WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Most Australian organisations arrive at ISO 27001 the same way. A large customer sends a security questionnaire, or a tender lists it under mandatory criteria, and suddenly "we take security seriously" is no longer a sufficient answer. A certificate answers the question in one line, which is a large part of why demand keeps climbing.

The current edition is ISO/IEC 27001:2022. It restructured Annex A into 93 controls grouped under four themes: organisational, people, physical and technological. If you read content still describing 114 controls across 14 domains, it predates the 2022 revision and should be treated with caution generally.

Nathan ISO Consulting builds information security management systems for Australian organisations. We run the scoping and risk assessment, prepare the Statement of Applicability, support control implementation, conduct your internal audit and take you through Stage 1 and Stage 2 with a JAS-ANZ accredited certification body.

Where ISO 27001 sits in the Australian security landscape

Australia has an unusually crowded set of security frameworks, and choosing between them is the question we get asked most often. They do different jobs.

FrameworkWhat it isWhen you need it
ISO/IEC 27001Certifiable international management system standard covering the whole security programEnterprise and international procurement, broad assurance, most private-sector tenders
Essential EightACSC baseline of eight technical mitigation strategies with four maturity levelsCommonwealth entities and their suppliers; often requested alongside ISO 27001
IRAPAssessment of a system against the ACSC Information Security Manual by an endorsed assessorHandling Australian Government data at PROTECTED or above
SOC 2US attestation report issued by a CPA firm against trust services criteriaSelling to US enterprise buyers; less recognised in Australian government procurement
APRA CPS 234Prudential standard on information security for APRA-regulated entitiesBanks, insurers and superannuation funds, and their material service providers

These are rarely alternatives to one another. A SaaS company selling to both Australian government and US enterprise commonly ends up holding ISO 27001, demonstrating Essential Eight maturity, and producing a SOC 2 report. The ISMS is what makes the other two manageable rather than three separate projects.

Legal and regulatory obligations underneath

ISO 27001 is voluntary. Several things it helps you handle are not.

ObligationWho it applies toWhat it requires
Privacy Act 1988 (Cth), APP 11Most organisations above the turnover threshold, plus targeted small businessesReasonable steps to protect personal information from misuse, interference, loss and unauthorised access
Notifiable Data Breaches schemeEntities covered by the Privacy ActNotification to affected individuals and the OAIC where a breach is likely to result in serious harm. Australian law does not impose a 72-hour deadline
Security of Critical Infrastructure Act 2018Responsible entities across energy, water, transport, communications, health, data storage and other declared sectorsA critical infrastructure risk management program covering all hazards, including cyber
APRA CPS 234APRA-regulated entities and their material service providersInformation security capability proportionate to threats, control testing, and incident notification
Protective Security Policy FrameworkCommonwealth entities and, by flow-down, their suppliersProtective security governance, information, personnel and physical security requirements
State privacy legislationNSW, Victorian and Queensland public sector agencies and their contracted service providersInformation privacy principles under the PPIP Act, the Privacy and Data Protection Act 2014 and the Information Privacy Act 2009
My Health Records Act 2012Healthcare providers and connected systemsSpecific access, audit and breach obligations for My Health Record data
Consumer Data RightAccredited data recipients and data holdersInformation security controls prescribed under the CDR rules

Which of these apply depends on your sector, your customers and your contracts. We identify them during scoping, because they usually shape the ISMS boundary more than anything else does.

How Nathan ISO Consulting assists

ServiceWhat we deliver
ScopingDefining the ISMS boundary: which services, systems, locations and people are in. Scope decisions drive everything downstream and are difficult to change later
Gap analysisAssessment against the 93 Annex A controls and the Clause 4 to 10 requirements, with a written gap register by effort and priority
Information asset inventoryWhat information you hold, where it lives, who can reach it and what happens if it is lost
Risk assessment and treatmentThreat and vulnerability analysis, risk criteria agreed with management, and a risk treatment plan with owners
Statement of ApplicabilityEvery one of the 93 controls addressed with a justification for inclusion or exclusion. Auditors examine this more closely than any other document
Policy and control implementation supportAccess control, supplier security, secure development, logging and monitoring, incident response, ICT continuity
Regulatory mappingPrivacy Act, NDB, SOCI, CPS 234, PSPF and state privacy obligations mapped to the controls that satisfy them
Essential Eight alignmentWhere Commonwealth-facing work applies, mapping Essential Eight maturity against the ISMS so both are evidenced once
Internal audit and management reviewFull internal audit against all clauses and applicable controls, findings closed, documented review
Certification body selectionShortlisting JAS-ANZ accredited bodies on your scope, sector and audit approach
Stage 1 and Stage 2 attendanceWe attend both and close out findings ourselves
Post-certification supportSurveillance preparation, annual risk reassessment, and the ongoing evidence cycle that keeps the certificate live

Why organisations choose Nathan over other providers

Australia has no shortage of ISO consultants. Most of them fall into one of two camps. Some sell a documentation pack, email it over, and leave you to work out how to make it real. Others charge for a long project and produce a system so heavy that nobody uses it once the auditor leaves. We have been called in to fix both.

What most providers doWhat we do
Supply a Statement of Applicability with generic justificationsWrite control justifications from your own risk assessment, because this is the document auditors dig into hardest
Run a single risk workshop and never revisit itBuild a live risk process with defined criteria, named owners and a reassessment cycle
Scope the ISMS across the whole company to look impressiveScope to what you can genuinely evidence, and tell you when narrower is stronger
Treat Essential Eight, SOC 2 and ISO 27001 as three separate projectsMap them against one control set so evidence is produced once and used three times
Ignore supplier and cloud securityBring cloud infrastructure, contractors and offshore development into scope, because Annex A expects it
Document incident response and never exercise itRun the tabletop exercise and keep the minutes, closing a common finding before it is raised
Stop at the certificateStay on for surveillance, annual risk reassessment and the evidence cycle that keeps the certificate live

Our implementation process

StageWhat happensDuration
1. ScopingISMS boundary defined across services, systems, locations and people.1–2 weeks
2. Gap analysisAssessment against the 93 Annex A controls and Clause 4 to 10 requirements.2 weeks
3. Risk assessmentAsset inventory, threat and vulnerability analysis, risk criteria agreed, treatment plan produced.3–4 weeks
4. Statement of ApplicabilityAll 93 controls addressed with justification for inclusion or exclusion.1–2 weeks
5. Control implementationPolicies, access control, supplier security, secure development, logging, incident response, ICT continuity.6–12 weeks
6. Internal audit and reviewFull internal audit against all clauses and applicable controls, findings closed, management review.2–3 weeks
7. Certification auditStage 1 documentation review, remediation window, then Stage 2.3–5 weeks

ISO 27001 certification services across Australia

Information security work is largely location-independent, so most of an ISO 27001 project runs remotely regardless of where you are. We attend on site where physical security controls, data centres or restricted areas need to be assessed in person, and for Stage 2 where the certification body requires it.

State / TerritoryCities and regions we serve
New South WalesSydney CBD, North Sydney, Parramatta, Macquarie Park, Newcastle, Wollongong, Central Coast
VictoriaMelbourne CBD, Docklands, Cremorne and Richmond, South Melbourne, Geelong
QueenslandBrisbane CBD, Fortitude Valley, South Brisbane, Gold Coast, Sunshine Coast, Townsville, Cairns
Western AustraliaPerth CBD, West Perth, Subiaco, Fremantle, Bunbury
South AustraliaAdelaide CBD, Mawson Lakes, Technology Park, Osborne
Australian Capital TerritoryCanberra, Barton, Deakin and the Parliamentary Triangle — weighted toward Commonwealth suppliers
TasmaniaHobart, Launceston
Northern TerritoryDarwin, Palmerston

Where first certification audits go wrong

A Statement of Applicability produced from a template with generic justifications. This is the document auditors dig into hardest, and copied justifications are obvious.

A risk assessment done once, in a workshop, and never revisited. Clause 6 expects a live process with defined criteria and documented ownership.

Access reviews that were never performed. Leavers still holding active accounts is among the most frequently raised findings in Australian audits.

Supplier security ignored. Cloud infrastructure, contractors and offshore development are all in scope, and Annex A expects evidence of assessment and contractual controls.

Incident response documented but never exercised. A tabletop exercise with minutes takes half a day and closes the finding before it is raised.

Scope drawn too wide to look impressive, then impossible to evidence across the whole organisation.

Industries we work with

Software and SaaS, managed service providers and IT services, financial services and fintech, health technology and medical software, professional services handling client data, Commonwealth and state government suppliers, education and training providers, telecommunications, and logistics and supply chain technology.

FAQ'S

Annex A of the 2022 edition contains 93 controls grouped into four themes: organisational, people, physical and technological. This replaced the 2013 structure of 114 controls across 14 domains. Content still citing 114 controls is out of date.

For Australian and international procurement, ISO 27001 is generally more recognised, and it is a certifiable standard rather than an attestation report. SOC 2 carries more weight with US enterprise buyers. Companies selling into both markets frequently hold both.

Partially. The Essential Eight is a set of specific technical mitigations, while ISO 27001 is a broader management system. Many Essential Eight controls map to Annex A, but neither substitutes for the other. Commonwealth-facing suppliers are often asked for both.

It supports compliance with Australian Privacy Principle 11 by demonstrating reasonable security steps, but it is not a privacy standard. For privacy management specifically, ISO/IEC 27701:2025 is the applicable standard and can now be certified independently.

Yes, and it is a common and legitimate approach for SaaS companies. The scope statement on your certificate must accurately describe what is covered, and prospective customers will read it, so scope it to what you can genuinely evidence.

They serve different purposes. IRAP assesses a specific system against the Information Security Manual for handling Australian Government data. ISO 27001 certifies your organisational management system. Government suppliers commonly need IRAP; commercial buyers commonly ask for ISO 27001.

All capital cities and major regional centres, including Sydney, Melbourne, Brisbane, Perth, Adelaide, Canberra, Hobart and Darwin. Most of an ISO 27001 project runs remotely, with on-site attendance where physical security controls or data centres need assessment in person.

Typically 16 to 28 weeks. Control implementation is the longest phase because it involves real technical change rather than documentation. Organisations with mature security practices already in place can move considerably faster.

Talk to our ISO 27001 team

If a customer questionnaire or tender triggered this, send it to us. Reading the actual requirement is faster than guessing at scope, and occasionally it turns out you need something narrower than full certification.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance