ISO 27001 certification, priced before you call us.
$4,300 per month over 12 months. One price, one framework, up to 50 people, everything an auditor will ask for. Ex GST, certification body fees excluded.
ISO/IEC 27001:2022 certified consultancy · Lead Auditors since 2008 · CREST-certified penetration testers · Australia-based staff · Sydney, since 2014
Choose where you are
Certification Readiness
ISO 27001 Certification Readiness
$4,300 per month
12-month term. $51,600 in total. Ex GST.
Framework: Your choice of ISO/IEC 27001:2022, ISO/IEC 42001:2023 or SOC 2.
Timeline: Audit-ready in 3 to 12 months, depending on where you start.
Everything in the price
This is the full programme from first assessment to your Stage 2 audit, run by a Lead Auditor and a project manager, not a template pack with a help desk.
Assess
Gap assessment and prioritised remediation roadmap
Certification scope, boundaries and interface mapping
Security architecture and licensing rationalisation review, one day: what you already pay for, what overlaps, what is missing
Build
ISMS governance model and responsibility matrix
Risk methodology, risk register and risk treatment plan
Statement of Applicability
Customised policy and procedure suite
Incident response, business continuity and disaster recovery plans
Prove
Tabletop exercise run by a Cliffside security architect
Employee ISMS training and control-owner briefings
Internal audit, performed by a Cliffside auditor who did not lead your implementation
Management review and governance meetings, chaired by Cliffside
Support
Stage 1 and Stage 2 readiness packs, and a Cliffside consultant with you during both audits
Dedicated Lead Auditor and project manager for the term
Cybereen compliance platform in your own tenant, included for the term
One framework. Up to 50 employees. One site. Certification body fees are not included. The fee covers the certification programme and is billed over 12 months; if you certify early, the remaining months provide our basic Continuous Compliance service, so you enter your first surveillance period already supported.
A named ISMS Manager, Lead Auditor oversight and attendance at your surveillance audit. Every deliverable below is stated so you can hold us to it.
Every month
These happen in the same order each month, whether or not an audit is near.
Named Virtual ISMS Manager as your single point of contact
ISMS governance meeting, chaired by Cliffside
Risk-based sampling of control evidence, with gaps identified and assigned
Risk and treatment plan review
Corrective-action register maintained and overdue items chased
Policy and document review tracking
Two customer security questionnaires supported
One-page executive report: what is working, what is overdue, what could produce a finding, who must act
Every year
These are scheduled into the ISMS calendar at the start of the term.
Internal audit performed by a Cliffside auditor who is not your ISMS Manager
Risk register and Statement of Applicability refresh
Management review, prepared and facilitated
Tabletop exercise run by a Cliffside security architect
ISMS refresher briefing for staff and control owners
Surveillance or recertification audit preparation and attendance
Cybereen compliance platform in your own tenant
One framework. One legal entity and certification scope. You keep the ISMS owner role and operate your controls; we manage the rhythm, test the evidence and tell you where the position is not defensible. Certification body fees are not included. Evidence sampling is risk-based, not a monthly test of every control.
Most compliance packages are priced to keep you subscribed. Ours starts with four days that might tell you not to buy the rest..
Standalone gap assessment: $7,200, four days, a written recommendation and a roadmap you can take anywhere. If we conclude you can certify with a smaller engagement, or none, that is what the report says. If you proceed with us within 90 days, the fee is credited in full.
The core price covers what every certification needs; the items below depend on your environment, so they are priced separately and shown here rather than discovered in month seven.
External penetration test
$5,900
Standard external scope, CREST-certified testers. Most certification bodies expect to see one before Stage 2.
Managed SOC coverage around the clock, scoped to your environment.
Microsoft 365 security review
Quoted separately
Configuration review across identity, email, endpoints and data protection.
Additional frameworkExtending an operating ISMS to ISO 42001 or SOC 2. Quoted separately.
Not included
These are outside the price and we will say so in the proposal, not after it.
Certification body feesPenetration testing, unless addedSecurity tooling licencesTechnical remediation and engineering changesFormal legal adviceTravel and accommodationA guaranteed certification decision
The programme
How the programme runs
Certification is a sequence, and most of the delay in any programme sits in the second stage, where controls have to be operated and evidenced rather than written.
01
Stage 1 · Weeks 1 to 4
Assess
Gap assessment against Clauses 4 to 10 and Annex A, certification scope agreed, remediation roadmap presented to leadership. Architecture and licensing rationalisation review delivered.
02
Stage 2 · Months 2 to 5
Build
Governance model, risk assessment, Statement of Applicability, policy and procedure suite, IRP, BCP and DR, supplier and cloud governance, evidence register. Weekly delivery stand-ups, fortnightly executive reporting.
03
Stage 3 · Months 4 to 7
Operate and prove
Controls run and generate evidence. Training delivered. Tabletop exercise. Internal audit and corrective actions. Management review.
04
Stage 4 · Months 6 to 12
Certify
Stage 1 audit, findings closed, Stage 2 audit, Cliffside in the room for both. Certification decision from your independent certification body.
Stage 1 auditStage 2 audit
Timelines assume your control owners complete assigned actions within agreed windows. Where they do not, we tell you early and in writing.
Included, not an add-on
A security architecture review that can reduce your costs
Every programme includes a security architecture and licensing review run by a Cliffside security architect, because certification is the right moment to look at what you are already paying for.
Rationalise your controls
We map the tools you already pay for against the controls you actually need, flag the overlaps, and show you where the same licence spend is doing the job twice. The savings can be considerable.
Find the gaps
The same review identifies the architectural areas with no control at all, so remediation lands in your roadmap rather than in your Stage 2 findings.
Cybereen in the price
The Cybereen compliance platform runs in your own tenant for the term of the engagement, included in the monthly fee, not billed alongside it.
The written recommendations are delivered before any commercial offer from us is made. If the honest recommendation is to buy less, that is the recommendation you get.
Deliverables
What you actually receive
Activities are not deliverables, so this is the list of things that exist at the end of the programme that did not exist at the start.
A defined and approved ISMS scope
A documented, operating governance model with named owners
A risk register and treatment plan your board has seen
An approved Statement of Applicability
A controlled ISMS documentation set in your own Cybereen tenant
Indexed audit evidence mapped to every clause and control
An internal audit report and closed corrective actions
Documented management review
Stage 1 and Stage 2 readiness packs
A written architecture and licensing review with three to five recommendations, including where we think you are overspending
The guarantee question
Our commitment
We are asked for a guarantee on almost every call, so here is the honest version of one.
We cannot guarantee you a certificate. The audit is conducted by an independent certification body that we do not control, and that is exactly why the certificate is worth having. What we can guarantee is that we stay on the engagement until you pass, provided the actions assigned to your team are completed. If your Stage 2 raises findings, we work them with you; we do not send a variation.
"Cliffside gave us an honest picture of our ISO 27001 readiness that none of our previous assessors had. They told us we were closer than we thought in some areas, and further behind in others, and they were right on both counts."
Head of Information Security · ASX-listed financial services organisation
The people
Who delivers
The price buys people, so you should know who they are before you pay for them.
Delivery team
Every engagement is overseen by an ISO 27001 Lead Auditor certified since 2008 and handled day to day by a certified ISO 27001 Lead Auditor. The tabletop exercise and the architecture review are delivered by a Cliffside security architect holding SABSA and CISSP. Penetration testing, where you add it, is performed by CREST-certified testers. All delivery staff are based in Australia.
The firm
Cliffside Cybersecurity has been ISO/IEC 27001:2022 certified in its own right, certified by BSI, and has operated from Sydney since 2014 with Australia-based staff.
Stay Certified
Stay certified without running compliance by spreadsheet
Passing the audit proves the ISMS worked on the day. We operate it afterwards: governance, evidence testing, corrective actions and surveillance preparation, with a named person accountable for the rhythm.
A month in the service
The same rhythm every month, so nothing is rediscovered the week before the auditor arrives.
Sample
01
Evidence tested against the annual sampling plan; missing, stale or contradictory items recorded.
Chase
02
Owners, actions and overdue decisions followed up in writing.
Meet
03
Governance meeting held, decisions and accepted risks recorded.
Report
04
One page to management: what could fail, who has to act, and where the delay is ours.
Where the responsibility sits
The boundary matters, so here is where the responsibility sits.
What we manage
ISMS calendar and operating cadence
Evidence register and sampling
Risk register and corrective actions
Management review and governance records
Audit preparation and attendance
What you receive
A monthly status you can act on
Named owners and due dates for open actions
Evidence gaps found before an auditor finds them
Audit-ready management review records
Fewer last-minute evidence requests
What remains with you
Operating your controls
Risk acceptance decisions
Policy approval
Remediation
The ISMS owner role
We are asked what the monthly fee guarantees, so here is the honest version.
Every month we tell you, in writing, what could produce a finding and who has to act, including where the delay is ours. We do not control the certification body and we do not operate your controls; we manage the rhythm, test the evidence and say directly where the position is not defensible.
Your certificate is dated. Your ISMS should not be.
Thirty minutes. Bring your last audit report and we will tell you what the next one is likely to find.
The fee is for the certification programme, not for time. Billing it over 12 months keeps the monthly figure predictable. If you certify early, the remaining months deliver our basic Continuous Compliance service, so you are supported into your first surveillance audit rather than left at the certificate. If you would rather pay the same total over 9 or 6 months, ask; the fee does not change.
Does the price change if we choose SOC 2 or ISO 42001 instead of ISO 27001?
No. One price covers one framework of your choice.
Is the penetration test included?
No. It is a $5,900 add-on, priced separately because scope varies with your environment. Most certification bodies expect to see evidence of one before Stage 2, so most clients add it.
Who does the internal audit?
A Cliffside auditor who did not lead your implementation. ISO 27001 requires the internal audit to be objective and impartial; having the implementer audit their own work is a finding waiting to happen.
Do we keep Cybereen after the term?
Cybereen is in your own tenant for the term of the engagement. After the term, you can continue to use it at $67 per user per month.
Can our IT provider or MSP work with you?
Yes. We integrate with your existing team and providers; control ownership stays with your organisation.
What if we only want the gap assessment first?
That is how most engagements should start. The standalone gap assessment is $7,200, delivered in four days by the Lead Auditor: Clauses 4 to 10 and Annex A assessed, certification scope proposed, a prioritised roadmap, and a written recommendation on the size of engagement you actually need, which may be smaller than this programme. The roadmap is yours to take anywhere. If you proceed with us within 90 days, the $7,200 is credited in full.
Stay certified
Who does the internal audit if you are running our ISMS?
A Cliffside auditor who is not your ISMS Manager. ISO 27001 requires objectivity and impartiality; having the person who operates the rhythm also audit it is a finding waiting to happen.
We certified with someone else. Can we start here?
Yes. The first month is an onboarding review of your ISMS, registers and last audit report, and the sampling plan is built from what we find. If the ISMS needs uplift before it can be operated, we tell you what that costs before you commit.
What happens at a surveillance audit?
Preparation starts in the ISMS calendar three months out: document register, Statement of Applicability review, control-owner preparation and auditor access. Your ISMS Manager attends the audit and coordinates responses to findings.
Can we leave with our ISMS intact?
Yes. The ISMS lives in your Cybereen tenant and the registers, evidence index and records are yours.
Can we pay the year up front?
Yes, at the same total. Some clients prefer it for budgeting; it makes no difference to the service.
You now know the price. The call is about whether it fits.
Thirty minutes, no slides. We ask about your scope, your people and your deadline, and tell you if this programme is the right shape for you or if something smaller would do.