ISO 27001 · Delivered Remotely · Australia · US · UK
ISO 27001 certification — without buying a third-party GRC platform.
We deliver ISO 27001 inside your existing Microsoft 365 environment, on Checkpoint — our own console, included in the engagement. Fixed-price, audit-ready in 10–14 weeks, and a 100% first-time pass rate across every client we've certified. No Vanta, no Drata, no Secureframe — and no annual licence fee waiting for you in year two.
- 10–14 weeks
- Fixed-price
- 100% first-time pass
- $0 third-party platform fees
Same certificate. Different economics.
Most ISO 27001 consultants will tell you that getting certified means buying a third-party GRC platform — Vanta, Drata, Secureframe, or one of the Australian alternatives. Then they'll spend three months configuring it, train your team on yet another tool, and bill you for both. We don't — we deliver on Checkpoint, our own console, included in the engagement.
Typical path
Consultant + third-party GRC platform
- Consultant fees for ISMS build
- $15–60k/year GRC platform licence
- New tool for your team to learn
- Evidence locked inside platform vendor
- Licence cost compounds across surveillance years
3-year cost (mid-market):
~$135k
Our approach
Senior consultant, M365-native
- Fixed-price ISMS build, no overruns
- $0 in third-party platform licences
- Evidence lives in SharePoint where your team already works
- Controls enforced via Entra, Intune, Defender, Purview
- Surveillance audits typically 80%+ cheaper than year one
3-year cost (mid-market):
~$60k
~$75k saved
Figures based on typical mid-market scope (50–200 staff). Precise estimate confirmed on call.
What's included in the engagement
Every ISO 27001 engagement covers the same scope, from kickoff through to certificate. Fixed-price, milestone-gated, no upsells.
Scoping & gap analysis
Weeks 1–2. We define what's actually in scope (and just as importantly, what isn't), review your current M365 environment, and produce a gap analysis against every Annex A control with concrete remediation actions.
Risk register & SoA
A risk register populated with real risks (not framework template placeholders), each with likelihood, impact, owner, and treatment direction. Statement of Applicability mapping every Annex A control to your environment with justification. On Checkpoint, a posture scan proposes status for 19 of the 93 controls directly from live Microsoft 365 signal — you confirm or dismiss, nothing writes itself.
Policy framework
Information security, access control, asset management, incident response, supplier security — all written specifically for your environment, not generic templates. Reviewed and approved through your normal governance process.
Control implementation
Conditional Access policies in Entra. Endpoint policies in Intune. DLP and information protection in Purview. Backup, logging, monitoring. Every control built directly inside your existing M365 environment with ring-based deployment.
Evidence pack & ISMS
Evidence captured at the point of change — Power BI dashboards from M365 audit logs, SharePoint libraries with retention and approval workflows. By certification you have months of operating evidence, not a frantic scramble.
Internal audit & certification support
Full internal audit including dress rehearsal of the external audit. We support you through Stage 1 documentation review and Stage 2 operational audit, on call for assessor questions and additional evidence requests.
What your deliverables look like
Everything lives inside your Microsoft 365 tenant — not a third-party platform. Here's what a typical Risk Register and Statement of Applicability look like inside SharePoint.
Risk Register — SharePoint List
Statement of Applicability — ISO 27001 Controls
19 Annex A controls — access control, monitoring, malware protection, device and vulnerability management — get their status proposed automatically. The physical security and organisational/HR process controls need a human either way.
A typical 12-week timeline
Compressed for under-50-staff scope, extended for 500+ staff. Most mid-market engagements land in this range.
Weeks 1–2
Assess
Scoping interviews, environment review, gap analysis, risk register draft, fixed-price proposal for remaining phases.
Weeks 3–8
Implement
Policy framework, control implementation, SoA finalised, evidence capture automation, training rollout.
Weeks 9–10
Internal audit
Full internal audit and dress rehearsal of the external audit. Any findings remediated before booking certification.
Weeks 11–12
Certify
External certification audit (Stage 1 + Stage 2). We support throughout. Certificate issued on successful completion.
ISO 27001 certification — what's different by region
The standard is global but the context is local — regulatory drivers, procurement requirements, and which accreditation body signs off all vary by where you're certifying.
Australian Privacy Act alignment
ISO 27001 Annex A controls directly map to Australian Privacy Principles under the Privacy Act 1988. Organisations handling personal information benefit from combining ISO 27001 with ISO 27701, achieving dual assurance from a single evidence set — and preparing for the Privacy Act reforms expected in 2026.
Government & defence procurement
Commonwealth entities, state government contractors, and DISP members increasingly require ISO 27001 alongside Essential Eight. We regularly deliver both frameworks simultaneously — one control set, two compliance outcomes — for organisations in Brisbane, Canberra, and across Australia.
Certification body selection
Australian certification bodies include BSI, Bureau Veritas, SAI Global, and LRQA. All are JASANZ-accredited. We help you choose based on auditor availability, sector expertise, and fees — without the referral arrangement that conflicts some consultants' advice.
ACSC & ASD alignment
The Australian Cyber Security Centre's guidelines and ASD's Information Security Manual share significant control overlap with ISO 27001. For organisations in regulated sectors, we map your ISO 27001 implementation to ACSC best practice simultaneously — no duplicated effort.
Healthcare & APRA-regulated sectors
Healthcare organisations subject to the My Health Records Act, and financial institutions under APRA CPS 234, find that ISO 27001 provides the evidence structure regulators and auditors expect. We've delivered ISO 27001 for health SaaS, pathology providers, and APRA-regulated entities.
Based in Brisbane, national delivery
Compliance365 is headquartered in Brisbane, Queensland, and delivers ISO 27001 engagements across Australia — Sydney, Melbourne, Canberra, Perth, and remote. All work is delivered by senior practitioners, not juniors supervised from offshore.
ISO 27001 is a genuinely global standard — a certificate issued in Australia is recognised the same way in Austin or London. What differs outside Australia is which accreditation body signs off, and which regulatory hooks make the business case.
ANAB and UKAS accreditation
US certification bodies are accredited by ANAB; UK bodies by UKAS — the equivalent of JASANZ in Australia. Several certification bodies (BSI, DNV, LRQA) operate across all three, so the same auditor relationship can often carry across a multinational group. We help you choose based on where your certificate actually needs to be recognised.
NIS2 exposure for UK and EU-adjacent SaaS
The EU's NIS2 directive reaches well beyond EU-headquartered companies — if you sell into the EU supply chain, your customers' own NIS2 obligations increasingly flow down to you contractually. ISO 27001 is the most direct way to answer that requirement with an internationally recognised certificate rather than a bespoke questionnaire response.
US state privacy law overlap
ISO 27001's Annex A controls provide the security backbone that CCPA/CPRA and similar US state privacy laws expect organisations to demonstrate. Combined with ISO 27701, it's the same dual-assurance approach we use for the Australian Privacy Act — one evidence set, not two parallel programmes.
Who this is for
ISO 27001 is the right certification for organisations in one of these situations:
Enterprise procurement is asking
You've had a customer or prospect ask for ISO 27001 in a tender, vendor questionnaire, or contract clause. Their procurement team has it as a tickbox requirement and you need it to keep the deal alive.
You're scaling into regulated markets
Government, finance, healthcare, defence-adjacent sectors. ISO 27001 is the baseline signal that gets you onto the panel or shortlist. Without it, you don't get evaluated.
Your insurer or board is pushing
Cyber insurance renewal is harder than it used to be. Board members want demonstrable evidence that security is governed properly. ISO 27001 satisfies both.
You're consolidating frameworks
You may already have SOC 2 or Essential Eight and want to add ISO 27001 with shared controls and evidence — not three separate parallel programmes. We deliver combined engagements regularly.
Common questions
Answered plainly. If you have a question not covered here, the fastest way to get a real answer is a 30-min call.
How long does it take?
10–14 weeks for most Australian mid-market organisations (50–500 staff). Under-50-staff focused scope can complete in 8 weeks. Enterprise environments (500+) typically take 14–20 weeks.
What does it cost?
Fixed-price, ranging $25k–$130k depending on company size and scope. Includes everything from gap assessment through certification support. Certification body fees ($8k–$25k) are separate and paid directly to your auditor.
Do we need to buy Vanta or Drata?
No. We deliver entirely inside your existing M365 environment, on Checkpoint — included in the engagement. Over three years (cert + two surveillance audits) this typically saves $45k–$180k in avoided third-party platform licence costs.
Will this disrupt our team?
The nominated internal contact typically spends 2–4 hours per week. We work within your existing change management process. Engineering teams don't need to learn a new tool.
What's your first-time pass rate?
100% across all engagements. Two weeks before any external audit, we run an internal dress rehearsal. If we wouldn't pass our own review, we don't book the external one.
Can we combine this with SOC 2 or Essential Eight?
Yes — and this is one of our most common engagements. A single set of controls and evidence can satisfy all three. Combined engagements typically reduce total cost by 30–40% versus running them sequentially.
What if we fail the certification audit?
It hasn't happened — but the mechanism is this: if Stage 1 (documentation review) raises findings, we close them before Stage 2 is booked. If Stage 2 raises minor non-conformities, the certification body gives a window to close them. Major non-conformities are rare and preventable with a proper dress rehearsal, which we run two weeks before every external audit.
What about surveillance audits in years 2 and 3?
ISO 27001 certification runs on a 3-year cycle: initial certification, then annual surveillance audits in years 2 and 3, then recertification. Surveillance audits are lighter than the initial — typically 30–50% of the effort. Because your evidence lives in Microsoft 365 and is maintained continuously, surveillance prep is hours not weeks. Existing clients get preferential rates on surveillance support.
Real ISO 27001 results
Two recent certifications — both first-time passes, both unlocked revenue.
ISO 27001 in 12 Weeks — Seed-to-Series-A FinTech
Brisbane B2B payments fintech was losing enterprise deals at the security questionnaire stage. Certified in 12 weeks inside M365. Two contracts worth $620k ARR signed within 30 days.
Read case study →SOC 2 Type II + ISO 27001 from a Single Evidence Set
Melbourne network provider needed ISO 27001 for Australian procurement and SOC 2 for US expansion simultaneously. Both delivered in 14 weeks — AUD $4.2M in contracts unlocked.
Read case study →Related frameworks
ISO 27001 is often the foundation. Most clients add one or two related frameworks with shared controls and evidence.
Get a realistic scope in 30 seconds
Three questions. Instant estimate including the third-party platform licence costs you'll avoid. No sign-up.
Estimate based on typical engagement patterns. Precise scope confirmed on call after reviewing your environment.
Keep reading — ISO 27001
Guides, checklists and case studies
Ready to scope your ISO 27001 engagement?
A free 30-minute call gives you a precise scope, realistic timeline, and a fixed-price quote. No sales pitch. If you don't need us yet, we'll tell you.