Skip to main content
Rules Mate

Who must comply with ISO/IEC 27001 ISMS certification — increasingly customer-mandated?

The applicability test for ISO/IEC 27001 ISMS certification — increasingly customer-mandated (ASD), computed across 35 industries, 9 business structures and 6 size bands.

Short answer: Only if

Applies only if your customers or tenders require ISO 27001. Whether it applies turns on a fact that no industry, structure or size settles on its own.

What the obligation is

Information Security Management System per ISO 27001 increasingly required by customers + government.

ISO/IEC 27001 sets requirements for an Information Security Management System (ISMS). Certification by accredited certification body (JAS-ANZ). Not legally mandated but: customer + government tender required; reasonable-steps evidence under APP 11; aligned with ASD ISM where applicable.

The applicability test

Applies only if your customers or tenders require ISO 27001. Whether it applies turns on a fact that no industry, structure or size settles on its own.

How the regulator frames it: Voluntary; commercially mandated by customers / tenders.

What triggers it: Customer or tender requirement.

Jurisdiction: Commonwealth law, so the test is the same in every state and territory.

Which industries are in or out

Outcome across the 35 industries Rules Mate maps (2 of 35: only if a further fact applies; 33 of 35: no).

IndustryAnswer
Fintech (non-bank)Only if a further fact applies
Software & SaaSOnly if a further fact applies
No33 other industries

Business structure and size

Structure does not change the answer in the 2 industries it can reach: for every structure the answer is "only if a further fact applies".

Size does not change the answer in the 2 industries it can reach: at every size band the answer is "only if a further fact applies".

Worked examples

Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:

  • Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires a trigger outside this questionnaire.
  • Pty Ltd company in fintech (non-bank) with 6–19 employees, turnover $1M–$3M: check whether it applies. applies only if your customers or tenders require ISO 27001.

When you need to check further

The engine shows this obligation as "check whether this applies" when a business has industry: Software & SaaS / Fintech (non-bank). It then applies only if your customers or tenders require ISO 27001. That fact is not something Rules Mate can infer from industry, structure or size.

What you must do, and when

When due
Continuous; surveillance audits + recertification cycle.
Frequency
Ongoing
Evidence to keep
ISMS documentation; ISO 27001 certificate; audit reports.
Status
Current
Priority
High

Penalty for not complying

Maximum penalty: Loss of certification + commercial / tender consequences.

Audit or assurance level

Voluntary certification. Authority: ISO 'Management system standards' (certification is not a requirement); ISO/IEC 17021-1:2015.

Frequency: No legal requirement. If you choose accredited certification: a 3-year cycle (initial stage 1 and 2 audits, annual surveillance audits, recertification in year 3).

Who can perform it: A certification body accredited (in Australia and New Zealand, by JAS-ANZ) to ISO/IEC 17021-1. Without accredited certification you may make a supplier's self-declaration of conformity (ISO/IEC 17050-1), but you must not describe the business as holding ISO certification. ISO itself does not issue certificates.

Where it sits in the corpus

Rules Mate tracks 9 published obligations tagged "cyber", 4 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated high priority, and is an ongoing duty.

Regulator, legislation and tools

Regulated by Australian Signals Directorate (Australian Cyber Security Centre).

ASD: Cyber security guidance and incident response. Publishes the Information Security Manual (ISM), Essential Eight, and Right Fit For Risk requirements for federal subcontractors.

Free tools that help with this obligation:

Questions

Who must comply with ISO/IEC 27001 ISMS certification — increasingly customer-mandated?
Applies only if your customers or tenders require ISO 27001. Whether it applies turns on a fact that no industry, structure or size settles on its own.
Does ISO/IEC 27001 ISMS certification — increasingly customer-mandated apply to sole traders?
Only if a further fact applies. Looking in the 2 industries it can reach and every size band, the engine's answer for a sole trader is: only if a further fact applies.
Does ISO/IEC 27001 ISMS certification — increasingly customer-mandated apply to businesses with 1–5 employees?
Only if a further fact applies (1–5 employees, turnover $100K–$1M).
When is "ISO/IEC 27001 ISMS certification — increasingly customer-mandated" due?
Continuous; surveillance audits + recertification cycle.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.