Skip to main content
Rules Mate

Does ISO/IEC 27001 ISMS certification — increasingly customer-mandated apply to software and SaaS?

A computed answer from the Rules Mate applicability engine, with the exact condition, the outcome for every structure and size, and the primary source.

Short answer: Only if

Only if your customers or tenders require ISO 27001. Being in this industry makes the obligation worth checking (Industry: Software & SaaS), but the trigger is a fact the industry alone does not settle.

The obligation in brief

ISO/IEC 27001 ISMS certification — increasingly customer-mandated. ISO/IEC 27001 sets requirements for an Information Security Management System (ISMS). Certification by accredited certification body (JAS-ANZ).

Trigger: Customer or tender requirement.

Why software & saas get a different answer

Rules Mate runs its applicability engine across 9 business structures and 6 size bands for each of the 35 industries it maps. For 33 of those industries the answer for "ISO/IEC 27001 ISMS certification — increasingly customer-mandated" is no. Software & SaaS is one of the 2 where the answer is different: only if.

The deciding fact for software and SaaS: Industry: Software & SaaS; applies only if your customers or tenders require ISO 27001.

About the industry: Tech companies — captured by Privacy Act, Online Safety Act, AI Voluntary Standard, and SOCI if critical-infrastructure-aligned.

Compare a professional services (general) business with 6–19 employees structured as a Pty Ltd company: the obligation does not apply (Requires a trigger outside this questionnaire).

Answer by business structure and size

Each cell is the engine's outcome for a business in software & saas with that structure and size, assuming it sells to consumers and small businesses and holds customer contact details. "Check" means the obligation turns on a fact the industry does not settle.

"ISO/IEC 27001 ISMS certification — increasingly customer-mandated": outcome for software and SaaS by structure and size
StructureNo employees1–5 employees6–19 employees20–99 employees100–499 employees500+ employees
Sole traderCheckCheckCheckCheckCheckCheck
PartnershipCheckCheckCheckCheckCheckCheck
TrustCheckCheckCheckCheckCheckCheck
Pty Ltd companyCheckCheckCheckCheckCheckCheck
Public companyCheckCheckCheckCheckCheckCheck
Not-for-profit (unregistered)CheckCheckCheckCheckCheckCheck
Registered charityCheckCheckCheckCheckCheckCheck
Super fundCheckCheckCheckCheckCheckCheck
Foreign companyCheckCheckCheckCheckCheckCheck

What the obligation requires

When due
Continuous; surveillance audits + recertification cycle.
Evidence to keep
ISMS documentation; ISO 27001 certificate; audit reports.
Maximum penalty
Loss of certification + commercial / tender consequences
Regulator
ASD
Jurisdiction
Commonwealth (national)

Other obligations where software & saas differ from the norm

Other industries with a non-default answer

Questions

Does ISO/IEC 27001 ISMS certification — increasingly customer-mandated apply to software and SaaS?
Only if your customers or tenders require ISO 27001. Being in this industry makes the obligation worth checking (Industry: Software & SaaS), but the trigger is a fact the industry alone does not settle.
Is the answer the same for every industry?
No. For 33 of the 35 industries Rules Mate maps, the answer is no. Software & SaaS is one of 2 industries with a different answer.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.