Services
Almost every engagement starts because somebody external set an obligation. Below is what we work with, organised by who's likely to be asking. All of it runs through the same five modules and the same control architecture — so where frameworks overlap, the work is mapped once rather than rebuilt each time.
The modules
You can enter at any point. Plenty of clients come to us at 03 with a system they built themselves, or at 04 with an assessment two weeks away.
01
Where you actually stand against the framework, and a prioritised roadmap to close the distance.
02
Policies, risk register, Statement of Applicability and evidence workflows, constructed inside your own environment.
03
The independent audit every management system needs before an external assessor arrives.
04
Representation alongside your team through Stage 1, Stage 2 or a government assessment.
05
Retained support so the system is still working when the surveillance audit comes around.
For private enterprise
The certifications enterprise buyers, insurers and procurement teams ask for by name. They share the same underlying structure, which is why the second and third cost far less than the first.
The one that unblocks enterprise sales. If a customer's security review has stalled your deal, this is usually what they want to see.
Privacy management for personal information — how you collect it, use it and let it go. Now a standalone certification, so you can pursue it with or without 27001. Relevant if you handle customer data at scale.
For organisations building or deploying AI. Covers your AI inventory, impact assessments, data provenance and human oversight — the world's first certifiable AI management standard.
Often a hard gate on government and large corporate tenders — the box you tick to be allowed to bid at all. ISO 9001:2026, the sixth and current edition, was published on 16 September 2026. Transition timing should be confirmed with the appointed certification body.
For managed service providers and IT vendors who need to prove disciplined, repeatable service delivery.
Demand is rising alongside APRA CPS 230. Proves you've planned to keep operating through disruption, not just hoped to.
Not certifiable, but it's the methodology sitting underneath most enterprise risk frameworks
ISO/IEC 27017:2026 & 27018:2025
Cloud-specific control extensions for SaaS and cloud-native platforms — normally added to a 27001 scope rather than certified on their own.
For federal government and their suppliers
Whether you're an agency or a supplier carrying obligations flowed down through a contract, these assessments run on documentation and evidence. We build both before the assessor arrives.
System Security Plans, control mapping and continuous monitoring for OFFICIAL: Sensitive and PROTECTED systems, against the current ISM release.
Governance, information, personnel and physical security — the policy layer above the ISM's technical controls.
Membership for businesses in the defence supply chain, across governance, personnel, physical and ICT security.
The cyber accreditation required of employment services and training providers under DEWR contracts, built on ISO 27001 and the ASD ISM.
Data sovereignty and ownership requirements for providers hosting government data. Readiness and reform-transition advisory (new certifications are currently paused by Home Affairs).
For state and territory government
Every state and territory runs its own. If you're an agency you have a reporting obligation; if you supply one, your contract almost certainly passes that obligation to you.
Administered by OVIC under the Privacy and Data Protection Act 2014. Twelve mandatory standards, Security Risk Profile Assessments, Information Asset Registers and the Protective Data Security Plans agencies submit.
Mandatory requirements, Essential Eight alignment and annual attestation to Cyber Security NSW, within the Department of Customer Service.
Agency information security obligations under the QGEA, with annual reporting through the state's assurance process.
The WA government's cyber security requirements for agencies and their providers, administered by the Office of Digital Government.
Tiered, risk-based cyber security obligations for public sector agencies, sitting under the SA Protective Security Framework.
Whole-of-government protective security across information, personnel and physical domains, administered by the Department of Premier and Cabinet.
The ACT Protective Security Framework and Cyber Security Policy, covering information, personnel and physical security for Territory entities.
Security uplift for Northern Territory government entities and their suppliers, aligned to ASD ISM and PSPF baselines and DCDD requirements.
For critical infrastructure and regulated sectors
Energy, water, health, transport, data storage, finance and communications. These obligations carry statutory reporting, board-level accountability and real penalties — and they don't wait for your certification timeline.
Critical infrastructure obligations — asset registration, mandatory incident reporting and a Critical Infrastructure Risk Management Program with an annual board-approved report, now expanded under the enhanced CIRMP Rules for high-risk asset classes.
Maturity self-assessment and uplift for electricity, gas and liquid fuel participants. The 2023 Framework Core at Security Profile 2 is now a named compliance pathway under the enhanced CIRMP Rules.
Operational resilience, business continuity and material service provider oversight — in force since 1 July 2025, with the last transitional relief ending 1 July 2026. Increasingly demanded of suppliers, not just regulated entities.
Information security capability for APRA-regulated entities and the third parties that handle their data — covering control implementation, testing and assurance.
For businesses selling into global markets
Fintech, SaaS and data businesses meet a different set of expectations the moment they sell into North America or Europe. Most of it maps onto controls you'll already hold from ISO work.
The report US enterprise buyers ask for by name. We prepare the control environment and evidence across the five Trust Services Criteria; the attestation itself is issued by an independent CPA firm, as Type I (design) or Type II (operating effectiveness over time).
Scoping, segmentation and control implementation for environments that store, process or transmit card data, to v4.0.1. We prepare you for validation via Self-Assessment Questionnaire or a QSA-led Report on Compliance — we are not a QSA, so the formal assessment is done independently.
A prioritised set of 18 controls with three Implementation Groups (IG1–IG3), scaled to your risk. No certification — a practical, high-impact starting point that maps into ISO 27001, NIST and the Essential Eight.
The US voluntary framework for governing AI risk — the practical counterpart to ISO 42001. We build the risk-management program and pair it with a 42001 management system for organisations operating across both markets.
A voluntary, risk-based framework organising cybersecurity across six functions — Govern, Identify, Protect, Detect, Respond, Recover. We use it as the strategic backbone and maturity baseline that other frameworks map into.