How to choose an ISO 27001 certification body in Australia
Blog

ISO 27001 Certification Body: How to Choose One

An ISO 27001 certification body is the independent organisation that audits your information security management system and issues your certificate. Choose one that is accredited for the ISO/IEC 27001 scheme specifically, by JAS-ANZ in Australia or another accreditation body recognised internationally. Accreditation is the single filter that matters most, because a certificate from a body without it may not be accepted by the enterprise and government customers you are certifying for.

Beyond accreditation, the useful differences between certification bodies come down to auditor experience in your sector, how many audit days they quote, and their availability against your timeline. This guide covers how to check each one, and what to ask before you sign.

What does an ISO 27001 certification body actually do?

An ISO 27001 certification body audits your information security management system against the standard and, if you pass, issues a certificate. It is deliberately separate from anyone who helped you build the ISMS. A certification body cannot both consult on your ISMS and certify it, because that would compromise the independence the certificate is meant to represent.

The engagement runs across a three year cycle. A stage 1 audit reviews your documentation, scope and statement of applicability. A stage 2 audit checks that the ISMS is genuinely operating and gathers evidence against the controls you declared applicable. If you pass stage 2, the certificate is issued and remains valid for three years, subject to surveillance audits in each of the intervening years and a full recertification audit before it expires.

Timeline of the ISO 27001 certification cycle from stage 1 audit through stage 2, certificate issue, two surveillance audits and recertification
You are buying a three year relationship, not a one off audit.

That cycle is why the choice matters more than it first appears. You are not buying a single audit. You are choosing who will be in your business, asking questions of your team, for three years.

What is an accredited ISO 27001 certification body?

An accredited certification body is one that has itself been assessed by a national accreditation body against ISO/IEC 17021-1, the standard that sets requirements for organisations providing management system certification. In Australia and New Zealand that accreditation body is the Joint Accreditation System of Australia and New Zealand, known as JAS-ANZ, which is the joint government appointed accreditation authority for both countries.

Accreditation matters for a practical reason rather than a philosophical one. Anybody can print a certificate. Accreditation is the mechanism by which a customer, an insurer or a government buyer can trace your certificate back to an independently supervised process. Accreditation bodies are also linked internationally, so an accredited Australian certificate is recognised by overseas customers in a way an unaccredited one is not.

Diagram of the accreditation chain from JAS-ANZ to the certification body to your ISO 27001 certificate, and the difference between accredited and non accredited certificates
The accreditation mark on a certificate is what lets a customer trace it back to a supervised process.

One trap catches Australian businesses regularly. A certification body may hold accreditation for ISO 9001 or ISO 45001 but not for ISO/IEC 27001. Accreditation is granted scheme by scheme. Check that the body you are considering is accredited for information security management specifically, and verify it on the accreditation body’s own register rather than taking the claim from a sales page.

Accredited or non accredited: does it change what you get?

A non accredited ISO 27001 certificate is not automatically worthless. The audit may have been thorough and the findings genuine. What you lose is external supervision of the certification body itself, and with it the ability to prove to a sceptical customer that the certificate means what it claims.

Accredited certificateNon accredited certificate
Who supervises the certification bodyAn accreditation body such as JAS-ANZ, against ISO/IEC 17021-1Nobody outside the certification body
Verifiable on a public registerYes, through the accreditation bodyUsually only on the certifier’s own website
Accepted in enterprise procurementGenerally yesFrequently rejected or queried
Accepted in government tendersGenerally yesCommonly excluded by tender conditions
Recognised overseasYes, through international accreditation arrangementsNot reliably
Audit rigourGoverned by accreditation requirements on audit duration and auditor competenceSet by the certification body alone
The difference between an accredited and a non accredited certificate is who supervises the certifier.

The decision rule is simple. If you are pursuing ISO 27001 because a customer, a tender or an insurer asked for it, go accredited. If you would fail their check anyway, the cheaper certificate has cost you the entire project.

How do you compare quotes from ISO 27001 certification bodies?

Quotes from certification bodies are usually built from audit days, so the number of days quoted is the number to compare, not the headline figure. Accreditation requirements set expectations for how many audit days an organisation of your size and complexity should require, which is one reason an unusually low quote deserves a question rather than a signature.

Ask each certification body for the following in writing before you compare anything:

  • The number of audit days for stage 1, stage 2, each surveillance audit and recertification, quoted separately.
  • Whether travel time and expenses are included or billed on top, which matters if you are outside a capital city.
  • Whether the audit can be conducted remotely, in part or in full, and under what conditions.
  • The name and sector background of the proposed lead auditor.
  • Their current availability, since a body that cannot audit you for six months is not a real option if you have a customer deadline.
  • What happens if a major nonconformity is raised, including the cost of any follow up audit.

Auditor experience deserves more weight than most businesses give it. An auditor who understands SaaS will ask sharper questions about your cloud environment and waste less of your time on controls that do not apply. An auditor who has only ever audited manufacturers will take longer to reach the same place. You are allowed to ask who you will get, and to say no.

Is being ISO 27001 compliant the same as being certified?

No. Being ISO 27001 compliant means you believe your information security management system meets the requirements of the standard. Being ISO 27001 certified means an accredited certification body has audited it and issued a certificate saying so. Only the second one can be verified by a customer.

The distinction matters commercially. Claiming compliance is common in Australian SaaS marketing and it is not dishonest, provided the claim is accurate. It will not, however, satisfy a procurement team that asked for certification, and stating or implying certification you do not hold creates a real contractual risk.

If you are earlier in the journey, our guides to running an ISO 27001 gap analysis and working through the certification checklist cover the work that has to happen before a certification body is worth approaching.

When should you approach a certification body?

Approach certification bodies once your ISMS is built and has been operating long enough to produce evidence, but before you are fully ready to be audited. Waiting until you are ready is a common and expensive mistake, because certification body availability is often the longest lead time in the whole project.

A sensible sequence is to complete a gap analysis, build and operate the ISMS, run an internal audit and a management review, and approach certification bodies for quotes while the ISMS is running rather than after. That way the booking is in place by the time your evidence has matured.

Bear in mind that a certification body will want to see evidence the ISMS has been operating, not just that the documents exist. Our guide to what to expect at stage 1 and stage 2 explains what the auditor will actually ask for, and our internal audit guide covers the step most businesses underestimate.

Common questions

Do I need ISO 27001 certification?

You need ISO 27001 certification when a customer, a tender or a contract requires it. It is not mandatory in Australia under any general law. Most Australian businesses pursue it because enterprise or government buyers ask for it during procurement, or because it replaces answering long security questionnaires for every prospect. If nobody has asked, certification may still be useful, but the case is weaker.

Who needs ISO 27001 certification?

Typically businesses that handle other organisations’ data and sell to buyers who check. That covers SaaS providers, managed service providers, data processors, and suppliers into government and financial services. Size is not the trigger, and small Australian businesses certify regularly. The trigger is whether your customers demand independent proof that you manage information security properly.

How long does ISO 27001 certification last?

An ISO 27001 certificate is valid for three years from issue. It is not a set and forget document. Your certification body conducts a surveillance audit in each of the two intervening years, and a full recertification audit before the three years expire. Failing to complete a surveillance audit can result in your certificate being suspended or withdrawn.

Is ISO 27001 certification mandatory in Australia?

No. There is no Australian law that requires ISO 27001 certification for businesses generally. Specific sectors face their own obligations, and individual contracts or tenders frequently make certification a condition of doing business, but that is a commercial requirement rather than a legal one. Treat it as a market access decision.

Can an individual be ISO 27001 certified?

No. ISO 27001 certifies an organisation’s information security management system, not a person. Individuals can hold ISO 27001 related qualifications such as lead auditor or lead implementer training, which are personal certifications issued by training providers. Those are useful credentials, but they are a different thing entirely from an organisation holding a certificate.

Can my consultant also certify us?

No, and you should be wary of anyone offering both. Independence requirements prevent a certification body from certifying a management system it helped design or implement. A consultant helps you build and prepare the ISMS. An accredited certification body audits it independently. Keeping those roles separate is what makes the certificate credible to your customers.


Get your ISMS ready before you pick a certifier

Siege Cyber helps Australian businesses build an information security management system that will hold up under an accredited audit. We do not certify, which is exactly why we can be straight with you about what your auditor will find. See our ISO 27001 services, or our cyber security advisory services if you need help working out whether certification is the right call at all.

Talk to us about where you actually stand.