Support for businesses pursuing ISO 27001 certification — gap analysis, ISMS build, technical control implementation and audit preparation, from a certified provider.
Why this page is worth reading
Most ISO 27001 consulting is sold by organisations that have never been certified themselves. That is not disqualifying, but it does mean the advice comes from having read the standard rather than from having sat opposite an auditor being asked for evidence.
JTIT was certified to ISO/IEC 27001:2022 in August 2026 — certificate 0253322, Intertek SAI Global, under JAS-ANZ accreditation. We went through scoping, the Statement of Applicability, the technical remediation and both audit stages, on our own operations.
To be clear about what that does and does not mean: our certification is ours. It does not make you compliant, and engaging us does not transfer it. What it means is that when we tell you an auditor will want evidence of how you review privileged access, we know that because we were asked.
What certification actually involves
A defined scope. ISO 27001 certifies a scope, not a company. This is the first decision and the one with the largest cost consequence — a scope covering every function, site and system is dramatically more expensive than one covering the service your customer is actually asking about. Getting it right is worth thinking hard about.
A management system, not a control checklist. This is where organisations coming from the Essential Eight are surprised. ISO 27001 requires risk assessment methodology, defined objectives, internal audit, management review and demonstrated continual improvement. The Annex A controls are important, but the clauses governing how you run the system are what most first-time audits find gaps in.
Evidence of operation. The system must have been running. Records of risk reviews, incidents, access reviews, internal audits — accumulated over months. This is the structural reason a three-month certification is not credible.
Where implementations fail
Template documentation. A downloaded policy pack describing an organisation you are not. Auditors read policies against practice, and the mismatch is obvious immediately.
Scope creep. Starting broad because it sounds more impressive, then discovering the cost.
Documentation without technical work. Policies asserting controls that are not implemented. The access control policy says privileged access is reviewed quarterly; nobody has ever reviewed it.
Treating it as a project. Certification is the start of a cycle with annual surveillance audits. A system built for the audit and then abandoned fails the first surveillance visit.
What we do
Gap analysis and scoping first, because it produces the real project size and sometimes the answer is that you should not do this yet.
Then the management system — risk methodology, Statement of Applicability, policies written against how you operate — and the technical controls, which is where being an IT provider rather than a documentation consultancy matters. Access control, logging, patching, backup and incident response are things we implement rather than describe.
Then internal audit, management review and preparation for Stage 1 and Stage 2 with your chosen accredited certification body.
Start here instead, possibly
If no customer has asked you for ISO 27001 by name, an Essential Eight assessment is very likely the proportionate answer. It costs a fraction as much, satisfies most Australian tender and supply chain requests, and the control work overlaps substantially with what ISO 27001 would require later.
We would rather tell you that than sell you a twelve-month programme you did not need.