Black Shard

ISO 27001 readiness in Australia.

ISMS scoping, an Annex A gap analysis, a Statement of Applicability, and the policies, risk register and operating records an accredited auditor samples at stage two.

ISO/IEC 27001 certifies that an information security management system exists, operates, and is independently audited. Stage one of the audit reviews the documentation; stage two samples the records of the system in operation.

Readiness work starts with the current environment. The management system is scoped, risk is assessed against that scope, each Annex A control is identified as met, partial or missing, the gaps are prioritised against the audit date, and the management machinery is started early enough to have generated records by the time the auditor samples them.

What ISO 27001 certifies

ISO/IEC 27001 is the international standard for information security management systems. The clauses that carry the certification are the management ones: you define the scope of the ISMS, establish a risk assessment and treatment method, set objectives, assign roles, run internal audits, and hold management reviews. Annex A supplies the reference control set; the certificate attaches to the management system that selects, operates and reviews those controls.

The 2022 revision reorganised Annex A into 93 controls across four themes, organisational, people, physical and technological, down from the 114 of the previous edition, and added eleven that did not previously exist as named controls, among them threat intelligence, information security for use of cloud services, ICT readiness for business continuity, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. The transition window for certificates issued against the older edition closed on 31 October 2025, so any certificate live now is a 2022 certificate.

Certification is an audit in two stages. Stage one reviews your documentation and readiness. Stage two audits the system in operation, sampling records to test whether what is documented is what happens. After that, surveillance audits run each year and recertification on a three-year cycle, so the elapsed time is set by the certification body's calendar as much as by how fast gaps close.

What readiness work involves

The first decision is scope. Scope too wide and the whole organisation is committed to machinery it does not need; scope too narrow and the certificate does not answer the question the buyer is asking. Scope is set by which information, which systems, which locations and which people sit inside the boundary, and each of those choices has to hold up under an auditor's questioning.

From there the work is risk assessment against the scoped system, control selection justified in the Statement of Applicability, and the gap between what Annex A expects and what the environment does today. That gap is where the engineering sits: access control that is enforced, logging that is retained and reviewed, secure development practices visible in the pipeline, supplier management that reflects who touches your data.

Documentation is produced from the operating system: the information security policy, the risk assessment and treatment methodology, the risk register, the Statement of Applicability, the topic-specific policies the selected controls require, and the records the clauses demand, meaning internal audit results, management review minutes, corrective actions, and competence evidence.

  • Scoping of the Information Security Management System, with the boundary defensible under questioning
  • A gap analysis against Annex A controls, assessed against each environment as it runs
  • A Statement of Applicability that justifies every inclusion and every exclusion
  • Core policies and the documentation an auditor expects, written to your organisation
  • A risk register and treatment plan maintained after certification, because surveillance audits sample it

The evidence problem, and why timing decides it

Stage two is an evidence audit. The auditor samples: the last internal audit, the management review that considered it, an access review from this quarter, a change that went through the process, the risk register moving. A management system switched on three weeks before the audit has no records to sample, and records cannot be backdated.

That is the most common reason a readiness program runs late. The controls close on an engineering schedule. The management cycle does not compress: an internal audit and a management review have to have happened, and the operating records have to have accumulated, before anyone can audit them.

So the program is sequenced backwards from the audit date. The machinery that needs elapsed time starts first, while gaps are still open, so the records build while remediation runs. Everything else is scheduled against that spine.

Where we sit, and where we do not

We prepare organisations for certification. We do not certify them: certification is issued by accredited certification bodies, and a firm that did the readiness work cannot audit its own work.

The firm's own certification and self-assessment position is on our trust page. What we bring is the engineering half of the problem, which is where readiness programs usually stall. Control gaps are configuration, code and process changes in live systems, and the firm designs, builds and operates production software. A control is recorded as closed when the evidence exists.

ISO 27001 or SMB1001: which certificate do you need?

Answer the question your buyer is asking. ISO 27001 is what enterprise and government procurement names in contract clauses, and it is the standard recognised offshore. It is also the heavier of the two: certification-body fees at the initial audit, surveillance fees annually, and the standing internal cost of operating a management system.

SMB1001 is the Australian tiered standard sized for smaller businesses, certified through CyberCert and listed on a public registry. At Gold a director formally attests against the standard's twenty-seven controls. It answers an Australian buyer quickly and verifiably, and it carries little weight offshore.

The two are not a hierarchy, and the control work overlaps enough that neither is wasted if you later need the other. Our comparison page sets them side by side on assessment model, effort, cost shape, recognition and maintenance.

What does ISO 27001 readiness cost?

Readiness runs as a defined program with milestones toward your audit date, and the quote comes before the work. The drivers are the scope, meaning how many systems, environments, locations and people sit inside the ISMS boundary; the starting position, meaning how much documented process, risk management and access governance already exists; the gap depth, meaning how much of Annex A is a configuration change and how much is a system that has to be built; the runway, meaning whether the audit date leaves time for the management cycle to generate records; and whether we execute remediation hands-on or hand your team a plan to execute. Certification-body fees are separate and paid to the certification body directly; they recur, so budget for them early.

Send a brief with your target audit date, the rough shape of the scope you have in mind, and who is asking you for the certificate.

Questions, answered

How long does ISO 27001 certification take?
The constraint is rarely the gap-closing work. The management system has to operate long enough to produce the evidence stage two samples: an internal audit, a management review, access reviews, a risk register that visibly moves. We sequence the elapsed-time machinery first so it accumulates records while remediation runs, and we say early if a target date does not leave room for it.
Can Black Shard certify us against ISO 27001?
No. Certification is issued by accredited certification bodies after a stage one documentation review and a stage two audit of the system in operation, and a firm that did the readiness work cannot audit its own work.
What is the Statement of Applicability?
The document that records which Annex A controls apply to your ISMS, which do not, and the justification for each decision. Auditors read it closely because it is where a scope drawn to avoid work becomes visible. It is written once and maintained thereafter.
Do we need ISO 27001 if we already hold SMB1001?
Only if your buyers ask for it. SMB1001 answers an Australian buyer quickly and is publicly verifiable; ISO 27001 is what enterprise and offshore procurement names in contracts. The underlying control work overlaps substantially, so holding one reduces the work for the other.
What changed in the 2022 revision?
Annex A was reorganised into 93 controls across four themes and eleven new controls were named, including threat intelligence, security for cloud services, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. The transition window for older certificates closed on 31 October 2025.
Can you do the remediation, or only tell us what is wrong?
Both. The firm builds and operates production software, so control gaps that are configuration, code or pipeline changes can be closed hands-on. Where you have an internal team or a provider, we hand over a plan precise enough to execute and verify the work at each milestone.
Do you work with organisations outside Brisbane?
Yes. An Australian firm, head office in Brisbane, delivering Australia-wide. Readiness work is largely remote by nature: scoping, gap analysis against cloud tenancies and directories, documentation, and the management cycle all run without anyone travelling.

Tell us the audit date and the scope you have in mind.

Brisbane head office. Work delivered across Australia.

Open a brief[email protected]