ISO 27001 consulting, internal audits and mentoring for Australian organisations
You work directly with a qualified ISO Lead Auditor from the first conversation through to your certification audit, so the person who learns your business is the person who builds your system. Most small and medium organisations reach certification in three to six months. We work with clients Australia wide, on site and remotely.
Talk to an ISO 27001 consultant →ISO 27001 certification is fast becoming the ticket to play for Australian businesses handling customer data. Enterprise buyers, government panels and overseas customers increasingly ask for it by name. Streamline builds practical, right-sized information security management systems aligned to how your business actually operates, built to certify first time, led by an experienced ISO Lead Auditor.
What ISO 27001 certification involves
Certification means two things: an information security management system that genuinely meets ISO/IEC 27001:2022, covering scope, risk assessment, the Statement of Applicability and the Annex A controls that apply to you, and a certification audit by an accredited certification body. In Australia, look for accreditation by JAS-ANZ, the joint accreditation body for Australia and New Zealand.
It is not a technical checklist. Roughly a third of the 93 Annex A controls are about people and organisation rather than technology, and the numbered clauses that sit in front of Annex A are almost entirely about governance: understanding your context, deciding your scope, assessing risk, setting objectives, auditing yourself and reviewing performance. You can have excellent firewalls and still fail an ISO 27001 audit.

What our ISO 27001 clients say
“We have recently gone through ISO 27001 certification and Streamline helped us achieve our goal. Scott was great, he made the whole process manageable, achievable and structured. Saved us hours and hours of work and managed the whole project seamlessly. Very professional, responsive and great quality in service. Thanks Streamline we greatly appreciate your assistance.”
Leigh Killian, Account Lead Australia/NZ, Cordel
“We engaged Scott from Streamline ISO Consultants to help us with our ISO 27001 certification process. Scott was essential to our company obtaining the accreditation and supported us throughout the entire process in a very professional manner. At no stage was Scott unsure as to what needed to be done and was always well prepared for every eventuality.”
Shane Goodwin, IT Manager, Inspect Real Estate
“We recently completed our ISO 9001 and ISO 27001 audits with Scott and couldn’t be happier with the experience. Scott was friendly, professional, efficient, and clearly very knowledgeable.”
Jason Williams, MAX (Tabcorp)
The process, step by step
- Gap analysis. Where your current security practices stand against the standard, written up clause by clause. See our gap analysis audits.
- Scope and context. An agreed scope statement naming the services, sites, systems and people the certificate will cover. This is the most consequential decision in the project.
- Risk assessment and Statement of Applicability. Identify your information risks and select the Annex A controls that treat them, with a stated reason recorded against every exclusion.
- Development and implementation. Policies, controls and evidence built around how you already work, not a binder of templates.
- Internal audit and management review. The independent internal audit required by clause 9.2, plus the management review. Any nonconformity is raised and closed here, before the certification body sees it.
- Certification audit. Stage 1 checks your documented system against the standard. Stage 2 checks whether you actually do what your documents say, and samples records to prove it. After that it is annual surveillance audits, with full recertification every three years.
Certification is awarded by an accredited certification body, not by a consultant. Our job is to build and audit the system so that when the certification body arrives, it passes.
How long does it take?
Three to six months for most small and medium organisations, and the range matters in both directions. Anything shorter is usually rushed: the system has to actually run for a while before there is enough evidence to audit, and no amount of consulting speeds up that part. Anything much longer and the project starts to lose momentum, which in our experience derails more certifications than any technical problem. A tight scope in an organisation with decent existing security habits sits at the shorter end. A wide scope starting from very little sits at the longer end.
What does it cost?
There are two separate bills and it helps to see them apart. There is consultant support to design and implement the system, which typically runs roughly $5,000 to $25,000 depending on scope. Then there is the certification body’s own fee for the two-stage audit, which they set according to your size, scope and number of sites.
Taken together, most small to medium businesses land in the region of $15,000 to $30,000. Our ISO 27001 certification cost guide sets out the full 2026 breakdown. We would rather give you a realistic figure once we know your scope than publish a number that turns out to be wrong for you.
Government funding for ISO certification
Grants may be available to help with the cost of ISO 27001 certification. Funding is usually offered through broader programs covering cyber security and digital uplift, business capability or industry modernisation, where certification counts as eligible expenditure. Our guide shows how to search the free business.gov.au Grants and Programs Finder for programs your business may be eligible for.
Government Grants & Funding for ISO Certification (AU) →ISO 27001 certification in Australia: who needs it?
Almost nobody pursues ISO 27001 unprompted. In our experience, across Australian organisations, the requirement arrives from one of five places.
A customer or a prospect has asked for it. This is the most common by a wide margin, and it usually arrives as a line in a contract, a security questionnaire or a tender. What exactly they asked for is worth pinning down, and we come back to that below.
You are bidding for work you cannot currently reach. Government, financial services, health and enterprise procurement increasingly treat certification as a pass or fail gate. The certificate does not win the work, but its absence stops you competing for it.
You hold data that would hurt you to lose. Some organisations arrive here on their own, usually after an incident or a near miss, or because a director asked a question that nobody in the room could answer.
You need one credential that travels. If you sell into several markets, ISO 27001 is the most widely recognised internationally, which is why it appears in contracts more often than the alternatives.
You believe in it. A small percentage, in our experience, and usually the best clients to work with. Nobody forced the issue. They want their systems assessed independently against an established framework, by someone with no stake in the answer, because they think that discipline makes the organisation better. If that is you, the certificate is almost incidental. The value is in the assessment.
On whether small companies and startups can do this: yes, and often faster than large ones, because the scope is smaller and there are fewer people to bring along. Size affects effort, not eligibility.
Be clear about what you need
If a customer, tender or contract prompted the project, read the requirement carefully before committing to certification. If you are pursuing information security improvement voluntarily, start by defining the outcome you want. ISO 27001 certification, Essential Eight maturity, SOC 2, TISAX and broader security advisory work solve different problems and produce different forms of assurance.
- A clause naming ISO 27001. That is this page. It means a certificate issued by an accredited certification body, and the work described above is what it takes to earn one.
- An Essential Eight maturity level. A different framework, and not a certification. If a tender named a level, start with Essential Eight assessment and uplift.
- SOC 2. An attestation report rather than a certification, and usually asked for by buyers in North America. See SOC 2 readiness.
- TISAX. The automotive supply chain’s own assessment, and not interchangeable with the others. See TISAX readiness.
- A security questionnaire with no framework named. Common, and often the answer is not certification at all, or not yet. Cyber and information security advisory covers the work that gets you through the questionnaire.
These frameworks share a common core, so building more than one together costs less than bolting the second on later. If you are bringing AI into the business, ISO 42001 is designed to integrate with your ISMS and shares the same structure.
Holding personal information: yours or someone else’s
There are two ways a business ends up holding personal or confidential information, and both create an obligation. You may hold it directly, given to you by your own customers, patients or members. Or you may hold it as a service provider, on behalf of someone else’s customers.
Our ISO 27001 clients have one thing in common, and it is not their industry. Business process outsourcers running functions for larger organisations. Debt collectors holding financial and contact details on people who never chose to deal with them. Medical practices and allied health providers sitting on patient records. Software and managed service providers whose platforms hold their clients’ data. Some hold their own customers’ information, some hold someone else’s, and several do both. Either way, that custodianship is the point at which someone starts asking how you manage it.
The obligation does not distinguish between the two. Australian Privacy Principle 11 requires reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. APP 11.3, added by the 2024 Privacy Act reforms, makes explicit that those reasonable steps include technical and organisational measures. It applies to personal information held after 11 December 2024, regardless of when it was first collected, and what counts as reasonable is scaled to your size and resources, the sensitivity of the information and the risk of harm if it is compromised.
Outsourcing does not move the obligation along. Using a cloud or third-party provider does not transfer your APP 11 obligations, and you are expected to manage those providers. That is why the questionnaires travel down a supply chain: whoever collected the information is still answerable for it. The OAIC benchmarks security against the AS/NZS ISO/IEC 27000 series, and asks whether cloud providers are certified to it.
Certification is not an automatic tick of legal compliance, but it is a recognised, independently audited way to show you have taken the technical and organisational measures APP 11.3 expects, and it is the shortest answer you can give. Our article on securing personal information under APP 11.3 sets out how the standard maps to the principle.
Where projects come unstuck
These five things account for most of the trouble we see on ISO 27001 projects. Sometimes we are involved early enough to design around them. Just as often we meet them when an organisation asks us to review a system that is already in place and not working as well as it should. Either way they are worth knowing before you start, because every one of them is easier to avoid than to unpick later.
The scope is wrong. Drawn too tight and the certificate does not answer the question your customer was actually asking, which means doing it again properly in eighteen months. Drawn too wide and the project becomes slow and expensive for no security benefit. Arguing this out properly at the start is the highest-leverage hour in the whole engagement.
The Statement of Applicability is a tick-list. The standard expects the controls you mark applicable to be the ones you selected because they treat risks you actually identified. On most systems we review, the risk register and the Statement of Applicability were built separately and have never been reconciled. An auditor finds this quickly, by picking three applicable controls and asking which identified risk each one treats. We have written up how that gap forms and how auditors find it in detail.
The system was written but never operated. Documentation on its own produces no evidence. Stage 2 audits sample records. A policy nobody follows generates nothing to sample, and that gap is precisely what the auditor is looking for.
Suppliers were left out. Most organisations’ real exposure sits in services they do not run themselves. A scope that does not acknowledge your cloud providers and subcontractors is describing a different organisation from the one your customer is assessing.
There is no project plan. This is the quiet one, and it derails more projects than any technical failure. Without a schedule naming the key dates and milestones, timelines creep and the project loses momentum, the internal audit and management review get left too late, and the certification body cannot fit you in when you are finally ready.
We produce a project plan at the start and share it with your certification body, so they can schedule Stage 1 and Stage 2 around your actual milestones rather than a guess. Dates can still move, and often do, but everyone stays across where the project really is instead of discovering a problem in the last fortnight.
Building your ISMS with your own team or AI?
ISO 27001 mentoring gives your people expert guidance through the build and the independent internal audit (clause 9.2) you cannot run in-house, so your ISMS genuinely conforms and certifies first time, without full-consultancy cost.
See how mentoring works →Three ways to get there with Streamline
- We build it. End-to-end ISMS development and implementation, with the scope argued out properly at the start and the Statement of Applicability derived from your actual risk assessment.
- You build it, we mentor. ISO mentoring for teams building in-house or with AI tools, so the system stays genuinely in your own hands.
- You have built it, we check it. An independent internal audit or a certification readiness review confirms you will pass before you book the audit.
A full build runs in the order set out above. Every step leaves you with something you keep, and every step needs something from you: your existing documents, a few hours with the people who do the work, and the contract clause or tender that started this, because it decides the scope.
At handover you have a working management system in your own hands, the evidence trail behind it, and people who understand why each part of it is there. The same applies to a transition plan if you are moving an existing system to the current version of the standard.
Why Streamline
You work directly with an experienced information security auditor who knows exactly what certification bodies look for. We are ISO consultants across Australia, covering Brisbane, Sydney, Melbourne and remote, and independence matters: we prepare you for certification, and the certification body audits the result.
Certification isn’t the expensive option. Incidents are.
The OAIC recorded 1,205 notifiable data breaches in 2025, the highest since the scheme began. Only 716 were malicious or criminal. The other 489 were not attacks at all: human error, misconfiguration, access that was never revoked. Weigh the certification figure above against that, not against zero.
What poor quality and incidents really cost →Common questions
How does ISO 27001 compare to SOC 2?
Different instruments. SOC 2 is an attestation report written about you by a licensed accounting firm against the AICPA trust services criteria, and it is more common in the United States. ISO 27001 is a certifiable standard, audited by an accredited certification body, and it is the one named most often in Australian and international contracts. If a customer asked for one specifically, get that one. Our ISO 27001 vs SOC 2 comparison goes into the detail.
Can we use our Essential Eight work?
Yes, and it is not wasted. The Essential Eight is a set of prescriptive technical mitigations from the Australian Signals Directorate, and it maps well onto the technological controls in Annex A. It will not cover the organisational, people and supplier controls, or any of the management system clauses, and there is no certificate attached to it. See Essential Eight vs ISO 27001.
Do we have to implement all 93 controls?
No. You have to address all 93 in your Statement of Applicability, saying whether each one applies and why. Justified exclusions are entirely normal. A Statement of Applicability with no exclusions usually means nobody made a decision.
Who issues the certificate?
An accredited certification body, independent of us. We build and audit the system, they certify it. See ISO certification bodies in Australia if you need to choose one.
Where do we start?
Usually with a gap analysis against the standard, so you know what you already have before committing budget. If a customer has given you a deadline, tell us what it is and we will tell you honestly whether it is achievable.
Not sure what your customer is actually asking for?
We are happy to have a free chat by Teams, Zoom or phone, read the clause they sent you and tell you what it does and does not require. No obligation and no sales pitch.
Book a free consultation →Ready to get started?
Tell us where you are starting from and we will map a realistic path to ISO 27001 certification. Send us the clause or the questionnaire you have been asked to answer and we will tell you what it actually requires. If ISO 27001 is the right answer, we will set out what the build looks like for your scope and what it asks of your people.
Talk to an ISO 27001 consultant
Email hello@streamline.business, or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.
Book a free consultation →










