ISO 27001 Certification in Australia, in Five Months

Most ISO 27001 projects run over because nobody agreed what "done" looked like at the start. CERTIFY fixes the price, fixes the scope and fixes the timeline: certified in five months for $3,750 a month, with an Australian team doing the work alongside you. The external penetration test your auditor will expect is included, not sold separately.

You Need ISO 27001, But You Don't Have Time to Become an Expert

Your biggest prospect has sent through a vendor security questionnaire and ISO 27001 is on it. Or a tender has made it mandatory. Either way there is a deal sitting still, and the clock is the problem, not the standard.

The usual answer is a consultant on day rates, a scope that grows, and a timeline nobody will commit to in writing. You end up paying for the uncertainty rather than the outcome.

CERTIFY is the opposite arrangement. One monthly fee, one agreed scope, and a certificate at month five. We carry the risk of the programme running long, because we are the ones who can actually control most of it.

What you get for $3,750 a month

  • A complete, customised ISMS, written for your business rather than pulled from a template library
  • An Australia-based compliance team, not an offshore document mill
  • An external penetration test, included. Not an add-on, not discounted, included. At our published rates that is $5,900 to $16,500 of testing inside the subscription
  • Risk assessment and risk treatment plan
  • Employee ISMS training
  • Internal audit and management review, run for you
  • Incident response, disaster recovery and business continuity planning
  • Tabletop exercise
  • A free compliance management platform, with no separate subscription
  • Ongoing support through to certification and beyond

What is not included: the certification body's audit fee. You engage and pay them directly, which is how it has to work, because the firm that prepares you cannot also audit you. Australian certification bodies typically charge between $5,000 and $35,000 for the certification audit. That is a wide range because the fee tracks audit days, which track the size of your scope, the number of sites and the complexity of your environment. A single-site business with a tight ISMS scope sits at the lower end. We will give you a specific figure on the first call once we know your scope, and we will tell you before you commit rather than after.

The timeline, month by month

Month What Siege Cyber does What you end the month with
1 Kickoff, scope the ISMS, gap analysis against Annex A, agree the risk methodology A scope statement, a gap report and a plan with named owners
2 Write the policy suite, build the risk register, run the risk assessment and treatment plan A complete, customised ISMS on paper, signed off by management
3 Implement controls, collect the first evidence, employee ISMS training, external penetration test, internal audit and management review Controls operating, a test report for Annex A 8.8, and the two records Stage 2 will ask for
4 Book the certification body, prepare the Statement of Applicability, walk the team through what Stage 1 asks Stage 1 audit passed, with any findings written up
5 Close Stage 1 findings, assemble the evidence pack, brief the team for Stage 2 sampling Stage 2 audit passed, certificate issued
6 to 12 Operate the ISMS, quarterly evidence reviews, corrective actions, prepare for surveillance A live ISMS and no surprise at the first surveillance audit

Why month 3 carries the weight. ISO 27001 sets no minimum operating period, but Stage 2 samples what your ISMS actually did, and an ISMS with a fortnight of history has nothing to sample. Pulling the internal audit and management review forward to month 3 gives the auditor two months of operating evidence by the time Stage 2 runs, and it means Stage 1 finds gaps while there is still time to close them.

What the five months depends on. Two things, and we will be straight about both. The first is that we book your certification body in month 1, not month 4, because auditors fill up months ahead. The second is that the decisions only you can make, principally signing off the risk treatment plan in month 2, happen in days rather than weeks. Get those two right and five months holds. We will tell you on the first call if anything in your situation makes it unlikely, rather than agreeing to it and explaining later.

What you actually have to do

The objection we hear most is that you do not have anyone to run this. Here is the real commitment.

Month Your time What only you can do
1 Half a day a week Name an internal owner, confirm scope, give access to systems and documents
2 Half a day a week Approve the risk treatment plan and the policy suite. This is the decision that sets the whole schedule
3 One day a week Implement technical controls in your own systems, attend the management review, staff complete training
4 Two days in the audit week Be available for the auditor's interviews
5 onward Two hours a month Approve access reviews, keep evidence flowing, attend the quarterly review

Roughly one day a week for four months, then two hours a month. That is the honest total.

What we do not do: implement controls inside your systems, and act as your auditor. The first is a scoping point. The second is a rule, and a buyer who knows the standard will check.

Work we have done

A managed IT services provider, 125 staff. A government tender made ISO 27001 certification mandatory. We completed the gap analysis and ISMS build in 14 weeks. They certified first time, with two minor nonconformities, both closed before the certificate was issued.

A SaaS business, 15 staff, Sydney. They came to us after losing an enterprise deal over the lack of a security certification. We built their ISMS from scratch through CERTIFY in 10 weeks. They passed Stage 1 and Stage 2 with zero major nonconformities, and reopened the stalled deal within a fortnight.

On those timeframes. The figures above are the ISMS build, not the full engagement. Both clients moved quickly on the decisions only they could make, which is the single biggest reason they landed where they did. Five months to certificate is what we commit to.

What actually causes a programme to slip

Four things move these dates, and none of them is the consultant working slower.

  1. The risk treatment plan stalls in month 2. Someone senior has to accept residual risk in writing. If that waits for a board meeting, everything waits with it. We book the approval slot during kickoff, before anyone needs it.
  2. The certification body has no availability. Auditors book out months ahead, especially over the Australian June to August period. We provisionally book Stage 1 in month 1, not month 4.
  3. Technical controls sit with a third party. MFA, logging, backups and access reviews often live with an MSP who was not in the kickoff. We name them in month 1.
  4. Staff turnover mid programme. Losing the internal owner costs roughly a month. Naming a deputy at kickoff is free, and it is the cheapest insurance in the engagement.

These four are exactly what a fixed monthly fee protects you from paying for. That is the argument for CERTIFY over hourly consulting, and it is a stronger one than any list of deliverables, because it is about who carries the risk.

Common questions

How long does ISO 27001 certification take?

Five months through CERTIFY. Stage 1 lands at month 4 and Stage 2 at month 5. The two things that can move it are certification body availability, which is why we book provisionally in month 1, and how quickly your business signs off the risk treatment plan in month 2.

How much does ISO 27001 certification cost in Australia?

CERTIFY is $3,750 a month on a 12 month subscription, which is $45,000 for the year and includes an external penetration test. The certification body's audit fee is separate and paid by you directly, typically $5,000 to $35,000 depending on the size of your scope and the number of sites.

Is a penetration test required for ISO 27001?

Not formally. The standard does not mandate it. But auditors increasingly expect evidence that your controls work in practice, and Annex A 8.8 covers technical vulnerability management. A penetration test is the clearest evidence available, which is why we include one rather than sell it separately.

Can you audit us as well as prepare us?

No, and neither can anyone else who prepared you. The firm doing the preparation cannot independently certify the result. We work alongside certification bodies but you engage them directly.

Do we need to be in Brisbane?

No. We are Brisbane based and work with clients across Australia. Most of the work is done remotely, with on-site attendance where it genuinely helps.

What happens after we are certified?

Surveillance audits, annually. CERTIFY covers you through the first twelve months. After that most clients move to MAINTAIN at $2,450 a month, which keeps the ISMS operating and the evidence flowing so the surveillance audit is uneventful.

What clients and partners say

These are about our penetration testing work rather than about compliance programmes. We have included them here because the external penetration test is part of CERTIFY, and because they are real, named and checkable. When we have compliance clients willing to be quoted, we will add those too.

Overall our experience with Peter and the Siege Cyber team was excellent. He was very professional in understanding our needs and delivered a thorough and comprehensive security report. We wouldn’t hesitate in recommending Siege Cyber to our customers.

Stefan Alpert, General Manager, FriendlyWare Partners, NSW

We have partnered with Peter and the team at Siege Cyber as a trusted advisor to perform penetration testing and vulnerability assessments to deliver our clients visibility and a clear understanding of their security footprint. Leveraging the results Siege Cyber provide has enabled our SME and enterprise clients to have peace of mind that security baselines, actionable security plans and roadmaps are in place and helping to protect their ICT systems and data.

Sam Gilchrist, GM Sales, eNerds, NSW

Siege Cyber are thorough and professional in their approach to penetration testing and the outcome report is well structured and delivered. Peter and the team are very knowledgeable and are a pleasure to work with, I’d recommend them to anyone.

Sasha Hajenko, Director, Blue Phoenix Systems, ACT

We engaged Peter of Siege Cyber to perform a penetration test on one of our largest clients that has critical logistics systems running 24/7. Peter was the utmost professional and worked directly with Intellica and the client’s senior leadership team throughout the process to ensure confidentiality of information and avoidance of impact on operational activities. I highly recommend Peter and Siege Cyber and look forward to utilising them for future engagements.

Oliver Caldwell, Managing Director, Intellica, QLD

Ensure your organisation's cybersecurity aligns with industry standards through Siege Cyber's ISO 27001 Framework Gap Analyses service. As a leading ISO 27001 certification company, our experts will identify gaps in your security posture and provide actionable recommendations to enhance your defences. For ISO 27001 certification in Australia and comprehensive insights on how our ISO 27001 compliance services can fortify your cybersecurity strategy, download our detailed datasheet today.

Not sure a packaged engagement is what you need yet? Our ISO 27001 certification consulting page covers the standard itself, what the certification audit involves and how an ISMS is scoped.