ISO/IEC 27001 Information Security Management Systems

ISO/IEC 27001 is the internationally agreed standard for managing information security, protecting the data your business holds, and proving you take its security seriously.

Certified by a JASANZ-accredited body (like us!), that protection isn't just something you claim. It's proof your customers, your partners, and regulators can trust. The recognised mark that you manage your information responsibly and have built the system to keep it secure.

‍

Certified with Impact ISO 27001 Information Security badge in gold color.
Trusted by CLIENTS AROUND THE WORLD

What is ISO/IEC 27001?

ISO/IEC 27001 is the world's best-known standard for information security management. Used by organisations in over 150 countries, it's the recognised framework for keeping the information your business holds secure and proving to everyone who depends on you that it is.

At its heart is a risk-based approach. Rather than handing you a fixed checklist, the standard asks you to understand what information you hold, identify the threats to it like attacks, human error, system failure, physical theft and put the right controls in place to manage those specific risks. It covers far more than IT: people, processes, physical security, and suppliers all fall within scope, because information security is never just a technology problem.

To help, the standard comes with a catalogue of security controls (known as Annex A) spanning everything from access management and encryption to staff training and incident response. You apply the ones that address your risks, and document why. Like other ISO management standards, it scales to any organisation; a software company, a professional services firm, or a business simply holding sensitive customer data of any size.

In practice, being certified to ISO/IEC 27001 means you've built an Information Security Management System (ISMS) that meets the internationally agreed best practice and had an independent, accredited body (like us!) verify it. It's the difference between saying your data is safe and being able to prove it.

Close-up of a colorful microchip circuit board with blue, purple, and red components.

DO WE NEED ISO/IEC 27001?

ISO/IEC 27001 is how you prove your business can be trusted with data, and protect it before something goes wrong.

‍CCustomer and partner trust - Data breaches make headlines and end relationships. ISO/IEC 27001 shows your customers and partners that protecting their information isn't an afterthought, it's independently verified, and something you can prove rather than promise.

Wins you business - Certification is increasingly a requirement, not a nice-to-have. More and more tenders, enterprise clients, and procurement teams won't sign until you can show ISO/IEC 27001, so it opens doors that stay firmly shut to competitors who can't.

Real protection against real threats - Cyber attacks, ransomware, and human error are business risks, not just IT problems. ISO 27001 helps you identify where you're genuinely exposed and put the right controls in place, reducing the likelihood and the impact of an incident before it happens.

Fewer breaches, lower costs - The cost of a serious data breach; downtime, recovery, lost customers, reputational damage dwarfs the cost of preventing one. A structured security system is one of the most effective investments you can make against that risk.

Compliance made manageable - Privacy and data-protection obligations are only getting stricter. ISO 27001 gives you a structured way to meet your legal and regulatory requirements around information, so compliance becomes something you manage deliberately rather than scramble to prove.

Security that's more than technology - Most breaches come down to people and process, not just systems. ISO 27001 builds security into how your whole organisation works: staff awareness, supplier management, physical security, and incident response so you're protected across the board, not just at the firewall.

EVERY AUDIT WE RUN IS
DESIGNED TO DO THREE THINGS.

01

GOOD FOR YOUR TEAM.

Practical improvements. Human-to-human conversations. Flexible, remote-first, and built around how and your team actually work.

02

Good ASSESSORS

People who are passionate about improving your business and genuinely invested in your growth, year after year.

03

Good for the world

Every audit funds health, community, and
environmental impact through our Good Fund. We're a B Corp and a 1% for the Planet member. This isn't a side project; it's embedded into everything we do.

THIS IS WHAT CERTIFICATION LOOKS LIKE WHEN IT GIVES A DAMN.
WELCOME TO BEING CERTIFIED WITH IMPACT™.

Six reasons we're
‍your partner

Internationally recognised

JASANZ and IAF accreditation. Recognised in 100+ countries. Listed on the IAF CertSearch register, giving clients, regulators, and government tenders the proof they need.

Collaborative by design

We look for conformity first. Where there's a gap, we work with your team to close it through practical recommendations in plain language, not a clause-by-clause finding list.

Flexible audits, built around yoU

Stage 1 is usually remote. Stage 2 is scheduled around your team, with asynchronous elements built in wherever possible. We adapt to you, not the other way around.

Consultant, DIY & platform-friendly

We play well with others. GRC platforms, internal consultants or your own internal setup - we fit seamlessly into your existing setup and keep things moving.

You’ll know us by name

From first enquiry to certificate, you'll have a dedicated point of contact at every stage. Our leadership team is hands-on; a member of our senior team attends every opening or closing meeting personally to say g’day. Call us, WhatsApp us, email us. Our door is always open.

People who are invested in your growth

We only work with auditors who are genuinely passionate about improving your business and invested in your business, year after year.

From G'day to
getting started.

Let's have a chat
‍

Book a discovery call with José, our CEO. This is really an opportunity to say G’day, have a conversation to understand your business, and see if we're the right fit.

We'll send you a quote within THE DAY

We’re upfront about our pricing. Transparent pricing based on your team size and business complexity. There are no hidden fees or surprises. And as a B Corp, we never want price to be a barrier. If you receive a more competitive quote from another JASANZ-accredited body, let us know, and we'll do our best to match it.

We get started
‍

Once you sign your fee proposal, our team will call you to welcome you to A Good Certification Group and walk you through the plan - tentative dates, your assessor, and everything you need to know before we kick off.

What our clients say

Certification Oceania were fantastic with our Surveillance audit! A Pleasure to work with, I couldn't recommend them more highly to anyone looking for a certification partner.

Natalia S, CEO
ISO 27001

I had a great experience working with Good Certification Group/Certification Oceania to achieve our ISO 14001 and ISO 45001, and maintain our ISO 9001 certifications. Their team was professional, knowledgeable, and easy to work with throughout the entire process.They provided clear guidance and practical support, making what can be a complex process feel smooth and well-managed.

Christabel W, Systems & Communications Manager
ISO 9001, ISO 45001 & ISO 14001

We recently completed our ISO 9001 certification with Certification Oceania and had a genuinely positive experience throughout the process. A special mention to our auditor, Niko Tovia, who was exceptional. His approach was not just about compliance, but about helping us truly understand our systems.

‍

Shikha P, Operations Manager
ISO 9001

Certification Oceania have been so professionally flexible, and able to adjust their auditing arrangements to suit our busy business ramp up. The process of audits is well explained in advance, and they are very genuine in finding and explaining tangible gaps within a Quality Management System that actually drive an improvement your business will grow from.

Jason H, Business Development Manager
ISO 9001

Jose, and all the team at Certification Oceania, are supportive and customer focused. Actevate will always recommend this company for their dedication to their clients and for making the certification process feel achievable and a lot less daunting.

Robert Migliore, Director/Founder
ISO 9001

How it works

YEAR 1

Stage 1

This is usually remote, and we can do this whenever you're ready

Think of this as your gap analysis. We review your documentation, identify what's looking good, flag any areas of concern, and make sure you're show-ready for Stage 2.

YEAR 1

Stage 2

We recommend roughly 1-4 weeks after Stage 1

This is where your system steps onto the main stage. Your assessor will review your operations, meet your team, and assess your management system against the requirements of your chosen standard. This can be done remotely, on-site or a hybrid of the two - we'll confirm what's right for your business during audit planning.

Your certificate will be issued within 2 weeks of your Stage 2.

‍

YEAR 2

Surveillance 1

We return to check progress, make sure your system is being maintained, and identify new opportunities to improve. We look at what's working well and where small tweaks could make a big difference, keeping your system strong, your team confident, and your certification meaningful.

‍

YEAR 3

Surveillance 2

This is about consistency and ongoing value. We assess long-term performance, review trends, follow up on previous improvements, and help you keep your system lean, effective, and useful. Because great certification isn't just about the moment you achieve it, it's about what you do with it over time.

YEAR 4

Recertification

Following two surveillance audits, you will have a recertification audit, where we will review all the requirements of your chosen standard(s) and reissue your certificate to reflect a new three-year certification cycle.

FAQs

They're often mentioned together, and both are recognised internationally, but they're different things. ISO/IEC 27001 is a certification; an accredited body verifies your information security management system against the standard, and you receive a certificate recognised worldwide. SOC 2 is an attestation report, produced by an independent auditor, describing how your controls operated over a period of time.

In practice, they serve similar goals through different mechanisms, and which one clients ask for often comes down to context. ISO 27001 is the globally recognised certifiable standard, while SOC 2 is frequently requested by clients in the technology and SaaS space. The good news is they overlap heavily, so if you already hold one, achieving the other is far less work.

No and this is the most common misconception. Any organisation that holds sensitive information needs to protect it, whatever the industry. Professional services firms, healthcare providers, financial services, manufacturers, government suppliers - if you handle customer data, financial records, intellectual property, or personal information, ISO 27001 applies to you. It's about protecting information, not about being a software company.

It's much broader than IT, and that's the point of ISO 27001. Most security incidents involve people and process. For example, a staff member clicking a phishing link, a supplier with weak controls, a laptop left on a train, not just technology failures. ISO 27001 covers all of it: staff awareness, access management, physical security, supplier relationships, and incident response, alongside the technical controls. It builds security into how your whole organisation works.

Because having good security and being able to prove it are two different things. Certification gives you independent, accredited verification that your security actually works; the evidence a client, regulator, or tender panel will accept, rather than taking your word for it. The process itself also tends to surface gaps that even strong teams hadn't spotted, because it looks at your security systematically rather than piece by piece.

No. ISO 27001 is risk-based, not a fixed checklist. The standard includes a catalogue of reference controls (Annex A), but you apply the ones that address your organisation's actual risks and document why the others don't apply. That's what makes it work for a five-person firm and a multinational alike, it scales to the risks that are genuinely relevant to you.

They're close cousins, and increasingly pursued toether. ISO 27001 governs how you secure information; ISO 42001 governs how you manage AI responsibly. Both are risk-based, both share the same underlying structure, and both deal heavily with data and controls, so if you hold ISO 27001 and are now adopting AI, ISO 42001 is a natural next step, and the two can often be audited together.

Three years. After initial certification, we carry out lighter surveillance audits each year to confirm your information security management system is working in practice, then a recertification audit at the three-year mark.

Get Certified with impactTM