Black Shard

Get the controls working before the assessment starts.

Readiness work for the Essential Eight, SMB1001 and ISO 27001, and reviews of obligations under the Australian Privacy Principles.

Talk to us about your framework

The engagement starts with the current environment. We identify which requirements are already met, which are partially implemented and which need technical or procedural work. Remediation is then prioritised against the target framework and assessment date.

Evidence, and which framework comes first

Evidence is collected as each control is implemented, so the position is already on the record when the assessment date arrives. SMB1001 vs Essential 8 comes down to what has to be shown: the Essential Eight is the Australian Signals Directorate's self-assessed hardening baseline with no certificate, and SMB1001 is a tiered certification listed on a public registry. ISO 27001 for SMBs usually follows SMB1001, once a contract or an offshore buyer names it.

Essential Eight uplift

Assessment and uplift across the ASD Essential Eight maturity model.

What you get

  • A current maturity rating across all eight strategies
  • An uplift plan to the target maturity level
  • Evidence recorded for each mitigation as it is implemented

SMB1001 certification readiness

Preparation for certification at your target SMB1001 tier.

What you get

  • A gap review against the target tier
  • Remediation sequenced against the certification date
  • An evidence pack prepared for the certifying assessor

ISO 27001 readiness

Scope, gap analysis and ISMS groundwork toward ISO 27001 certification, led by a certified ISO/IEC 27001:2022 Lead Auditor.

What you get

  • Scoping of the Information Security Management System
  • A gap analysis against Annex A controls
  • Core policies and the documentation an auditor expects

Privacy Act / APP uplift

Data mapping and gap review against the Australian Privacy Principles, including preparation for the reform program.

What you get

  • A data map of what you hold and where
  • A gap review against the Australian Privacy Principles
  • Changes required ahead of the 2026 Privacy Act reforms

AML/CTF independent evaluation

Independent evaluation of your AML/CTF program under section 26F(4)(f) of the AML/CTF Act: risk assessment, policy design and compliance testing, reported in writing to the governing body.

What you get

  • An evaluation of the ML/TF risk assessment and the AML/CTF policy design against the Act, the regulations and the Rules
  • Compliance testing on sampled customer, transaction and personnel records, with the sample and the method recorded
  • A written independent evaluation report delivered to the governing body and the approving senior manager

How it is shaped

A defined program with milestones toward the certification or audit date.

Recent work of this kind

  • Client confidential

    Essential Eight assessment and uplift: authentication, patching, privilege, backups, the same program our own estate runs at Maturity Level 3.

  • Client confidential

    ISO 27001, SOC 2 and SMB1001 audit readiness for a clinical software platform: scoping, gap analysis, control set, assessor documentation.

Questions, answered

Which frameworks does your compliance work cover?

The frameworks Australian businesses are asked for. Essential Eight uplift: a maturity rating, an uplift plan and an evidence trail. SMB1001 readiness: a gap review, remediation and an evidence pack. ISO 27001 readiness: ISMS scoping, an Annex A gap analysis and core policies. Privacy Act uplift: a data map, an APP gap review and changes for the 2026 reforms.

SMB1001 or Essential 8: which should we do first?

Whichever the buyer in front of you names. A tender naming an Essential Eight maturity level needs an assessment against that level; no SMB1001 tier substitutes. A buyer or insurer asking for a certification needs SMB1001, since the Essential Eight has no certificate. Where neither is named, start with Essential Eight hardening, which carries into SMB1001 evidence.

Does readiness work end in certification?

Readiness takes you to the audit. Where the framework certifies, the certificate comes from the certifying assessor, the way CyberCert issued our own SMB1001:2026 Gold. Where it is a maturity model, the work ends in a rated position and an uplift plan. Either way we map the environment, close the gaps and build the evidence trail.

Who performs the work?

Engineers who build and run production software in regulated industries. Black Shard holds SMB1001:2026 Gold, verifiable on the public CyberCert registry, so the person mapping your environment to a framework has run the same controls in production: least-privilege access, patching, multi-factor authentication and audit trails.

How is our data handled during an engagement?

On the practices we apply to our own estate. Access is least-privilege and administrative privilege is granted deliberately. Data is encrypted in transit and at rest, few third parties touch it, and client data is hosted in Australian regions. We comply with the Privacy Act 1988, including the Notifiable Data Breaches scheme.

What do we receive, and who owns it?

A written deliverable specific to the framework, and all of it is yours: the reports, the policies, and the evidence pack belong to the business. Every gap comes back with the change that closes it, so your team can act on it directly, and the evidence pack is built to be handed straight to the assessor.

What happens after delivery?

The finish line is the audit. A certificate is a snapshot on the day it issues; operating discipline holds it up between renewals: the patching, access reviews and evidence habits the uplift put in place. Frameworks move too, as the 2026 Privacy Act reforms show. Our advisory and vCISO work gives that discipline a standing owner.

Do you deliver outside Brisbane?

Yes. The work runs against your environment and your documentation, so location changes nothing about a gap review or an evidence pack. Scoping, the gap analysis and the evidence handover run on a call.

How is the cost set?

Scope first, then the number. Compliance work runs as a program with milestones toward your certification or audit date, or as a fixed-scope engagement. The framework, your target tier or maturity level, the environments in scope and the evidence that already exists drive it. We do not publish rate cards or ranges; send a brief with the framework and date.

Tell us which framework you are preparing for.

Brisbane head office.

Open a briefinfo@blackshard.com.au