What is not included: the certification body's audit fee. You engage and pay them directly, which is how it has to work, because the firm that prepares you cannot also audit you. Australian certification bodies typically charge between $5,000 and $35,000 for the certification audit. That is a wide range because the fee tracks audit days, which track the size of your scope, the number of sites and the complexity of your environment. A single-site business with a tight ISMS scope sits at the lower end. We will give you a specific figure on the first call once we know your scope, and we will tell you before you commit rather than after.
| Month | What Siege Cyber does | What you end the month with |
|---|---|---|
| 1 | Kickoff, scope the ISMS, gap analysis against Annex A, agree the risk methodology | A scope statement, a gap report and a plan with named owners |
| 2 | Write the policy suite, build the risk register, run the risk assessment and treatment plan | A complete, customised ISMS on paper, signed off by management |
| 3 | Implement controls, collect the first evidence, employee ISMS training, external penetration test, internal audit and management review | Controls operating, a test report for Annex A 8.8, and the two records Stage 2 will ask for |
| 4 | Book the certification body, prepare the Statement of Applicability, walk the team through what Stage 1 asks | Stage 1 audit passed, with any findings written up |
| 5 | Close Stage 1 findings, assemble the evidence pack, brief the team for Stage 2 sampling | Stage 2 audit passed, certificate issued |
| 6 to 12 | Operate the ISMS, quarterly evidence reviews, corrective actions, prepare for surveillance | A live ISMS and no surprise at the first surveillance audit |
Why month 3 carries the weight. ISO 27001 sets no minimum operating period, but Stage 2 samples what your ISMS actually did, and an ISMS with a fortnight of history has nothing to sample. Pulling the internal audit and management review forward to month 3 gives the auditor two months of operating evidence by the time Stage 2 runs, and it means Stage 1 finds gaps while there is still time to close them.
What the five months depends on. Two things, and we will be straight about both. The first is that we book your certification body in month 1, not month 4, because auditors fill up months ahead. The second is that the decisions only you can make, principally signing off the risk treatment plan in month 2, happen in days rather than weeks. Get those two right and five months holds. We will tell you on the first call if anything in your situation makes it unlikely, rather than agreeing to it and explaining later.
The objection we hear most is that you do not have anyone to run this. Here is the real commitment.
| Month | Your time | What only you can do |
|---|---|---|
| 1 | Half a day a week | Name an internal owner, confirm scope, give access to systems and documents |
| 2 | Half a day a week | Approve the risk treatment plan and the policy suite. This is the decision that sets the whole schedule |
| 3 | One day a week | Implement technical controls in your own systems, attend the management review, staff complete training |
| 4 | Two days in the audit week | Be available for the auditor's interviews |
| 5 onward | Two hours a month | Approve access reviews, keep evidence flowing, attend the quarterly review |
Roughly one day a week for four months, then two hours a month. That is the honest total.
What we do not do: implement controls inside your systems, and act as your auditor. The first is a scoping point. The second is a rule, and a buyer who knows the standard will check.
A managed IT services provider, 125 staff. A government tender made ISO 27001 certification mandatory. We completed the gap analysis and ISMS build in 14 weeks. They certified first time, with two minor nonconformities, both closed before the certificate was issued.
A SaaS business, 15 staff, Sydney. They came to us after losing an enterprise deal over the lack of a security certification. We built their ISMS from scratch through CERTIFY in 10 weeks. They passed Stage 1 and Stage 2 with zero major nonconformities, and reopened the stalled deal within a fortnight.
On those timeframes. The figures above are the ISMS build, not the full engagement. Both clients moved quickly on the decisions only they could make, which is the single biggest reason they landed where they did. Five months to certificate is what we commit to.
Four things move these dates, and none of them is the consultant working slower.
These four are exactly what a fixed monthly fee protects you from paying for. That is the argument for CERTIFY over hourly consulting, and it is a stronger one than any list of deliverables, because it is about who carries the risk.
Five months through CERTIFY. Stage 1 lands at month 4 and Stage 2 at month 5. The two things that can move it are certification body availability, which is why we book provisionally in month 1, and how quickly your business signs off the risk treatment plan in month 2.
CERTIFY is $3,750 a month on a 12 month subscription, which is $45,000 for the year and includes an external penetration test. The certification body's audit fee is separate and paid by you directly, typically $5,000 to $35,000 depending on the size of your scope and the number of sites.
Not formally. The standard does not mandate it. But auditors increasingly expect evidence that your controls work in practice, and Annex A 8.8 covers technical vulnerability management. A penetration test is the clearest evidence available, which is why we include one rather than sell it separately.
No, and neither can anyone else who prepared you. The firm doing the preparation cannot independently certify the result. We work alongside certification bodies but you engage them directly.
No. We are Brisbane based and work with clients across Australia. Most of the work is done remotely, with on-site attendance where it genuinely helps.
Surveillance audits, annually. CERTIFY covers you through the first twelve months. After that most clients move to MAINTAIN at $2,450 a month, which keeps the ISMS operating and the evidence flowing so the surveillance audit is uneventful.
These are about our penetration testing work rather than about compliance programmes. We have included them here because the external penetration test is part of CERTIFY, and because they are real, named and checkable. When we have compliance clients willing to be quoted, we will add those too.
Overall our experience with Peter and the Siege Cyber team was excellent. He was very professional in understanding our needs and delivered a thorough and comprehensive security report. We wouldn’t hesitate in recommending Siege Cyber to our customers.
Stefan Alpert, General Manager, FriendlyWare Partners, NSW
We have partnered with Peter and the team at Siege Cyber as a trusted advisor to perform penetration testing and vulnerability assessments to deliver our clients visibility and a clear understanding of their security footprint. Leveraging the results Siege Cyber provide has enabled our SME and enterprise clients to have peace of mind that security baselines, actionable security plans and roadmaps are in place and helping to protect their ICT systems and data.
Sam Gilchrist, GM Sales, eNerds, NSW
Siege Cyber are thorough and professional in their approach to penetration testing and the outcome report is well structured and delivered. Peter and the team are very knowledgeable and are a pleasure to work with, I’d recommend them to anyone.
Sasha Hajenko, Director, Blue Phoenix Systems, ACT
We engaged Peter of Siege Cyber to perform a penetration test on one of our largest clients that has critical logistics systems running 24/7. Peter was the utmost professional and worked directly with Intellica and the client’s senior leadership team throughout the process to ensure confidentiality of information and avoidance of impact on operational activities. I highly recommend Peter and Siege Cyber and look forward to utilising them for future engagements.
Oliver Caldwell, Managing Director, Intellica, QLD