Skip to content
Practitioner guideVerified October 2026

ISO 27001 for NZ and Australian SMEs: The Practical Path to Certification

How a New Zealand or Australian SME gets to ISO/IEC 27001:2022 certification without building a bureaucracy: the clauses auditors test, what the Statement of Applicability needs, the four Annex A themes, Stage 1 and Stage 2, and a mapping to SOC 2.

By Krish Pasumarthi, Founder, CybrGenCRISC, CDPSE, ISO/IEC 42001 Lead Auditor

steps and themes
18steps and themes
Annex A controls
93Annex A controls
certification stages
2certification stages
year certificate cycle
3year certificate cycle

How to read each card

Owner tag
Who usually leads it: leadership, the ISMS lead, or IT and engineering.
What the auditor checks
What the certification body looks for, in plain language.
Do this first
The first concrete step.
Evidence produced
The documents and records the auditor will ask for.
Framework mapping
The ISO/IEC 27001:2022 clause or Annex A range, and the nearest SOC 2 criteria.
Watch out
The nonconformity we see most often.

General information, not certification advice. Certification is granted only by an accredited certification body. SOC 2 mappings are CybrGen's practitioner mapping. Annex A references follow ISO/IEC 27001:2022 including Amendment 1:2024.

Stage 01

1. Context and leadership

What does the ISMS cover, and who is directing it?

Clauses 4 and 5 set the scope, the policy and the people accountable. Everything else is built on them.

Leadership

Understand your context and interested parties

  • Management system clause

The standard starts by asking what affects your ability to protect information: your market, regulators, customers, suppliers and, since the 2024 amendment, whether climate change is a relevant issue.

What the auditor checks
That internal and external issues and interested parties' requirements are identified, and that they visibly feed the scope and risk assessment.
Do this first
List the issues and interested parties on one page: customers and their contract requirements, regulators such as the Privacy Commissioner, key suppliers, staff and owners. Note climate change and whether it is relevant.
Evidence produced
  • Context and interested parties register
  • Legal, regulatory and contractual requirements list
Framework mapping

ISO/IEC 27001:2022

  • Clause 4.1 Understanding the organisation and its context
  • Clause 4.2 Needs and expectations of interested parties

SOC 2 (2017 TSC)

  • CC3.1 Specifies suitable objectives
Watch out

Since Amendment 1 in 2024, auditors look for a considered position on climate change. A short note on whether it is relevant to information security, and why, is usually enough for an SME.

LeadershipMandatory document: Documented information the standard requires

Set a scope you can defend

  • Management system clause

The scope decides what the certificate covers. Customers will read it, so it must match what they think they are buying from you.

What the auditor checks
A documented scope covering boundaries, locations, products and interfaces with outside parties, consistent with context and risk.
Do this first
Write the scope statement in one paragraph naming the products, teams, locations and supporting systems covered, then test it against the question a customer will ask: does this include my data?
Evidence produced
  • Documented ISMS scope
  • Boundary and interfaces description
Framework mapping

ISO/IEC 27001:2022

  • Clause 4.3 Determining the scope of the ISMS

SOC 2 (2017 TSC)

  • DC 200 Description criteria
Watch out

A scope that is too narrow to be useful, such as excluding the product customers use, is spotted quickly by buyers. Narrow scope saves audit days but can cost deals.

LeadershipMandatory document: Documented information the standard requiresNonconformity hotspot: Where we most often see audit nonconformities

Get leadership commitment, a policy and named roles

  • Management system clause

ISO 27001 is a management system. Auditors will interview leadership, not just the person who wrote the documents, to see that security is directed from the top.

What the auditor checks
An approved information security policy, assigned roles and responsibilities, and leaders who can explain the objectives and their part in the ISMS.
Do this first
Have the leadership team approve a one-page information security policy, name an ISMS owner, and assign each Annex A area to a person who will speak to it at audit.
Evidence produced
  • Approved information security policy
  • Roles and responsibilities matrix
  • Leadership meeting minutes
Framework mapping

ISO/IEC 27001:2022

  • Clause 5.1 Leadership and commitment
  • Clause 5.2 Policy
  • Clause 5.3 Roles, responsibilities and authorities

SOC 2 (2017 TSC)

  • CC1.2 Board oversight
  • CC1.3 Structures, reporting lines and authorities
Watch out

A chief executive who cannot say what the ISMS is for is a common Stage 2 finding. Brief leadership before the audit, not on the morning of it.

Stage 02

2. Risk and the SoA

Which risks matter, and which controls answer them?

Clauses 6 and 8. Risk drives control selection, and the Statement of Applicability records every decision.

ISMS leadMandatory document: Documented information the standard requiresNonconformity hotspot: Where we most often see audit nonconformities

Define a risk method and run the risk assessment

  • Management system clause

Risk drives everything in ISO 27001: which controls you select, which you exclude, and where you spend. The method must give consistent, comparable results when repeated.

What the auditor checks
A documented risk assessment process with acceptance criteria, risks identified with owners, and results retained.
Do this first
Choose a simple likelihood and impact scale with a clear acceptance threshold, then assess the top risks to confidentiality, integrity and availability with a named owner for each.
Evidence produced
  • Risk assessment methodology
  • Risk register with owners and ratings
  • Risk assessment results with date
Framework mapping

ISO/IEC 27001:2022

  • Clause 6.1.2 Information security risk assessment
  • Clause 8.2 Information security risk assessment

SOC 2 (2017 TSC)

  • CC3.2 Identifies and analyses risk
  • CC3.4 Identifies and assesses changes
Watch out

A risk register with no owners, or owners who do not know they own a risk, will draw a nonconformity. Owners must accept residual risk explicitly.

ISMS leadMandatory document: Documented information the standard requiresNonconformity hotspot: Where we most often see audit nonconformities

Write the risk treatment plan and Statement of Applicability

  • Management system clause

The Statement of Applicability lists all 93 Annex A controls, says whether each applies, why, and whether it is implemented. It is the document auditors and many customers ask for first.

What the auditor checks
Every Annex A control addressed with a justification for inclusion or exclusion, consistent with the risk treatment plan, and approved by risk owners.
Do this first
Start from the risk register, select controls for each risk, then walk all 93 Annex A controls and record applicable or not, with a one-line reason for each.
Evidence produced
  • Statement of Applicability
  • Risk treatment plan
  • Risk owner approval of residual risk
Framework mapping

ISO/IEC 27001:2022

  • Clause 6.1.3 Information security risk treatment
  • Clause 8.3 Information security risk treatment

SOC 2 (2017 TSC)

  • CC3.2 Identifies and analyses risk
  • CC5.1 Selects and develops control activities
Watch out

Excluding a control because it is inconvenient, rather than because no risk calls for it, is the classic SoA failure. Exclusions need a risk-based reason.

LeadershipMandatory document: Documented information the standard requires

Set measurable objectives and plan changes

  • Management system clause

Objectives show what the ISMS is meant to achieve. The 2022 edition also asks you to plan changes to the ISMS rather than let them happen by accident.

What the auditor checks
Information security objectives that are measurable, monitored and communicated, with plans saying who, what, when and how results are evaluated.
Do this first
Set three to five objectives tied to the business, such as 100 percent MFA coverage or all critical vulnerabilities fixed within 14 days, and report them at management review.
Evidence produced
  • Information security objectives with measures
  • Objective tracking reports
  • Change planning records
Framework mapping

ISO/IEC 27001:2022

  • Clause 6.2 Information security objectives
  • Clause 6.3 Planning of changes

SOC 2 (2017 TSC)

  • CC3.1 Specifies suitable objectives
Watch out

Objectives such as "improve security awareness" cannot be measured. If you cannot tell whether you met it, the auditor cannot either.

Stage 03

3. People and documents

Do people know their part, and can you find the current version of every document?

Clause 7: competence, awareness, communication and documented information.

ISMS leadMandatory document: Documented information the standard requires

Build competence and awareness

  • Management system clause

People with ISMS roles need the competence to do them, and everyone needs to know the policy, their part in it and what happens if they ignore it.

What the auditor checks
Evidence of competence for people in ISMS roles, and staff who can describe the policy and how to report an incident.
Do this first
Record the competence needed for each ISMS role and how each person meets it, and run short awareness training for all staff covering the policy, reporting and their responsibilities.
Evidence produced
  • Competence records for ISMS roles
  • Awareness training records
  • Communication plan
Framework mapping

ISO/IEC 27001:2022

  • Clause 7.2 Competence
  • Clause 7.3 Awareness
  • Clause 7.4 Communication

SOC 2 (2017 TSC)

  • CC1.4 Commitment to competence
  • CC2.2 Internal communication
Watch out

Auditors interview staff at random. If people cannot say how they would report a lost laptop or a suspicious email, training records will not save you.

ISMS lead

Control your documents and records

  • Management system clause

ISO 27001 requires certain documents and records, and that they are controlled: versioned, approved, available to the people who need them and protected.

What the auditor checks
Mandatory documented information exists, with version control, approval and access control.
Do this first
Put the ISMS documents in one controlled location with version history, an owner and a review date for each, and retire copies held elsewhere.
Evidence produced
  • Document register with owners, versions and review dates
  • Controlled document repository
Framework mapping

ISO/IEC 27001:2022

  • Clause 7.5 Documented information

SOC 2 (2017 TSC)

  • CC2.1 Uses relevant, quality information
Watch out

More documents are not better. Write what the standard requires and what your people actually use. Every extra procedure is another thing the auditor can test you against.

Stage 04

4. Annex A controls

Are the controls you selected actually running?

93 controls in four themes. Your Statement of Applicability decides which apply. Most SMEs implement the large majority, and start with the ones customers ask about.

ISMS lead

Organisational controls (37)

  • Annex A control theme

The largest theme: policies, asset inventory, access control, supplier and cloud security, incident management, continuity, legal requirements and threat intelligence.

What the auditor checks
That the organisational controls selected in your SoA are implemented and operating, with evidence, especially suppliers, access and incidents.
Do this first
Start with the controls customers ask about most: asset inventory, access control, supplier security, cloud services, incident management and business continuity.
Evidence produced
  • Asset and supplier registers
  • Access control policy and reviews
  • Incident and continuity plans with test records
Framework mapping

ISO/IEC 27001:2022

  • A.5.1 to A.5.37

SOC 2 (2017 TSC)

  • CC5 Control activities
  • CC6.2 to CC6.3 Access
  • CC7.4 Incident response
  • CC9.2 Vendor risk
Watch out

A.5.23 Information security for use of cloud services was new in 2022. For SaaS-heavy SMEs it is one of the most important controls and one of the most often thinly evidenced.

Leadership

People controls (8)

  • Annex A control theme

Screening, terms of employment, awareness, disciplinary process, leavers, confidentiality agreements, remote working and event reporting.

What the auditor checks
A sample of joiners and leavers showing screening, agreements and access removal, and a remote working approach that matches how people actually work.
Do this first
Add screening, confidentiality and policy acknowledgement to onboarding, and tie access removal to the leaver process with a same-day target.
Evidence produced
  • Onboarding and offboarding records
  • Signed confidentiality agreements
  • Remote working policy
Framework mapping

ISO/IEC 27001:2022

  • A.6.1 to A.6.8

SOC 2 (2017 TSC)

  • CC1.4 Commitment to competence
  • CC6.2 User registration and removal
Watch out

Contractors and offshore team members are usually where people controls are missed. They belong in the same process as employees.

IT and engineering

Physical controls (14)

  • Annex A control theme

Secure areas, entry, equipment, clear desk, storage media, cabling, maintenance and secure disposal. For cloud-first SMEs many are inherited from providers or limited to the office and home working.

What the auditor checks
That applicable physical controls are in place at your locations, and that controls inherited from data centre providers are supported by their certifications.
Do this first
Walk the office with the SoA in hand, record what applies, and collect your cloud and data centre providers' ISO 27001 certificates or SOC 2 reports for the rest.
Evidence produced
  • Office physical security review
  • Provider certificates or reports
  • Equipment disposal records
Framework mapping

ISO/IEC 27001:2022

  • A.7.1 to A.7.14

SOC 2 (2017 TSC)

  • CC6.4 Physical access
  • CC6.5 Disposal of assets
Watch out

Excluding all physical controls because you are cloud-hosted rarely survives audit. Laptops, home offices and disposal still apply.

IT and engineering

Technological controls (34)

  • Annex A control theme

Endpoints, privileged access, authentication, malware, vulnerabilities, configuration, backup, logging, monitoring, network security, cryptography and secure development.

What the auditor checks
Configuration and records that show the technical controls in your SoA operate, sampled across the period since implementation.
Do this first
Use a security baseline such as NCSC's Critical Controls to implement the core: MFA, patching, endpoint protection, backups, logging and configuration management.
Evidence produced
  • Configuration exports and reports
  • Vulnerability and patch reports
  • Backup and restore test records
  • Log and monitoring evidence
Framework mapping

ISO/IEC 27001:2022

  • A.8.1 to A.8.34

SOC 2 (2017 TSC)

  • CC6.1 Logical access security
  • CC7.1 to CC7.2 Detection and monitoring
  • CC8.1 Change management
Watch out

Several technological controls were new in 2022, including configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. Check each has a real answer.

NCSC Critical Controls (opens in a new tab)

Stage 05

5. Evaluate

How do you know the ISMS works?

Clause 9: measurement, an impartial internal audit and a management review, all before the certification audit.

ISMS leadMandatory document: Documented information the standard requires

Measure whether the ISMS is working

  • Management system clause

You decide what to measure, how and when, and who analyses the results. Good measures come straight from your objectives and key controls.

What the auditor checks
Defined measures with methods and timing, and retained results that are evaluated, not just collected.
Do this first
Pick a handful of measures linked to your objectives, collect them monthly, and review the trend at management review.
Evidence produced
  • Measurement plan
  • Monitoring results and trend reports
Framework mapping

ISO/IEC 27001:2022

  • Clause 9.1 Monitoring, measurement, analysis and evaluation

SOC 2 (2017 TSC)

  • CC4.1 Ongoing and separate evaluations
Watch out

Dashboards nobody reviews are not evaluation. Record what the numbers mean and what you decided as a result.

ISMS leadMandatory document: Documented information the standard requiresNonconformity hotspot: Where we most often see audit nonconformities

Run an independent internal audit

  • Management system clause

Before certification, the whole ISMS must be internally audited by someone objective and impartial, with findings tracked to closure.

What the auditor checks
An audit programme, an internal audit covering the ISMS and Annex A before Stage 2, auditor independence from the work audited, and findings acted on.
Do this first
Plan an internal audit covering every clause and the applicable Annex A controls, and use someone who did not build the ISMS: an external auditor, or a trained colleague from another area.
Evidence produced
  • Internal audit programme
  • Internal audit report
  • Corrective action log
Framework mapping

ISO/IEC 27001:2022

  • Clause 9.2 Internal audit

SOC 2 (2017 TSC)

  • CC4.1 Ongoing and separate evaluations
  • CC4.2 Evaluates and communicates deficiencies
Watch out

The person who wrote the ISMS auditing their own work fails the impartiality requirement. In a small team, bring in an external internal auditor.

LeadershipMandatory document: Documented information the standard requiresNonconformity hotspot: Where we most often see audit nonconformities

Hold a management review

  • Management system clause

Leadership must formally review the ISMS, covering a defined list of inputs, and record decisions about improvement and change.

What the auditor checks
A management review before Stage 2 covering all required inputs, with recorded decisions and actions.
Do this first
Book a 90-minute leadership meeting after the internal audit, use an agenda that covers every input the standard lists, and minute the decisions.
Evidence produced
  • Management review agenda and minutes
  • Decisions and actions log
Framework mapping

ISO/IEC 27001:2022

  • Clause 9.3 Management review

SOC 2 (2017 TSC)

  • CC1.2 Board oversight
  • CC4.2 Evaluates and communicates deficiencies
Watch out

Missing inputs, such as interested party feedback or results of risk treatment, are a frequent minor nonconformity. Work from a checklist of the required inputs.

Stage 06

6. Improve and certify

Are you ready for Stage 1, Stage 2 and every year after?

Clause 10 and the certification cycle: fix causes, pass the two-stage audit and keep the ISMS running.

ISMS leadMandatory document: Documented information the standard requires

Fix nonconformities at the root

  • Management system clause

When something goes wrong, the standard expects you to correct it, find the cause and stop it recurring, then improve the ISMS continually.

What the auditor checks
Nonconformities recorded with root cause, corrective action and a check that the action worked.
Do this first
Log every internal audit finding and incident lesson in one corrective action register with cause, action, owner, due date and an effectiveness check.
Evidence produced
  • Corrective action register
  • Effectiveness reviews
Framework mapping

ISO/IEC 27001:2022

  • Clause 10.1 Continual improvement
  • Clause 10.2 Nonconformity and corrective action

SOC 2 (2017 TSC)

  • CC4.2 Evaluates and communicates deficiencies
Watch out

Closing a finding by fixing the instance, not the cause, invites the same finding next year. Ask why until you reach a process change.

Leadership

Choose an accredited certification body and pass Stage 1 and Stage 2

  • Management system clause

Certification is a two-stage external audit. Stage 1 reviews your documentation and readiness; Stage 2 tests whether the ISMS operates in practice.

What the auditor checks
Stage 1: scope, mandatory documents, SoA, internal audit and management review. Stage 2: interviews and samples showing the ISMS and selected controls operate.
Do this first
Get quotes from accredited certification bodies, check accreditation (JAS-ANZ in New Zealand and Australia, or another IAF member), and book Stage 1 once internal audit and management review are done.
Evidence produced
  • Certification body proposal and accreditation
  • Stage 1 report and actions
  • Stage 2 report and certificate
Framework mapping

ISO/IEC 27001:2022

  • ISO/IEC 17021-1 certification process (applies to the certification body)
Watch out

A certificate from an unaccredited body may not be accepted by customers or tenders. Check accreditation before you sign, not after.

Leadership

Keep it running through surveillance and recertification

  • Management system clause

Certificates run a three-year cycle with surveillance audits in the years between. The ISMS has to keep operating, not just exist on certification day.

What the auditor checks
At surveillance: internal audits, management reviews, corrective actions and a sample of controls since the last visit.
Do this first
Put the annual cycle in the calendar: risk review, internal audit, management review and surveillance audit, with an owner for each.
Evidence produced
  • Annual ISMS calendar
  • Surveillance audit reports
  • Updated SoA and risk register
Framework mapping

ISO/IEC 27001:2022

  • Clause 9 Performance evaluation
  • Clause 10 Improvement

SOC 2 (2017 TSC)

  • CC4.1 Ongoing and separate evaluations
Watch out

The year after certification is when ISMSs go quiet. Surveillance auditors notice when the only activity was the month before their visit.

Documented information

The documents and records the standard requires

Write these well and keep them current. Add other documents only when your people need them.

Mandatory documented information in ISO/IEC 27001:2022
Scope of the ISMS4.3
Information security policy5.2
Risk assessment process6.1.2
Risk treatment process6.1.3
Statement of Applicability6.1.3 d
Information security objectives6.2
Evidence of competence7.2
Documented information the organisation determines is necessary7.5.1 b
Operational planning and control records8.1
Risk assessment results8.2
Risk treatment results8.3
Monitoring and measurement results9.1
Internal audit programme and results9.2
Management review results9.3
Nonconformities and corrective actions10.2

Annex A controls you select may need their own documents, such as an access control policy or incident procedure. Your Statement of Applicability tells you which.

The path

A six-month path to certification

Typical for a focused SME with an engaged leadership team. Larger scopes take longer, and some certification bodies need notice to book audits.

  1. Months 1 to 2

    Phase 1: Define and assess

    1. 1.Context, interested parties and scope
    2. 2.Policy, roles and objectives
    3. 3.Risk method and risk assessment
    4. 4.Draft the Statement of Applicability

    Exit criteria

    An approved scope, a risk register with owners and a draft SoA.

  2. Months 2 to 4

    Phase 2: Implement and operate

    1. 1.Implement the controls the SoA selects
    2. 2.Run awareness training
    3. 3.Start collecting measures and records
    4. 4.Choose and book an accredited certification body

    Exit criteria

    Controls operating with evidence, and audit dates booked.

  3. Months 4 to 6

    Phase 3: Evaluate and certify

    1. 1.Independent internal audit and corrective actions
    2. 2.Management review
    3. 3.Stage 1, close any findings, then Stage 2

    Exit criteria

    A certificate, and an annual ISMS calendar already running.

From the field

Where ISO 27001 projects stall

  • Buying a document toolkit

    A hundred templated procedures you do not follow create more nonconformities than they prevent. Write fewer, truer documents.

  • Excluding controls without a risk reason

    The Statement of Applicability must justify exclusions from risk, not convenience. Auditors read the reasons.

  • No impartial internal audit

    The person who built the ISMS cannot audit it. Small teams need an external internal auditor.

  • Leadership absent

    If leaders cannot explain the policy and objectives at interview, it shows. Brief them early.

  • Unaccredited certification

    Some certificates are not issued under accreditation. Check JAS-ANZ or another IAF member before you buy.

  • Going quiet after the certificate

    Surveillance audits test the year since. An ISMS that only wakes before audits is visible in the records.

One control set

ISO 27001 and SOC 2: build once, report twice

Most SOC 2 security controls land on Annex A. ISO 27001 adds the management system around them.

How ISO/IEC 27001 and SOC 2 compare
ControlsAnnex A covers most of what the SOC 2 Common Criteria test. Each card above shows the nearest SOC 2 criteria.
Management systemISO 27001 requires clauses 4 to 10. SOC 2 has no direct equivalent, though governance and monitoring criteria overlap.
What you receiveA public certificate from an accredited certification body, versus a SOC 2 attestation report from a CPA firm shared under NDA.
Who asksMany UK, European, Asian and public sector buyers prefer ISO 27001. US buyers usually ask for SOC 2.
CycleThree-year certificate with annual surveillance, versus SOC 2 Type II reports typically renewed each year.

Build the controls once against both, map them to one model, and the second framework becomes an extension rather than a new project.

Regional overlays

ISO 27001 in New Zealand and Australia

New Zealand

Voluntary certification; common in tenders and enterprise supply chains

  • Certification bodies operating in New Zealand are typically accredited by JAS-ANZ or another IAF member accreditation body.
  • Privacy Act 2020 requirements belong in the legal and contractual requirements your ISMS identifies, and IPP 5 security safeguards align naturally with Annex A.
  • Government agencies work to NZISM and the Protective Security Requirements. ISO 27001 supports supplier assurance but does not replace an agency's own assessment.
  • NCSC's Critical Controls are a practical starting point for the technological controls in Annex A.

Australia

Voluntary certification; frequently required by government and regulated buyers

  • JAS-ANZ accredits certification bodies in Australia as well as New Zealand.
  • APRA-regulated customers use ISO 27001 as evidence when assessing suppliers under CPS 234 and CPS 230, alongside their own due diligence.
  • ASD's Essential Eight is a practical way to implement and evidence many Annex A technological controls.
FAQ

Questions we get asked

How long does ISO 27001 certification take for a small business?

For a focused SME with an engaged leadership team, about six months from start to certificate is typical: two months to define and assess, two to implement and operate, and two to audit internally, review and complete Stage 1 and Stage 2. Larger scopes take longer.

Do we have to implement all 93 Annex A controls?

No. You must consider all 93 in your Statement of Applicability and justify any exclusion based on risk. Most SMEs find the large majority apply, but controls such as outsourced development or secure areas may not.

Is ISO 27001:2013 still valid?

No. The transition period for certificates issued against the 2013 edition ended on 31 October 2025. Certification is now against ISO/IEC 27001:2022, including Amendment 1:2024, which added climate change considerations to clauses 4.1 and 4.2.

What is the difference between Stage 1 and Stage 2 audits?

Stage 1 checks that your ISMS is designed and documented and that you are ready. Stage 2 tests that it operates in practice, through interviews and samples of records and controls.

Can our consultant also certify us?

No. Certification must come from an accredited certification body that is independent of the people who helped you build the ISMS. Check that the body is accredited, for example by JAS-ANZ, before you engage it.

Should we do ISO 27001 or SOC 2 first?

Follow your buyers. If most ask for SOC 2, start there; if tenders and international customers ask for ISO 27001, start there. Design one control set that maps to both and the second takes a fraction of the effort.

Planning ISO 27001 for the first time?

CybrGen builds lean ISMSs for New Zealand and Australian organisations: scope, risk, Statement of Applicability, controls and internal audit, ready for an accredited certification body. One control set, mapped to SOC 2 and the other frameworks your customers ask for.