Reach out to us today and ensure your business stays protected.
Security Solution Consultants (SSC) prepares Australian and New Zealand organisations for independent certification and assurance against ISO/IEC 27001, ISO/IEC 42001, ISO 9001, ISO 14001, SOC 2 and the critical infrastructure frameworks regulators expect. We scope and build the management system, run the internal audit, close the gaps and stay with you through the external audit, so you reach certification with controls that reduce real risk rather than a folder of paperwork.

How certification works. SSC is your implementation and readiness partner. ISO certificates are issued by independent certification bodies that are accredited, in Australia and New Zealand, by JAS-ANZ or another member of the International Accreditation Forum. SOC 2 reports are issued by licensed CPA firms. Keeping the adviser and the auditor separate protects the independence and value of your certificate, and we help you choose an accredited body that fits your scope and budget.
Each standard below is also a ready-made module in GRCLens, our GRC platform, so your controls, evidence, risks and audit findings live in one place before, during and after certification.
| Standard or scheme | What it covers | Who issues it | Suits |
|---|---|---|---|
| ISO/IEC 27001:2022 | Information security management system (ISMS) | Accredited certification body | Any organisation that holds customer or sensitive data |
| ISO/IEC 42001:2023 | Artificial intelligence management system (AIMS) | Accredited certification body | Organisations that build, provide or use AI |
| ISO 9001 | Quality management system (QMS) | Accredited certification body | Manufacturers, service providers, government suppliers |
| ISO 14001 | Environmental management system (EMS) | Accredited certification body | Construction, manufacturing, logistics, tender bidders |
| ISO 45001:2018 | Occupational health and safety (OH&S) management system | Accredited certification body | Construction, energy, field services, manufacturing |
| ISO 22301:2019 | Business continuity management system (BCMS) | Accredited certification body | Financial services, critical infrastructure, IT providers |
| ISO/IEC 20000-1:2018 | IT service management system (SMS) | Accredited certification body | Managed service providers and internal IT |
| ISO 22361:2022 | Crisis management capability (guidance standard) | Not certifiable; independent capability assessment | Boards and executive crisis teams |
| SOC 2 Type 1 and Type 2 | Controls over a service, against the AICPA Trust Services Criteria | Licensed CPA firm (attestation report) | SaaS and cloud providers selling to enterprise customers |
| PCI DSS v4.0.1 | Protection of payment card data | Qualified Security Assessor or self-assessment | Merchants and service providers that handle card data |
| SOCI Act CIRMP and AESCSF | Critical infrastructure risk management and energy sector cyber maturity | Board-approved annual report; independent assessment | Energy, water, ports, data storage and other critical assets |
| ISA/IEC 62443 | Security of industrial automation and control systems | Assessment against the standard; product schemes available | Operators and suppliers of operational technology |
| IRAP (Australian ISM) | Security of systems used by Australian government | ASD-endorsed IRAP assessor | Cloud and software providers selling to government |

ISO management system standards, including ISO/IEC 27001, ISO/IEC 42001, ISO 9001, ISO 14001, ISO 45001, ISO 22301 and ISO/IEC 20000-1, share the same harmonised structure: clauses 4 to 10 cover context, leadership, planning, support, operation, performance evaluation and improvement in the same order. That means one set of governance documents, one risk method, one internal audit program and one management review can serve several certificates.
Certification bodies can also run combined audits for integrated systems, which usually reduces total audit days compared with separate audits. We design the system so each standard’s specific requirements, such as the Annex A controls in ISO/IEC 27001 and ISO/IEC 42001, sit on a shared foundation.

ISO/IEC 42001:2023 is the first certifiable international standard for an artificial intelligence management system. It applies whether you develop AI models, provide AI-enabled services or use AI tools in your operations. Customers and procurement teams increasingly ask suppliers to show how AI is governed, and the standard gives you an auditable answer.
Our ISO 42001 work covers:
Further reading: AI governance for business, the agentic AI risk assessment checklist and ISO 31000 vs ISO 23894 for AI risk.

A SOC 2 report is an independent attestation, issued by a licensed CPA firm, on the controls over a service you provide. It is assessed against the AICPA Trust Services Criteria across five categories: security, availability, processing integrity, confidentiality and privacy. Security is always in scope; the others are added when they matter to your customers.
We help SaaS and technology companies in Brisbane, Sydney, Melbourne, Auckland and Wellington with scoping, gap assessment, control design, evidence collection in GRCLens, and a readiness review before the CPA firm starts. Because most SOC 2 controls overlap with ISO/IEC 27001, many clients build both on the same control set. Read more in SOC reports explained and on our security compliance page.

Under the Security of Critical Infrastructure Act 2018 (SOCI), responsible entities must maintain a Critical Infrastructure Risk Management Program (CIRMP) and give the Department of Home Affairs an annual report approved by the board, council or governing body within 90 days of the end of the Australian financial year, which falls on 28 September. Significant cyber incidents must be reported to ASD within 12 hours, and other incidents with a relevant impact within 72 hours.
We provide:
For financial services we also assess against APRA CPS 234 and CPS 230, and for New Zealand clients against the Protective Security Requirements and sector requirements such as HISO 10029 for health.

Timelines depend on scope, size and how much is already in place. A focused scope with existing policies can be ready for Stage 1 within a few months; multi-site or multi-standard programs take longer. A SOC 2 Type 2 report also needs an observation period of at least three months.
Ready to start? Contact our certification team for a scoping call, or explore the standards in GRCLens.
No. ISO certificates are issued by independent certification bodies that are accredited by an accreditation body such as JAS-ANZ. SSC prepares you for certification, runs the internal audit and supports you through the external audit. Keeping the adviser separate from the auditor protects the independence of your certificate.
Certification is when an independent body audits your management system and confirms it meets a standard such as ISO/IEC 27001. Accreditation is when an accreditation body, such as JAS-ANZ in Australia and New Zealand, confirms that the certification body itself is competent and impartial. Always check that your certifier is accredited for the standard you need.
Yes. ISO management system standards share the same structure, so ISO/IEC 27001, ISO 9001, ISO 14001, ISO 45001, ISO 22301 and ISO/IEC 42001 can run as one integrated system with shared policies, risk management, internal audit and management review. Certification bodies can audit them together, which usually reduces total audit days.
It depends on your customers. ISO/IEC 27001 is recognised internationally and common in Australian, New Zealand, Asian and European procurement. SOC 2 is what many United States customers ask for. The controls overlap heavily, so many SaaS providers build one control set and obtain both.
ISO/IEC 42001 applies to organisations that use AI as well as those that develop it. If AI tools influence decisions about customers, staff or operations, or customers are asking how you govern AI, the standard gives you a structured and auditable answer. Certification is optional; many organisations start by aligning to it.
Both standards have new editions in 2026. ISO 14001:2026 certificates must transition from the 2015 edition before May 2029, and a three-year transition is also expected for ISO 9001:2026. The changes are moderate, so the move can usually be planned into your normal surveillance or recertification audit.
An ISO management system certificate is usually valid for three years, with surveillance audits in the second and third years and a recertification audit before it expires.

Secure your cloud environments & ensure safe migration with compliance-ready.
Stay informe with the latest cybersecurity news, expert tips.
Copyright © 2026 All Rights Reserved.