ISO/IEC 27001 Information Security Management Systems
ISO/IEC 27001 is the internationally agreed standard for managing information security, protecting the data your business holds, and proving you take its security seriously.
Certified by a JASANZ-accredited body (like us!), that protection isn't just something you claim. It's proof your customers, your partners, and regulators can trust. The recognised mark that you manage your information responsibly and have built the system to keep it secure.




















What is ISO/IEC 27001?
ISO/IEC 27001 is the world's best-known standard for information security management. Used by organisations in over 150 countries, it's the recognised framework for keeping the information your business holds secure and proving to everyone who depends on you that it is.
At its heart is a risk-based approach. Rather than handing you a fixed checklist, the standard asks you to understand what information you hold, identify the threats to it like attacks, human error, system failure, physical theft and put the right controls in place to manage those specific risks. It covers far more than IT: people, processes, physical security, and suppliers all fall within scope, because information security is never just a technology problem.
To help, the standard comes with a catalogue of security controls (known as Annex A) spanning everything from access management and encryption to staff training and incident response. You apply the ones that address your risks, and document why. Like other ISO management standards, it scales to any organisation; a software company, a professional services firm, or a business simply holding sensitive customer data of any size.
In practice, being certified to ISO/IEC 27001 means you've built an Information Security Management System (ISMS) that meets the internationally agreed best practice and had an independent, accredited body (like us!) verify it. It's the difference between saying your data is safe and being able to prove it.

DO WE NEED ISO/IEC 27001?
ISO/IEC 27001 is how you prove your business can be trusted with data, and protect it before something goes wrong.
CCustomer and partner trust - Data breaches make headlines and end relationships. ISO/IEC 27001 shows your customers and partners that protecting their information isn't an afterthought, it's independently verified, and something you can prove rather than promise.
Wins you business - Certification is increasingly a requirement, not a nice-to-have. More and more tenders, enterprise clients, and procurement teams won't sign until you can show ISO/IEC 27001, so it opens doors that stay firmly shut to competitors who can't.
Real protection against real threats - Cyber attacks, ransomware, and human error are business risks, not just IT problems. ISO 27001 helps you identify where you're genuinely exposed and put the right controls in place, reducing the likelihood and the impact of an incident before it happens.
Fewer breaches, lower costs - The cost of a serious data breach; downtime, recovery, lost customers, reputational damage dwarfs the cost of preventing one. A structured security system is one of the most effective investments you can make against that risk.
Compliance made manageable - Privacy and data-protection obligations are only getting stricter. ISO 27001 gives you a structured way to meet your legal and regulatory requirements around information, so compliance becomes something you manage deliberately rather than scramble to prove.
Security that's more than technology - Most breaches come down to people and process, not just systems. ISO 27001 builds security into how your whole organisation works: staff awareness, supplier management, physical security, and incident response so you're protected across the board, not just at the firewall.
EVERY AUDIT WE RUN IS
DESIGNED TO DO THREE THINGS.
GOOD FOR YOUR TEAM.
Practical improvements. Human-to-human conversations. Flexible, remote-first, and built around how and your team actually work.
Good ASSESSORS
People who are passionate about improving your business and genuinely invested in your growth, year after year.
Good for the world
Every audit funds health, community, and
environmental impact through our Good Fund. We're a B Corp and a 1% for the Planet member. This isn't a side project; it's embedded into everything we do.
THIS IS WHAT CERTIFICATION LOOKS LIKE WHEN IT GIVES A DAMN.
WELCOME TO BEING CERTIFIED WITH IMPACT™.
Six reasons we're
your partner
Internationally recognised
JASANZ and IAF accreditation. Recognised in 100+ countries. Listed on the IAF CertSearch register, giving clients, regulators, and government tenders the proof they need.
Collaborative by design
We look for conformity first. Where there's a gap, we work with your team to close it through practical recommendations in plain language, not a clause-by-clause finding list.
Flexible audits, built around yoU
Stage 1 is usually remote. Stage 2 is scheduled around your team, with asynchronous elements built in wherever possible. We adapt to you, not the other way around.
Consultant, DIY & platform-friendly
We play well with others. GRC platforms, internal consultants or your own internal setup - we fit seamlessly into your existing setup and keep things moving.
You’ll know us by name
From first enquiry to certificate, you'll have a dedicated point of contact at every stage. Our leadership team is hands-on; a member of our senior team attends every opening or closing meeting personally to say g’day. Call us, WhatsApp us, email us. Our door is always open.
People who are invested in your growth
We only work with auditors who are genuinely passionate about improving your business and invested in your business, year after year.
From G'day to
getting started.
Let's have a chat
Book a discovery call with José, our CEO. This is really an opportunity to say G’day, have a conversation to understand your business, and see if we're the right fit.
We'll send you a quote within THE DAY
We’re upfront about our pricing. Transparent pricing based on your team size and business complexity. There are no hidden fees or surprises. And as a B Corp, we never want price to be a barrier. If you receive a more competitive quote from another JASANZ-accredited body, let us know, and we'll do our best to match it.
We get started
Once you sign your fee proposal, our team will call you to welcome you to A Good Certification Group and walk you through the plan - tentative dates, your assessor, and everything you need to know before we kick off.
What our clients say
How it works
FAQs
What's the difference between ISO 27001 and SOC 2?
They're often mentioned together, and both are recognised internationally, but they're different things. ISO/IEC 27001 is a certification; an accredited body verifies your information security management system against the standard, and you receive a certificate recognised worldwide. SOC 2 is an attestation report, produced by an independent auditor, describing how your controls operated over a period of time.
In practice, they serve similar goals through different mechanisms, and which one clients ask for often comes down to context. ISO 27001 is the globally recognised certifiable standard, while SOC 2 is frequently requested by clients in the technology and SaaS space. The good news is they overlap heavily, so if you already hold one, achieving the other is far less work.
Isn't ISO 27001 just for tech companies?
No and this is the most common misconception. Any organisation that holds sensitive information needs to protect it, whatever the industry. Professional services firms, healthcare providers, financial services, manufacturers, government suppliers - if you handle customer data, financial records, intellectual property, or personal information, ISO 27001 applies to you. It's about protecting information, not about being a software company.
Isn't information security just an IT problem?
It's much broader than IT, and that's the point of ISO 27001. Most security incidents involve people and process. For example, a staff member clicking a phishing link, a supplier with weak controls, a laptop left on a train, not just technology failures. ISO 27001 covers all of it: staff awareness, access management, physical security, supplier relationships, and incident response, alongside the technical controls. It builds security into how your whole organisation works.
We already have good IT security. Why do we need certification?
Because having good security and being able to prove it are two different things. Certification gives you independent, accredited verification that your security actually works; the evidence a client, regulator, or tender panel will accept, rather than taking your word for it. The process itself also tends to surface gaps that even strong teams hadn't spotted, because it looks at your security systematically rather than piece by piece.
Do we have to apply every control in the standard?
No. ISO 27001 is risk-based, not a fixed checklist. The standard includes a catalogue of reference controls (Annex A), but you apply the ones that address your organisation's actual risks and document why the others don't apply. That's what makes it work for a five-person firm and a multinational alike, it scales to the risks that are genuinely relevant to you.
How does ISO 27001 relate to ISO 42001?
They're close cousins, and increasingly pursued toether. ISO 27001 governs how you secure information; ISO 42001 governs how you manage AI responsibly. Both are risk-based, both share the same underlying structure, and both deal heavily with data and controls, so if you hold ISO 27001 and are now adopting AI, ISO 42001 is a natural next step, and the two can often be audited together.
How long is an ISO/IEC 27001 certificate valid?
Three years. After initial certification, we carry out lighter surveillance audits each year to confirm your information security management system is working in practice, then a recertification audit at the three-year mark.







