Evidence pack prepared for an ISO 27001 certification audit

Security you can prove.

Essential Eight assessments and ISO 27001 compliance services, Melbourne and Sydney.

Being secure and being able to prove it are two different jobs. We run the controls, keep the evidence current, and hand you something an auditor, an insurer or a tender panel will actually accept. AWD services are ISO 27001 certified, so we are documenting a process we already live with.

ISO 27001 certified Independently audited
Almost all onshore & in-house Melbourne & Sydney teams
Same day response guarantee Real engineers, no scripts

Where you stand

Essential Eight maturity.

The eight controls, each scored from Maturity Level 0 to 3. This is where a real assessment starts.

Application control

ML0

Patch applications

ML1

Office macros

ML2

User application hardening

ML3

Restrict admin privileges

ML0

Patch operating systems

ML1

Multi-factor authentication

ML2

Regular backups

ML3
What is the Essential Eight?

Eight mitigation strategies published by the Australian Signals Directorate, each scored from Maturity Level Zero to Maturity Level Three. It is the Australian baseline for practical cyber security uplift.

Is the Essential Eight mandatory?

For non-corporate Commonwealth entities, yes, under the Protective Security Policy Framework. NSW government agencies must implement it to at least Maturity Level 1 under the NSW Cyber Security Policy. Defence Industry Security Program members must meet or exceed Maturity Level 2 on systems used to correspond with Defence. For private business generally it is not law, but it is increasingly a contractual requirement flowed down by customers.

Is the Essential Eight being replaced?

ASD announced in June 2026 that it will replace the Essential Eight with a new “Essentials” series over roughly two years, with separate guidance for enterprise IT, operational technology and cloud. The Essential Eight remains current and both will run side by side during the transition. Work done now is not wasted, and we took part in the consultation.

What is the difference between ISO 27001 aligned and ISO 27001 certified?

Alignment means your controls match the standard and the evidence exists. Certification means an accredited certification body has audited you and issued a certificate. AWD prepares, governs and supports the process. Only an accredited certification body can certify you, and in Australia those bodies are accredited by JAS-ANZ or another IAF Multilateral Recognition Arrangement signatory.

How long does ISO 27001 certification take?

Typically nine to eighteen months from gap analysis to Stage 2 audit, depending on scope and how much is already documented.

Do we need ISO 27001 or the Essential Eight?

Essential Eight if you want measurable security uplift and your customers ask about ACSC alignment. ISO 27001 if you need a certificate to satisfy enterprise customers, insurers or offshore partners. Many businesses do the Essential Eight first and use it as the foundation.

Who has to comply

Who actually has to comply, and who just gets asked.

There is a lot of loose talk about the Essential Eight being required to win government work. Here is what is actually true.

01

Commonwealth entities

Mandatory. Non-corporate Commonwealth entities must meet Maturity Level 2 under the Protective Security Policy Framework.

02

NSW government agencies

Mandatory. A minimum of Maturity Level 1 under the NSW Cyber Security Policy.

03

Defence industry

Mandatory for Defence Industry Security Program members, at Maturity Level 2 or above on the ICT corporate systems used to correspond with Defence.

04

State agencies

Mandatory in Queensland under IS18. Several other states apply it to their own agencies, so check your jurisdiction.

05

Private business

Not mandatory, but asked about constantly. It is not in the Commonwealth Procurement Rules. It turns up instead in customer security questionnaires, insurer underwriting, and supply chain requirements flowed down by larger clients.

The practical position: for most Australian businesses the Essential Eight is not a legal obligation, it is a commercial one.

The journey

ISO 27001 certification timeline.

Six milestones from first look to certified. A clear path, with no surprises at the audit.

  1. 01
    Gap analysis
  2. 02
    ISMS build
  3. 03
    Internal audit
  4. 04
    Stage 1 audit
  5. 05
    Stage 2 audit
  6. 06
    Certified

Which framework

ISO 27001 vs Essential Eight vs SMB1001.

Three routes to demonstrable security. This is how to work out which one fits where you are.

Consideration ISO 27001 Essential Eight SMB1001
Best for Larger & regulated orgs Any Australian business Small business, fast start
Audit / certification Included Self or assessed Tiered certification
Government alignment International standard ACSC / federal SMB supply chain
Effort High Medium Low

Cost of inaction

The cost of doing nothing.

Skipping certification does not remove the risk, it just moves it onto the balance sheet. These are the Australian figures, self-reported to the ASD.

The cost of doing nothing

$56,600
Average self-reported cost of cybercrime per report, small business
$97,200
Average self-reported cost of cybercrime per report, medium business
1,205
Data breach notifications to the OAIC in 2025, the highest on record

ASD Annual Cyber Threat Report 2024-25; OAIC Notifiable Data Breaches, calendar year 2025.

Proof

We hold the badge ourselves

AWD services are ISO 27001 certified and independently audited, so the process we run you through is the same one we passed. Here is one certified client, anonymised.

AWD ISO/IEC 27001:2022 certification
AWD quarterly vCIO review session with a client
Case study • Not-for-profit

A national charity reached Essential Eight Maturity Level 2 in six months.

“They turned a daunting framework into a clear plan, and we passed without the last-minute panic we expected.”

Anonymised • sector label only.

Start here

Not sure where to start?

A no-obligation conversation about your infrastructure, security posture and operational risk. No lock-in, and a response within one business day.