Services

The standards/frameworks, grouped by who is asking.

Almost every engagement starts because somebody external set an obligation. Below is what we work with, organised by who's likely to be asking. All of it runs through the same five modules and the same control architecture — so where frameworks overlap, the work is mapped once rather than rebuilt each time.

The modules

Five modules, in the order they usually happen.

You can enter at any point. Plenty of clients come to us at 03 with a system they built themselves, or at 04 with an assessment two weeks away.

01

Gap analysis

Where you actually stand against the framework, and a prioritised roadmap to close the distance.

02

Build

Policies, risk register, Statement of Applicability and evidence workflows, constructed inside your own environment.

03

Internal audit

The independent audit every management system needs before an external assessor arrives.

04

Audit support

Representation alongside your team through Stage 1, Stage 2 or a government assessment.

05

Maintenance

Retained support so the system is still working when the surveillance audit comes around.

For private enterprise

ISO management systems.

The certifications enterprise buyers, insurers and procurement teams ask for by name. They share the same underlying structure, which is why the second and third cost far less than the first.

ISO/IEC 27001:2022

Information Security Management System

The one that unblocks enterprise sales. If a customer's security review has stalled your deal, this is usually what they want to see.

ISO/IEC 27701:2025

Privacy Information Management System

Privacy management for personal information — how you collect it, use it and let it go. Now a standalone certification, so you can pursue it with or without 27001. Relevant if you handle customer data at scale.

ISO/IEC 42001:2023

Artificial Intelligence Management System

For organisations building or deploying AI. Covers your AI inventory, impact assessments, data provenance and human oversight — the world's first certifiable AI management standard.

ISO 9001:2026

Quality Management System

Often a hard gate on government and large corporate tenders — the box you tick to be allowed to bid at all. ISO 9001:2026, the sixth and current edition, was published on 16 September 2026. Transition timing should be confirmed with the appointed certification body.

ISO/IEC 20000-1:2018

IT Service Management System

For managed service providers and IT vendors who need to prove disciplined, repeatable service delivery.

ISO 22301:2019

Business Continuity Management System

Demand is rising alongside APRA CPS 230. Proves you've planned to keep operating through disruption, not just hoped to.

ISO 31000:2018

Risk Management System

Not certifiable, but it's the methodology sitting underneath most enterprise risk frameworks

ISO/IEC 27017:2026 & 27018:2025

Cloud Security and Privacy

Cloud-specific control extensions for SaaS and cloud-native platforms — normally added to a 27001 scope rather than certified on their own.

For federal government and their suppliers

Commonwealth and defence frameworks.

Whether you're an agency or a supplier carrying obligations flowed down through a contract, these assessments run on documentation and evidence. We build both before the assessor arrives.

ASD ISM

Information Security Manual

System Security Plans, control mapping and continuous monitoring for OFFICIAL: Sensitive and PROTECTED systems, against the current ISM release.

PSPF

Protective Security Policy Framework

Governance, information, personnel and physical security — the policy layer above the ISM's technical controls.

DISP

Defence Industry Security Program

Membership for businesses in the defence supply chain, across governance, personnel, physical and ICT security.

RFFR

Right Fit For Risk

The cyber accreditation required of employment services and training providers under DEWR contracts, built on ISO 27001 and the ASD ISM.

HCF

Hosting Certification Framework

Data sovereignty and ownership requirements for providers hosting government data. Readiness and reform-transition advisory (new certifications are currently paused by Home Affairs).

For state and territory government

Eight jurisdictions, eight schemes.

Every state and territory runs its own. If you're an agency you have a reporting obligation; if you supply one, your contract almost certainly passes that obligation to you.

Victoria

Victorian Protective Data Security Standards

Administered by OVIC under the Privacy and Data Protection Act 2014. Twelve mandatory standards, Security Risk Profile Assessments, Information Asset Registers and the Protective Data Security Plans agencies submit.

New South Wales

Cyber Security Policy

Mandatory requirements, Essential Eight alignment and annual attestation to Cyber Security NSW, within the Department of Customer Service.

Queensland

Information and Cyber Security Policy (IS18)

Agency information security obligations under the QGEA, with annual reporting through the state's assurance process.

Western Australia

WA Government Cyber Security Policy

The WA government's cyber security requirements for agencies and their providers, administered by the Office of Digital Government.

South Australia

South Australian Cyber Security Framework (SACSF)

Tiered, risk-based cyber security obligations for public sector agencies, sitting under the SA Protective Security Framework.

Tasmania

Tasmanian Protective Security Policy Framework (TAS-PSPF)

Whole-of-government protective security across information, personnel and physical domains, administered by the Department of Premier and Cabinet.

Australian Capital Territory

Security risk management

The ACT Protective Security Framework and Cyber Security Policy, covering information, personnel and physical security for Territory entities.

Northern Territory

Territory & Commonwealth-aligned security

Security uplift for Northern Territory government entities and their suppliers, aligned to ASD ISM and PSPF baselines and DCDD requirements.

For critical infrastructure and regulated sectors

Where security is legislated, not recommended.

Energy, water, health, transport, data storage, finance and communications. These obligations carry statutory reporting, board-level accountability and real penalties — and they don't wait for your certification timeline.

SOCI Act 2018

Security of Critical Infrastructure Act

Critical infrastructure obligations — asset registration, mandatory incident reporting and a Critical Infrastructure Risk Management Program with an annual board-approved report, now expanded under the enhanced CIRMP Rules for high-risk asset classes.

AESCSF

Australian Energy Sector Cyber Security Framework

Maturity self-assessment and uplift for electricity, gas and liquid fuel participants. The 2023 Framework Core at Security Profile 2 is now a named compliance pathway under the enhanced CIRMP Rules.

APRA CPS 230

Operational Risk Management

Operational resilience, business continuity and material service provider oversight — in force since 1 July 2025, with the last transitional relief ending 1 July 2026. Increasingly demanded of suppliers, not just regulated entities.

APRA CPS 234

Information Security

Information security capability for APRA-regulated entities and the third parties that handle their data — covering control implementation, testing and assurance.

For businesses selling into global markets

What overseas buyers ask for.

Fintech, SaaS and data businesses meet a different set of expectations the moment they sell into North America or Europe. Most of it maps onto controls you'll already hold from ISO work.

SOC 2

Trust Services Criteria

The report US enterprise buyers ask for by name. We prepare the control environment and evidence across the five Trust Services Criteria; the attestation itself is issued by an independent CPA firm, as Type I (design) or Type II (operating effectiveness over time).

PCI DSS

Cardholder Data Security

Scoping, segmentation and control implementation for environments that store, process or transmit card data, to v4.0.1. We prepare you for validation via Self-Assessment Questionnaire or a QSA-led Report on Compliance — we are not a QSA, so the formal assessment is done independently.

CIS Controls

Technical baseline

A prioritised set of 18 controls with three Implementation Groups (IG1–IG3), scaled to your risk. No certification — a practical, high-impact starting point that maps into ISO 27001, NIST and the Essential Eight.

NIST AI RMF

AI Risk Management

The US voluntary framework for governing AI risk — the practical counterpart to ISO 42001. We build the risk-management program and pair it with a 42001 management system for organisations operating across both markets.

NIST CSF

NIST Cybersecurity Framework

A voluntary, risk-based framework organising cybersecurity across six functions — Govern, Identify, Protect, Detect, Respond, Recover. We use it as the strategic backbone and maturity baseline that other frameworks map into.

Not sure which frameworks apply to you?

Most organisations answer to several at once. Book a scoping call and we will map your obligations across every tier — and show you the shortest path to covering them.