Pricing

Published where scope is knowable. Written where it is not.

ISO certification work breaks into five modules with defined boundaries, so every one of them carries a published starting price. Government, critical infrastructure and international work turns on your environment, your regulator and your deadline, so it is priced in writing after a scoping call rather than guessed at here. Everything is fixed-price against a defined scope and built inside your own tenant — not a compliance platform you have to keep renting.

$0
Third-party platform fees. We build inside your own environment, so there is nothing to keep renting.
5 modules
Take one, combine several, or run the full lifecycle. Nothing is bundled by force.
100%
Australian-owned, onshore delivery
ISO certification
State & Local Government
Federal Government
Critical infrastructure & regulated
Global markets

ISO certification programmes

Take one module, combine several, or run the full lifecycle through to a certificate issued by an accredited certification body. Soveriq certifies against ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001, ISO 9001, ISO/IEC 20000-1 and ISO 22301. Modules run consecutively are scoped as a single programme rather than added together, because consecutive modules remove duplicated discovery. All figures are from prices, excluding GST.

MOD
Engagement
What you receive
From (ex GST)
01
Gap analysisSingle standard
Assessment against the clauses and Annex A controls of your target standard, with a gap register, an effort estimate, and a certification timeline you can take to a board or a customer.
$1,900
02
Management system buildISMS · PIMS · AIMS · QMS
Your ISMS, PIMS, AIMS or QMS built end to end — scope, risk assessment, Statement of Applicability, policy suite and evidence workflows — standing inside your own tenant rather than a subscription platform you keep renting.
$11,900
03
Internal audit as a serviceClause 9.2
The mandatory internal audit conducted by an auditor independent of your team, with a non-conformance report and corrective action plan your certification body will accept.
$1,900
04
Audit defenceStage 1 and Stage 2
We sit with you through both stages, present evidence, translate what the auditor is actually asking for, and draft responses to any non-conformance raised.
$2,900
05
Maintenance retainerSurveillance years
Risk register upkeep, annual internal audit and management review, awareness training records, and surveillance audit preparation across years one and two — so the system does not quietly decay between visits.
$1,900per month

Certification body audit fees are separate and payable to that body directly — typically $8,000 to $20,000 across the initial three-year cycle depending on headcount, sites and standards in scope. We take no referral fee from any of them.

State and territory government

For agencies, departments and their contracted service providers carrying protective data security obligations to a state regulator.

VPDSS · OVIC PDSP · NSW CSP · QLD IS18 · SACSF · WA CSP · Essential Eight

This work is priced against your scope rather than published here. The cost turns on whether the submission covers one organisation or a shared service, the state of your information asset register before we start, the distance to your next attestation or submission window, and whether Essential Eight uplift sits inside or outside scope. Send us the framework, the deadline and the point you are starting from, and you will have a defined scope and a fixed price within one business day.

Engaged directly, or as a subcontractor to the prime holding your contract. Use Book to Scope and you will have a written scope and a fixed price within one business day. These frameworks are assessed and implemented, not certified — Soveriq is not an accredited certification body.

Federal government and defence supply chain

For Commonwealth entities, and for the vendors who must satisfy Commonwealth security requirements to hold or win the contract.

PSPF Release 2026 · ASD ISM · Essential Eight

This work is priced against your scope rather than published here. The cost turns on the size and classification of the system boundary, whether obligations apply to you directly or flow down by contract, how many of the mandatory plans already exist in usable form, and the annual reporting cycle you are working back from. Send us the framework, the deadline and the point you are starting from, and you will have a defined scope and a fixed price within one business day.

Engaged directly, or as a subcontractor to the prime holding the contract. Use Book to Scope and you will have a written scope and a fixed price within one business day. These frameworks are assessed and implemented, not certified — Soveriq is not an accredited certification body or an IRAP assessor.

Critical infrastructure and regulated entities

Where the obligation is legislated, the report is board-approved, and the penalties are personal. Priced for the accountability that carries.

SOCI Act · CIRMP · AESCSF v2 · APRA CPS 230 · APRA CPS 234

This work is priced against your scope rather than published here. The cost turns on the number of responsible entities and risk management programs, whether operational technology sits inside the assessed estate, the Security Profile you are targeting and the distance you have to travel, and how many material service providers require assessment. Send us the framework, the deadline and the point you are starting from, and you will have a defined scope and a fixed price within one business day.

Multi-asset portfolios and operational technology environments are scoped on inspection. Board and risk committee reporting can be built into the engagement. Use Book to Scope and you will have a written scope and a fixed price within one business day. These obligations are assessed and implemented, not certified — Soveriq is not an accredited certification body.

Global markets

For Australian businesses selling into North American, European and enterprise supply chains, where the buyer names the framework before they name the price.

SOC 2 · GDPR · PCI DSS v4.0.1 · NIST CSF 2.0 · NIST AI RMF

This work is priced against your scope rather than published here. The cost turns on the number of product environments and jurisdictions in scope, your merchant or service provider level where PCI DSS applies, the length of the observation window your buyer will accept, and whether one report or several regulatory scopes are required. Send us the framework, the deadline and the point you are starting from, and you will have a defined scope and a fixed price within one business day.

Quoted in Australian dollars. Audit, assessor and QSA fees are payable to those firms directly and sit outside our scope — we prepare you for those assessors and sit with you through the assessment, but we do not issue the report ourselves. Use Book to Scope and you will have a written scope and a fixed price within one business day.

How these prices work

Prices are floors, not estimates

Every figure is a genuine starting price for a defined scope. Scope is agreed on a free scoping call and fixed in the statement of work before any fee is payable. We do not raise a fixed price mid-engagement.

Where we cannot audit our own work

If Soveriq builds your system under Module 02, we cannot then provide independent audit, assurance or review of those same controls under Module 03. Impartiality requirements do not allow it. In that case Module 03 is delivered as readiness validation, labelled as such in writing, and genuine independence is supplied by someone independent of the build. We would rather lose the second engagement than compromise the first.

What sits outside the fee

All prices exclude GST. Certification body, IRAP assessor, CPA firm and QSA fees are payable to those organisations directly — we take no referral fee from any of them. Travel outside Melbourne is charged at cost and agreed in advance. Software you already licence stays yours; we do not resell tooling.

Where fixed price does not fit

Where an engagement genuinely suits time and materials rather than fixed price, commercial terms are set out in writing against the scope in front of us. Where fixed price would serve you better for the same outcome, we will say so before you commit to the other structure.

Current editions only

We work to the edition in force, not the one still sitting in old collateral. ISO/IEC 27701 moved to a standalone 2025 edition, superseding the 2019 extension. ISO 9001:2026 publishes on 16 September 2026. PCI DSS v4.0.1 is the only active version, and its once future-dated requirements have been mandatory since March 2025. If a scope statement or a competing proposal still cites the superseded edition, it is out of date.

Combining modules

Modules 01 and 02 together, or the full 01 to 05 lifecycle, are scoped as a single programme rather than added together. Running consecutive modules removes duplicated discovery, and the programme price reflects that. A second standard built on the same management system costs materially less than the first, because the shared clauses are already done.

Start here

Tell us what you've been asked to prove.

Send us the standard/framework, the deadline and where you are starting from. You'll have a written scope and a fixed price within one business day — not a discovery call booked to arrange another discovery call.