There is no single price for ISO 27001 certification in Australia, because what people call “the cost” is actually four separate invoices from three different parties, plus your own team’s time. Pages that quote one number are averaging across businesses of wildly different sizes.

What follows is each component, what drives it up and down, our own fixed price for the part we provide, and the costs that most often get missed until they arrive.

The four components

Component Who you pay How it is priced
Preparation A consultancy, or nobody if you do it in-house Fixed fee or hourly. This is usually the largest external cost and the only one you have real control over.
Certification audit An accredited certification body Auditor days. The number of days is set by the standard, not negotiated. The day rate varies by body.
Surveillance audits The same certification body Fewer auditor days, once a year, for the three years the certificate runs.
Your own time Nobody, but it is real The single most underestimated line. Someone internal has to own the ISMS, answer the auditor and keep it running.

1. Preparation: the part you control

You have three options, and the right one depends far more on whether you have internal capacity than on the price.

Approach What it costs When it makes sense
In-house, from scratch No external fee, but realistically several months of one person’s time at something like half to two-thirds of their week. You already employ someone who has implemented a management system before and you can spare them.
Template pack A few hundred to a few thousand dollars. You have the expertise to adapt generic documents to how your business actually operates. Auditors can tell when this has not been done.
Consultancy, fixed price Our CERTIFY package is $3,750 per month on a 12-month subscription, excluding GST, for organisations up to 50 employees. That is $45,000 for the year, currently reduced to $2,750 per month, or $33,000, on contracts signed by 31 December 2026. You want a date you can give the customer who asked for the certificate, and you would rather not learn a management system standard in order to pass an audit.
Consultancy, hourly Open-ended by construction. Rarely. Nobody knows at the start how much evidence is missing, so the hours always grow. If you go this way, insist on a capped scope.

A fixed-price package should state what is included. Ours covers the gap analysis, the ISMS scope and risk assessment, the Statement of Applicability, the policies and procedures written against how you actually work, implementation support for the Annex A controls, the internal audit, the management review, and attendance through both stages of the certification audit. The certification body’s own fee is not included, because we are not the certification body.

2. The certification audit: priced in auditor days, not negotiated

This is the part people are surprised by, and it is worth understanding the mechanism rather than hunting for a number.

Accredited certification bodies do not set audit duration freely. ISO/IEC 27006, the standard that governs bodies certifying information security management systems, sets out how much audit time is required based on the effective number of people in scope, adjusted for the complexity of what you do. A body that undercuts that by cutting days risks its own accreditation. So the number of days is broadly fixed for your size, and what varies between bodies is the day rate.

Initial certification is done in two visits:

Stage What happens Outcome
Stage 1 A readiness review. The auditor checks that the ISMS exists, that the scope and Statement of Applicability make sense, and that the internal audit and management review have been done. A list of findings to clear before Stage 2. Failing here is a delay, not a disaster.
Stage 2 The full audit. The auditor tests whether the controls you say you have are actually operating, by sampling evidence and interviewing people. Certification, or non-conformities to close out first.
Surveillance, years 1 and 2 A shorter audit each year confirming the ISMS is still running. The certificate stays valid.
Recertification, year 3 A full audit again. A new three-year certificate.

Two practical consequences. First, the total cost of ownership is a three-year number, not a one-off, so compare bodies on the full cycle rather than the initial audit alone. Second, because the day count scales with headcount, the same certificate costs a 15-person company materially less than a 150-person one, which is why a single published figure is meaningless.

We obtain comparable quotes from several accredited bodies as part of the engagement, so you are choosing on scope and industry experience rather than on whichever one you found first.

3. What pushes the number up

Driver Effect
Headcount in scope The main driver of audit days. Scoping honestly but tightly is the single biggest lever on cost.
Number of physical sites Multiple sites can add sampling requirements and travel.
Scope breadth Certifying one product line is cheaper than certifying the whole company. Certify what the customer actually asked about.
Starting maturity If you already run access reviews, patching, logging and backups with evidence, most of the work is documenting what exists. If none of that is in place, it has to be built first.
Regulated industry Health, finance and critical infrastructure attract complexity adjustments and sometimes a more specialised auditor.
Deadline pressure A tender deadline removes your ability to schedule the audit when it is convenient, and sometimes your ability to shop between bodies.

4. The costs people forget

  • Penetration testing. Annex A expects technical vulnerability management and most auditors will want to see testing evidence. Budget for it as part of the project rather than discovering it during Stage 2.
  • Tooling. You may need logging, endpoint protection, a password manager or an asset register you do not currently pay for. Usually modest, occasionally not.
  • Remediation. The gap analysis sometimes finds something that costs real money to fix, such as replacing an unsupported system. This is the one genuinely unpredictable line, which is why the gap analysis comes first.
  • Staff time during the audit. The auditor will interview people. Those people stop doing their jobs for a few hours each.
  • Keeping it alive. An ISMS that nobody maintains fails its first surveillance audit, and a failed surveillance audit can suspend the certificate. Our MAINTAIN package covers this at $2,450 per month, and doing it internally is cheaper in cash and more expensive in attention.

Doing ISO 27001 and SOC 2 together

If both are on the horizon, doing them together is considerably cheaper than doing them in sequence, because they rest on the same underlying controls. You build one management system and have it assessed twice, rather than running two projects. Our CERTIFY package covers ISO 27001, SOC 2 and ISO 42001 at the same monthly fee, so the preparation cost does not double. The two assessment fees remain separate, because they come from two different independent parties: an accredited certification body for ISO 27001, and a CPA firm for SOC 2.

Five ways to spend less

  1. Scope tightly. Certify the part of the business the customer asked about. Scope creep is the most expensive mistake available, and it compounds every year for three years.
  2. Do the gap analysis before you commit to a date. Any timeline quoted before someone has looked at what you already have is a guess.
  3. Get more than one audit quote. Day counts are broadly set by the standard, day rates are not.
  4. Use a fixed price for preparation. It is the only component where the open-ended version has no ceiling.
  5. Combine frameworks if two are coming. See above.

What we charge

CERTIFY, covering ISO 27001, SOC 2 or ISO 42001: standard $3,750 per month, reduced to $2,750 per month on contracts signed by 31 December 2026. MAINTAIN, for ongoing ISMS maintenance after certification: $2,450 per month. All prices are 12-month subscriptions, exclude GST, and are for organisations up to 50 employees. Certification body audit fees are quoted separately by the body, and we obtain those quotes for you.

Frequently asked questions

How much does ISO 27001 certification cost in Australia?

It is four costs, not one: preparation, the initial certification audit, annual surveillance audits for three years, and your own team’s time. For a business under 50 people, preparation is normally the largest external line, and ours is fixed at $3,750 per month on a 12-month subscription, currently $2,750 per month on contracts signed by 31 December 2026. The certification body’s audit fee is separate and is priced on auditor days, which scale with your headcount and scope.

Why will nobody give me a single price?

Because the audit duration is set by ISO/IEC 27006 based on the effective number of people in scope and the complexity of what you do. The same certificate genuinely costs a 15-person company much less than a 150-person one, so any single published figure is an average across businesses that have nothing in common.

Is the certification body fee included in a consultancy’s price?

It should not be, and if a consultancy includes it you should ask how. A certification body has to be independent of the organisations it certifies under ISO/IEC 17021-1, so the two fees come from two separate parties. A good consultancy will obtain the audit quotes for you without marking them up.

What is the ongoing cost after we are certified?

The certificate runs on a three-year cycle, with a surveillance audit in each of years one and two and a full recertification audit in year three, all paid to the certification body. Separately, someone has to keep the management system running, including risk reviews, internal audits and management reviews. We cover that under MAINTAIN at $2,450 per month, and plenty of organisations do it internally instead.

Can we get certified without a consultancy?

Yes, and some organisations should. If you employ someone who has implemented a management system before and you can give them the time, the external cost drops to the audit fees alone. What you are buying from a consultancy is speed and a much lower chance of a delayed or failed audit.

Does ISO 27001 require a penetration test?

The standard does not name a penetration test as a mandatory control, but Annex A expects technical vulnerability management, and in practice most auditors want to see evidence of technical testing appropriate to your risk. Budget for it rather than being surprised by it during Stage 2.

Is it cheaper to do ISO 27001 and SOC 2 at the same time?

Considerably, yes, because both rest on the same underlying controls. You build one management system and have it assessed twice. The preparation cost does not double, although the two assessment fees remain separate because they come from two different independent parties.

Related reading