Cyber security compliance, explained
Plain English guides to IRAP, the Essential Eight, ISO 27001 and 42001, SOC 2 and virtual CISO, written by an ASD endorsed assessor.
Browse by framework
Filter the guides below by framework.
Start here: the six framework guides
The pillar guide for each framework, the best place to begin.
Latest Guides
-
The IRAP Documents You Need: What to Prepare Before an Assessment
The documents an IRAP assessment runs on, from the System Security Plan annex to the SRMP, monitoring and incident response plans, and…
-
IRAP for Defence: Do You Need It for DISP and Defence Contracts?
IRAP is not a DISP requirement. DISP sets an Essential Eight Maturity Level 2 ICT baseline; IRAP assesses a specific system against…
-
How Long Does an IRAP Assessment Take?
ASD sets no fixed length for an IRAP assessment. A moderately complex system runs about 12 to 16 weeks once readiness is…
-
vCISO Pricing Models: How Virtual CISO Services Are Priced
How virtual CISO services are priced: the common retainer, tiered and day rate models, what drives the fee, and how Cybernion scopes…
-
What Does a Virtual CISO Do? The Scope of the Role
A virtual CISO owns the direction and accountability of your security programme, not the hands on build. Here is exactly what the…
-
Virtual CISO for Startups and Scaleups: Do You Need One?
Whether a startup or scaleup needs a virtual CISO, the real trigger, and when to move to a full time hire.
-
vCISO vs an MSSP: What’s the Difference and Which Do You Need?
A vCISO and an MSSP solve different problems. A virtual CISO owns your security strategy, risk decisions and board reporting. A Managed…
-
What Is a Virtual CISO? An Australian Guide
A virtual CISO is the CISO role engaged part time on a retainer. It carries full accountability for security strategy, risk and…
-
When Do You Need a Virtual CISO?
A virtual CISO is the right move when cyber security needs an accountable owner at management level and a full time CISO…
-
vCISO vs a Full Time CISO: Which Does Your Business Need?
A vCISO and a full time CISO are the same role at different capacity. When a part time retainer is enough, and…
-
SOC 2 Readiness Checklist for Australian Companies
What to prepare before a SOC 2 audit: scope the Trust Services Criteria, stand up the controls, and collect the evidence a…
-
The SOC 2 Trust Services Criteria Explained
The five SOC 2 Trust Services Criteria explained: Security, Availability, Processing Integrity, Confidentiality and Privacy, and which ones you actually need.
-
SOC 2 for Australian SaaS Selling into the US: What You Need to Know
Why US customers ask Australian SaaS companies for SOC 2, how it differs from ISO 27001, whether you need a Type I…
-
Virtual CISO: The Complete Australian Guide
What a virtual CISO is, when you need one, what they do, how pricing works, and how a vCISO leads your Essential…
-
What Is SOC 2? An Australian Guide
SOC 2 is an attestation report, not a certification. What it covers, Type I versus Type II, and how it compares with…
-
SOC 2 Type I vs Type II: Which Report Do You Need?
A Type I tests control design on a single day; a Type II tests whether controls operated over a period. Which one…
-
SOC 2 Cost in Australia: What Drives the Price
What a SOC 2 report costs in Australia, broken into readiness, the licensed CPA firm audit fee, tooling and the observation period,…
-
How Long Does SOC 2 Take?
SOC 2 has no single duration. A Type I can follow a few weeks of readiness; a Type II adds an observation…
-
ISO 42001 Certification Cost in Australia: What Drives the Price
ISO 42001 certification has no set price. The cost tracks your AI footprint, splitting across building the management system, audit fees over…
-
ISO 42001 for AI Product Companies: What You Need to Know
What ISO 42001 means for companies that build and sell AI: what it certifies, where the scope widens for a provider, and…
-
SOC 2: The Complete Guide for Australian Technology Companies
SOC 2 is an attestation report against the AICPA Trust Services Criteria, not a certification. What Australian technology companies need to know…
-
How Much Does an IRAP Assessment Cost in Australia?
What an IRAP assessment costs in Australia, the price drivers by classification, and the internal costs most budgets miss.
-
IRAP vs ISO 27001: Which Does Your Business Need?
ISO 27001 certifies your management system; IRAP assesses one system against the ISM for Australian Government use. What each is, where they…
-
How to Become an IRAP Assessor in Australia
What it takes to become an ASD endorsed IRAP assessor in Australia: citizenship, five years of experience, Category A and B qualifications,…
-
Entity Assessor vs IRAP Assessor: What’s the Difference?
Not every ISM assessment needs an IRAP assessor. When your own assessors can do the work, when an independent IRAP assessor is…
-
IRAP and the Hosting Certification Framework: How They Fit Together
The Hosting Certification Framework certifies the provider; IRAP assesses the system against the ISM. What each covers, the three HCF levels, and…
-
How Often Do You Need an IRAP Assessment? The 24 Month Rule Explained
There is no annual IRAP cycle. The working rule is the 24 month limit in PSPF requirement 0109, with a material change…
-
IRAP vs FedRAMP: What’s the Difference and Which Do You Need?
IRAP and FedRAMP are the cloud security regimes of two different governments. What each assesses against, who runs it, which you need,…
-
ISM June 2026 Changes: The New AI Controls Explained
The ISM June 2026 update adds four AI controls and broadens a cryptography rule. What changed, who it applies to, and whether…
-
What Classification Does Your Government Cloud Need?
The classification of a government cloud is set by the owning agency, not the provider. What OFFICIAL: Sensitive, PROTECTED and SECRET mean…
-
IRAP for SaaS and Cloud Providers: What You Need to Know
IRAP for SaaS and cloud providers explained: what the assessment covers, how the shared responsibility model works, which classification to choose, and…
-
Australian Government Information Classifications: OFFICIAL to SECRET
Australian Government information classifications run from OFFICIAL to SECRET. Who sets the level, what each means, and what changes in an IRAP…
-
Essential Eight vs ISM vs IRAP: How the Three Fit Together
The Essential Eight, the ISM and IRAP are not rival choices. They are three layers of one ASD system, and which you…
-
What Is the ISM? The Australian Government Information Security Manual Explained
The Information Security Manual (ISM) is the ASD catalogue of cyber security controls that Australian government systems, and IRAP assessments, are measured…
-
Essential Eight Maturity Levels (ML0 to ML3) Explained
ASD's Essential Eight maturity model has four levels. What ML0 to ML3 mean, why your weakest strategy sets the score, and which…
-
Essential Eight Assessment Cost in Australia
What an Essential Eight assessment costs in Australia, what drives the price, and why reaching Maturity Level Two is the larger spend.
-
IRAP Readiness Checklist: How to Prepare for an IRAP Assessment
A practical IRAP readiness checklist: the classification and scope decisions, the documents, the control evidence, and the timeline to prepare before an…
-
Essential Eight: The Complete Australian Guide
What the Essential Eight is, the maturity model, who needs it, how an assessment works, what it costs, and how it relates…
-
What Is the Essential Eight?
The Essential Eight is ASD’s set of eight mitigation strategies. What each one does, the four maturity levels, who must comply, and…
-
Is IRAP a Certification?
IRAP is an assessment, not a certification. There is no certificate and no pass mark. What an IRAP assessor produces, and who…
-
ISO 42001 Readiness Checklist for Australian Organisations
A clause by clause ISO 42001 readiness checklist for Australian organisations: the management system, the Annex A controls, the documents to prepare,…
-
AI Risk Assessment Under ISO 42001: What It Requires
ISO 42001 asks for two linked exercises: an AI risk assessment of risks to your objectives, and an AI system impact assessment…
-
Why AI Governance Matters Now
AI governance moved from optional to expected. Why it matters now in Australia, what the EU AI Act and ISO 42001 change,…
-
ISO 42001 vs the EU AI Act: Which Governs Your AI?
ISO 42001 is a voluntary AI management standard; the EU AI Act is binding law. Where they overlap, where they do not,…
-
ISO 27001 for SaaS: What Australian Software Companies Need to Know
ISO 27001 for SaaS companies: what the certificate covers, the cloud and secure development controls that matter most, how to scope a…
-
ISO 42001: The Complete Guide to AI Management Systems
ISO 42001, published as ISO/IEC 42001:2023, is the first international standard for an AI management system. It sets out how to govern…
-
What Is ISO 42001?
ISO 42001 is the world’s first certifiable AI management system standard. What it requires, who needs it, the AI impact assessment, and…
-
ISO 27001 vs SOC 2: Which Does Your Organisation Need?
ISO 27001 certifies a management system; SOC 2 is a CPA firm's report against the AICPA criteria. Which you need depends on…
-
ISO 27001 Annex A Controls Explained
The 93 Annex A controls in ISO 27001:2022, grouped into four themes, what changed in 2022, and why you select from them…
-
The ISO 27001 Statement of Applicability Explained
The Statement of Applicability is the ISO 27001 document that maps every Annex A control to your risk treatment, with a reason…
-
ISO 27001 Stage 1 vs Stage 2 Audit Explained
ISO 27001 certification is a two stage audit. Stage 1 reviews your ISMS documentation and readiness; Stage 2 tests whether it actually…
-
What Is ISO 27001:2022? A Plain Guide for Australian Organisations
ISO 27001:2022 is the international standard for an information security management system. What it certifies, what Annex A requires, and whether you…
-
ISO 27001 Certification Cost in Australia: What Drives the Price
ISO 27001 certification has no list price. What drives the cost, why audit fees scale with the number of people in scope,…
-
How Long Does ISO 27001 Certification Take in Australia?
How long ISO 27001 certification takes in Australia, the stages and what they involve, why the management system must run before the…
-
ISO 27001 Readiness Checklist for Australian Organisations
What to have in place before a certification body arrives: the clauses 4 to 10 management system, the Statement of Applicability, the…
-
Essential Eight Compliance Checklist
What to verify for each of the eight mitigation strategies, which maturity level you need to reach, and how Essential Eight compliance…
-
Essential Eight vs ISO 27001: Which Does Your Organisation Need?
The Essential Eight and ISO 27001 solve different problems. Which your organisation needs depends on whether you sell to government or commercial…
-
ISO 27001: The Complete Australian Guide
ISO 27001:2022 is the international standard for an information security management system. What it requires, what certification costs and takes, and how…
-
How Long Does an Essential Eight Assessment Take?
How long an Essential Eight assessment takes in Australia, the two phases involved, and what makes it faster or slower.
-
Essential Eight vs the ISM: How They Fit Together
The Essential Eight is a subset of the ISM, not an alternative to it. What each covers, which applies to you, and…
-
Essential Eight for Commonwealth Entities: The Maturity Level Two Expectation
Since 1 July 2022 the PSPF has required non corporate Commonwealth entities to reach Essential Eight Maturity Level Two across all eight…
-
Essential Eight Changes in 2026: What Is Actually Changing
The Essential Eight maturity levels are not changing on 1 July 2026. The bigger change is broader. ASD is evolving the Essential…
-
IRAP Assessment: The Complete Australian Guide
A complete guide to IRAP assessment in Australia: whether you need it, what it is, cost, timeline, the process, the report, and…