Skip to main content
Service

ISO 27001 support from a provider that has been through the audit

We hold ISO/IEC 27001:2022 certification ourselves, under JAS-ANZ accreditation. That is the whole reason our advice on getting you there is worth anything.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

Support for businesses pursuing ISO 27001 certification — gap analysis, ISMS build, technical control implementation and audit preparation, from a certified provider.

Why this page is worth reading

Most ISO 27001 consulting is sold by organisations that have never been certified themselves. That is not disqualifying, but it does mean the advice comes from having read the standard rather than from having sat opposite an auditor being asked for evidence.

JTIT was certified to ISO/IEC 27001:2022 in August 2026 — certificate 0253322, Intertek SAI Global, under JAS-ANZ accreditation. We went through scoping, the Statement of Applicability, the technical remediation and both audit stages, on our own operations.

To be clear about what that does and does not mean: our certification is ours. It does not make you compliant, and engaging us does not transfer it. What it means is that when we tell you an auditor will want evidence of how you review privileged access, we know that because we were asked.

What certification actually involves

A defined scope. ISO 27001 certifies a scope, not a company. This is the first decision and the one with the largest cost consequence — a scope covering every function, site and system is dramatically more expensive than one covering the service your customer is actually asking about. Getting it right is worth thinking hard about.

A management system, not a control checklist. This is where organisations coming from the Essential Eight are surprised. ISO 27001 requires risk assessment methodology, defined objectives, internal audit, management review and demonstrated continual improvement. The Annex A controls are important, but the clauses governing how you run the system are what most first-time audits find gaps in.

Evidence of operation. The system must have been running. Records of risk reviews, incidents, access reviews, internal audits — accumulated over months. This is the structural reason a three-month certification is not credible.

Where implementations fail

Template documentation. A downloaded policy pack describing an organisation you are not. Auditors read policies against practice, and the mismatch is obvious immediately.

Scope creep. Starting broad because it sounds more impressive, then discovering the cost.

Documentation without technical work. Policies asserting controls that are not implemented. The access control policy says privileged access is reviewed quarterly; nobody has ever reviewed it.

Treating it as a project. Certification is the start of a cycle with annual surveillance audits. A system built for the audit and then abandoned fails the first surveillance visit.

What we do

Gap analysis and scoping first, because it produces the real project size and sometimes the answer is that you should not do this yet.

Then the management system — risk methodology, Statement of Applicability, policies written against how you operate — and the technical controls, which is where being an IT provider rather than a documentation consultancy matters. Access control, logging, patching, backup and incident response are things we implement rather than describe.

Then internal audit, management review and preparation for Stage 1 and Stage 2 with your chosen accredited certification body.

Start here instead, possibly

If no customer has asked you for ISO 27001 by name, an Essential Eight assessment is very likely the proportionate answer. It costs a fraction as much, satisfies most Australian tender and supply chain requests, and the control work overlaps substantially with what ISO 27001 would require later.

We would rather tell you that than sell you a twelve-month programme you did not need.

What you get with JTIT

Concrete deliverables, not vague promises.

Advice from the other side of the audit

JTIT went through certification in 2026. We know which evidence auditors ask for and where implementations fall over, because ours was tested.

Scope defined before anything else

Certification covers a defined scope. Getting that wrong makes the project far larger and more expensive than it needed to be, and it is the first decision.

Technical controls we can actually implement

Most ISO consultants write documentation and hand you a list. We do the access control, logging, patching and backup work as well.

Documentation that reflects reality

An ISMS describing a business you do not run fails at the first audit. Policies written against how you actually work, not from a template pack.

Realistic timelines

Certification is typically a six to twelve month undertaking for a business new to it. Anyone promising three months is skipping something an auditor will find.

Maintained, not just achieved

Surveillance audits happen annually. The system has to keep running — internal audits, management review, risk reassessment — or the certificate lapses.

How it works

A predictable, no-surprises process.

  1. 01

    Scope and gap analysis

    Define what certification will cover, then assess current state against the Annex A controls and the management system clauses. Produces the real project size.

  2. 02

    Build the management system

    Risk assessment methodology, Statement of Applicability, policies and procedures — written against your operations rather than adapted from a template.

  3. 03

    Implement the controls

    The technical work: access control, logging and monitoring, patching, backup, supplier management, incident response. This is usually the largest part.

  4. 04

    Internal audit and certification

    Internal audit, management review, corrective actions, then Stage 1 and Stage 2 external audits with your chosen certification body.

Frequently asked questions

Is JTIT itself ISO 27001 certified?

Yes. JTIT Pty Ltd holds ISO/IEC 27001:2022 certificate number 0253322, issued by Intertek SAI Global under JAS-ANZ accreditation, valid to 4 August 2029. The certified scope covers our IT solutions and support services including managed IT, cloud, cybersecurity, web design and hosting, business phone systems and data recovery. The certificate is published on our site with the scope quoted verbatim so you can verify it independently.

How long does certification take?

For an organisation starting from scratch, typically six to twelve months to Stage 2, depending on scope, size and how much of the technical groundwork already exists. Businesses that already have decent access control, patching and backup discipline move faster because those are the controls, not just the documentation. Be wary of anyone promising certification in three months — the standard requires evidence that the management system has been operating, and you cannot produce operating evidence for a system that started last month.

What does it cost?

Two separate costs. The certification body's audit fees are theirs and depend on your headcount and scope. The implementation effort — consulting, documentation, technical remediation, internal audit — is the larger figure for most organisations and varies enormously with your starting point. A gap analysis is the only honest way to give you a number, and it is worth doing before committing to anything.

Do we need ISO 27001 or is Essential Eight enough?

Usually it comes down to who is asking. The Essential Eight is a technical control baseline and is far cheaper to demonstrate; it satisfies most Australian tender and supply chain requests. ISO 27001 is a certified management system with international recognition, and it is what large enterprise customers, international clients and some regulated sectors specifically require. If nobody has asked you for ISO 27001 by name, start with an Essential Eight assessment.

Can you be our certification body as well?

No, and no one can do both. Certification bodies must be independent of the organisations they audit, which is a requirement of their own accreditation. We help you implement and prepare; an accredited body such as the one that certified us performs the audit. Any provider offering to both implement and certify is not describing accredited certification.

Related services

Most clients combine a few of these — we'll help you decide what's right for your size and risk profile.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote