
ISO 27001 certification typically costs an Australian SME A$20,000 to A$80,000 in the first year. The certification audit alone runs A$10,000 to A$25,000 from a JAS-ANZ-accredited body. The rest goes on consulting or software plus internal time. Certification then runs on a three-year cycle, with annual surveillance audits as a recurring cost.
What does the audit itself cost?
Expect A$10,000 to A$25,000 for the certification audit, quoted as auditor-days at the day rate on the certification body's rate card. That figure covers both stages. Stage 1 reviews your documentation; Stage 2 tests whether the information security management system (ISMS) actually operates the way the documents claim.
Who you buy from matters as much as the price. In Australia, JAS-ANZ accreditation (the Joint Accreditation System of Australia and New Zealand) is the mark of a legitimate certifier. Anyone can sell you a certificate. Only a JAS-ANZ-accredited body can sell you one that a buyer's security team will accept, so check the JAS-ANZ register before you sign the engagement letter, not after.
Get quotes from two or three accredited bodies. Day rates and quoted audit durations vary, and the quotes are itemised enough to compare like for like. Rate cards usually price travel as a separate line, so a certifier with auditors based in your city saves a little. The cheapest accredited certifier is not automatically the wrong choice. An unaccredited one always is.
What drives the price up or down?
Three variables set most of the quote: the scope of your ISMS, your headcount, and how many sites the auditor has to cover. Certification bodies feed them into standard tables that fix the minimum number of audit days, so each one moves the price directly.
Scope is the lever you control.
ISO 27001 lets you certify a defined scope, one product or one business unit, rather than the whole organisation. A tight scope honestly drawn around what your customers care about cuts audit days and cuts preparation work harder. Draw it so narrowly that it excludes the systems buyers ask about, though, and it will pass audit and fail sales calls. Buyers read the scope statement on the certificate.
Headcount matters because more people means more interviews and more evidence to sample. Sites matter because the auditor visits them, physically or virtually. A thirty-person single-office SaaS company sits at the bottom of the range. A two-hundred-person firm across three states does not.
Everything else in the first-year bill depends on how you prepare. Full-service consultants cost the most and leave the least knowledge behind. Compliance software plus a part-time internal owner costs less and keeps the knowledge in-house. Working straight from the standard with no help is cheapest on paper and slowest in practice. Here is how the first cycle typically breaks down:
| # | Cost item | Typical range | Notes |
|---|---|---|---|
| 1 | Gap assessment and ISMS build (consultants, software, or both) | A$10,000 to A$55,000 | The biggest variable; driven by how much you outsource |
| 2 | Internal time | Never on an invoice | Often the largest real cost; someone must own the ISMS |
| 3 | Certification audit (Stage 1 + Stage 2) | A$10,000 to A$25,000 | JAS-ANZ-accredited body, priced in auditor-days |
| 4 | First-year total | A$20,000 to A$80,000 | Tight scope and software-led preparation lands you at the low end |
| 5 | Surveillance audits (years two and three) | A fraction of the initial audit fee, each year | Priced per day off the same rate card; confirm before signing |
| 6 | Recertification audit (start of year four) | Quoted off the same rate card as the initial audit | Opens the next three-year cycle |
What are the recurring costs?
Certification is a subscription, not a purchase. The certificate runs on a three-year cycle: a full audit in year one, a surveillance audit in each of years two and three, then a recertification audit to open the next cycle. Miss a surveillance audit and the certificate is suspended. Your customers' vendor-risk tools will notice.
Surveillance audits are shorter than the initial audit because the auditor samples the ISMS rather than reworking all of it, and they are priced off the same rate card. Ask the certification body to quote all three years up front so the recurring line is visible before you commit. Budget alongside it for the internal work the standard requires every year regardless: internal audits, management reviews, staff awareness training, and keeping the risk assessment current.
The recurring cost nobody puts in the spreadsheet is drift. Controls that were real at certification decay into documents nobody follows, and the year-two surveillance audit is where the gap surfaces. A named owner for the ISMS, even at a fraction of one role, is cheaper than rebuilding evidence in a panic every audit season.
Is it worth it versus SOC 2 or Essential Eight in Australia?
Match the framework to the buyer. Australian government buyers assess you against the Essential Eight. US enterprise buyers expect a SOC 2 report. Buyers across APAC and Europe ask for ISO 27001, and that is where the certificate earns its keep.
The Essential Eight is the Australian Signals Directorate's set of baseline mitigation strategies, and there is no certificate to buy. You demonstrate maturity against its eight controls. If government is your market, spend the money on that uplift before you spend it on any certification (see our guide to the Essential Eight maturity levels).
US enterprise security teams want SOC 2 because their vendor-risk process is built around it; an ISO certificate usually earns you a longer questionnaire, not a shorter one. ISO 27001 is the reverse case. It is the default ask across APAC and Europe. And it travels: one certificate answers a buyer in Sydney and a buyer in Frankfurt.
If you sell into more than one of these markets, the frameworks overlap heavily. The access-control and logging work you do for one substantially covers the others. The waste is running them as separate projects with separate evidence piles. Zavior's control register maps each control you operate across ISO 27001, SOC 2 and the Essential Eight, so you build the evidence once and answer every framework with it.
Frequently asked questions
How long does it take?
Plan in quarters, not weeks. Most of the elapsed time goes into building and operating the ISMS before the auditor arrives; the audit itself is measured in days. The variables that drive cost (scope, headcount, sites) drive the timeline too, and you need evidence that controls have actually operated, which no consultant can compress to zero.
Do Australian government buyers ask for ISO 27001 or Essential Eight?
Essential Eight, in most cases. Government procurement assesses suppliers against the Australian Signals Directorate's Essential Eight rather than asking for an ISO certificate, so a certificate alone will not answer the question. ISO 27001 still helps because much of the underlying work overlaps, but for a government-heavy pipeline it is the second spend, not the first.
Can a startup afford it?
At the bottom of the range, yes. A tightly scoped, software-led certification with a JAS-ANZ-accredited body can land near the A$20,000 end of the first-year range, and it is usually bought to win a specific enterprise deal that pays for it several times over. The larger cost is founder and engineer time, so do not start until a real buyer is asking.
Zavior · Data Protection
Most of that first-year figure is not the audit. It is building the controls and evidence a JAS-ANZ assessor samples, and that is the work Zavior does: policies written for your real data flows, classification staff can follow, and the certification itself managed to the audit. The same programme scopes down for a lean startup or a school, so the first bill stays proportional to what you actually put in scope.
Book a free 30-minute business assessment →