Skip to searchSkip to main content
  • Get your business certified.

    One fixed price, one team, no surprises.

Why you're here

Questionnaire

One of your customers, suppliers or key stakeholders sent you a cyber security questionnaire and you need some support.

Insurer

One of your insurers asked for some level of cyber security certification at a recent renewal.

Tender

A tender that you are bidding for has request some level of cyber security certification or governance to be in place.

The problem with buying cyber security by the hour

You ask three consultants what it costs to get certified. 


You ask three consultants what it costs to get certified. All three come back with a day rate, a scope marked "to be confirmed", and a gap assessment that tells you what's wrong without fixing any of it.


Six weeks later you've spent real money and you're still not certified.


We do it differently. One price agreed up front, one team who owns the whole job, and a certification at the end of it.

What others quote

Day rates, hours uncapped
One-off engagements & limited traction
Scope marked "TBC"
A gap assessment, then a separate quote to fix it
A list of actions, handed back to you
No date for certification

How we do it

One fixed price, agreed before we start
Yearly reviews & ongoing compliance as a service
Scope locked at the scoping call
Assessment, remediation or both in the same engagement
We do the work, not just the report
A target certification date in writing*

* No lock-in contracts. If we can't get you certification-ready, you don't pay.
Terms and Conditions Apply

Choose your standard

Three standards, three different reasons. Here's how to tell which one your customer, insurer or tender is actually asking for.

SMB1001

Popular | Great Starting Point

Australia's tiered cyber security standard, built for small business. Five levels from Bronze to Diamond — you certify at the level your customers actually need.


Choose this standard if
      • A customer or insurer has asked for proof and named a level
      • You've never formally documented your security
      • ISO 27001 feels like overkill, because it probably is
What you walk away with:

A certificate from the accredited certification body, valid 12 months.



Typical timeframe: 

      • Bronze, Silver and Gold: 2 to 4 weeks
      • Platinum and Diamond: 6 to 8 weeks

Essential Eight

Most requested in Australian tenders

The Australian Signals Directorate's eight technical controls, scored from Maturity Level 0 to 3. Government and enterprise procurement teams recognise it immediately.


Choose this standard if
      • A tender or government contract specifies a maturity level
      • Your insurer asked about patching, MFA and backups at renewal
      • You want technical uplift, not paperwork
What you walk away with:

An assessed maturity level, an evidence pack, and a roadmap to the next level.


Typical timeframe: 

      • Maturity Level 1: 4 to 8 weeks
      • Maturity Level 2: 6 to 10 weeks
      • Maturity Level 3: 8 to 12 weeks

ISO 27001

Most requested in Australian tenders

The international information security standard. A full management system, externally audited in two stages. The one large enterprises and offshore clients ask for by name.

Choose this standard if
      • An enterprise or overseas client has specified ISO 27001
      • You're selling software or handling other people's data at scale
      • You've outgrown a tiered attestation

What you walk away with:

Certification from an accredited body, with annual surveillance audits.


Typical timeframe: 

      • 4 to 6 months

What the price covers

Every engagement covers the same ground. What changes between standards is what you end up with — so here's exactly what's included, standard by standard.

Scope

Applies to your whole business; there's no partial scope. Your decision is which level. 

Assessment reporting

A clear written picture of where you stand, and what has to change to reach your target level.

Required documents

Get full drafted copies of context specific documents that are required at each level of the standard.

Evidence collection

The SelfCybr team will work with your stakeholders to collect all the required evidence and present it the way an assessor expects it.

Certification

We deal with the certification body or assessor on your behalf. We will send you the submission for final signature before managing the certification process for you. Certification platform fee is included.

Uplift

Most businesses already have an IT provider, and the controls are theirs to configure — we tell them exactly what's needed and check the result. If you'd rather we did the work, or you don't have a provider, you can add that service on when getting started.

Scope

Applies to your whole environment; there's no partial scope. Your decision is which maturity level. 

Assessment reporting

A clear written picture of where you stand, and what has to change to reach your target level.

Supporting documentation

Patching schedules, backup and restore procedures, application control and access policies — the documentation that makes your maturity level defensible and repeatable, rather than a point-in-time snapshot.

Evidence collection

We collect and package the evidence for your maturity level, so you can hand it straight to a tender response, an insurer, or a customer's security questionnaire without rebuilding it each time.

Uplift

Regular technical meetings with the SelfCybr team to work with your stakeholders to implement the technical controls to the maturity requirements. Implementation is included here, because with the Essential Eight the technical work is the engagement.

Roadmap

Clear roadmap for what is required and recommendations for achieving the next level of maturity (if applicable).

No certification exists

The Essential Eight has no formal certification — anyone offering you one is selling something else. What you get is an assessed maturity level with the evidence to back it, which is what tenders and insurers actually ask for.

Scope

The one standard where scope is a real decision. We define your scope statement with you at the start — it can cover your whole business, a single product line, or one site. Getting this right is the difference between a manageable certification and an unmanageable one.

Risk assessment & treatment

ISO is built on your risk assessment, not a fixed control list. We run the assessment with you, produce the risk treatment plan, and write the Statement of Applicability — the document your auditor will open first.

Required documents

ISO prescribes a mandatory document set — information security policy, SoA, risk methodology, objectives, and the operational procedures underneath them. All drafted for your business at your defined scope.

Evidence collection

Stage 1 tests whether your documentation holds up. Stage 2 tests whether you're actually doing it. We collect and package evidence for both, so the auditor finds what they're looking for without a scramble.

Internal audit & review

ISO requires you to audit yourself and hold a documented management review before the certification body will proceed. We run the internal audit and chair the review, and produce the records your auditor will ask for.

Certification

We prepare your submission and deal with the accredited certification body through Stage 1 and Stage 2. Their audit fees are paid directly to them — you're never paying us a margin on someone else's invoice.

ISO 27001 is ongoing, not a one-off

Certification lasts three years, with a surveillance audit each year in between. The management system has to keep running — internal audits, management reviews, risk reassessment. We'll tell you what that costs to maintain before you commit, not after you're certified.

​Pricing starts from

Contact us for more information!