Certify HubFree quote
Data centre aisle lined with server racks

Independent certification of the way your business protects information.

Certification to ISO/IEC 27001:2022, issued through a JAS-ANZ accredited conformity assessment body and maintained through annual surveillance.

Verified protection for the data you hold.

ISO/IEC 27001:2022 is the international standard for information security management systems. Certification confirms that your business identifies its information risks, applies proportionate controls and keeps them working, verified by independent audit.

Client and business data protected

An ISMS built to ISO/IEC 27001:2022 covers the information that matters: client records, financial data, credentials, intellectual property and the systems that hold them. Risks are assessed, controls are selected from the standard's control set and evidence is kept that each control operates as intended.

Entry to government and enterprise supply chains

Government agencies and large enterprises increasingly require ISO 27001 certification from suppliers that touch their data. A current certificate satisfies that requirement, answers lengthy security questionnaires with one verifiable document and keeps your business eligible for work where certification is an expected condition of supply.

A stronger cyber insurance position

Insurers ask detailed questions about security controls before writing or renewing cyber cover. A certified ISMS gives your broker audited answers: documented controls, tested incident response and independent verification. That changes the quality of the conversation about premiums, excesses and the conditions attached to your policy.

Trust customers can verify

Certification gives customers an independent basis for trusting you with their information. The certificate is issued through a JAS-ANZ accredited body and your listing on the JAS-ANZ register is publicly searchable, so a prospective client can verify your security credentials before the first meeting.

Audits that engage with your systems

ISO 27001 audits examine architectures, logs and control evidence directly, so audit findings engage with how your technology actually operates and the report is useful to the people who run it.

Fibre patch cables connected to a network panel in a dark server rack

Four steps to a Certificate of Confidence.

ISO 27001 certification follows the same Stage 1 and Stage 2 pathway as every standard we certify, coordinated end to end by your Practice Manager.

Stage 1 audit

A pre-certification audit reviews your management system against ISO/IEC 27001:2022. Any Areas of Concern are reported clearly, so you know exactly what needs attention before Stage 2.

Areas of Concern actioned

You address each reported concern, with your Practice Manager as the single point of contact for questions, scheduling and progress along the way.

Stage 2 audit

An on-site certification audit assesses the system in operation. On a successful result, Equal Assurance, a JAS-ANZ accredited conformity assessment body, issues your Certificate of Confidence and lists your business on the JAS-ANZ register.

Annual surveillance

The same auditor returns each year to confirm the system remains effective and certification stays current, with findings that build on a working knowledge of your business.

For any business that holds data someone else values.

ISO 27001 suits managed service providers, software businesses, professional firms holding client files, health and financial services providers, and any supplier into government or enterprise environments where certification is expected. Certify Hub audits companies from Brisbane across Australia and internationally.

Works alongside other standards

ISO 27001 shares its management system structure with ISO 9001, and businesses holding a quality certification already have much of the framework in place. The two standards can run as one integrated system with combined surveillance audits, which keeps effort and audit days contained.

Which version of the standard do you certify against?

ISO/IEC 27001:2022, the current edition. Certification to the 2022 edition covers the revised control set in Annex A, so the certificate you present to clients and tender panels reflects the current requirements of the standard.

Who conducts the audits?

The same auditor returns for your annual surveillance audits, building a working knowledge of your environment, and a single Practice Manager coordinates the whole program on your behalf.

Who issues the certificate?

Equal Assurance, an independent Conformity Assessment Body accredited by JAS-ANZ, makes the certification decision and issues a Certificate of Confidence. Your business is then listed on the public JAS-ANZ register, where clients and government buyers verify certification.

How does the process start?

With a free, no-obligation quote. From there the Stage 1 pre-certification audit reviews your ISMS and reports any Areas of Concern, you action them, and the Stage 2 audit completes certification. Annual surveillance keeps it current.

Start your ISO 27001 certification.

A quote for ISO 27001 certification is free and carries no obligation.