Search for an ISO 27001 certification company in Australia and you will get three completely different kinds of organisation in the same list of results. They do different jobs, they cannot legally do each other’s jobs, and picking the wrong one is the most common reason a certification project stalls.

This page sorts out which is which, explains how to check that a certification body is genuinely accredited, and sets out what to look for in a consultancy. We are a consultancy ourselves, so our own position is stated plainly at the end, including the cases where we are not the right fit.

The three things people mean by “ISO 27001 certification company”

Type What they actually do Can they issue your certificate?
Certification body Audits your information security management system against ISO/IEC 27001 and issues the certificate. Also called a registrar or a conformity assessment body. In Australia these are accredited by JAS-ANZ. Yes. This is the only type that can.
Consultancy Prepares you for that audit. Scopes the ISMS, runs the gap analysis, writes the policies and procedures, implements the Annex A controls, runs the internal audit and management review, and sits with you through the audit. No. Prohibited from doing so.
Certified company An ordinary business that holds an ISO 27001 certificate itself. Many Australian MSPs and SaaS companies advertise this. It says something about them as a supplier, not about their ability to certify you. No.

The part most comparison pages get wrong. A certification body cannot also be your consultant. ISO/IEC 17021-1, the standard that governs bodies issuing management system certificates, requires them to be impartial and bars them from providing management system consultancy to the organisations they certify. If a single firm offers to both implement your ISMS and issue your certificate, that is a red flag about the value of the certificate, not a convenience.

How to check an Australian certification body is real

An ISO 27001 certificate is only worth what the accreditation behind it is worth. A certificate issued by an unaccredited body will often be rejected by the enterprise customer or government buyer who asked you for it in the first place, which means paying twice.

In Australia, accreditation comes from JAS-ANZ, the Joint Accreditation System of Australia and New Zealand, which is the government-appointed accreditation body under a treaty between the two countries. JAS-ANZ publishes a public register of every body it accredits and the exact standards each one is accredited for.

Three checks, in order:

  1. Find the body on the JAS-ANZ register. Not a logo on their website, the register itself at jas-anz.org. Being on the register for one standard does not mean they are on it for ISO/IEC 27001, so check the standard specifically.
  2. Check the scope covers your industry. Accreditation is granted by technical scope. A body accredited for ISO 27001 in one sector is not automatically accredited for yours.
  3. Ask who the auditor is and what they have audited. You are buying audit days from a named person. Ask for their background before you sign, not after.

Accreditation from a recognised overseas body, such as UKAS in the United Kingdom or ANAB in the United States, is also generally accepted in Australia under the IAF multilateral recognition arrangement. What is not acceptable is a certificate from a body with no accreditation at all.

What to look for in an ISO 27001 consultancy

This is the decision that determines whether you get certified on time and whether the management system survives the first surveillance audit. Nine things worth asking about.

What to ask Why it matters A good answer sounds like
Is the price fixed? Hourly consulting on a certification project is open-ended by design. The scope always grows, because nobody knows at the start how much evidence is missing. A fixed monthly or project fee with the deliverables listed.
Who writes the documentation? Some consultancies sell you a template pack and leave you to fill it in. An auditor can tell the difference between a policy that describes your business and a template with your logo on it. They write it with you, based on how you actually operate.
Who runs the internal audit? ISO 27001 requires an internal audit and a management review before the certification audit. These are commonly left out and commonly cause a delay. Both are in scope and scheduled.
Is the work done in Australia? Your ISMS documentation contains your asset register, your risk register and your security gaps. Where that sits, and who sees it, is itself a security question. Named Australian team, no offshore subcontracting.
What happens after certification? The certificate runs on a three-year cycle with surveillance audits each year. An ISMS nobody maintains fails the first surveillance audit. A defined maintenance arrangement, priced separately and clearly.
Will they help choose the certification body? A consultancy that works with several bodies can match the body to your industry and get you comparable quotes. They obtain quotes for you and explain the differences.
Do they do penetration testing too? Annex A expects technical testing. Having it under one roof removes a handover, though it is not essential. Either an in-house capability or a named partner.
How many clients per consultant? Certification work is dense for a few months. A consultant carrying twenty projects cannot give yours the attention it needs in those months. A number they are willing to tell you.
Can you speak to a client they certified? Not a logo wall, a conversation with someone who went through the audit. Yes, and they arrange it.

Red flags

  • A guaranteed certificate. No consultancy can guarantee the outcome of an independent audit. Anyone who does either misunderstands the process or is describing an arrangement you do not want.
  • One firm offering to implement and certify. Covered above. It compromises the certificate.
  • A fixed number of weeks with no gap analysis first. Nobody can know the timeline before they have seen what is already in place.
  • Certification without an internal audit. It is a clause 9.2 requirement, not an optional extra.
  • Pricing that excludes the certification body. Not a red flag by itself, audit fees genuinely are separate, but it has to be said up front rather than discovered.

ISO 27001, SOC 2 or both

Most Australian companies that come to us asking about ISO 27001 have been asked for it by a customer. It is worth checking which one the customer actually wants before you start, because the two are different products.

ISO 27001 SOC 2
What you get A certificate, valid three years with annual surveillance audits. An audit report covering a period of time, reissued annually.
Who issues it A JAS-ANZ or equivalently accredited certification body. A CPA firm.
Who usually asks for it Australian enterprise, government and European customers. North American customers, especially SaaS buyers.
Underlying system An information security management system you have to keep running. Controls operating over the observation window.

The two overlap heavily in practice, so doing both is considerably cheaper than doing them one after the other. If both are on the horizon, build one management system and have it assessed twice.

Where Siege Cyber fits, and where we do not

We are a consultancy, not a certification body. We prepare Australian businesses for the ISO 27001 audit and we cannot issue the certificate, by design.

We suit you if you are an Australian business of roughly 2 to 200 people, you have been asked for ISO 27001 or SOC 2 by a customer or a tender, and you want a fixed price rather than an open-ended hourly engagement. Our CERTIFY package covers ISO 27001, SOC 2 and ISO 42001 on a fixed monthly fee, and includes the gap analysis, the ISMS build, the documentation, the internal audit, the management review and support through the certification audit itself. Work is done by our own team in Australia, with no offshore subcontracting.

We are not the right fit if you want a template pack to implement yourself, if you need the certificate issued rather than the preparation done, if you are a large enterprise with an existing internal GRC team that needs augmenting by the hour, or if you need IRAP assessment, which requires an ASD-endorsed IRAP assessor.

CERTIFY, fixed price

ISO 27001, SOC 2 or ISO 42001 on a 12-month subscription, excluding GST, for organisations up to 50 employees. Standard price $3,750 per month. Reduced to $2,750 per month on contracts signed by 31 December 2026. Ongoing maintenance after certification is $2,450 per month under MAINTAIN.

Frequently asked questions

Who can issue an ISO 27001 certificate in Australia?

Only an accredited certification body. In Australia accreditation comes from JAS-ANZ, and certificates from bodies accredited by recognised overseas equivalents such as UKAS or ANAB are generally accepted here as well. A consultancy cannot issue the certificate, because ISO/IEC 17021-1 requires certification bodies to be independent of the organisations they certify.

Can the same company help us implement ISO 27001 and certify us?

No. ISO/IEC 17021-1 bars a certification body from providing management system consultancy to an organisation it certifies. If one firm offers to do both, the certificate it issues is likely to be questioned by the customer who asked you for it.

How do I check whether a certification body is accredited?

Look them up on the JAS-ANZ public register at jas-anz.org rather than relying on a logo on their website, and check that the accreditation specifically covers ISO/IEC 27001 and your industry scope. Accreditation is granted scope by scope.

Do we need a consultancy at all?

No. Plenty of organisations certify without one, particularly if they already have someone experienced in management systems and the time to run the project. A consultancy buys speed and reduces the risk of a failed or delayed audit. It is a cost and time trade-off, not a requirement of the standard.

How long does ISO 27001 certification take in Australia?

For a small to mid-sized Australian business starting from very little, six to twelve months from gap analysis to certificate is a realistic range, with the ISMS implementation phase being the longest part. Organisations with mature security practices already in place move considerably faster.

Is an unaccredited ISO 27001 certificate worth anything?

Rarely. The reason you are being asked for the certificate is usually that a customer or a tender requires it, and those requirements almost always specify accredited certification. An unaccredited certificate often has to be redone, which means paying twice.

Related reading