Most Australian organisations arrive at ISO 27001 the same way. A large customer sends a security questionnaire, or a tender lists it under mandatory criteria, and suddenly "we take security seriously" is no longer a sufficient answer. A certificate answers the question in one line, which is a large part of why demand keeps climbing.
The current edition is ISO/IEC 27001:2022. It restructured Annex A into 93 controls grouped under four themes: organisational, people, physical and technological. If you read content still describing 114 controls across 14 domains, it predates the 2022 revision and should be treated with caution generally.
Nathan ISO Consulting builds information security management systems for Australian organisations. We run the scoping and risk assessment, prepare the Statement of Applicability, support control implementation, conduct your internal audit and take you through Stage 1 and Stage 2 with a JAS-ANZ accredited certification body.
Where ISO 27001 sits in the Australian security landscape
Australia has an unusually crowded set of security frameworks, and choosing between them is the question we get asked most often. They do different jobs.
| Framework | What it is | When you need it |
|---|---|---|
| ISO/IEC 27001 | Certifiable international management system standard covering the whole security program | Enterprise and international procurement, broad assurance, most private-sector tenders |
| Essential Eight | ACSC baseline of eight technical mitigation strategies with four maturity levels | Commonwealth entities and their suppliers; often requested alongside ISO 27001 |
| IRAP | Assessment of a system against the ACSC Information Security Manual by an endorsed assessor | Handling Australian Government data at PROTECTED or above |
| SOC 2 | US attestation report issued by a CPA firm against trust services criteria | Selling to US enterprise buyers; less recognised in Australian government procurement |
| APRA CPS 234 | Prudential standard on information security for APRA-regulated entities | Banks, insurers and superannuation funds, and their material service providers |
These are rarely alternatives to one another. A SaaS company selling to both Australian government and US enterprise commonly ends up holding ISO 27001, demonstrating Essential Eight maturity, and producing a SOC 2 report. The ISMS is what makes the other two manageable rather than three separate projects.
Legal and regulatory obligations underneath
ISO 27001 is voluntary. Several things it helps you handle are not.
| Obligation | Who it applies to | What it requires |
|---|---|---|
| Privacy Act 1988 (Cth), APP 11 | Most organisations above the turnover threshold, plus targeted small businesses | Reasonable steps to protect personal information from misuse, interference, loss and unauthorised access |
| Notifiable Data Breaches scheme | Entities covered by the Privacy Act | Notification to affected individuals and the OAIC where a breach is likely to result in serious harm. Australian law does not impose a 72-hour deadline |
| Security of Critical Infrastructure Act 2018 | Responsible entities across energy, water, transport, communications, health, data storage and other declared sectors | A critical infrastructure risk management program covering all hazards, including cyber |
| APRA CPS 234 | APRA-regulated entities and their material service providers | Information security capability proportionate to threats, control testing, and incident notification |
| Protective Security Policy Framework | Commonwealth entities and, by flow-down, their suppliers | Protective security governance, information, personnel and physical security requirements |
| State privacy legislation | NSW, Victorian and Queensland public sector agencies and their contracted service providers | Information privacy principles under the PPIP Act, the Privacy and Data Protection Act 2014 and the Information Privacy Act 2009 |
| My Health Records Act 2012 | Healthcare providers and connected systems | Specific access, audit and breach obligations for My Health Record data |
| Consumer Data Right | Accredited data recipients and data holders | Information security controls prescribed under the CDR rules |
Which of these apply depends on your sector, your customers and your contracts. We identify them during scoping, because they usually shape the ISMS boundary more than anything else does.
How Nathan ISO Consulting assists
| Service | What we deliver |
|---|---|
| Scoping | Defining the ISMS boundary: which services, systems, locations and people are in. Scope decisions drive everything downstream and are difficult to change later |
| Gap analysis | Assessment against the 93 Annex A controls and the Clause 4 to 10 requirements, with a written gap register by effort and priority |
| Information asset inventory | What information you hold, where it lives, who can reach it and what happens if it is lost |
| Risk assessment and treatment | Threat and vulnerability analysis, risk criteria agreed with management, and a risk treatment plan with owners |
| Statement of Applicability | Every one of the 93 controls addressed with a justification for inclusion or exclusion. Auditors examine this more closely than any other document |
| Policy and control implementation support | Access control, supplier security, secure development, logging and monitoring, incident response, ICT continuity |
| Regulatory mapping | Privacy Act, NDB, SOCI, CPS 234, PSPF and state privacy obligations mapped to the controls that satisfy them |
| Essential Eight alignment | Where Commonwealth-facing work applies, mapping Essential Eight maturity against the ISMS so both are evidenced once |
| Internal audit and management review | Full internal audit against all clauses and applicable controls, findings closed, documented review |
| Certification body selection | Shortlisting JAS-ANZ accredited bodies on your scope, sector and audit approach |
| Stage 1 and Stage 2 attendance | We attend both and close out findings ourselves |
| Post-certification support | Surveillance preparation, annual risk reassessment, and the ongoing evidence cycle that keeps the certificate live |
Why organisations choose Nathan over other providers
Australia has no shortage of ISO consultants. Most of them fall into one of two camps. Some sell a documentation pack, email it over, and leave you to work out how to make it real. Others charge for a long project and produce a system so heavy that nobody uses it once the auditor leaves. We have been called in to fix both.
| What most providers do | What we do |
|---|---|
| Supply a Statement of Applicability with generic justifications | Write control justifications from your own risk assessment, because this is the document auditors dig into hardest |
| Run a single risk workshop and never revisit it | Build a live risk process with defined criteria, named owners and a reassessment cycle |
| Scope the ISMS across the whole company to look impressive | Scope to what you can genuinely evidence, and tell you when narrower is stronger |
| Treat Essential Eight, SOC 2 and ISO 27001 as three separate projects | Map them against one control set so evidence is produced once and used three times |
| Ignore supplier and cloud security | Bring cloud infrastructure, contractors and offshore development into scope, because Annex A expects it |
| Document incident response and never exercise it | Run the tabletop exercise and keep the minutes, closing a common finding before it is raised |
| Stop at the certificate | Stay on for surveillance, annual risk reassessment and the evidence cycle that keeps the certificate live |
Our implementation process
| Stage | What happens | Duration |
|---|---|---|
| 1. Scoping | ISMS boundary defined across services, systems, locations and people. | 1–2 weeks |
| 2. Gap analysis | Assessment against the 93 Annex A controls and Clause 4 to 10 requirements. | 2 weeks |
| 3. Risk assessment | Asset inventory, threat and vulnerability analysis, risk criteria agreed, treatment plan produced. | 3–4 weeks |
| 4. Statement of Applicability | All 93 controls addressed with justification for inclusion or exclusion. | 1–2 weeks |
| 5. Control implementation | Policies, access control, supplier security, secure development, logging, incident response, ICT continuity. | 6–12 weeks |
| 6. Internal audit and review | Full internal audit against all clauses and applicable controls, findings closed, management review. | 2–3 weeks |
| 7. Certification audit | Stage 1 documentation review, remediation window, then Stage 2. | 3–5 weeks |
ISO 27001 certification services across Australia
Information security work is largely location-independent, so most of an ISO 27001 project runs remotely regardless of where you are. We attend on site where physical security controls, data centres or restricted areas need to be assessed in person, and for Stage 2 where the certification body requires it.
| State / Territory | Cities and regions we serve |
|---|---|
| New South Wales | Sydney CBD, North Sydney, Parramatta, Macquarie Park, Newcastle, Wollongong, Central Coast |
| Victoria | Melbourne CBD, Docklands, Cremorne and Richmond, South Melbourne, Geelong |
| Queensland | Brisbane CBD, Fortitude Valley, South Brisbane, Gold Coast, Sunshine Coast, Townsville, Cairns |
| Western Australia | Perth CBD, West Perth, Subiaco, Fremantle, Bunbury |
| South Australia | Adelaide CBD, Mawson Lakes, Technology Park, Osborne |
| Australian Capital Territory | Canberra, Barton, Deakin and the Parliamentary Triangle — weighted toward Commonwealth suppliers |
| Tasmania | Hobart, Launceston |
| Northern Territory | Darwin, Palmerston |
Where first certification audits go wrong
A Statement of Applicability produced from a template with generic justifications. This is the document auditors dig into hardest, and copied justifications are obvious.
A risk assessment done once, in a workshop, and never revisited. Clause 6 expects a live process with defined criteria and documented ownership.
Access reviews that were never performed. Leavers still holding active accounts is among the most frequently raised findings in Australian audits.
Supplier security ignored. Cloud infrastructure, contractors and offshore development are all in scope, and Annex A expects evidence of assessment and contractual controls.
Incident response documented but never exercised. A tabletop exercise with minutes takes half a day and closes the finding before it is raised.
Scope drawn too wide to look impressive, then impossible to evidence across the whole organisation.
Industries we work with
Software and SaaS, managed service providers and IT services, financial services and fintech, health technology and medical software, professional services handling client data, Commonwealth and state government suppliers, education and training providers, telecommunications, and logistics and supply chain technology.
FAQ'S
Annex A of the 2022 edition contains 93 controls grouped into four themes: organisational, people, physical and technological. This replaced the 2013 structure of 114 controls across 14 domains. Content still citing 114 controls is out of date.
For Australian and international procurement, ISO 27001 is generally more recognised, and it is a certifiable standard rather than an attestation report. SOC 2 carries more weight with US enterprise buyers. Companies selling into both markets frequently hold both.
Partially. The Essential Eight is a set of specific technical mitigations, while ISO 27001 is a broader management system. Many Essential Eight controls map to Annex A, but neither substitutes for the other. Commonwealth-facing suppliers are often asked for both.
It supports compliance with Australian Privacy Principle 11 by demonstrating reasonable security steps, but it is not a privacy standard. For privacy management specifically, ISO/IEC 27701:2025 is the applicable standard and can now be certified independently.
Yes, and it is a common and legitimate approach for SaaS companies. The scope statement on your certificate must accurately describe what is covered, and prospective customers will read it, so scope it to what you can genuinely evidence.
They serve different purposes. IRAP assesses a specific system against the Information Security Manual for handling Australian Government data. ISO 27001 certifies your organisational management system. Government suppliers commonly need IRAP; commercial buyers commonly ask for ISO 27001.
All capital cities and major regional centres, including Sydney, Melbourne, Brisbane, Perth, Adelaide, Canberra, Hobart and Darwin. Most of an ISO 27001 project runs remotely, with on-site attendance where physical security controls or data centres need assessment in person.
Typically 16 to 28 weeks. Control implementation is the longest phase because it involves real technical change rather than documentation. Organisations with mature security practices already in place can move considerably faster.
Talk to our ISO 27001 team
If a customer questionnaire or tender triggered this, send it to us. Reading the actual requirement is faster than guessing at scope, and occasionally it turns out you need something narrower than full certification.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving