SecurSentry
← Essential Eight hub
Essential Eight

ISO 27001 in Australia: Certification, Cost and the Essential Eight

What ISO 27001 is, how you get certified in Australia, and where it fits alongside the Essential Eight and SMB1001 for a small business.

The short version

If you sell to larger companies, government or overseas clients, eventually someone hands you a security questionnaire asking whether you hold ISO 27001. In Australia that question sits in a slightly crowded field, next to the Essential Eight and the newer SMB1001 standard, and it is easy to feel unsure about which one you actually need. This guide walks through what ISO 27001 is in plain English, how certification works here in Australia, and how it fits alongside the other two so you can make a sensible call for your own business.

The short version: these standards are not competitors fighting for the same job. They answer different questions from different customers, and once you can see how they line up, the path forward gets a lot clearer.

What ISO 27001 actually is

ISO/IEC 27001 is the international standard for running an information security management system, which is a structured way of deciding what to protect and proving you actually do it.

The phrase “management system” is the part people trip over. ISO 27001 is not a checklist of firewall settings. It asks you to look at your business, work out what information matters and what could go wrong, and then put sensible controls in place to manage those risks. That process of assessing risk and choosing controls is the heart of the standard.

Two documents do most of the heavy lifting. The first is your risk assessment, where you identify the threats to your information and decide how to treat each one. The second is your Statement of Applicability, which lists which controls you have selected and, importantly, justifies any you have chosen to leave out. ISO 27001:2022 gives you a menu of 93 controls in Annex A, grouped into four themes: organisational, people, physical and technological. You do not have to apply all 93. You apply the ones your risk assessment says are relevant, and you explain the rest.

Why customers like it

ISO 27001 is recognised worldwide. When an enterprise or international buyer sees a valid certificate from an accredited body, they can trust it without auditing you themselves. That recognition is the whole point, and it is why the standard travels well across borders.

How certification works in Australia

In Australia, a credible ISO 27001 certificate comes from a certification body accredited by JAS-ANZ, following a two-stage audit and a three-year cycle.

Here is where the accreditation detail matters. JAS-ANZ, the Joint Accreditation System of Australia and New Zealand, is the government-backed body that accredits certification bodies in both countries. It is our equivalent of the UK’s UKAS. A certificate issued by a JAS-ANZ-accredited body is credible and is recognised internationally through mutual-recognition arrangements covering a large number of countries. A certificate from a body with no accreditation behind it may not carry the same weight when a customer checks, so it is worth confirming accreditation before you sign anything.

The audit itself runs in two stages. Stage 1 is a documentation review, where the auditor checks that your management system is designed correctly and that the required policies and records exist. Stage 2 is the implementation audit, where the auditor returns to see the system actually working, interviews staff and inspects evidence. Once certified, you are on a three-year cycle with annual surveillance audits in between and a full recertification in year three.

On cost, be wary of anyone quoting a single tidy figure. For a small Australian business, first-year outlay commonly lands somewhere in the range of roughly AUD $15,000 to $35,000 once you add together preparation, any consulting help and the certification body’s audit fees. The external audit portion is typically a smaller slice, often in the low thousands to several thousand dollars, with the larger cost being the time and work of getting ready. Surveillance audits in the following years are usually a few thousand dollars each. Treat these as ballpark ranges, not quotes, because size, scope and how much you do in-house all move the number.

ISO 27001 vs the Essential Eight

The Essential Eight and ISO 27001 do different jobs: one is a prescriptive technical baseline, the other is a risk-based management standard.

The Essential Eight is published by the Australian Signals Directorate through the Australian Cyber Security Centre. It is a set of eight specific technical mitigation strategies, things like patching applications, restricting administrative privileges and using multi-factor authentication. You measure your implementation against maturity levels running from ML0 up to ML3. Crucially, the Essential Eight is a baseline, not a certification. There is no certificate at the end of it, and no accreditation body sits behind it.

It is also mandatory in one specific place. Non-corporate Commonwealth entities, meaning federal government agencies, are required to implement the Essential Eight under the Protective Security Policy Framework. Private businesses are not legally bound by it, but it is widely expected in government and defence supply chains, so if you sell into that world you will very likely be asked about your maturity level.

ISO 27001, by contrast, does not tell you exactly which technical settings to use. It asks you to assess your risks and choose appropriate controls, then have an accredited body verify the whole system. One is prescriptive and technical; the other is a documented, audited way of managing security overall.

Different questions, different customers

Government and defence buyers tend to ask, "What is your Essential Eight maturity?" Enterprise and international buyers tend to ask, "Are you ISO 27001 certified?" Knowing which question your customers actually ask tells you where to start. If you want a fuller side-by-side of the technical strategies, our Essential Eight controls explained guide breaks them down one by one.

Where SMB1001 sits

SMB1001 is the Australian tiered cybersecurity certification built specifically for small and medium business, filling the gap between an internal baseline and full ISO 27001.

SMB1001, in its current 2026 edition, was designed to be accessible for smaller organisations that find ISO 27001 too heavy for where they are today. It has five tiers: Bronze, Silver, Gold, Platinum and Diamond. The lower three tiers (Bronze, Silver and Gold) are self-attested, meaning a company director signs off that the controls are in place. The top two tiers (Platinum and Diamond) require external verification by an independent organisation, which gives a customer a stronger level of assurance.

That tiered design is the appeal. A very small business can start at Bronze, demonstrate a credible baseline quickly, and step up the tiers as it grows or as customers ask for more. It gives you a certificate to show, without the full weight of an ISMS. If you are weighing SMB1001 against the government baseline, we compare them directly in Essential Eight vs SMB1001.

Which should an Australian small business do first

Start with whichever one your customers are actually asking about, and pick the lightest option that satisfies that demand today.

There is no universal right answer, only the right answer for your situation. A few honest rules of thumb help:

If your growth depends on government or defence contracts, the Essential Eight is where attention usually goes first, because that is the language those buyers use. If you are a small business that wants a recognised certificate quickly and without a large project, SMB1001 at Bronze or Silver is often the pragmatic starting point. If you are chasing enterprise deals or selling overseas, and a customer has specifically named ISO 27001 in a contract or questionnaire, then ISO 27001 is the target and it is worth the investment.

The mistake to avoid is doing the biggest, most expensive standard first out of a vague sense that more is better. Match the standard to the demand in front of you. You can always climb higher later, and the next section explains why climbing is easier than it looks.

A quick gut check

Ask your three most important prospects or customers what security certification or baseline they expect from suppliers. Their answers will tell you more about where to start than any general guide.

How the work carries across

Because all three standards protect the same information using overlapping controls, effort you put into one rarely goes to waste on the others.

Multi-factor authentication, patching, access controls, backups, staff awareness and a decent asset inventory show up everywhere. The Essential Eight strategies map neatly onto a good chunk of ISO 27001’s technical controls in Annex A. The evidence you gather for an SMB1001 tier, things like documented policies and proof that controls are running, is the same kind of evidence an ISO 27001 auditor wants to see. Do the Essential Eight properly and you have quietly built a foundation for ISO 27001. Certify at an SMB1001 tier and you have already written policies you will reuse.

What ISO 27001 adds on top is the wrapper: the risk assessment, the Statement of Applicability and the audited management system that ties the individual controls together and proves they are maintained over time. So the sensible path for a growing business is often to build the baseline first and then formalise it into a full management system when a customer’s requirement makes the certificate worth it. You are not starting again each time. You are adding a layer.

A practical takeaway

The three standards are best understood as a ladder rather than a menu of rivals. The Essential Eight gives you a solid technical baseline, SMB1001 gives smaller businesses a recognised certificate at a tier that suits them, and ISO 27001 gives you the internationally recognised management system that opens enterprise and overseas doors. Start where your customers are pointing, do the work once, and let it carry forward.

If you are not yet sure which rung you are on, the clearest first step for most Australian small businesses is to understand the technical baseline everyone builds from. Our Essential Eight hub is the place to begin, with plain-English guides to the eight strategies and how they map to the bigger standards.

This article is general information only and not legal, compliance or financial advice. Costs and requirements vary by organisation; where in doubt, consult a qualified professional or a JAS-ANZ-accredited certification body.

Frequently asked questions

Is ISO 27001 certification legally required in Australia?

No. ISO 27001 is a voluntary international standard. There is no Australian law that forces a private business to be certified. It becomes effectively necessary when a customer, tender or contract requires it, which is common when you sell to enterprise, government or overseas clients that expect a recognised security certification.

How long does ISO 27001 certification take?

For most small Australian businesses the work takes somewhere in the range of three to twelve months before the Stage 2 audit, depending on how much you already have documented and how much time you can put in. The bulk of the effort is building and running the management system, not the audit itself, so honest preparation is where the timeline is won or lost.

What is the difference between accreditation and certification?

Certification is the certificate your business earns for meeting the standard. Accreditation is the layer above it: JAS-ANZ accredits the certification body that issues your certificate. Choosing a JAS-ANZ-accredited body is what makes your certificate credible and recognised, both in Australia and through international mutual-recognition arrangements.

Do I need the Essential Eight and ISO 27001, or just one?

It depends on who is asking. Government and defence supply chains often ask about the Essential Eight, while enterprise and international customers usually ask for ISO 27001. Many businesses end up doing both over time. Because the underlying security work overlaps, doing one first makes the second easier rather than doubling the effort.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

Essential Eight

The Essential Eight Checklist for Australian Small Business

28 Jun 2026 · 7 min
Essential Eight

The Essential Eight Controls, Explained Simply

28 Jun 2026 · 7 min
Essential Eight

Essential Eight Maturity Levels (ML1–ML3), Explained

28 Jun 2026 · 7 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.