ISO 27001 is the international, certifiable standard for an information security management system. You assess 93 Annex A controls against your risks, record the decisions in a Statement of Applicability, then pass a Stage 1 and Stage 2 audit by an accredited certification body. First-year cost at Australian market rates: A$30,000–95,000 ex GST.
Certification is normally three separate purchases: a consultant to build the ISMS, a compliance platform to track it, and the security operations a Stage 2 auditor tests — logging, monitoring, vulnerability management. Secure60 delivers all three as one engagement on one platform, which reduces the tool spend, the process effort of standing up the management system, and the cost of the audit itself, because the evidence is live rather than reconstructed the month before.
Secure60 holds ISO 27001:2022 certification, so the system we build for you is the one we run. Book a readiness call and we’ll scope your gap, your timeline and a number.
ISO 27001 is the international standard for an information security management system, or ISMS. A management system means a defined scope, assessed risks, chosen controls, and evidence that the whole system runs continuously. It is certifiable, which is why buyers ask for it by name: a certificate from an accredited body is proof a customer can accept without auditing you themselves.
The control catalogue is Annex A: 93 controls in four themes.
| Theme | Controls |
|---|---|
| Organisational | 37 |
| People | 8 |
| Physical | 14 |
| Technological | 34 |
The standard is risk-based. All 93 controls are assessed against your risks, the ones your risks justify are implemented, and the exclusions are recorded with justifications in your Statement of Applicability. Consideration of every control is mandatory; implementation of every control is not. The control library lists all 93.
Two audits produce the certificate. Stage 1 is a documentation review, checking that the ISMS exists on paper: scope, risk assessment, Statement of Applicability, policies. Stage 2 covers interviews and evidence, checking that what is documented operates — access reviews that happened, logs that were kept and monitored, incidents that were handled.
Both stages are performed by an accredited certification body, independent of whoever helped you prepare, Secure60 included. A provider offering to both implement and certify is describing something the accreditation rules do not permit.
The certificate then runs on a three-year cycle: surveillance audits in years two and three checking the system still operates, then full recertification. Surveillance is straightforward for organisations that kept the ISMS running after Stage 2 and expensive for those that did not.
At Australian market rates, first-year certification runs A$30,000–95,000 ex GST across implementation, a compliance platform and the certification audit, with lower costs in years two and three. What does ISO 27001 cost in Australia? prices every component, by company size, across the full three-year cycle.
The sequence is fixed — gap assessment, risk assessment, controls and policies, internal audit, Stage 1, Stage 2 — and the calendar depends on your scope, how much security you already run, and how much of your team’s time the project can draw on. How long does ISO 27001 certification take? works through the stages and what compresses or extends each one.
Reading Annex A as a mandatory checklist is the most expensive misreading of the standard, because it commits budget to controls your risk assessment would have excluded.
You assess all 93 and implement the ones your risks justify, with the reasoning recorded in your Statement of Applicability. The SoA shapes the audit, and auditors read exclusions as closely as implementations.
What fails Stage 2 audits is rarely a missing control. It is a control that exists in documentation and is not operating — a monitoring policy with no monitoring behind it, a logging standard with no logs retained. Documentation gets you through Stage 1; operation gets you through Stage 2.
Most tools hand you a to-do list; we do the list and run the security behind it. One engagement covers the ISMS build, the Annex A controls, and the operational layer Stage 2 auditors test hardest: logging, monitoring, vulnerability management, and governance and evidence kept current between audits rather than reconstructed before them. Secure60 holds ISO 27001:2022 certification, so the system we build for you is the one we run. The certification audit stays with an accredited certification body; our work is making sure you enter it with nothing to explain away.
Is ISO 27001 legally required in Australia?
No. The requirement is market-driven: enterprise customers, overseas buyers and security questionnaires ask for it, and contracts increasingly require it. That makes it optional in law and mandatory in practice once a large enough customer asks.
Do we have to implement all 93 Annex A controls?
No. You assess all 93 against your risks and record which apply, and why the rest do not, in your Statement of Applicability. Auditors read exclusion justifications as carefully as implementations.
Who certifies us?
An accredited certification body, independent of whoever prepared you. Secure60 builds the ISMS, implements the controls and runs the security behind them. The certification audit itself is performed by the accredited body.
How long is the certificate valid?
Three years, provided you pass an annual surveillance audit in years two and three. At the end of the cycle you complete a full recertification. The budget and the staffing both need to cover the cycle rather than the certificate alone.
What does ISO 27001 cost?
At Australian market rates, first-year certification runs A$30,000–95,000 ex GST across implementation, platform and audit, with lower costs in years two and three. The cost page breaks it down line by line. Those are market ranges rather than Secure60 pricing.
Should we do SOC 2 instead?
Only where a US buyer specifically requires it. SOC 2 is an AICPA attestation report, dominant in the US market; ISO 27001 is the international certification. We focus on ISO 27001 — the comparison page covers when each applies.