Why you're here
The problem with buying cyber security by the hour
You ask three consultants what it costs to get certified.
You ask three consultants what it costs to get certified. All three come back with a day rate, a scope marked "to be confirmed", and a gap assessment that tells you what's wrong without fixing any of it.
Six weeks later you've spent real money and you're still not certified.
We do it differently. One price agreed up front, one team who owns the whole job, and a certification at the end of it.
What others quote
How we do it
* No lock-in contracts. If we can't get you certification-ready, you don't pay.
Terms and Conditions Apply
Choose your standard
Three standards, three different reasons. Here's how to tell which one your customer, insurer or tender is actually asking for.
Popular | Great Starting Point
Australia's tiered cyber security standard, built for small business. Five levels from Bronze to Diamond — you certify at the level your customers actually need.
- A customer or insurer has asked for proof and named a level
- You've never formally documented your security
- ISO 27001 feels like overkill, because it probably is
A certificate from the accredited certification body, valid 12 months.
Typical timeframe:
- Bronze, Silver and Gold: 2 to 4 weeks
- Platinum and Diamond: 6 to 8 weeks
Essential Eight
Most requested in Australian tenders
The Australian Signals Directorate's eight technical controls, scored from Maturity Level 0 to 3. Government and enterprise procurement teams recognise it immediately.
- A tender or government contract specifies a maturity level
- Your insurer asked about patching, MFA and backups at renewal
- You want technical uplift, not paperwork
An assessed maturity level, an evidence pack, and a roadmap to the next level.
Typical timeframe:
- Maturity Level 1: 4 to 8 weeks
- Maturity Level 2: 6 to 10 weeks
- Maturity Level 3: 8 to 12 weeks
ISO 27001
Most requested in Australian tenders
The international information security standard. A full management system, externally audited in two stages. The one large enterprises and offshore clients ask for by name.
- An enterprise or overseas client has specified ISO 27001
- You're selling software or handling other people's data at scale
- You've outgrown a tiered attestation
Certification from an accredited body, with annual surveillance audits.
Typical timeframe:
- 4 to 6 months
What the price covers
Every engagement covers the same ground. What changes between standards is what you end up with — so here's exactly what's included, standard by standard.
Pricing starts from
Contact us for more information!
