| ISO 27001 is the international standard for an information security management system, a documented set of policies, risk decisions and controls that an organisation runs and improves over time. Certification means an accredited third party has audited that system and confirmed it meets the standard. |

The question arrives from a customer’s procurement team. It sits in a renewal pack between the insurance certificates and the health and safety declarations, and it asks whether your business holds ISO 27001.
Nobody in the office knows the answer. The contract is one of the larger ones on the books, the response is due in a fortnight, and the question has no obvious owner.
Most New Zealand businesses meet this standard through a sales process rather than a security review. A customer asks, and a certification nobody had considered becomes a commercial problem with a deadline attached.
For a good number of those businesses the honest answer is that they do not need the certificate, and a smaller, faster scheme will satisfy the customer. For others it is the price of staying on the supplier panel.
Working out which group you are in takes about a week and costs very little. Getting it wrong costs either a contract or a year of work you did not have to do.
A wrong answer in either direction is expensive. Some businesses spend a year and $80,000 building a management system their customer never asked to see. Others lose a panel place because nobody answered the question in time.
What Is ISO 27001?
ISO 27001 is the international standard that sets out the requirements for an information security management system, usually shortened to ISMS. It describes how an organisation identifies its information risks, decides which controls to apply, records those decisions, and keeps checking that the arrangement still holds.
You will see it written as ISO/IEC 27001:2022, because ISO publishes it jointly with the International Electrotechnical Commission. ISO’s page for the standard confirms that ISO/IEC 27001 is the official reference and that the current edition dates from October 2022. One change has been made since: Amendment 1:2024 is a single free page asking organisations to consider climate change, and it will not alter how your business is audited.
A firewall cannot be certified and neither can a policy document. An auditor looks at how the decisions get made: who decided what, on what evidence, and what happens when something changes.
What is an ISMS?
An ISMS is the set of policies, processes, risk decisions and records an organisation uses to manage information security on purpose instead of by habit. It covers people and paperwork as much as technology, which surprises most owners.
For a 40 person firm that usually means a folder of about twenty documents, a risk register, an asset inventory, a schedule of reviews, and dated evidence that the reviews happened. The technology sits underneath it and is largely what you already run.
ISO writes the standard to fit everybody, stating that its requirements apply to all organisations regardless of type, size or nature. So it tells you to run a risk assessment without telling you what your risks are.
That first risk assessment is the same exercise as a cyber security assessment, widened from the network to cover information wherever it sits, including paper, laptops, cloud services and the suppliers who hold your data. ISO/IEC 27005 is the companion standard covering information security risk management, and it is where to look if you want a documented method to follow.
What is the difference between ISO 27001 and ISO 27002?
ISO/IEC 27001 contains the requirements you are audited against, and ISO/IEC 27002 is the companion guidance explaining how each control can be implemented. No organisation is certified to ISO/IEC 27002.
Buy 27001 first. Most businesses end up buying 27002 as well, because Annex A lists the controls by name without saying much about how to put them in place.
What Are the Requirements of ISO 27001?
Six things, and only two of them are technical. An ISMS needs a risk assessment, a Statement of Applicability, the Annex A controls you have chosen to apply, documented policies and procedures, an internal audit programme, and a management review that senior people attend. Everything else in the standard describes how those six are run and kept current.
- A risk assessment covering the information your business holds, wherever it sits
- A Statement of Applicability recording which controls apply and which do not
- The applied controls themselves, drawn from the Annex A list
- Documented policies and procedures your staff can find without asking
- An internal audit programme that runs to a published schedule
- A management review that senior people attend and that gets minuted

Those six sit inside a numbered structure your auditor works through. Clauses 4 to 10 cover context of the organisation, leadership, planning, support, operation, performance evaluation and improvement, and Annex A is the control list Clause 6 sends you to. Anyone quoting for the work will refer to them by clause number, so it is worth recognising the numbering when it appears in a proposal.
Show an auditor a risk you identified, the control you chose to address it, evidence that the control runs, and a review that confirmed it, and you have covered most of what the standard asks for. The six pieces are built to feed each other.
What is a Statement of Applicability?
A Statement of Applicability, written as SoA in most documentation, lists every Annex A control alongside a decision: applied, or excluded with a stated reason. Auditors reach for it before anything else, because it sets out what the organisation is claiming and why.
The 2022 edition carries 93 Annex A controls arranged in four themes, which are organisational, people, physical and technological. The withdrawn 2013 edition had 114 controls in fourteen groups, so a business working from an old template will produce an SoA that fails to line up with the standard it is being audited against. Check which edition any template was written for before you use it.
A business with no software development team excludes the secure development controls, writes a sentence explaining why, and moves on. Auditors expect exclusions.
What are Annex A controls?
Annex A controls are the reference list of information security measures the standard expects an organisation to consider, covering access control, supplier relationships, physical security, logging, backup, incident management and more. Your risk assessment decides which ones apply, and the Statement of Applicability records the decision.
Most of the technical controls are already delivered by a competent managed service. Multi-factor authentication, patching, backup testing, endpoint protection, logging and quarterly access reviews are ordinary day-to-day work. Ask your provider which of those are already reported to you monthly.
Businesses trip on the evidence, not the control itself. Multi-factor authentication has been switched on for two years and nobody can produce a record showing it was on in March.
How do internal audit and management review work?
Internal audit is somebody independent of the work checking that the ISMS operates the way it is documented, and management review is the scheduled meeting where leadership examines the results and makes decisions. Both are mandatory, both must be minuted, and both are where a first certification attempt commonly comes unstuck.
Independent does not have to mean external. A finance manager can audit the IT controls and an IT manager can audit the joiner and leaver process, so long as neither is reviewing their own work.
A one-off assessment of your posture is a separate exercise. A security audit tells you where you stand on the day it is run, and the internal audit programme inside an ISMS is the recurring version of that discipline, on a schedule the standard expects you to publish in advance.
Who Needs ISO 27001 Certification?
Businesses whose customers require it in a contract, and very few others. The usual trigger is a procurement questionnaire from a government agency, a bank, an insurer, a health provider or a large corporate, where certification is listed as a condition of supply.

ISO counted over 70,000 certificates across 150 countries in its 2022 survey. That is a small population for a standard this well known, and it clusters in technology firms, financial services and businesses holding other people’s data under contract. If your customers are local trade accounts, you are almost certainly outside it.
Government buyers are a case of their own. Agencies work to the New Zealand Information Security Manual, known as NZISM and maintained by the Government Communications Security Bureau as part of the Protective Security Requirements framework, so a tender may reference that as well as a certification. Read the question closely before you assume which one is being asked for.
When is certification worth the cost?
When a named contract, or a class of contracts you intend to bid for, requires it. Work out what that revenue is worth over three years and set it against the total cost of a certification cycle, because this is a commercial decision before it is a security one.
Take an illustrative example: a Christchurch software firm with 30 staff is asked for certification by a government agency on a contract worth $250,000 a year. Three years of that work is $750,000, set against a certification cycle of perhaps $60,000 to $90,000 once internal time is counted. Those numbers are made up to show the sizes involved and are not quoted from a real job.
That arithmetic is easy. The harder call comes when no single contract covers the cost and you are backing work you have not won yet.
There is a competitive driver as well. Where three firms are shortlisted and one holds the certificate, the procurement scorecard does the rest without anybody arguing about security.
When is Cyber Essentials enough?
When no customer contract demands the certificate and the goal is to get the baseline right. Cyber Essentials checks that a defined set of foundational controls is configured properly, which suits most small and mid-sized New Zealand businesses, while the full standard asks for a managed system with third-party audit behind it.
SOC 2 is the other name that comes up, usually from a customer in the United States. It is an American attestation report produced by an accounting firm against a set of trust services criteria, covering similar ground with different paperwork and no certificate at the end. A New Zealand business selling into both markets can end up asked for one of each.
Start with the lighter scheme. A business that cannot pass a baseline check will not survive a Stage 2 audit, and none of that work is wasted, because most of those same controls appear somewhere in Annex A.
Privacy Act 2020 obligations sit outside all of this and apply to every agency holding personal information in New Zealand, whether or not it holds a certificate of any kind.
Under information privacy principle 5, the Office of the Privacy Commissioner sets out that an agency holding personal information must protect it with security safeguards that are reasonable in the circumstances. That covers loss, and it covers access, use, modification or disclosure the agency has not authorised. A certificate is one way of showing you have done that thinking, and it has never been a substitute for doing it.
How Do You Get ISO 27001 Certified?
Through six stages that take twelve to eighteen months for a business starting from a standing start. A gap analysis, an implementation phase, a Stage 1 audit of the documentation, a Stage 2 audit of the evidence, the certificate itself, then surveillance audits in each of the following years.

The sequence rarely varies, because certification bodies work to a common set of accreditation rules set out in ISO/IEC 27006:
- Gap analysis. Compare what you run today against the standard and Annex A, and produce a costed list of what is missing. Two to four weeks.
- Implement. Write the policy set, run the risk assessment, build the Statement of Applicability, and close the technical gaps. Six to twelve months is typical.
- Operate. Run the ISMS for at least three months so there is something to audit, including one internal audit and one management review.
- Stage 1 audit. The certification body reviews your documentation and your scope, then tells you whether you are ready to proceed.
- Stage 2 audit. The auditor tests whether the system works in practice, interviewing staff and sampling records. Any non-conformities are raised here.
- Certification and surveillance. The certificate runs for three years, with a surveillance audit each year and a full recertification audit at the end of the cycle.
Only an accredited certification body can issue the certificate. No IT provider and no consultant can, and ISO makes the point that a certificate from an accredited body carries an extra layer of confidence, because an accreditation body has independently confirmed that certification body’s competence.
In New Zealand, certification bodies are typically accredited through JAS-ANZ, the Joint Accreditation System of Australia and New Zealand. Ask any prospective certification body who accredits them and for which standard, because a certificate from an unaccredited body will not satisfy a procurement team.
What happens in a Stage 1 audit?
The certification body reviews your documentation and confirms your scope makes sense. The auditor reads the Statement of Applicability, the risk assessment, the policy set and your internal audit results, then reports anything that would stop a Stage 2 audit from succeeding. Allow one to two audit days for it.
A Stage 1 that comes back with a list of corrections is the cheapest feedback you will get in the whole project, so work through the findings before the auditor returns.
What happens in a Stage 2 audit?
The auditor tests whether the documented system is being operated. That means interviews with staff outside the project team, samples of access reviews and change records, and a walk through any incidents and how they were handled.
Findings come back as major or minor non-conformities. A minor one gets a corrective action plan and a deadline, a major one holds up the certificate until it is resolved and verified. Observations carry no deadline at all.
Project teams underestimate the staff interviews. An auditor will ask a warehouse supervisor what they do with a suspicious email, and that answer carries more weight than the policy folder.
What is a surveillance audit?
A surveillance audit is a shorter annual check that the ISMS is still being operated between certifications. The certification body samples part of the system each year, and a full recertification audit comes around at the end of the three year cycle.
The ongoing cost sits here, and so does most lapsed certification. An ISMS nobody maintained after month four shows up at the first surveillance audit.
How Much Does ISO 27001 Certification Cost in New Zealand?
Budget $45,000 to $90,000 across a first three year cycle for a business of 20 to 60 staff. Certification body fees make up roughly a third of that, and internal staff time makes up the largest share, which is the line most first-time budgets leave out.
| What you pay for | What it covers | Typical range |
|---|---|---|
| Gap analysis | A structured comparison of your current controls and documents against the standard and Annex A | $5,000 to $12,000, one-off |
| Implementation support | Policy set, risk assessment, Statement of Applicability, closing the control gaps | $15,000 to $40,000, or internal time |
| Certification body audit | The Stage 1 and Stage 2 audits and issue of the certificate | $10,000 to $20,000 in year one |
| Surveillance audits | The shorter annual check in years two and three | $4,000 to $8,000 a year |
| Internal staff time | Project hours, internal audits, management reviews, evidence gathering | The largest line, and seldom costed |
| Tooling | A compliance platform if you choose to use one, plus any gaps in your IT stack | $0 to $15,000 a year |
Those ranges are what we see quoted in the South Island market, and they move with scope far more than with headcount. A certificate covering one product team in one office costs a fraction of one covering an entire organisation, and you set the scope, not the auditor. Write the scope statement before you ask anybody for a price.
Internal time is the line owners feel most, because it comes out of people who already have a job. For six to nine months somebody senior loses roughly a day a week to this. On a $120,000 salary that is about $18,000 of time before an auditor has invoiced you for anything.
Why do certification quotes vary so much?
Because the word certification covers three separate purchases. A certification body sells the audit, a consultant sells the implementation, and an IT provider closes the technical gaps, so a quote that looks cheap has usually left two of the three out.
Ask every quote to state the scope in one sentence, the number of audit days included, and who writes the documentation. Those three answers explain almost every difference between two numbers that sit thousands of dollars apart.
Who Does What in a Certification Project?
An IT provider gets the technical controls working and produces the evidence an auditor will ask for. That covers access control, multi-factor authentication, patching, logging, backup and recovery testing, endpoint protection, and the records showing each of them operated across the audit period.
Exodesk does not issue certificates and neither does any other IT company. The split that works is your provider getting the controls running and documented, and an accredited auditor judging them.
Roughly two thirds of Annex A sits outside IT altogether. Supplier contracts, HR screening, physical access to the building, clear desk arrangements and incident communications belong to the business, and no managed service will cover them on your behalf. Name an owner for each of those before the gap analysis starts.
Where do businesses get stuck?
Evidence and scope, in that order. The controls themselves are usually in reasonable shape by the time a business reaches Stage 2, and what fails is that nobody can show the access review happened in April. Scope is the other one, drawn so wide that the audit takes twice as long as it needed to and costs accordingly.
The second common failure is treating the certificate as a project with an end date. The standard asks for a system that keeps running, and the surveillance audit in year two is where that becomes visible.
What should you do this week?
Find out whether any customer contract or live tender names the standard as a requirement. That single fact decides whether this is a funded project or a someday one.
Then get a gap analysis from a practitioner who has sat through a Stage 2 audit. Half a day will tell you whether you are twelve months out or three.
Get Your Security Controls Audit-Ready
Exodesk has supported South Island businesses since 1989 and works with organisations across Canterbury, Otago and Southland from offices in Christchurch and Dunedin. We get the technical controls in place, produce the evidence your auditor will ask for, and work alongside your certification body through Stage 1 and Stage 2. If you are scoping your wider cyber security programme at the same time, we can look at both in one conversation.
Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.
Frequently Asked Questions
What is ISO 27001?
ISO 27001 sets out what an organisation must do to manage information security in a structured, repeatable way, covering risk assessment, choice of controls, documentation, internal audit and management review. Businesses pursue it when a customer’s procurement process demands independent proof that security is managed rather than assumed. The certificate is issued by an audit body accredited for the purpose, lasts three years, and is checked annually in between.
What is an ISMS?
An ISMS, short for information security management system, is the combined set of policies, procedures, risk records and review routines a business uses to keep information secure by design. The ISMS is what ISO 27001 audits, and no single piece of technology can be certified on its own.
How long does ISO 27001 certification take?
Most businesses starting from nothing take twelve to eighteen months to reach certification, while one with mature security and good documentation can get there in six to nine. Certification bodies generally want to see at least three months of the system operating, including one internal audit and one management review.
How much does ISO 27001 cost in New Zealand?
A New Zealand business of 20 to 60 staff should plan on somewhere between $45,000 and $90,000 over the first three years, which covers the gap analysis, implementation support, both certification audits and two annual surveillance visits. Fees charged by the certification body are usually the smallest slice of that. Staff hours are the biggest, and they are what most budgets forget to price. Narrow the scope and the whole number falls.
What is the difference between ISO 27001 and Cyber Essentials?
Cyber Essentials confirms that a defined list of baseline technical controls is in place and can be completed in weeks. ISO 27001 requires a full management system with risk assessment, documentation, internal audit and a third-party audit against the standard, and it takes months. Most New Zealand small businesses should complete a baseline scheme first and move up only when a customer contract requires certification.
Is ISO 27001 mandatory in New Zealand?
No. ISO 27001 is a voluntary certification and no New Zealand law requires a business to hold it. The Privacy Act 2020 does oblige every agency that holds personal information to apply security safeguards reasonable in the circumstances, which is a legal duty and not a matter of choice. That duty applies whether or not a business is certified to any standard.
What is a Statement of Applicability?
The Statement of Applicability lists every Annex A control and records whether the organisation applies it, together with the justification for including or excluding each one. Auditors usually read it before anything else, because it defines what is being claimed. The 2022 edition of the standard carries 93 Annex A controls grouped into organisational, people, physical and technological themes.
Can an IT provider certify us to ISO 27001?
No. Certification is issued only by a certification body accredited for that standard, so an IT provider or a consultant cannot issue it. What an IT provider does is implement and evidence the technical controls the auditor will test, which is usually the largest single block of work in the project.
What happens if we fail the Stage 2 audit?
Failing outright is rare, because the Stage 1 audit exists to catch that in advance. The usual outcome is a list of non-conformities, where a minor finding is closed with a corrective action plan and a major finding holds up the certificate until it is fixed and verified.
Do businesses in Christchurch and Dunedin get ISO 27001 certified?
Yes. South Island businesses that supply government agencies, banks, insurers or large corporates do hold the certification, most often in software, professional services and organisations handling customer data under contract. Audits are usually a mix of on-site days in Christchurch or Dunedin and remote review, and the certifying body must hold accreditation for the standard it is auditing you against.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international standard with a certificate issued by an accredited certification body after a Stage 1 and Stage 2 audit. SOC 2 is an American attestation report written by an accounting firm against trust services criteria, and it produces a report for customers to read instead of a certificate. New Zealand businesses selling to United States customers are sometimes asked for SOC 2 and asked for ISO 27001 by everyone else.
Where should we start with ISO 27001?
Start by confirming whether a customer contract or a live tender names the standard, because that answer decides whether the project is urgent or optional. Then commission a gap analysis against the standard and Annex A, which takes two to four weeks and produces a costed list of what is missing. From there you can weigh certification against a lighter baseline scheme with a real budget in front of you.

