IRAP · PSPF · Essential Eight · SOCI · ISO 27001 · ISO 42001

The compliance platform forAustralian regulated environments.

From IRAP assessment to Essential Eight implementation. PSPF-classified from UNOFFICIAL to TOP SECRET, hosted only in Australian regions, and used by the assessors who sign the certificates.

ap-southeast-2 only
US CLOUD Act excluded
ISO 27006 §9.4.9 audit workflows

What US-centric GRC platforms can't do — and we do natively.

IRAP-ready, PSPF-classified

Every policy, control and piece of evidence is labelled UNOFFICIAL → TOP SECRET. Cross-classification data flows blocked automatically. IRAP assessor workbench included, not bolted on.

Essential Eight Maturity Simulator

Interactive ML0 → ML3 path planner. Set targets per strategy, get exact requirements, effort in days, and quick-wins for every gap — sourced from the Nov 2023 ACSC model.

SOCI Act / CIRMP native

Register critical assets, capture all four mandatory hazard categories, and draft the annual CIRMP report to CISC. No incumbent has this.

Assessor ↔ Implementer marketplace

Zero re-keying between implementation and assessment. Client scope, PSPF and framework hand off directly into an assessor engagement.

Certification Body white-label

Run the assessor side of AuditPro under your own brand, colours, JAS-ANZ number, and sub-domain. Full peer/technical/lead reviewer workflows a CB can sign off.

AU-sovereign by construction

Data residency locked to Australian regions. Sovereign hosting attestation. US CLOUD Act exclusion. Not an afterthought — a hard requirement offshore platforms struggle with.

Head to head

AuditPro vs the alternatives

Offshore platforms treat Australian requirements as an afterthought. We built AuditPro for the assessors, certification bodies, and Defence-adjacent operators they don't serve.

Comparison mode

Real vendor categories, names withheld.

CapabilityAuditProUS GRC Platform AUS GRC Platform B
IRAP assessor workbench (ASD-format SSP, SRMP, SAR)
PSPF classification on every artefact (U → TOP SECRET)
Essential Eight ML0→ML3 maturity simulator
SOCI Act critical asset & CIRMP annual report
DEWR RFFR + TPES surveillance readiness
ISO 27006 §9.4.9 minor NC thresholds in the AI
Peer / technical / lead reviewer workflow a CB signs off
ISO 42001 (AI management systems) implementation
Australian data residency locked (ap-southeast-2 only)
US CLOUD Act exclusion attestation
Certification body white-label
SOC 2 continuous monitoring

Anonymised comparison based on public documentation of leading US-headquartered GRC platforms as of 2026-07. Vendor names withheld; capability claims reflect published product scope at time of review.

Eight frameworks. One platform. Two sides.

Every framework is implementable by the client-side implementer, and assessable by the assessor-side workbench. Two sides, one shared source of truth.

IRAP Readiness & Assessment

Essential Eight (ML1 → ML3)

ACSC ISM (PSPF-scoped)

DEWR RFFR + TPES

ISO/IEC 27001:2022

ISO/IEC 42001 (AI MS)

ISO 9001 · 14001 · 45001

SOCI Act / CIRMP

Built for the assessors who sign the certificates.

Not compliance theatre. Not a US template with a maple leaf. A platform Australian certification bodies, IRAP assessors, and Defence-adjacent operators actually trust.

Get started free