ISO/IEC 27001 is the international standard for an information security management system (ISMS): a documented, audited process for identifying information security risks and controlling them, not a single product or checklist. A business seeking certification defines the scope of what the ISMS covers, runs a formal risk assessment, applies controls proportionate to those risks (drawn from the standard's Annex A control set), and has the result independently audited by an accredited certification body. Certification is not permanent. It runs on a three-year cycle: an initial two-stage audit, then annual surveillance audits to confirm the ISMS is still operating, and a full recertification audit at the end of the cycle.
What is ISO 27001?
Published 3 September 2026 · Reviewed 3 September 2026 · By Steven MoreySteven Morey has spent 27 years in digital, leading marketing and sales for technology businesses in Australia and the US. Through Opollo, his MSP marketing agency, he's run thousands of campaigns for hundreds of managed service providers. That's where the pricing questions in these guides come from.
Who asks for it
In Australia, ISO/IEC 27001 most often comes up in security questionnaires from enterprise or government clients, cyber insurance applications, and as a prerequisite in tenders that involve handling sensitive data. A managed IT provider that holds it has had its own internal security practices audited, separately from any security work it does for clients.
What certification does not mean
A certificate is scoped to specific services, and sometimes specific offices, not automatically the whole business. It also proves that a process exists and was followed at audit time, not that a breach can never happen. See how to verify an ISO certificate for what to actually check before relying on one.