Security Certification and Accreditation Services

Yellow circular logo with intertwined abstract shapes next to "Business Continuity Management (BCM).
EASMLens external attack surface management platform logo
NSPM network security policy management logo
PhishLens phishing simulation and awareness logo

Security Solution Consultants (SSC) prepares Australian and New Zealand organisations for independent certification and assurance against ISO/IEC 27001, ISO/IEC 42001, ISO 9001, ISO 14001, SOC 2 and the critical infrastructure frameworks regulators expect. We scope and build the management system, run the internal audit, close the gaps and stay with you through the external audit, so you reach certification with controls that reduce real risk rather than a folder of paperwork.

Embossed gold certification seal on an audit binder beside a padlock, representing security certification and accreditation
Certification is evidence of a working management system, not the goal in itself.

How certification works. SSC is your implementation and readiness partner. ISO certificates are issued by independent certification bodies that are accredited, in Australia and New Zealand, by JAS-ANZ or another member of the International Accreditation Forum. SOC 2 reports are issued by licensed CPA firms. Keeping the adviser and the auditor separate protects the independence and value of your certificate, and we help you choose an accredited body that fits your scope and budget.

Certifications and assessments we support

Each standard below is also a ready-made module in GRCLens, our GRC platform, so your controls, evidence, risks and audit findings live in one place before, during and after certification.

Standard or schemeWhat it coversWho issues itSuits
ISO/IEC 27001:2022Information security management system (ISMS)Accredited certification bodyAny organisation that holds customer or sensitive data
ISO/IEC 42001:2023Artificial intelligence management system (AIMS)Accredited certification bodyOrganisations that build, provide or use AI
ISO 9001Quality management system (QMS)Accredited certification bodyManufacturers, service providers, government suppliers
ISO 14001Environmental management system (EMS)Accredited certification bodyConstruction, manufacturing, logistics, tender bidders
ISO 45001:2018Occupational health and safety (OH&S) management systemAccredited certification bodyConstruction, energy, field services, manufacturing
ISO 22301:2019Business continuity management system (BCMS)Accredited certification bodyFinancial services, critical infrastructure, IT providers
ISO/IEC 20000-1:2018IT service management system (SMS)Accredited certification bodyManaged service providers and internal IT
ISO 22361:2022Crisis management capability (guidance standard)Not certifiable; independent capability assessmentBoards and executive crisis teams
SOC 2 Type 1 and Type 2Controls over a service, against the AICPA Trust Services CriteriaLicensed CPA firm (attestation report)SaaS and cloud providers selling to enterprise customers
PCI DSS v4.0.1Protection of payment card dataQualified Security Assessor or self-assessmentMerchants and service providers that handle card data
SOCI Act CIRMP and AESCSFCritical infrastructure risk management and energy sector cyber maturityBoard-approved annual report; independent assessmentEnergy, water, ports, data storage and other critical assets
ISA/IEC 62443Security of industrial automation and control systemsAssessment against the standard; product schemes availableOperators and suppliers of operational technology
IRAP (Australian ISM)Security of systems used by Australian governmentASD-endorsed IRAP assessorCloud and software providers selling to government

Information security, privacy and payments

  • ISO/IEC 27001:2022 (ISMS). The most widely recognised information security certification. We cover scoping, risk assessment, the Statement of Applicability, the 93 Annex A controls, internal audit and management review. See our dedicated ISO 27001 certification service and our guide to ISO 27001 certification cost in Australia.
  • SOC 2 Type 1 and Type 2. Readiness for the attestation enterprise buyers, especially in the United States, ask SaaS and cloud providers for. More detail below.
  • PCI DSS v4.0.1. Scoping, gap assessment and remediation for merchants and service providers. See PCI DSS compliance advisory.
  • IRAP readiness. Preparing cloud and software services, documentation and evidence for assessment against the Australian Government Information Security Manual by an ASD-endorsed IRAP assessor.

Artificial intelligence

  • ISO/IEC 42001:2023 (AIMS). The first certifiable management system standard for artificial intelligence, covering AI risk and impact assessment, data quality, system lifecycle and third-party AI. More detail below.

Quality, environment and safety

  • ISO 9001 quality management. ISO 9001:2026 was published on 16 September 2026 and replaces the 2015 edition. A three-year transition is expected, and the changes are moderate, so certified organisations can plan the move alongside their normal audit cycle.
  • ISO 14001 environmental management. ISO 14001:2026 was published in April 2026, with clearer risk and opportunity requirements, a stronger life cycle perspective and new requirements for planning changes. Certificates to the 2015 edition need to transition before May 2029.
  • ISO 45001:2018 occupational health and safety. Hazard identification, worker consultation and legal compliance, often combined with ISO 9001 and ISO 14001 in one integrated system.

Resilience and service management

  • ISO 22301:2019 business continuity. Business impact analysis, continuity strategies, exercising and improvement. See our business continuity management service.
  • ISO 22361:2022 crisis management. A guidance standard, so it is not certified, but we assess your crisis capability against it: activation, leadership, decision-making, communication and learning.
  • ISO/IEC 20000-1:2018 IT service management. For managed service providers and internal IT teams that want to prove service quality to customers.

Why organisations choose SSC for certification

  • Risk-focused, not tick-box. We start from the risks that matter to your business and design controls that address them. Certification follows, and the controls keep working after the auditor leaves. This is the same approach we take to our own security, described in our Trust Centre.
  • We hold the certificate we help you earn. SSC is certified to ISO/IEC 27001 and follows a Secure by Design philosophy, including penetration testing, application code review and threat modelling of our own platforms.
  • One integrated system for several standards. Explained below, this saves effort, documents and audit days.
  • A platform, not just a report. GRCLens keeps your Statement of Applicability, risk register, evidence, internal audits and management reviews current, so surveillance audits are routine rather than a scramble.
  • Local and regional reach. We work with clients across Australia and New Zealand, and in Singapore, the UAE, Saudi Arabia, Malaysia, the United Kingdom and the Pacific.

Integrated management systems: certify once, comply many times

Five interlocking glass gears in different colours representing an integrated management system across ISO standards
ISO management system standards share one structure, so they can run as one system.

ISO management system standards, including ISO/IEC 27001, ISO/IEC 42001, ISO 9001, ISO 14001, ISO 45001, ISO 22301 and ISO/IEC 20000-1, share the same harmonised structure: clauses 4 to 10 cover context, leadership, planning, support, operation, performance evaluation and improvement in the same order. That means one set of governance documents, one risk method, one internal audit program and one management review can serve several certificates.

Certification bodies can also run combined audits for integrated systems, which usually reduces total audit days compared with separate audits. We design the system so each standard’s specific requirements, such as the Annex A controls in ISO/IEC 27001 and ISO/IEC 42001, sit on a shared foundation.

ISO/IEC 42001 certification for responsible AI

Glass cube of glowing neural filaments balanced on a brass scale against bound policy books, representing ISO 42001 AI governance
ISO/IEC 42001 balances AI innovation with governance and accountability.

ISO/IEC 42001:2023 is the first certifiable international standard for an artificial intelligence management system. It applies whether you develop AI models, provide AI-enabled services or use AI tools in your operations. Customers and procurement teams increasingly ask suppliers to show how AI is governed, and the standard gives you an auditable answer.

Our ISO 42001 work covers:

  • an AI system inventory, with purpose, data, owner and risk level for each system
  • AI risk assessment and AI system impact assessment
  • AI policy, roles and responsibilities, and human oversight
  • data quality and provenance controls across the AI system lifecycle
  • supplier and third-party AI controls
  • alignment with your ISO/IEC 27001 ISMS, so shared controls are evidenced once

Further reading: AI governance for business, the agentic AI risk assessment checklist and ISO 31000 vs ISO 23894 for AI risk.

SOC 2 readiness for SaaS and cloud providers

Five columns of different materials supporting a glass platform with a server cabinet, representing the SOC 2 Trust Services Criteria
SOC 2 reports against five Trust Services Criteria categories.

A SOC 2 report is an independent attestation, issued by a licensed CPA firm, on the controls over a service you provide. It is assessed against the AICPA Trust Services Criteria across five categories: security, availability, processing integrity, confidentiality and privacy. Security is always in scope; the others are added when they matter to your customers.

  • Type 1 reports on whether controls are suitably designed at a point in time.
  • Type 2 reports on whether controls operated effectively over an observation period, typically three to twelve months, and is the report most enterprise buyers expect.

We help SaaS and technology companies in Brisbane, Sydney, Melbourne, Auckland and Wellington with scoping, gap assessment, control design, evidence collection in GRCLens, and a readiness review before the CPA firm starts. Because most SOC 2 controls overlap with ISO/IEC 27001, many clients build both on the same control set. Read more in SOC reports explained and on our security compliance page.

Critical infrastructure audit and assessment

Inspector with a tablet showing a risk heat map at an electrical substation at dusk, representing critical infrastructure security assessment
Critical infrastructure obligations are assessed against risk, maturity and board accountability.

Under the Security of Critical Infrastructure Act 2018 (SOCI), responsible entities must maintain a Critical Infrastructure Risk Management Program (CIRMP) and give the Department of Home Affairs an annual report approved by the board, council or governing body within 90 days of the end of the Australian financial year, which falls on 28 September. Significant cyber incidents must be reported to ASD within 12 hours, and other incidents with a relevant impact within 72 hours.

We provide:

  • CIRMP assessment across cyber and information security, personnel, supply chain, and physical security and natural hazards, with evidence to support the board’s annual report
  • AESCSF maturity assessments for electricity, gas and liquid fuel entities; see our energy sector security assessment and AESCSF compliance guide
  • ISA/IEC 62443 assessments of industrial automation and control systems and OT networks
  • Critical infrastructure risk management linked to your enterprise risk framework; see enterprise risk management and CIRMP advisory

For financial services we also assess against APRA CPS 234 and CPS 230, and for New Zealand clients against the Protective Security Requirements and sector requirements such as HISO 10029 for health.

Our certification process

Stepping stones crossing a calm lake towards a lighthouse at sunrise, representing the staged certification journey
A clear, staged path from gap assessment to certification and beyond.
  1. Scope and gap assessment. We agree the scope, sites and services, then assess current practice against the standard and give you a prioritised roadmap.
  2. Design and implement. Policies, risk assessment and treatment, the Statement of Applicability or equivalent, and the controls themselves, built with your team.
  3. Internal audit and management review. Both are required by the ISO standards (clauses 9.2 and 9.3) before certification. We run the internal audit independently of the people who built the system.
  4. Stage 1 audit. The certification body reviews your documentation and readiness. We support you and help close any findings.
  5. Stage 2 audit. The certification body tests whether the system works in practice. A successful audit leads to a certificate, usually valid for three years.
  6. Surveillance and recertification. Annual surveillance audits in years two and three, then recertification. GRCLens keeps evidence current so each audit is routine.

Timelines depend on scope, size and how much is already in place. A focused scope with existing policies can be ready for Stage 1 within a few months; multi-site or multi-standard programs take longer. A SOC 2 Type 2 report also needs an observation period of at least three months.

Industries we work with

  • Financial services: ISO/IEC 27001, ISO 22301 and SOC 2 alongside APRA CPS 234 and CPS 230
  • Technology and SaaS: ISO/IEC 27001, SOC 2 and ISO/IEC 42001
  • Energy, water and utilities: SOCI CIRMP, AESCSF and ISA/IEC 62443
  • Government suppliers: ISO/IEC 27001, IRAP readiness and the Essential Eight
  • Health: ISO/IEC 27001 and, in New Zealand, HISO 10029
  • Construction, manufacturing and logistics: ISO 9001, ISO 14001 and ISO 45001 as one integrated system

Ready to start? Contact our certification team for a scoping call, or explore the standards in GRCLens.

Frequently asked questions

No. ISO certificates are issued by independent certification bodies that are accredited by an accreditation body such as JAS-ANZ. SSC prepares you for certification, runs the internal audit and supports you through the external audit. Keeping the adviser separate from the auditor protects the independence of your certificate.

Certification is when an independent body audits your management system and confirms it meets a standard such as ISO/IEC 27001. Accreditation is when an accreditation body, such as JAS-ANZ in Australia and New Zealand, confirms that the certification body itself is competent and impartial. Always check that your certifier is accredited for the standard you need.

Yes. ISO management system standards share the same structure, so ISO/IEC 27001, ISO 9001, ISO 14001, ISO 45001, ISO 22301 and ISO/IEC 42001 can run as one integrated system with shared policies, risk management, internal audit and management review. Certification bodies can audit them together, which usually reduces total audit days.

It depends on your customers. ISO/IEC 27001 is recognised internationally and common in Australian, New Zealand, Asian and European procurement. SOC 2 is what many United States customers ask for. The controls overlap heavily, so many SaaS providers build one control set and obtain both.

ISO/IEC 42001 applies to organisations that use AI as well as those that develop it. If AI tools influence decisions about customers, staff or operations, or customers are asking how you govern AI, the standard gives you a structured and auditable answer. Certification is optional; many organisations start by aligning to it.

Both standards have new editions in 2026. ISO 14001:2026 certificates must transition from the 2015 edition before May 2029, and a three-year transition is also expected for ISO 9001:2026. The changes are moderate, so the move can usually be planned into your normal surveillance or recertification audit.

An ISO management system certificate is usually valid for three years, with surveillance audits in the second and third years and a recertification audit before it expires.