Search for an ISO 27001 certification company in Australia and you will get three completely different kinds of organisation in the same list of results. They do different jobs, they cannot legally do each other’s jobs, and picking the wrong one is the most common reason a certification project stalls.
This page sorts out which is which, explains how to check that a certification body is genuinely accredited, and sets out what to look for in a consultancy. We are a consultancy ourselves, so our own position is stated plainly at the end, including the cases where we are not the right fit.
| Type | What they actually do | Can they issue your certificate? |
|---|---|---|
| Certification body | Audits your information security management system against ISO/IEC 27001 and issues the certificate. Also called a registrar or a conformity assessment body. In Australia these are accredited by JAS-ANZ. | Yes. This is the only type that can. |
| Consultancy | Prepares you for that audit. Scopes the ISMS, runs the gap analysis, writes the policies and procedures, implements the Annex A controls, runs the internal audit and management review, and sits with you through the audit. | No. Prohibited from doing so. |
| Certified company | An ordinary business that holds an ISO 27001 certificate itself. Many Australian MSPs and SaaS companies advertise this. It says something about them as a supplier, not about their ability to certify you. | No. |
The part most comparison pages get wrong. A certification body cannot also be your consultant. ISO/IEC 17021-1, the standard that governs bodies issuing management system certificates, requires them to be impartial and bars them from providing management system consultancy to the organisations they certify. If a single firm offers to both implement your ISMS and issue your certificate, that is a red flag about the value of the certificate, not a convenience.
An ISO 27001 certificate is only worth what the accreditation behind it is worth. A certificate issued by an unaccredited body will often be rejected by the enterprise customer or government buyer who asked you for it in the first place, which means paying twice.
In Australia, accreditation comes from JAS-ANZ, the Joint Accreditation System of Australia and New Zealand, which is the government-appointed accreditation body under a treaty between the two countries. JAS-ANZ publishes a public register of every body it accredits and the exact standards each one is accredited for.
Three checks, in order:
Accreditation from a recognised overseas body, such as UKAS in the United Kingdom or ANAB in the United States, is also generally accepted in Australia under the IAF multilateral recognition arrangement. What is not acceptable is a certificate from a body with no accreditation at all.
This is the decision that determines whether you get certified on time and whether the management system survives the first surveillance audit. Nine things worth asking about.
| What to ask | Why it matters | A good answer sounds like |
|---|---|---|
| Is the price fixed? | Hourly consulting on a certification project is open-ended by design. The scope always grows, because nobody knows at the start how much evidence is missing. | A fixed monthly or project fee with the deliverables listed. |
| Who writes the documentation? | Some consultancies sell you a template pack and leave you to fill it in. An auditor can tell the difference between a policy that describes your business and a template with your logo on it. | They write it with you, based on how you actually operate. |
| Who runs the internal audit? | ISO 27001 requires an internal audit and a management review before the certification audit. These are commonly left out and commonly cause a delay. | Both are in scope and scheduled. |
| Is the work done in Australia? | Your ISMS documentation contains your asset register, your risk register and your security gaps. Where that sits, and who sees it, is itself a security question. | Named Australian team, no offshore subcontracting. |
| What happens after certification? | The certificate runs on a three-year cycle with surveillance audits each year. An ISMS nobody maintains fails the first surveillance audit. | A defined maintenance arrangement, priced separately and clearly. |
| Will they help choose the certification body? | A consultancy that works with several bodies can match the body to your industry and get you comparable quotes. | They obtain quotes for you and explain the differences. |
| Do they do penetration testing too? | Annex A expects technical testing. Having it under one roof removes a handover, though it is not essential. | Either an in-house capability or a named partner. |
| How many clients per consultant? | Certification work is dense for a few months. A consultant carrying twenty projects cannot give yours the attention it needs in those months. | A number they are willing to tell you. |
| Can you speak to a client they certified? | Not a logo wall, a conversation with someone who went through the audit. | Yes, and they arrange it. |
Most Australian companies that come to us asking about ISO 27001 have been asked for it by a customer. It is worth checking which one the customer actually wants before you start, because the two are different products.
| ISO 27001 | SOC 2 | |
|---|---|---|
| What you get | A certificate, valid three years with annual surveillance audits. | An audit report covering a period of time, reissued annually. |
| Who issues it | A JAS-ANZ or equivalently accredited certification body. | A CPA firm. |
| Who usually asks for it | Australian enterprise, government and European customers. | North American customers, especially SaaS buyers. |
| Underlying system | An information security management system you have to keep running. | Controls operating over the observation window. |
The two overlap heavily in practice, so doing both is considerably cheaper than doing them one after the other. If both are on the horizon, build one management system and have it assessed twice.
We are a consultancy, not a certification body. We prepare Australian businesses for the ISO 27001 audit and we cannot issue the certificate, by design.
We suit you if you are an Australian business of roughly 2 to 200 people, you have been asked for ISO 27001 or SOC 2 by a customer or a tender, and you want a fixed price rather than an open-ended hourly engagement. Our CERTIFY package covers ISO 27001, SOC 2 and ISO 42001 on a fixed monthly fee, and includes the gap analysis, the ISMS build, the documentation, the internal audit, the management review and support through the certification audit itself. Work is done by our own team in Australia, with no offshore subcontracting.
We are not the right fit if you want a template pack to implement yourself, if you need the certificate issued rather than the preparation done, if you are a large enterprise with an existing internal GRC team that needs augmenting by the hour, or if you need IRAP assessment, which requires an ASD-endorsed IRAP assessor.
CERTIFY, fixed price
ISO 27001, SOC 2 or ISO 42001 on a 12-month subscription, excluding GST, for organisations up to 50 employees. Standard price $3,750 per month. Reduced to $2,750 per month on contracts signed by 31 December 2026. Ongoing maintenance after certification is $2,450 per month under MAINTAIN.
Only an accredited certification body. In Australia accreditation comes from JAS-ANZ, and certificates from bodies accredited by recognised overseas equivalents such as UKAS or ANAB are generally accepted here as well. A consultancy cannot issue the certificate, because ISO/IEC 17021-1 requires certification bodies to be independent of the organisations they certify.
No. ISO/IEC 17021-1 bars a certification body from providing management system consultancy to an organisation it certifies. If one firm offers to do both, the certificate it issues is likely to be questioned by the customer who asked you for it.
Look them up on the JAS-ANZ public register at jas-anz.org rather than relying on a logo on their website, and check that the accreditation specifically covers ISO/IEC 27001 and your industry scope. Accreditation is granted scope by scope.
No. Plenty of organisations certify without one, particularly if they already have someone experienced in management systems and the time to run the project. A consultancy buys speed and reduces the risk of a failed or delayed audit. It is a cost and time trade-off, not a requirement of the standard.
For a small to mid-sized Australian business starting from very little, six to twelve months from gap analysis to certificate is a realistic range, with the ISMS implementation phase being the longest part. Organisations with mature security practices already in place move considerably faster.
Rarely. The reason you are being asked for the certificate is usually that a customer or a tender requires it, and those requirements almost always specify accredited certification. An unaccredited certificate often has to be redone, which means paying twice.