Customer or tender asking for ISO 27001?
No obligation. We call you within one business day. Your details stay with us, never shared or sold. Prefer to talk now? Call 02 9099 1735.
2000+
companies certified - over our 20 years of operation
100%
first time audit pass rate, backed by our money-back guarantee
JAS-ANZ
your certificate is issued by a Tier 1 categorised Australian JAS-ANZ accredited certification body - same as the one we certified Samsung with




Week 1
Gap Analysis and scope agreed. We map what is missing.
Week 2
We write your policies and build the ISMS around how you work.
Week 3
Controls put in place, staff briefed, internal audit run.
Week 4
Certification audit. We are in the room with you.
| Comparison | The ISO Council | Compliance software | Typical consultant |
|---|---|---|---|
| Who does the work | We do 95% of it. | You have to do it yourself. | They mostly advise and guide. You write documents. |
| Hours from your team | About 1 hour a week. | Several hours a week, ongoing. | Several hours a week for months. |
| Timeline | 4 weeks. | 3 to 6 months. | 3 to 6 months. |
| If you fail the audit | Full refund of our fee. | Yours to fix and fund. | Rework usually billed as extra. |
| Ongoing subscription | None. Fixed project fee. | Annual licence fee. | Often a retainer. |
Your certification body invoices its audit fees separately, including the annual surveillance audits.
“We chose The ISO Council for our ISO 27001 certification and honestly could not believe how straightforward it was. The team did the heavy lifting, and we were certified in under four weeks. No headaches, no drama, just a clear process and a great result”.
Eugene Dagher
Governance and Risk Manager, Zenviron
“The ISO Council delivered exactly what they promised. Our team was flat out with client work and we had almost no capacity to run a certification project internally, but Zain and the team took it off our plate and got us certified in time for our tender submission”.
Margaret Munro
Chief Information Officer, mcrIT
The guarantee is set out in full in our Terms and Conditions.
Four weeks from kickoff to your certification audit, as long as we get the access and approvals we ask for on time. Most of that four weeks is our work, not yours.
About one hour a week. A kickoff session so we understand how you actually operate, answers to specific questions, and one person who can approve documents. We write the policies and build the ISMS.
Typically, ISO 27001 certification is an investment of anywhere from A$10,000 to A$40,000 and up. Where a business lands depends on its industry, headcount, how much sensitive data it holds, how complex its systems are, how much is already in place and how wide the scope is drawn. It also depends on whether you take the software route or use a consultant who does the work for you. Those two price very differently and leave very different amounts of work with your team. Our fee is fixed and agreed in writing before we start. No hourly billing. Your certification body invoices you separately for the audit itself, and we tell you that figure in writing before you commit. Your free Gap Analysis is what turns that range into your number.
An independent certification body accredited by JAS-ANZ issues your certificate, not us. We are consultants. We prepare you, build the ISMS, run the internal audit and attend the certification audit with you.
Your certificate runs on a three year cycle with annual surveillance audits from your certification body, which it invoices separately. We can stay on to maintain the ISMS and take you through those audits.
Find out exactly what stands between you and certification.
Or call 02 9099 1735