Does ISO/IEC 27001 ISMS certification — increasingly customer-mandated apply to software and SaaS?
A computed answer from the Rules Mate applicability engine, with the exact condition, the outcome for every structure and size, and the primary source.
Short answer: Only if
Only if your customers or tenders require ISO 27001. Being in this industry makes the obligation worth checking (Industry: Software & SaaS), but the trigger is a fact the industry alone does not settle.
The obligation in brief
ISO/IEC 27001 ISMS certification — increasingly customer-mandated. ISO/IEC 27001 sets requirements for an Information Security Management System (ISMS). Certification by accredited certification body (JAS-ANZ).
Trigger: Customer or tender requirement.
Why software & saas get a different answer
Rules Mate runs its applicability engine across 9 business structures and 6 size bands for each of the 35 industries it maps. For 33 of those industries the answer for "ISO/IEC 27001 ISMS certification — increasingly customer-mandated" is no. Software & SaaS is one of the 2 where the answer is different: only if.
The deciding fact for software and SaaS: Industry: Software & SaaS; applies only if your customers or tenders require ISO 27001.
About the industry: Tech companies — captured by Privacy Act, Online Safety Act, AI Voluntary Standard, and SOCI if critical-infrastructure-aligned.
Compare a professional services (general) business with 6–19 employees structured as a Pty Ltd company: the obligation does not apply (Requires a trigger outside this questionnaire).
Answer by business structure and size
Each cell is the engine's outcome for a business in software & saas with that structure and size, assuming it sells to consumers and small businesses and holds customer contact details. "Check" means the obligation turns on a fact the industry does not settle.
| Structure | No employees | 1–5 employees | 6–19 employees | 20–99 employees | 100–499 employees | 500+ employees |
|---|---|---|---|---|---|---|
| Sole trader | Check | Check | Check | Check | Check | Check |
| Partnership | Check | Check | Check | Check | Check | Check |
| Trust | Check | Check | Check | Check | Check | Check |
| Pty Ltd company | Check | Check | Check | Check | Check | Check |
| Public company | Check | Check | Check | Check | Check | Check |
| Not-for-profit (unregistered) | Check | Check | Check | Check | Check | Check |
| Registered charity | Check | Check | Check | Check | Check | Check |
| Super fund | Check | Check | Check | Check | Check | Check |
| Foreign company | Check | Check | Check | Check | Check | Check |
What the obligation requires
- When due
- Continuous; surveillance audits + recertification cycle.
- Evidence to keep
- ISMS documentation; ISO 27001 certificate; audit reports.
- Maximum penalty
- Loss of certification + commercial / tender consequences
- Regulator
- ASD
- Jurisdiction
- Commonwealth (national)
Other obligations where software & saas differ from the norm
Other industries with a non-default answer
Questions
- Does ISO/IEC 27001 ISMS certification — increasingly customer-mandated apply to software and SaaS?
- Only if your customers or tenders require ISO 27001. Being in this industry makes the obligation worth checking (Industry: Software & SaaS), but the trigger is a fact the industry alone does not settle.
- Is the answer the same for every industry?
- No. For 33 of the 35 industries Rules Mate maps, the answer is no. Software & SaaS is one of 2 industries with a different answer.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.