Choosing a compliance platform for Australian government and APRA compliance (2026)

Most compliance platforms are built for a global certification motion. If your assessment is Australian — an IRAP engagement against the ISM, Essential Eight maturity, APRA CPS 230 and CPS 234 — the buying criteria are different, and so is the product that satisfies them. This is the checklist we would use ourselves, and how CyberSentien answers each line.

By Aneis Samaan, founder of CyberSentien · Last updated August 2026

Read this knowing who wrote it

We build CyberSentien, so this is a vendor's page — and the five criteria below are the ones we would want applied to us. It makes no claim about any other vendor's product; every statement about ours is testable on the live engine today.

The five questions that decide it

Ignore feature counts. Five questions separate a platform that will hold up in an Australian assessment from one that will not.

1. What does it show you when the evidence is missing? This is the question that matters most and the one nobody asks in a demo. A platform that converts "no evidence" into a completion percentage is manufacturing confidence you will have to defend later.

2. Does it hold the ISM itself, at depth? An IRAP assessment is an assessment against the Information Security Manual. Essential Eight coverage is where the conversation starts, not where it ends.

3. Does it treat CPS 230 and CPS 234 as a pair? APRA supervises operational risk and information security together. A platform covering only the security standard leaves half the obligation unassessed.

4. Can the output be verified by someone who does not trust you? An assessor, a regulator or a client's auditor should be able to confirm a report has not been altered — without an account and without taking your word for it.

5. Who owns and controls the stack? In the government supply chain this is a procurement question about ownership and control, not a dropdown for where the disks sit.

How CyberSentien answers each one

Missing evidence renders as missing. A control with no artefact reads manual assessment required. A signal that has stopped reporting reads lost visibility. Evidence past its freshness window reads stale. The engine has no path from "nothing" to "compliant" — the state that embarrasses organisations in front of an assessor cannot be produced.

The full ISM, current. The complete control catalogue at IRAP depth, kept current with ASD's quarterly releases including June 2026, with per-control SAR-shaped output.

Both APRA standards. CPS 230 and CPS 234 first-class and assessed together, with CPS 220 alongside them — operational-risk and service-provider registers included, not mapped in from a security standard.

Independently verifiable output. Every artefact is timestamped and SHA-256-lineaged; every issued report carries an integrity anchor a third party can check without an account.

Australian, end to end. An Australian company (ACN 688 655 334) on Australian-sovereign infrastructure by design — see how we handle data.

And the international frameworks, on the same spine

Australian depth does not cost you global coverage. SOC 1, SOC 2 and SOC 3, ISO 27001, ISO 42001, PCI DSS, NIST 800-53, NIST CSF 2.0, CIS v8 and FedRAMP are all first-class, together with AI governance (the EU AI Act, NIST AI RMF, NSW AIAF, QLD FAIRA) and sector packs for schools, early childhood, and third-party risk — 42 frameworks in total.

Evidence is collected once and credited to every framework it satisfies, through a crosswalk validated so a mapping can never produce a verdict against a control that does not exist. One programme, not two. The platform page has the full picture.

What no platform can do for you

No software performs an IRAP assessment — only ASD-endorsed assessors do. No software issues an ISO 27001, SOC or PCI certificate — accredited certification bodies and auditors do. Any vendor implying otherwise is worth less trust on everything else they tell you.

What a platform decides is how much of the work is already done when the assessor arrives, and whether the evidence you hand over survives examination. That is the whole game, and it is what CyberSentien is built to win. See our guide to IRAP cost and readiness for where the time and money actually go.

Frequently asked questions

What should an Australian organisation look for in a compliance platform?

Whether it holds the ISM at depth, whether it treats APRA CPS 230 and CPS 234 as a pair, what it displays when evidence is missing, whether its output can be independently verified, and who owns and controls the infrastructure. Feature counts and integration totals rarely decide an Australian assessment.

Is there an Australian-owned compliance platform for government compliance?

Yes. CyberSentien is an Australian company (ACN 688 655 334) running on Australian-sovereign infrastructure, built around the ISM, Essential Eight and APRA standards rather than adding them to a global product.

Can we just use spreadsheets?

For a single framework with one assessor and real discipline, spreadsheets can hold. They stop scaling the moment evidence needs freshness tracking, a second framework needs the same artefact, or someone has to prove a report was not edited after the fact — which is precisely what an assessor tests.

Will any platform make us "IRAP certified"?

No. An IRAP assessment is performed by an ASD-endorsed assessor. A platform's job is to get you assessment-ready with evidence already assembled and verifiable.

How does CyberSentien handle APRA CPS 230?

As a first-class framework alongside CPS 234 and CPS 220, with operational-risk and service-provider registers and board-facing reporting. CPS 230 commenced on 1 July 2025.

Can we evaluate it before committing?

Yes. The demo is the real engine on sample clients — open it and try to make it show a pass it cannot prove.