Who must comply with ISO/IEC 27001 ISMS certification — increasingly customer-mandated?
The applicability test for ISO/IEC 27001 ISMS certification — increasingly customer-mandated (ASD), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Only if
Applies only if your customers or tenders require ISO 27001. Whether it applies turns on a fact that no industry, structure or size settles on its own.
What the obligation is
Information Security Management System per ISO 27001 increasingly required by customers + government.
ISO/IEC 27001 sets requirements for an Information Security Management System (ISMS). Certification by accredited certification body (JAS-ANZ). Not legally mandated but: customer + government tender required; reasonable-steps evidence under APP 11; aligned with ASD ISM where applicable.
The applicability test
Applies only if your customers or tenders require ISO 27001. Whether it applies turns on a fact that no industry, structure or size settles on its own.
How the regulator frames it: Voluntary; commercially mandated by customers / tenders.
What triggers it: Customer or tender requirement.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (2 of 35: only if a further fact applies; 33 of 35: no).
| Industry | Answer |
|---|---|
| Fintech (non-bank) | Only if a further fact applies |
| Software & SaaS | Only if a further fact applies |
| No | 33 other industries |
Business structure and size
Structure does not change the answer in the 2 industries it can reach: for every structure the answer is "only if a further fact applies".
Size does not change the answer in the 2 industries it can reach: at every size band the answer is "only if a further fact applies".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires a trigger outside this questionnaire.
- Pty Ltd company in fintech (non-bank) with 6–19 employees, turnover $1M–$3M: check whether it applies. applies only if your customers or tenders require ISO 27001.
When you need to check further
The engine shows this obligation as "check whether this applies" when a business has industry: Software & SaaS / Fintech (non-bank). It then applies only if your customers or tenders require ISO 27001. That fact is not something Rules Mate can infer from industry, structure or size.
What you must do, and when
- When due
- Continuous; surveillance audits + recertification cycle.
- Frequency
- Ongoing
- Evidence to keep
- ISMS documentation; ISO 27001 certificate; audit reports.
- Status
- Current
- Priority
- High
Penalty for not complying
Maximum penalty: Loss of certification + commercial / tender consequences.
Audit or assurance level
Voluntary certification. Authority: ISO 'Management system standards' (certification is not a requirement); ISO/IEC 17021-1:2015.
Frequency: No legal requirement. If you choose accredited certification: a 3-year cycle (initial stage 1 and 2 audits, annual surveillance audits, recertification in year 3).
Who can perform it: A certification body accredited (in Australia and New Zealand, by JAS-ANZ) to ISO/IEC 17021-1. Without accredited certification you may make a supplier's self-declaration of conformity (ISO/IEC 17050-1), but you must not describe the business as holding ISO certification. ISO itself does not issue certificates.
Where it sits in the corpus
Rules Mate tracks 9 published obligations tagged "cyber", 4 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated high priority, and is an ongoing duty.
Regulator, legislation and tools
Regulated by Australian Signals Directorate (Australian Cyber Security Centre).
ASD: Cyber security guidance and incident response. Publishes the Information Security Manual (ISM), Essential Eight, and Right Fit For Risk requirements for federal subcontractors.
Free tools that help with this obligation:
Questions
- Who must comply with ISO/IEC 27001 ISMS certification — increasingly customer-mandated?
- Applies only if your customers or tenders require ISO 27001. Whether it applies turns on a fact that no industry, structure or size settles on its own.
- Does ISO/IEC 27001 ISMS certification — increasingly customer-mandated apply to sole traders?
- Only if a further fact applies. Looking in the 2 industries it can reach and every size band, the engine's answer for a sole trader is: only if a further fact applies.
- Does ISO/IEC 27001 ISMS certification — increasingly customer-mandated apply to businesses with 1–5 employees?
- Only if a further fact applies (1–5 employees, turnover $100K–$1M).
- When is "ISO/IEC 27001 ISMS certification — increasingly customer-mandated" due?
- Continuous; surveillance audits + recertification cycle.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.