.
What ISO 27001 does for your business
Shorten enterprise sales cycles
Replace months of security-questionnaire back-and-forth with one auditable certificate buyers already trust.
Unlock regulated markets
Qualify for government, finance and healthcare work where 27001 is now a condition to even quote.
Lower your cyber premiums
Insurers are pricing 27001-certified organisations at reduced rates as breach costs climb.
Prove Privacy Act compliance
Demonstrate the documented, tested security safeguards the OAIC expects for personal information.
Satisfy APRA-regulated clients
Meet CPS 234 information-security expectations as a regulated entity or third-party provider.
Defend your supply-chain story
Give enterprise and regulated customers auditable evidence that their data is safe in your hands.
Who ISO 27001 is for in Australia
Not sure if ISO 27001 fits your sector? Tell us what you do, we'll tell you straight, no pressure.
Get my fixed-fee quoteWhat does ISO 27001 certification cost?
Your fee depends on one thing: the size of your organisation. Tell us your headcount and we'll send a single fixed fee covering gap analysis, documentation, consultancy and your certification audit, agreed upfront, no hourly billing, no surprises.
Five steps to certified
One dedicated Australian consultant from quote to certificate, we do the heavy lifting.
- 01
Quick quote & scope
Tell us your standard and headcount, your quote arrives within 24 hours, agreed before we start.
- 02
Gap analysis
Your dedicated consultant maps what you already have against the standard, so you only build what's missing.
- 03
System build
We write the policies, procedures and records with you, tailored to how your business actually operates.
- 04
Implementation & internal audit
We embed the system, train your team and run the internal audit to confirm you're ready.
- 05
Certification audit
We prepare and support you through the audit, independent or JAS-ANZ accredited, your choice.


EFQM 5★ Recognised for Excellence
Fewer than 400 organisations worldwide hold it, IMSM is one of them
Think of it as ISO certification for our own business, we hold ourselves to the same standard we hold you to.
It's an independent assessment of our own quality management against the European Foundation for Quality Management framework.
“IMSM provided excellent support throughout the certification. Expert guidance helped us educate people internally, and the implementation process was smooth.”
“Having our business ISO 9001 certified adds credibility to the organisation, but the processes and procedures introduced make for a far more productive and efficient workplace throughout the entire structure.”
ISO 27001, common questions
Is ISO 27001 the same as the Essential Eight?+
No, the Essential Eight is a prescriptive set of eight technical mitigations from the ACSC, while 27001 is a risk-based ISMS covering governance, people, physical and technological controls. In practice 27001 is the umbrella, and the Essential Eight sits in its technological layer.
We already have SOC 2, is 27001 duplicative?+
There's significant overlap, but SOC 2 is a US attestation for American buyers whereas 27001 is the certification Australian and European customers, insurers and regulators ask for, and we can bridge the two evidence bases.
Do I need to rebuild my entire IT environment?+
Almost never, 27001 is about defensible, documented, risk-proportionate controls, and most clients already have 60–70% in some form, so we formalise, fill gaps and evidence them.
What changed in the 2022 revision?+
Annex A was restructured into 93 controls across four clean themes, Organisational, People, Physical and Technological, and your Statement of Applicability documents which apply to you and why.
How long does certification take?+
Most Australian businesses reach the certification audit in as little as 2 months, with the timeline quoted upfront, and since most clients already have 60–70% of the controls in some form, things move quickly.
How does 27001 handle Privacy Act and NDB obligations?+
It demonstrates the security safeguards the OAIC expects for personal information and builds in detection, logging and notification workflows so eligible breaches are identified and reported within the 30-day window.
Ready to get ISO 27001 certified?
Most clients have their quote within 24 hours. Let's see what certification looks like for your business.