Most customers asking for ISO 27001 will accept a committed certification date plus evidence of the security you run today, and rarely require the certificate immediately. The response that keeps the deal open: reply promptly, establish what they need, send what exists, and commit to a date you can defend.
A request naming ISO 27001 means different things depending on who sent it and why, so the first step is establishing which question is being asked.
| What the request says | What it usually means |
|---|---|
| “Are you ISO 27001 certified?” | A yes/no for a procurement checklist. A committed certification date plus current evidence often satisfies it. |
| “Please complete the attached security questionnaire” | Accurate answers about the controls you run today. The certificate is one question among dozens — see what to do when a questionnaire is blocking a deal. |
| “Certification is required under our supplier policy” | A firm requirement, though the contractual test is often “certified within an agreed period” rather than certified at signature. Many supplier policies allow the former. |
| “Our security team would like to review your controls” | A conversation rather than a certificate. Evidence of logging, monitoring, access control and incident handling, presented by someone who can answer questions. |
In each case the customer’s security or procurement team needs to close a risk question. A certificate closes it fastest, and audit-ready evidence with a committed date closes it as well, on a timescale of this quarter.
Deals stall on silence more often than on a missing certificate, so the reply goes out within days. It covers four things.
ISO 27001:2022 certifies an information security management system. Annex A lists 93 controls across four themes — organisational, people, physical, technological — and the standard is risk-based, so you assess all 93 and document which apply in a Statement of Applicability. Certification is a two-stage audit by an accredited certification body: Stage 1 reviews documentation, Stage 2 tests evidence and interviews your people. Surveillance audits then run annually with full recertification every three years, which makes the date you give your customer the start of an ongoing obligation.
The cost and the timeline each have their own page: the cost of ISO 27001 in Australia and the certification timeline. Both inform the date before it goes in writing.
The common failure is treating it as purely a compliance problem: buying a platform subscription, receiving a 90-item control checklist, and going quiet on the customer for six weeks while trying to staff it. From the customer’s side that is an unanswered risk question from a supplier who has stopped responding, which is a worse position than the original request.
The reply keeps the deal open and the certification plan makes the reply true, in that order.
Most tools hand you a to-do list; we do the list and run the security behind it. When a customer request lands, we scope what certification takes for your organisation, give you a date you can put in writing, and build the ISMS with governance and evidence kept current, while the logging, monitoring and vulnerability management your auditor will test runs on our platform underneath. Secure60 holds ISO 27001:2022 certification. The certificate is issued by an accredited certification body rather than by us; our work is making sure you enter that audit ready.
Does the customer need our certificate before they'll sign?
Usually not. Most procurement and security teams are assessing risk, and will hold a deal open on a committed certification date plus evidence of the controls you run now. A direct question to the buyer establishes which applies — certification before signature is a rarer requirement than the request usually implies.
Can we say we're 'ISO 27001 compliant' without being certified?
No. Compliant or aligned, without a certificate, is a claim that cannot be substantiated, and a security team will ask for the certificate number. State what is true: which controls you run today, and the date you have committed to for certification.
Who issues the ISO 27001 certificate?
An accredited certification body, through a Stage 1 documentation review and a Stage 2 audit of evidence and interviews. Consultants and providers, Secure60 included, prepare you for that audit and do not issue the certificate.
We have SOC 2. Does that answer an ISO 27001 request?
Sometimes. SOC 2 is a US-market attestation report and ISO 27001 is the international certification, and they cover similar ground. Some customers accept one for the other and some do not, so ask. Secure60 focuses on ISO 27001 — see SOC 2 vs ISO 27001 for Australian companies.
What should we send while we're not yet certified?
What exists: your security policies, an outline of how you handle access, logging, vulnerabilities and incidents, and your certification plan with a date. Evidence of running controls carries more weight than a commitment to future ones.
What does certification cost and how long does it take?
At Australian market rates, budget across implementation, a platform and the audit — the full breakdown is in our cost guide. Timeline depends on your starting point; see how long certification takes.