There is no single price for ISO 27001 certification in Australia, because what people call “the cost” is actually four separate invoices from three different parties, plus your own team’s time. Pages that quote one number are averaging across businesses of wildly different sizes.
What follows is each component, what drives it up and down, our own fixed price for the part we provide, and the costs that most often get missed until they arrive.
| Component | Who you pay | How it is priced |
|---|---|---|
| Preparation | A consultancy, or nobody if you do it in-house | Fixed fee or hourly. This is usually the largest external cost and the only one you have real control over. |
| Certification audit | An accredited certification body | Auditor days. The number of days is set by the standard, not negotiated. The day rate varies by body. |
| Surveillance audits | The same certification body | Fewer auditor days, once a year, for the three years the certificate runs. |
| Your own time | Nobody, but it is real | The single most underestimated line. Someone internal has to own the ISMS, answer the auditor and keep it running. |
You have three options, and the right one depends far more on whether you have internal capacity than on the price.
| Approach | What it costs | When it makes sense |
|---|---|---|
| In-house, from scratch | No external fee, but realistically several months of one person’s time at something like half to two-thirds of their week. | You already employ someone who has implemented a management system before and you can spare them. |
| Template pack | A few hundred to a few thousand dollars. | You have the expertise to adapt generic documents to how your business actually operates. Auditors can tell when this has not been done. |
| Consultancy, fixed price | Our CERTIFY package is $3,750 per month on a 12-month subscription, excluding GST, for organisations up to 50 employees. That is $45,000 for the year, currently reduced to $2,750 per month, or $33,000, on contracts signed by 31 December 2026. | You want a date you can give the customer who asked for the certificate, and you would rather not learn a management system standard in order to pass an audit. |
| Consultancy, hourly | Open-ended by construction. | Rarely. Nobody knows at the start how much evidence is missing, so the hours always grow. If you go this way, insist on a capped scope. |
A fixed-price package should state what is included. Ours covers the gap analysis, the ISMS scope and risk assessment, the Statement of Applicability, the policies and procedures written against how you actually work, implementation support for the Annex A controls, the internal audit, the management review, and attendance through both stages of the certification audit. The certification body’s own fee is not included, because we are not the certification body.
This is the part people are surprised by, and it is worth understanding the mechanism rather than hunting for a number.
Accredited certification bodies do not set audit duration freely. ISO/IEC 27006, the standard that governs bodies certifying information security management systems, sets out how much audit time is required based on the effective number of people in scope, adjusted for the complexity of what you do. A body that undercuts that by cutting days risks its own accreditation. So the number of days is broadly fixed for your size, and what varies between bodies is the day rate.
Initial certification is done in two visits:
| Stage | What happens | Outcome |
|---|---|---|
| Stage 1 | A readiness review. The auditor checks that the ISMS exists, that the scope and Statement of Applicability make sense, and that the internal audit and management review have been done. | A list of findings to clear before Stage 2. Failing here is a delay, not a disaster. |
| Stage 2 | The full audit. The auditor tests whether the controls you say you have are actually operating, by sampling evidence and interviewing people. | Certification, or non-conformities to close out first. |
| Surveillance, years 1 and 2 | A shorter audit each year confirming the ISMS is still running. | The certificate stays valid. |
| Recertification, year 3 | A full audit again. | A new three-year certificate. |
Two practical consequences. First, the total cost of ownership is a three-year number, not a one-off, so compare bodies on the full cycle rather than the initial audit alone. Second, because the day count scales with headcount, the same certificate costs a 15-person company materially less than a 150-person one, which is why a single published figure is meaningless.
We obtain comparable quotes from several accredited bodies as part of the engagement, so you are choosing on scope and industry experience rather than on whichever one you found first.
| Driver | Effect |
|---|---|
| Headcount in scope | The main driver of audit days. Scoping honestly but tightly is the single biggest lever on cost. |
| Number of physical sites | Multiple sites can add sampling requirements and travel. |
| Scope breadth | Certifying one product line is cheaper than certifying the whole company. Certify what the customer actually asked about. |
| Starting maturity | If you already run access reviews, patching, logging and backups with evidence, most of the work is documenting what exists. If none of that is in place, it has to be built first. |
| Regulated industry | Health, finance and critical infrastructure attract complexity adjustments and sometimes a more specialised auditor. |
| Deadline pressure | A tender deadline removes your ability to schedule the audit when it is convenient, and sometimes your ability to shop between bodies. |
If both are on the horizon, doing them together is considerably cheaper than doing them in sequence, because they rest on the same underlying controls. You build one management system and have it assessed twice, rather than running two projects. Our CERTIFY package covers ISO 27001, SOC 2 and ISO 42001 at the same monthly fee, so the preparation cost does not double. The two assessment fees remain separate, because they come from two different independent parties: an accredited certification body for ISO 27001, and a CPA firm for SOC 2.
What we charge
CERTIFY, covering ISO 27001, SOC 2 or ISO 42001: standard $3,750 per month, reduced to $2,750 per month on contracts signed by 31 December 2026. MAINTAIN, for ongoing ISMS maintenance after certification: $2,450 per month. All prices are 12-month subscriptions, exclude GST, and are for organisations up to 50 employees. Certification body audit fees are quoted separately by the body, and we obtain those quotes for you.
It is four costs, not one: preparation, the initial certification audit, annual surveillance audits for three years, and your own team’s time. For a business under 50 people, preparation is normally the largest external line, and ours is fixed at $3,750 per month on a 12-month subscription, currently $2,750 per month on contracts signed by 31 December 2026. The certification body’s audit fee is separate and is priced on auditor days, which scale with your headcount and scope.
Because the audit duration is set by ISO/IEC 27006 based on the effective number of people in scope and the complexity of what you do. The same certificate genuinely costs a 15-person company much less than a 150-person one, so any single published figure is an average across businesses that have nothing in common.
It should not be, and if a consultancy includes it you should ask how. A certification body has to be independent of the organisations it certifies under ISO/IEC 17021-1, so the two fees come from two separate parties. A good consultancy will obtain the audit quotes for you without marking them up.
The certificate runs on a three-year cycle, with a surveillance audit in each of years one and two and a full recertification audit in year three, all paid to the certification body. Separately, someone has to keep the management system running, including risk reviews, internal audits and management reviews. We cover that under MAINTAIN at $2,450 per month, and plenty of organisations do it internally instead.
Yes, and some organisations should. If you employ someone who has implemented a management system before and you can give them the time, the external cost drops to the audit fees alone. What you are buying from a consultancy is speed and a much lower chance of a delayed or failed audit.
The standard does not name a penetration test as a mandatory control, but Annex A expects technical vulnerability management, and in practice most auditors want to see evidence of technical testing appropriate to your risk. Budget for it rather than being surprised by it during Stage 2.
Considerably, yes, because both rest on the same underlying controls. You build one management system and have it assessed twice. The preparation cost does not double, although the two assessment fees remain separate because they come from two different independent parties.