The questions we actually get asked.

Including the awkward ones. If yours isn't here, send it through.

How much does this cost?

ISO certification is published on the pricing page module by module, so you can see what each stage costs before you speak to anyone. Government, critical infrastructure and international framework work is not published, because the cost turns on your environment, your regulator and your deadline rather than on anything a table can capture. For that work, send us the framework, the deadline and the point you are starting from, and you will have a defined scope and a fixed price in writing within one business day. Where an engagement genuinely suits time and materials rather than fixed price, commercial terms are set out in writing against the scope in front of us.

Why publish prices when almost nobody in this market does?

Because the alternative wastes everyone's time. Providers in this market openly acknowledge that the hardest part for a first-time buyer is that nobody will quote transparently. If our number doesn't work for you, we'd both rather know today than after three meetings.

Is the published price the price we actually pay?

Yes, for the scope we agree. Every engagement on the pricing page carries a basis-of-price line — a single legal entity, one primary site, predominantly cloud infrastructure, and reasonable access to your team and evidence. If your situation sits outside that, we say so on the scoping call and price it before you commit, not after. We don't revise a fixed price mid-engagement because the work turned out larger than we estimated. That risk is ours, and pricing it correctly is our job.

Are you cheaper than the big firms?

Usually, and not by cutting scope. Two structural reasons: we don't carry large-firm overhead, and we don't put you on a compliance platform subscription, which removes roughly $15,000 to $60,000 a year from your program without touching our fee. Against a comparable mid-tier consultancy on like-for-like scope we're competitive rather than dramatically cheaper. If someone quotes you half our price, ask what's excluded.

How big is Soveriq?

Small and growing. Engagements are led by a named principal who scopes the work, delivers it and is present for the audit; as we add consultants and associates they work under that lead. The practical consequence for you is capacity — we take on a limited number of engagements at a time and will tell you if your timeline doesn't fit, rather than accepting the work and stretching it.

Can you guarantee we'll pass?

No, and nobody honestly can. What we can tell you is that we won't recommend you book Stage 2 until your internal audit and management review say you're ready — and if they say you aren't, we'll say that too.

How long does ISO 27001 take?

For a smaller organisation with a defined scope and reasonable existing practice, three to five months from gap analysis to Stage 2 is realistic. For a larger or less mature one, six to nine. Anyone quoting 30 days is selling documentation rather than a management system, and the auditor will find the difference.

Do we need to buy Vanta, Drata or similar?

Not with us. We build the same functions — control register, risk register, Statement of Applicability, evidence collection, review scheduling — inside the tenant you already pay for. If you already have one of those platforms and want to keep it, we'll work in it. We just won't ask you to buy one.

What does certification cost on top of your fee?

The certification body's fees are separate and paid to them, not to us — typically $8,000 to $20,000 across the initial three-year cycle, covering Stage 1, Stage 2 and the two surveillance audits, depending on your headcount, sites and how many standards are in scope. We'll help you get comparable quotes from JAS-ANZ accredited bodies, and we take no referral fee from any of them.

Can you build our system and also run the internal audit?

We can, and we'll disclose it in writing if we do. ISO requires the internal audit be objective, and a consultant auditing their own work sits uncomfortably with that. Some certification bodies accept it with disclosure; some don't. We'll tell you your body's position and support you using someone else if that's cleaner. As our team grows this stops being a question — the audit goes to someone who wasn't on the build.

We're a government agency. How do we procure this?

Several routes, and we'll point you to whichever is simplest for your entity. Soveriq is an Australian SME, which matters: Commonwealth Procurement Rules Exemption 17 permits direct engagement of an SME for procurements up to $500,000 including GST where value for money is demonstrated, after the Indigenous Procurement Policy set-aside is applied. The open-tender threshold for non-corporate Commonwealth entities also rose from $80,000 to $125,000 in November 2025. Full detail on the pricing page.

Do your consultants hold security clearances?

Soveriq's principal holds an Australian Government NV1 clearance. That clearance is sponsored through a separate arrangement rather than by Soveriq, and Soveriq is not currently a DISP member — membership is being pursued. What that means in practice: we advise on PSPF, ASD ISM, Essential Eight and DISP readiness, and we work with material at OFFICIAL and OFFICIAL: Sensitive. Engagements that require a Soveriq-sponsored clearance, or access above OFFICIAL: Sensitive, sit outside what we can take on until DISP is granted. We'll tell you that at the first conversation rather than let a procurement process discover it later.

What happens to our system when the engagement ends?

It stays where it was built: your tenant, your admin control. We hand over documentation and train the people who'll run it. No export, no migration, nothing to switch off — none of it was ever hosted by us.

Can you do more than one standard at once?

Yes, and it's the cheaper path. ISO 27001, 27701, 42001, 9001, 20000-1 and 22301 share the same management-system structure, so a second standard added to an existing build costs well under half of doing it standalone. Both numbers are on the pricing page.

We started and stalled. Can you pick it up?

Frequently. Clients arrive with half-built systems, a departed security manager or an audit six weeks out. We'll review what exists, tell you what's salvageable and price from there rather than starting over for the sake of it.

Are you a certification body?

No, and we couldn't be. Certification bodies are prohibited from consulting on systems they audit — that separation is what makes the certificate mean anything. We build and prepare; an accredited body assesses.

What if we just want a second opinion?

That's a legitimate engagement. A day reviewing a system someone else built, or a quote you've been given, is often the most useful money a client spends with us.

Still unanswered?

Send it through. If it's a good question we'll add it here.