From IRAP assessment to Essential Eight implementation. PSPF-classified from UNOFFICIAL to TOP SECRET, hosted only in Australian regions, and used by the assessors who sign the certificates.
Every policy, control and piece of evidence is labelled UNOFFICIAL → TOP SECRET. Cross-classification data flows blocked automatically. IRAP assessor workbench included, not bolted on.
Interactive ML0 → ML3 path planner. Set targets per strategy, get exact requirements, effort in days, and quick-wins for every gap — sourced from the Nov 2023 ACSC model.
Register critical assets, capture all four mandatory hazard categories, and draft the annual CIRMP report to CISC. No incumbent has this.
Zero re-keying between implementation and assessment. Client scope, PSPF and framework hand off directly into an assessor engagement.
Run the assessor side of AuditPro under your own brand, colours, JAS-ANZ number, and sub-domain. Full peer/technical/lead reviewer workflows a CB can sign off.
Data residency locked to Australian regions. Sovereign hosting attestation. US CLOUD Act exclusion. Not an afterthought — a hard requirement offshore platforms struggle with.
Offshore platforms treat Australian requirements as an afterthought. We built AuditPro for the assessors, certification bodies, and Defence-adjacent operators they don't serve.
Real vendor categories, names withheld.
| Capability | AuditPro | US GRC Platform A | US GRC Platform B |
|---|---|---|---|
| IRAP assessor workbench (ASD-format SSP, SRMP, SAR) | |||
| PSPF classification on every artefact (U → TOP SECRET) | |||
| Essential Eight ML0→ML3 maturity simulator | |||
| SOCI Act critical asset & CIRMP annual report | |||
| DEWR RFFR + TPES surveillance readiness | |||
| ISO 27006 §9.4.9 minor NC thresholds in the AI | |||
| Peer / technical / lead reviewer workflow a CB signs off | |||
| ISO 42001 (AI management systems) implementation | |||
| Australian data residency locked (ap-southeast-2 only) | |||
| US CLOUD Act exclusion attestation | |||
| Certification body white-label | |||
| SOC 2 continuous monitoring |
Anonymised comparison based on public documentation of leading US-headquartered GRC platforms as of 2026-07. Vendor names withheld; capability claims reflect published product scope at time of review.
Every framework is implementable by the client-side implementer, and assessable by the assessor-side workbench. Two sides, one shared source of truth.
IRAP Readiness & Assessment
Essential Eight (ML1 → ML3)
ACSC ISM (PSPF-scoped)
DEWR RFFR + TPES
ISO/IEC 27001:2022
ISO/IEC 42001 (AI MS)
ISO 9001 · 14001 · 45001
SOCI Act / CIRMP
Not compliance theatre. Not a US template with a maple leaf. A platform Australian certification bodies, IRAP assessors, and Defence-adjacent operators actually trust.
Get started free