All insights
ISO 27001 July 16, 2026 3 min read

How to Choose an ISO 27001 Consultant in Australia (2026 Guide)

Choosing an ISO 27001 consultant in Australia comes down to one structural fact most buyers learn too late: the consultant who builds your ISMS cannot be the body that certifies it. Certification is performed by an accredited certification body; the consultant’s job is to get you genuinely ready for that audit — and to leave behind a management system your organisation can actually operate. This guide covers what readiness work involves, what it costs, and how to tell a real consultant from a template mill.

What ISO 27001 readiness actually involves

ISO/IEC 27001:2022 certifies a management system, not a firewall. Competent readiness work covers:

  • Scoping — deciding which parts of the organisation the ISMS covers, which drives every downstream cost;
  • Risk methodology and assessment — the engine of the standard, and the first thing a stage-two auditor probes (see our guide to the ISO 27001 risk assessment);
  • The Statement of Applicability — justifying which Annex A controls apply and how they are implemented;
  • Control implementation and gap closure — the actual security work, not just its documentation;
  • Internal audit and management review — the operating evidence the certification audit expects to see;
  • Audit support — standing beside you at stage one and stage two.

Our ISO 27001 readiness service covers that full arc; the wider context is in ISO 27001 explained for Australian organisations.

What it should cost in Australia

CISO Advisory Australia publishes its fee: ISO/IEC 27001:2022 readiness from $12,500 AUD ex GST, fixed fee against a defined scope. The certification body’s audit fees are separate and paid to them directly. Be wary of comparing quotes without comparing scope — “ISO 27001 readiness” can mean a document pack emailed to you, or a management system built, operated and evidenced. They are not the same product, and the auditor will notice. Full fees on our pricing page.

The template-mill problem

The cheapest offers in this market sell a folder of policy templates with your logo on them. The failure mode is predictable: the stage-two auditor interviews staff who have never seen the policies, asks for records of a management review that never happened, and finds a risk register last touched the week the templates arrived. Nonconformities follow, certification slips a quarter, and the readiness work is repurchased — properly, this time. A management system that exists only as documents is not a management system; the standard’s whole premise is that it is operated.

How to tell a real consultant

  1. They ask about your scope before quoting. Anyone who prices ISO 27001 readiness without asking what is in scope is quoting for paperwork.
  2. They are independent of the certification body — required — and ideally independent of tooling vendors too, so the Statement of Applicability reflects your risk, not their catalogue.
  3. They plan for the audit period, not just the audit. Certification requires operating evidence; a consultant who cannot describe your first internal-audit cycle is selling documents.
  4. They can name the certification bodies they have taken clients through and describe how stage one differs from stage two — covered in our guide to ISO 27001 stage 1 and stage 2 audits.
  5. Their fee is fixed and their deliverables are written. Hourly ISMS consulting is an incentive problem wearing a lanyard.

Questions to ask before signing

  1. Who does the work — a senior practitioner or a junior with a template library?
  2. What exactly is delivered: documents, or an operated ISMS with evidence?
  3. How many Annex A controls do you expect will apply to us, and why?
  4. What happens if we get a nonconformity at stage two?
  5. Do you also sell SOC 2 readiness, and should we sequence them together? (If you serve US software customers, often yes — see ISO 27001 vs SOC 2.)

CISO Advisory Australia builds ISMSs designed to pass certification and then be genuinely run — senior-led, vendor-neutral, fixed fee. To scope yours, book a scoping call.

Frequently asked questions

Can the same firm do our ISO 27001 consulting and certification?

No — certification must be performed by an accredited certification body that is independent of whoever built your ISMS. The consultant's job is readiness: scope, risk methodology, Statement of Applicability, control implementation, internal audit and support through the stage one and stage two audits.

How much does an ISO 27001 consultant cost in Australia?

CISO Advisory Australia publishes its fee: ISO/IEC 27001:2022 readiness from $12,500 AUD ex GST as a fixed fee against a defined scope. The certification body's audit fees are separate. Compare quotes on scope, not price — a document pack and an operated, evidenced management system are different products.

What is wrong with template ISMS packages?

The stage-two auditor tests whether the management system is operated, not whether documents exist. Templates with your logo on them fail at the interview stage: staff have never seen the policies, there are no management-review records, and the risk register is stale. The readiness work then has to be bought again, properly, after a failed or delayed audit.

How do we tell a real ISO 27001 consultant from a document mill?

A real consultant asks about your scope before quoting, is independent of certification bodies and tooling vendors, plans your first internal-audit cycle and audit-period evidence rather than just the paperwork, can name certification bodies they have taken clients through, and works to a fixed written fee.

Talk to a Virtual CISO

Need this handled for your organisation?

Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.

Confidential. We typically respond same business day — or call us 24/7.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act