Back to ISO 27001

ISO 27001 Certification in Australia: A Practical Guide for SMBs, Startups and HealthTech

ISO 27001 certification Australia illustration: an AS/NZS ISO/IEC 27001 certificate with a map of Australia and a ribbon seal

Short answer: ISO 27001 certification in Australia works the same way as anywhere else: you build an information security management system (ISMS) against ISO/IEC 27001:2022, which Australia adopts identically as AS/NZS ISO/IEC 27001:2023, then pass a Stage 1 and Stage 2 audit by a certification body, ideally one accredited by JAS-ANZ.

Related guides:

Key takeaways

  • Australia does not have a separate ISO 27001 scheme. AS/NZS ISO/IEC 27001:2023 is an identical adoption of ISO/IEC 27001:2022, so a certificate against the international standard is what local buyers expect.
  • Pick a certification body accredited by JAS-ANZ (or another accreditation body in the international recognition arrangements) so your certificate is credible with enterprise and government buyers.
  • Certificates against the 2013 version expired or were withdrawn by 31 October 2025. Any supplier still showing a 2013 certificate is out of date.
  • ISO 27001 sits alongside Australian frameworks, not instead of them. It does not replace the Essential Eight, IRAP, the Hosting Certification Framework or APRA CPS 234, but it gives you the management system that makes all of them easier.
  • For most Australian SMBs, startups and SaaS companies the pull comes from enterprise procurement and security questionnaires, especially in financial services, health and government supply chains.

Is there an Australian version of ISO 27001?

Yes, but it is the same standard: AS/NZS ISO/IEC 27001:2023, a joint Australian and New Zealand adoption of ISO/IEC 27001:2022.

According to the AS/NZS ISO/IEC 27001:2023 listing on Intertek Inform, Standards Australia's distribution platform, "AS/NZS ISO/IEC 27001:2023 identically adopts ISO/IEC 27001:2022." The same listing identifies it as a joint standard of Standards Australia and Standards New Zealand. That explains the prefix change: the previous edition, AS ISO/IEC 27001:2015, was an Australian-only adoption ("AS") of ISO/IEC 27001:2013, while "AS/NZS" marks a joint trans-Tasman standard. Intertek Inform lists the 2015 edition as superseded by AS/NZS ISO/IEC 27001:2023 from 29 May 2024.

What this means in practice:

  • You implement the clauses and Annex A controls of ISO/IEC 27001:2022. The 2022 Annex A control set, which mirrors ISO/IEC 27002:2022, has 93 controls grouped into four themes (organisational, people, physical and technological), down from 114 in the previous version, according to BSI's summary of ISO/IEC 27002:2022.
  • A tender asking for "AS/NZS ISO/IEC 27001" is answered by a current ISO/IEC 27001:2022 certificate from an accredited body.

The 2022 transition deadline has passed

The International Accreditation Forum's mandatory document IAF MD 26 set a three-year transition period ending 31 October 2025. Under that document, "all certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of the transition period." First-time certifications now go straight to the 2022 version, and any supplier's 2013 certificate should be treated as no longer valid.

Who asks for ISO 27001 in Australia?

Mostly enterprise customers and their procurement teams, while government and regulators usually ask for their own frameworks and accept ISO 27001 as supporting evidence.

ISO 27001 is generally not a legal requirement in Australia. It is a market requirement that shows up in tenders, vendor risk questionnaires and contract schedules. The table shows the common drivers and what each one asks for.

Driver Who it applies to What they ask for Where ISO 27001 fits
Enterprise and mid-market buyers B2B SaaS, IT services, outsourced providers Security questionnaire, evidence of an ISMS, often a named certification A current certificate can answer many questionnaire items, though buyers decide how much they accept
APRA-regulated entities (banks, insurers, super funds) Their service providers that manage information assets Evidence that the provider's information security capability is adequate under CPS 234 Strong evidence, but the regulated entity still does its own assessment
Commonwealth agencies hosting data Data centre and cloud providers serving government directly Hosting Certification Framework certification, often supported by an IRAP assessment against the ISM Helpful foundation, not a substitute for HCF or IRAP
Commonwealth agencies (internally) Non-corporate Commonwealth entities Essential Eight, with Maturity Level Two as the mandatory baseline under the PSPF, per ASD's Essential Eight FAQ Suppliers may be asked how they support the agency's Essential Eight posture
Health sector Health service providers and HealthTech vendors handling health information Privacy Act compliance (health service providers are covered regardless of turnover), security questionnaires from hospitals and health networks Common way to show a mature security program to health buyers
Privacy-sensitive customers Any business holding personal information APP 11 "reasonable steps" to protect personal information, breach readiness An ISMS gives you documented, auditable reasonable steps

A few clarifications on the government rows, because they are often misreported:

  • The Hosting Certification Framework (HCF) was created by the Digital Transformation Agency and moved to the Department of Home Affairs in a machinery-of-government change on 1 May 2023, according to the HCF website. It currently applies to data centre and cloud service providers that host services directly for Australian government customers, with Strategic and Assured certification levels. The HCF application readiness guide notes that an IRAP report can be used as evidence. It does not list ISO 27001 as a requirement.
  • IRAP (the Infosec Registered Assessors Program) is run by the Australian Signals Directorate. ASD's IRAP assessor guidance describes assessors working against ASD's Information Security Manual (ISM), not ISO 27001.

If you host government data, plan for HCF and IRAP separately.

How does ISO 27001 fit with Essential Eight, the Privacy Act and CPS 234?

ISO 27001 is the management system, and the Australian frameworks are mostly control sets or legal obligations you can run inside it.

Essential Eight. ASD's Essential Eight is a set of eight technical mitigation strategies with maturity levels. It is prescriptive about controls like patching, MFA and application control, but it does not ask for a management system. ISO 27001 is the opposite: it requires risk-based governance but lets you choose controls. Many Australian companies map Essential Eight controls into their ISO 27001 Statement of Applicability and use their risk assessment to justify a target maturity level.

Privacy Act and the APPs. The OAIC states that businesses with annual turnover of $3 million or less are currently generally exempt (reform has been proposed), but health service providers and Commonwealth contractors, among others, are covered regardless of turnover. APP 11 requires reasonable steps to protect personal information. ISO 27001 does not make you Privacy Act compliant on its own, but your ISMS risk assessment, access controls and incident procedures are exactly the evidence you would point to.

APRA CPS 234. CPS 234 commenced on 1 July 2019. It requires regulated entities to evaluate the information security capability of third parties that manage their information assets, to notify APRA of material incidents no later than 72 hours after becoming aware, and to notify material control weaknesses within 10 business days. If you sell to a bank, insurer or super fund, your certificate is useful evidence for their third-party assessment. The APRA CPS 234 checklist breaks down the requirements.

The practical lesson: build one ISMS and one control library, then map these expectations onto it.

How do you choose a certification body in Australia?

Choose a certification body accredited for ISO/IEC 27001 by JAS-ANZ, or by another accreditation body that is part of the international recognition arrangements, and confirm the accreditation covers your scope.

The Joint Accreditation System of Australia and New Zealand (JAS-ANZ, also styled JASANZ) was established under a treaty between the two countries on 30 October 1991, according to New Zealand's Ministry of Business, Innovation and Employment. It accredits conformity assessment bodies such as certifiers, and it maintains a public register of accredited bodies at register.jasanz.org.

When shortlisting auditors, check:

  1. Accreditation status. Search the JAS-ANZ register for the body and confirm ISO/IEC 27001 is in its accredited scope.
  2. Sector experience. Ask about their SaaS and HealthTech audit experience.
  3. Independence. The body that certifies you should not also have built your ISMS.
  4. Audit logistics. Confirm remote audit options and how they handle sites across states or overseas.

What are the steps to ISO 27001 certification?

The steps are the same in Australia as anywhere else: build and run your ISMS, then pass the certification body's Stage 1 and Stage 2 audits and keep the certificate current through surveillance audits. Our ISO 27001 certification steps explained guide covers each step in detail. The Australian-specific points to plan for are:

  • Scope and interested parties. List local obligations alongside customer contracts: the Privacy Act and APPs, CPS 234 requirements passed down by financial services customers, and any Essential Eight target a government or regulated buyer has set.
  • Statement of Applicability. If Essential Eight strategies are in scope, map them to the relevant Annex A controls here so one set of evidence supports both.
  • Certification body. Confirm the body is JAS-ANZ accredited for ISO/IEC 27001 before you sign, as described above.
  • Certificate wording. Check whether your buyers expect the certificate to reference AS/NZS ISO/IEC 27001:2023 or ISO/IEC 27001:2022. The content is identical, but procurement teams sometimes ask.

ISO 27001 or SOC 2?

The right choice depends on who your buyers are: ask what they accept. US customers commonly ask for SOC 2, while ISO 27001 is an international standard that buyers outside the US often request.

If your pipeline includes US enterprise buyers you may need both. Our SOC 2 vs ISO 27001 comparison explains the differences in detail.

How SecureSlate helps

SecureSlate helps Australian SMBs, startups and HealthTech teams prepare for ISO 27001 certification without a large compliance team. Keep your risk register, Statement of Applicability and control evidence in one place, use policy templates, and run automated evidence collection from your cloud and SaaS stack. A single control library is mapped across frameworks, and you can track the Essential Eight as a framework and CPS 234 or Privacy Act expectations as custom frameworks. Internal audit and management review cycles are tracked alongside your controls as you prepare for Stage 2 and surveillance audits.

Start your free SecureSlate trial

FAQ

Is ISO 27001 mandatory in Australia?

Generally no. There is no broad law requiring Australian businesses to hold ISO 27001. It is usually required by contract or tender, especially by enterprise, financial services and health sector buyers. Regulated sectors have their own obligations, such as APRA CPS 234 and the Privacy Act, which ISO 27001 helps you evidence.

What is the difference between ISO/IEC 27001 and AS/NZS ISO/IEC 27001?

There is no difference in requirements. AS/NZS ISO/IEC 27001:2023 is the joint Australian and New Zealand identical adoption of ISO/IEC 27001:2022. It superseded the Australian-only AS ISO/IEC 27001:2015, which adopted the 2013 international version.

Does an ISO 27001 certificate satisfy the Essential Eight or IRAP?

No. The Essential Eight is a separate ASD maturity model, and IRAP assessments test systems against the Information Security Manual. Many controls overlap, but government buyers assess them separately.

Do Australian startups need a JAS-ANZ accredited auditor?

It is strongly recommended. Buyers generally expect certificates from an accredited certification body, and JAS-ANZ is the accreditation body for Australia and New Zealand. Check the JAS-ANZ register before you sign an engagement.

Is my ISO 27001:2013 certificate still valid?

No. Under IAF MD 26, all ISO/IEC 27001:2013 certifications expired or were withdrawn at the end of the transition period on 31 October 2025. You need a certificate against the 2022 version.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

Keep reading

Oct 1, 2026 · ISO 27001

ISMS-P Certification: A Guide for SaaS and HealthTech Vendors Entering South Korea

Jul 7, 2026 · TemplatesISO 27001

ISO 27001 Statement of Applicability Template: Free SoA Excel Download

Jul 5, 2026 · ISO 27001

ISO 27001 Consultant vs Compliance Automation Platform: Which Is Right for You?

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?