ISO 27001 Certification Consultants

Implementation & Ongoing Compliance Management

Get in Touch Our Services
Services

Thinking about ISO 27001?

We help Australian businesses implement and maintain ISO 27001 certification.

 

Implement new ISO 27001 systems, support ongoing ISMS maintenance, or step in for once-off projects

Businesses who handle confidential data such as IT services, professional services, healthcare, financial services, and government contractors

We build your ISMS around your governance, processes, and risk profile. We partner with your IT team on the technical controls

We publish indicative cost ranges below as a guide, and on request can provide a no-obligation quotation scoped to your needs

Who we are

The Australian Productivity Council dates back to the
1960s and has been working
with Australian businesses on management systems for decades.

Our practitioners have implemented and maintained ISO systems across most industries you can think of. We work with all businesses great and small, from owner-operated SMEs to multi-site operators with complex compliance obligations.

Productivity is in our blood so ISO systems that we build or maintain are focused on streamlining your business, not adding extra work.

More About us

Our Commitment
to our Clients

We pride ourselves on integrity, usefullness, expertise and value. We are proud that many of our clients have trusted us onging for decades.

Service

What we do

 

We build your ISO 27001 Information Security Management System from the ground up and get you certified. That means scoping your ISMS, risk assessment, writing the documentation, developing your Statement of Applicability, training your team, conducting your internal audit, and supporting you through the external certification audit.

Keeping your certification alive requires ongoing work: internal audits, management reviews, risk register updates, and maintaining your system as your business and threat environment evolve. We handle all of this through regular engagement, as often as you need us. We’ll also attend your external surveillance and recertification audits.

Need someone to run an internal audit while your usual person is unavailable? Want expert eyes on your system before a certification audit? Need your ISMS updated following a significant change to your technology or operations? We can step in for whatever you need, whenever you need it. No ongoing commitment required.

What does your business look like?

Either way, we’ve done it before. Tell us what your situation looks like and we’ll tell you honestly how we can help.

No Internal ISO 27001 Expertise

If you need it, we can step in and manage your ISMS implementation or maintenance for you. We handle the governance, risk assessment, documentation, and audit preparation. Your IT team handles the technical controls, or we can help you find someone who does. Either way, you get a certified, working system without needing to hire a dedicated CISO first.

In-house Information Security or Compliance Staff

We can work alongside your team where extra capacity or outside expertise is useful. That might mean running your internal audit as an independent party, updating your ISMS after a significant system or operational change, or helping you get an additional certification across the line without pulling your team off their day jobs.

View more

Industries we work with

We work across a wide range of industries. Some of the industries we see most often include:

If your industry isn’t listed, get in touch. If your business handles sensitive information, whether that’s client data, financial records, personal information, or commercially sensitive intellectual property, then ISO 27001 is worth a conversation.

What is
ISO 27001?

ISO 27001 is the international standard for Information Security Management Systems. It is a framework that helps your business identify the information assets that need protecting, assess the risks to those assets, implement appropriate controls, and demonstrate to the outside world, and to yourself, that you take information security seriously.

The three objectives at the heart of the standard are confidentiality (keeping information private), integrity (keeping it accurate and uncorrupted), and availability (making sure the right people can access it when they need to). An ISMS is the systematic approach to managing all three, across your people, your processes, and your technology.

It doesn’t prescribe exactly which technical controls you need to implement. It requires you to systematically identify your risks and make considered, documented decisions about how to treat them. The output is an ISMS that is tailored to your organisation, your risk profile, and your environment.

For a long time, ISO 27001 was largely the domain of specialist IT firms and organisations handling classified government data. That’s no longer the case. Almost every business today stores sensitive information digitally: client records, financial data, employee details, commercially sensitive work product. The frameworks that used to be reserved for the IT sector are now relevant and increasingly expected across professional services, healthcare, finance, and most industries that deal with enterprise or government clients.

The current version of the standard is ISO 27001:2022. If your business holds an older certification (ISO 27001:2013), transition to the 2022 version was required by October 2025. We can help with that too.

Benefits of ISO 27001

What does ISO 27001 actually do for your business?

ISO 27001 and the Australian regulatory landscape

ISO 27001 doesn’t exist in isolation. Australian businesses operate in a regulatory environment that is increasingly focused on information security and data protection, and the standard connects directly to several of the frameworks and obligations your business may already be navigating.

The Privacy Act and Notifiable Data Breaches

If your business handles personal information, and almost every business does, you have obligations under the Privacy Act. The Notifiable Data Breaches scheme requires you to notify individuals and the OAIC when a data breach is likely to cause serious harm. ISO 27001 provides the systematic controls and documentation that demonstrate you are taking those obligations seriously, and that give you a defensible position if something goes wrong.

Government contracting and the Essential Eight

Businesses supplying services to Australian Government agencies will increasingly encounter the Essential Eight, the ASD’s set of prioritised cybersecurity controls that are mandatory for Commonwealth entities and increasingly expected of their suppliers. ISO 27001 and the Essential Eight address overlapping ground: both require you to identify risks and implement appropriate controls. Holding ISO 27001 certification signals to government buyers that your security posture is systematic and audited. Your IT team handles the technical implementation of the controls; our role is to make sure the governance framework around them is solid.

IRAP and defence supply chain

Businesses that handle sensitive government or defence information may need to consider IRAP, the Information Security Registered Assessors Program. IRAP is a separate certification process, conducted by endorsed assessors against the Australian Government ISM. ISO 27001 provides a strong foundation for IRAP-bound businesses: the two frameworks share significant common ground, and the governance disciplines developed during ISO 27001 implementation directly support IRAP readiness.

View more

Be Tender Ready this Year

For a growing number of Australian businesses, ISO 27001 is no longer optional. Government agencies, large corporates, and enterprise buyers increasingly require it as a condition of engagement. Not a differentiator, a baseline. No certification, no contract.

The reason is straightforward. A procurement manager awarding work to a supplier who will handle sensitive data needs to be able to defend that decision. Pointing to an independently audited, internationally recognised information security certification is a defensible position. Pointing to nothing is not.

For businesses in IT services, professional services, healthcare, and finance, this pressure from enterprise clients and government buyers is the most common reason we see ISO 27001 enquiries. If you’ve been told certification is a requirement for an upcoming contract or tender, or if you’re seeing it come up repeatedly in enterprise sales conversations, we can move quickly. Tell us your deadline and we’ll tell you honestly what’s achievable.

Learn more about getting ISO to qualify for tenders

Integrated Management Systems

We can help you incorporate ISO 27001 as part of an Integrated Management System (IMS), bringing it together with standards like ISO 9001 (Quality) and ISO 45001 (Health & Safety) under one framework. 

For businesses that also hold or are pursuing ISO 9001, in particular, the overlap in management system structure (leadership commitment, internal audit, management review, continual improvement) is significant. Running them together reduces duplication and simplifies ongoing maintenance. If you’re considering more than one standard, that conversation is worth having early.

View more

What most business owners
get wrong about ISO 27001

“It’s only for tech companies.”

It’s not. ISO 27001 is relevant to any business that handles information other people have entrusted to it: personal data, financial records, health information, commercially sensitive client work. That covers most businesses in professional services, healthcare, finance, and government contracting. The standard adapts to the nature and scale of your information risks, not your industry label.

“Our IT team can handle this.”

They might be able to handle the technical controls, and that’s their domain, not ours. But ISO 27001 is a management system, not an IT project. It requires leadership commitment, documented risk decisions, governance processes, and audit-ready evidence. That’s governance work, not infrastructure work. The two need to work together.

“We’ll have to document everything from scratch.”

Probably not. Most businesses already have security practices. They’re just not documented or systematically applied. A gap analysis usually reveals more is in place than people expect. That said, the documentation ISO 27001 requires is genuinely substantive, especially the risk register and Statement of Applicability. The work is mostly formalising and connecting what already exists, but it’s real work.

“It’ll cost a fortune.”

It costs more than a lot of people expect going in. ISO 27001 is more complex than most other ISO standards. What we can tell you is that the cost is predictable once we understand your business, and we’ll give you a clear picture before you commit to anything. We can also tell you with confidence that the cost of a significant data breach is considerably higher.

“We’re too small for this.”

The standard scales. A small professional services firm with 15 staff has different risks and a very different ISMS scope than a 200-person IT services company. We build the system to fit the business, not the other way around.

 

Services

Why are you here?

Most businesses arrive at ISO 27001 from one of two directions. Some get here because a client, a contract, or a procurement panel has told them certification is required. Others get here because something (a near-miss, a client data incident, a board conversation about cyber risk) has made it clear that the current approach isn’t good enough. Both are valid. The process is the same either way.

This is the most common reason. Enterprise buyers, government agencies, and increasingly mid-market clients are requiring ISO 27001 as a condition of engagement. ISO 27001 is a substantive undertaking. The risk assessment alone requires real analytical work, and the standard touches people, processes, and technology across your whole organisation, not just your IT team. Our job is to manage that complexity for you, keep the process moving, and build a system that holds up, not just one that gets you over the line.

Also a good reason, and often the most valuable starting point. Maybe a near-miss made the risk feel real. Maybe your board has asked for greater confidence around information security. Maybe you’re growing and the informal approaches that worked at ten people won’t hold at fifty. ISO 27001 gives that genuine commitment a structured framework and independent verification. It’s a meaningful project. Done properly, it’s worth it.

Is ISO 27001 right for your business?

If you handle personal information, health records, financial data, or sensitive client information at any meaningful scale, or if your clients are enterprise buyers or government agencies, then ISO 27001 is almost certainly worth it. The certification addresses real risks and opens real doors.

If you’re a small business with minimal data holdings, no enterprise clients, and no regulatory pressure to demonstrate security credentials, the business case is weaker. The framework is scalable, but there’s a floor below which the overhead isn’t justified.

If you’re not sure which category you’re in, that’s exactly what our free discovery call is for. We’ll tell you honestly.

View more

Where we work

We work with businesses across Australia including Sydney, Melbourne, Brisbane, Perth, Adelaide, Canberra, Newcastle, Wollongong, Gold Coast, and Geelong, as well as other major regional centres. If you're outside these areas get in touch as we can work out on-site or remote solutions for regional clients.

Learn more about the areas we service

Frequently Asked Questions

Answers to some of the common questions people have regarding ISO 27001 support services.

How long does ISO 27001 certification take?

For most small and medium businesses, implementation runs between four and nine months from engagement to certification audit, and the range is genuinely that wide. ISO 27001 takes longer than most other ISO standards because the risk assessment methodology, the Statement of Applicability, and the Annex A control framework require more analytical work, and businesses vary considerably in how mature their existing security practices are. A business with disciplined IT governance and existing policies starts considerably further ahead than one starting from scratch. If you’re working to a tender deadline and need to move faster, get in touch and we’ll tell you honestly what’s achievable given your situation.

We’ve covered the detail in the What does it cost? section above. In short: $12,000 to $20,000 for most small businesses, $20,000 to $35,000 for most medium businesses, with a handful of variables that move the number. For once-off assistance or ongoing maintenance support, we need to talk to you to give a quote, but we generally find people are pleasantly surprised at how reasonable our rates are.

We’re consultants, not the certifying body. The actual certification is issued by an independent certification body accredited by JAS-ANZ, the Joint Accreditation System of Australia and New Zealand. JAS-ANZ accreditation is the mark of a legitimate certification body in this country, and any ISO 27001 certificate you hold should be from a JAS-ANZ accredited certifier. We work with several and will guide you through the choice without any referral fees or kickbacks influencing our recommendation.

The Statement of Applicability, usually called the SoA, is one of the defining documents of an ISO 27001 ISMS. It records all 93 controls in Annex A of the standard, states which apply to your organisation, which you have implemented, and why you’ve included or excluded each one. It’s essentially the documented reasoning behind your control decisions, and it’s one of the first things an auditor will want to see. Getting it right matters. A superficial SoA that ticks boxes without genuine analysis is a common audit vulnerability.

ISO 27001 certification runs on a three-year cycle. Within that cycle you’ll have annual surveillance audits, which are lighter-touch reviews to confirm your ISMS is still operating as it should. At the end of three years you go through a full recertification audit. We can support clients through all of it.

If the auditor identifies issues, they’ll issue either a minor or major nonconformance. Minor nonconformances are generally manageable and resolved in the normal course. Major nonconformances are more serious, so you’ll need to submit a corrective action plan and provide evidence that the issue has been fixed. Certification may be suspended in the meantime. A well-prepared business rarely encounters major nonconformances. Our job is to make sure you’re not walking into that audit with surprises. Where useful, we run an internal audit ahead of the certification audit as an independent assessment, so anything that needs fixing gets fixed before it counts.

Yes. The 2022 version of the standard introduced structural changes and 11 new controls. Transition to ISO 27001:2022 was required by October 2025. If your certificate still references the 2013 version, you need to act. We can scope the transition work for you. It’s not a full reimplementation, but it’s not trivial either, and it’s better managed deliberately than left until your next audit.

Yes, and for some businesses it makes sense to do so. Implementing ISO 27001 alongside ISO 9001 allows us to build them together as an Integrated Management System, sharing common processes like internal audit, management review, document control, and corrective action. If you’re considering more than one standard, it’s worth having that conversation early.

No. We work with businesses of all sizes. What matters is that ISO 27001 is the right fit for your situation, which is exactly what our free discovery call is designed to work out.

Contact Us

Got any Questions

If you have any questions about the ISO 27001 standard or what it requires,
our team will do our bes tot clear things up for you.

 

Get in Touch

Resources

A selection of news and articles about the fascinating world of compliance and ISO Management Systems

The Concept of ISO Certification Clearly Explained

The ISO 9000 quality management system had its origins in the American, British and NATO military procurement standards that were designed to manage contract performance.

Read more
Quality Speaks for Itself: Marketing Strategies

This article explains the benefits of getting an ISO 14001 Environmental Management System, and why it is a great idea to put this on your agenda for 2023.

Read more
Reasons to get an Environmental Management System in 2025

This article explains the benefits of getting an ISO 14001 Environmental Management System, and why it is a great idea to put this on your agenda for 2023.

Read more
Quality Assurance, Customer Satisfaction and ISO 9001

An anecdote from our Director's experience at a 1990s Design Award panel assessing a Ford vehicle, highlights how firms need to go beyond surveying customer satisfaction in setting goals for their Quality Management System.

Read more
What is Quality Assurance

This article explains the concept of Quality Assurance, why it is important to almost every organisation on earth, and distinguishes it from the narrower concept of 'Quality Control'. It also looks at the relationship of Quality [...]

Read more
ISO 9001 Certification

ISO 9001 is the best known global quality management system standard. This article explains the benefits of certification, how to get ready for audit, and gives a summary of the ISO 9001 Standard.

Read more
The Introduction of the ISO 9001 Global Quality Standard

The ISO 9001 quality management system had its origins in the American, British and NATO military procurement standards but has grown to be the worldwide standard for quality management systems.

Read more