What is ISO 27001 and Why It Matters for Australian Businesses
Alexander Sverdlov
Security Analyst

I have run more than 200 security assessments across 14 countries since 2013, and I can tell you that ISO 27001 is one of the most misunderstood standards a business will ever chase. Australian companies keep asking me the same thing: is it a certificate we buy, a checklist we tick, or a genuine change in how we run security? The honest answer is that it is the third one, and the businesses that treat it as the first two are the ones who fail their audit or, worse, pass the audit and still get breached. This article explains what ISO 27001 actually is, why it matters specifically for Australian businesses in 2026, and how to approach it without wasting a year and a large budget on the wrong things.
What ISO 27001 Actually Is
ISO/IEC 27001 is the international standard for an Information Security Management System, usually shortened to ISMS. The word that matters most in that phrase is "system." ISO 27001 is not a list of technical controls to install. It is a management framework that forces your organisation to identify its information risks, decide how to treat them, document those decisions, and then keep improving over time. The controls live in an annex (Annex A), but the heart of the standard is the management process around them.
The current version is ISO/IEC 27001:2022. It replaced the 2013 edition, and the transition deadline for organisations still certified against the old version was 31 October 2025, so any Australian business pursuing certification today should be working exclusively to the 2022 text. The 2022 update reorganised Annex A into 93 controls grouped under four themes - organisational, people, physical, and technological - rather than the 114 controls across 14 domains that the old 2013 version used. If a consultant is still quoting you "114 controls across 14 domains," that is a sign their material is out of date.
The clauses that carry the real weight
Certification is assessed against clauses 4 through 10 of the standard, not against Annex A alone. These are the parts auditors dig into:
Clause 4 - Context: understanding your organisation, your interested parties, and the scope of the ISMS.
Clause 5 - Leadership: demonstrable commitment from top management, an information security policy, and defined roles.
Clause 6 - Planning: risk assessment, risk treatment, and the Statement of Applicability that justifies which Annex A controls you apply and why.
Clause 7 - Support: resources, competence, awareness, and documented information.
Clause 8 - Operation: actually running the risk treatment you planned.
Clause 9 - Performance evaluation: monitoring, internal audit, and management review.
Clause 10 - Improvement: handling nonconformities and continually improving.
In my experience, businesses that struggle at audit almost always underinvest in clauses 9 and 10. They stand up policies and controls, then never run an internal audit or a management review, so they have no evidence that the system operates. The auditor is not only checking whether you have a control; they are checking whether you can prove it works and that leadership pays attention to it.
Why ISO 27001 Matters for Australian Businesses
ISO 27001 is voluntary. No Australian law forces a private company to certify. So why do so many Australian businesses pursue it? Because in 2026 it has become the shortest credible answer to a question every serious customer now asks: "How do we know our data is safe with you?"
The Australian regulatory and threat context
Several forces make information security a board-level issue here specifically:
The Privacy Act and the Notifiable Data Breaches scheme. Under the NDB scheme, organisations covered by the Australian Privacy Principles must notify the Office of the Australian Information Commissioner and affected individuals of an eligible data breach. Reforms passed in late 2024 and taking effect through 2025 and 2026 have strengthened enforcement and introduced a statutory tort for serious invasions of privacy, raising the stakes for poor data handling.
The Security of Critical Infrastructure Act (SOCI). If you operate assets in one of the defined critical infrastructure sectors, you already face risk management program obligations that map closely onto what an ISMS delivers.
The ACSC Essential Eight. The Australian Cyber Security Centre's Essential Eight is the baseline most Australian government buyers expect. ISO 27001 does not replace it, but a well-run ISMS makes it far easier to demonstrate and maintain your Essential Eight maturity.
Export and enterprise sales. Australian SaaS, fintech, and services companies selling into the US, UK, and EU are routinely asked for ISO 27001 or SOC 2 in procurement. Certification removes a recurring blocker from your sales cycle.
The concrete benefits, stated honestly
I will not promise you a specific contract value, because anyone who does is guessing. What I can tell you from repeated engagements is what certification reliably delivers:
Benefit | What it actually means in practice |
|---|---|
Shorter sales cycles | You answer security questionnaires with a certificate and Statement of Applicability instead of a two-week scramble. |
Fewer, less severe incidents | A functioning risk process finds and closes gaps before an attacker does. |
Access to enterprise and government buyers | Certification is often a hard requirement in procurement, so it opens tenders you were previously excluded from. |
A defensible position after an incident | If a breach does happen, evidence of a managed security system is what regulators and customers want to see. |
Internal discipline | Roles, ownership, and review cadence replace the "someone should look at that" culture that lets risk accumulate. |
How the Certification Process Works
Certification is issued by an accredited certification body after a two-stage external audit. It is important to understand the separation of roles: a consultancy like ours helps you build and prepare the ISMS, but we do not issue certificates. The certificate comes from an independent certification body, and using a firm that is genuinely independent of your build work is part of what makes the certificate credible. In Australia, look for a certification body accredited by JAS-ANZ.
Scoping. Decide which parts of the business, which systems, and which locations the ISMS covers. A tight, honest scope is easier to certify and maintain than an over-broad one.
Risk assessment and treatment. Identify your information risks, decide how to treat each, and record the decisions.
Statement of Applicability. Document which Annex A controls apply, which do not, and the justification for each.
Implementation. Put the controls and processes in place and run them long enough to generate evidence.
Internal audit and management review. Prove the system operates and that leadership reviews it.
Stage 1 audit. The certification body reviews your documentation and readiness.
Stage 2 audit. The auditor tests whether the ISMS operates as documented, then recommends certification.
Surveillance and recertification. Certificates run on a three-year cycle with annual surveillance audits in between.
A realistic first-time timeline for a small to mid-sized Australian company with no formal ISMS is roughly six to twelve months, depending on how much security maturity already exists. Anyone promising certification in a few weeks is either selling a worthless unaccredited certificate or setting you up to fail Stage 2.
The Mistakes That Cost Australian Businesses the Most
These are the failure patterns I see repeatedly on assessments:
Buying tools before doing the risk assessment. Companies purchase expensive scanning, SIEM, or GRC platforms, then discover half of it does not address their actual risks. The risk assessment comes first; it tells you what to buy.
Copy-paste policies nobody follows. A shelf full of downloaded policy templates is worthless if staff do not know they exist. Auditors interview your people, and unfollowed policies surface immediately.
Over-scoping. Trying to certify the entire organisation at once, including systems you barely control, turns a nine-month project into a two-year one.
Ignoring supplier risk. Most Australian businesses run on cloud and third-party services. Annex A expects you to manage supplier security, and this is a common gap.
Treating certification as the finish line. The surveillance audit comes every year. An ISMS that goes dormant the day after certification fails its first surveillance visit.
Confusing ISO 27001 with the Essential Eight. They complement each other. ISO 27001 is the management system; the Essential Eight is a set of technical mitigations. You generally want both.
ISO 27001 Versus the Alternatives
Australian businesses often ask whether they need ISO 27001, SOC 2, or the Essential Eight. They solve different problems:
Framework | Best suited to | Nature |
|---|---|---|
ISO 27001 | Global recognition, enterprise and international buyers | Certifiable management system |
SOC 2 | Selling SaaS into the US market | Attestation report by a CPA firm |
Essential Eight | Australian government and baseline hardening | Technical mitigation maturity model |
In practice, many of the Australian companies I work with pursue ISO 27001 as their governance backbone, maintain Essential Eight maturity as their technical baseline, and add SOC 2 if their US pipeline demands it. These are not competing choices so much as layers.
A Practical Path Forward
If you are starting from a standing position, here is the sequence I recommend before you spend a dollar on certification:
Run a gap assessment against ISO 27001:2022 to see how far you really are.
Fix the obvious technical basics first - multi-factor authentication, patching, backups, access reviews. These map to both Annex A and the Essential Eight.
Build the management layer: scope, risk assessment, Statement of Applicability, and the core policies you will actually follow.
Operate it for a few months, then run a genuine internal audit and management review.
Only then engage an accredited certification body for Stage 1.
This is the work we do with clients through our ISO 27001 readiness engagements: we get you genuinely prepared so the external audit is a formality rather than a gamble. If you want to understand your current gaps first, an IT security audit or a focused vulnerability assessment is usually the right starting point. Businesses that lack an in-house security leader to own the ISMS often bring in a virtual CISO to run the programme through certification and beyond. If you want to talk through where your organisation stands, get in touch and we will give you an honest read rather than a sales pitch.
Frequently Asked Questions
Is ISO 27001 mandatory for Australian businesses?
No. ISO 27001 is a voluntary international standard. However, it is frequently a contractual or procurement requirement, particularly when selling to large enterprises, government, or international customers, so in practice it can be effectively mandatory for the deals you want to win.
How many controls does ISO 27001:2022 have?
The 2022 version has 93 Annex A controls grouped under four themes: organisational, people, physical, and technological. This replaced the older 2013 structure of 114 controls across 14 domains. You do not have to implement all 93; your Statement of Applicability documents which ones apply to your risks and why.
How long does certification take?
For a small to mid-sized Australian company building an ISMS from scratch, a realistic timeline is six to twelve months to be ready for the Stage 2 audit. Organisations with existing security maturity move faster. Certificates then run on a three-year cycle with annual surveillance audits.
Does ISO 27001 replace the ACSC Essential Eight?
No. They work together. The Essential Eight is a set of technical mitigations and a maturity model favoured by Australian government buyers, while ISO 27001 is a management system for information security overall. A well-run ISMS makes it easier to implement, evidence, and maintain your Essential Eight maturity.
Can we issue our own ISO 27001 certificate?
No. A valid certificate is issued only by an independent, accredited certification body after a successful two-stage audit. In Australia, look for accreditation by JAS-ANZ. Consultants help you prepare the ISMS, but a consultant that also issues the certificate is a red flag, because independence is part of what makes the certificate trustworthy.
What does ISO 27001 cost?
Costs vary widely with organisation size, scope, and existing maturity, and split into two buckets: the preparation work (internal effort plus any consulting) and the certification body's audit fees. Rather than trust a fixed headline number, get scoped quotes based on your actual environment. The larger and more honest your scope, the more the audit will involve.

Alexander Sverdlov
Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.