Black Shard

Compliance you can prove.

Get audit-ready against the frameworks Australian businesses are actually asked for.

Certification is won on evidence, not intent. We get you ready to pass by mapping your environment to the framework, closing the gaps, and building the evidence trail an assessor expects.

Essential Eight uplift

Assessment and uplift across the ASD Essential Eight maturity model.

What you get

  • A current maturity rating across all eight strategies
  • An uplift plan to your target maturity level
  • An evidence trail for each mitigation

SMB1001 certification readiness

We hold SMB1001:2026 Gold ourselves. We will get you ready to certify.

What you get

  • A gap review against your target SMB1001 tier
  • Step-by-step remediation to close the gaps
  • An evidence pack ready for the certifying assessor

ISO 27001 readiness

Scope, gap analysis, and ISMS groundwork toward ISO 27001 certification.

What you get

  • Scoping of your Information Security Management System
  • A gap analysis against Annex A controls
  • Core policies and the documentation an auditor expects

Privacy Act / APP uplift

Map your data, meet the Australian Privacy Principles, prepare for reform.

What you get

  • A data map of what you hold and where
  • A gap review against the Australian Privacy Principles
  • Practical changes to be ready for the 2026 Privacy Act reforms

How it is shaped

A defined program with milestones toward your certification or audit date.

Every engagement includes

  • A director on the work

    A director reads the brief, scopes the engagement, and stays accountable for the result.

  • Fixed scope, quoted first

    Scope, timeframe, and price are agreed before work starts.

  • Findings validated by hand

    Every finding is checked by a human, written in plain English, and paired with a concrete fix.

  • Evidence an assessor expects

    An evidence trail built as the gaps close, ready for your assessor.

  • Least-privilege access

    We take only the access the work requires, and client data sits in Australian regions.

  • A report that is yours

    Written for your engineers and your board, and kept confidential.

Questions, answered

Which frameworks does your compliance work cover?
The frameworks Australian businesses are asked for. Essential Eight uplift: a current maturity rating across all eight strategies, an uplift plan to your target maturity level, and an evidence trail for each mitigation. SMB1001 certification readiness: a gap review against your target tier, step-by-step remediation, and an evidence pack ready for the certifying assessor. ISO 27001 readiness: scoping your Information Security Management System, a gap analysis against Annex A controls, and the core policies an auditor expects. Privacy Act uplift: a data map of what you hold and where, a gap review against the Australian Privacy Principles, and practical changes for the 2026 reforms. If a tender or client contract names something else, ask. Much of the control work overlaps, and we will say plainly if it sits outside our practice.
Does readiness work end in certification?
Readiness takes you to the audit; the certificate itself comes from the certifying assessor, not from us. Our own SMB1001:2026 Gold was issued by CyberCert the same way. The Essential Eight is the exception: it is the Australian Signals Directorate's maturity model rather than a certificate, so the work ends in a maturity rating and an uplift plan, not an assessor's stamp. Our part is the same in every case: map the environment to the framework, close the gaps, and build the evidence trail the assessor expects. Certification is won on evidence, and the evidence is what we build.
Who performs the work?
Engineers who build and run production software in regulated industries. Black Shard operates its own systems in production every day, and we hold SMB1001:2026 Gold ourselves, verifiable on the public CyberCert registry. That matters here because the person mapping your environment to a framework has run the same controls in production: least-privilege access, patching, multi-factor authentication, audit trails. You get controls that hold up in operation, not paper policies written to satisfy a checklist.
How is our data handled during an engagement?
On the same practices we publish on our trust page. Access is least-privilege: we ask for what the work requires and no more, and administrative privilege is granted deliberately, not by default. Data is encrypted in transit and at rest. We keep the set of third parties that touch data deliberately small and choose Australian regions for the services that host client data. We comply with the Privacy Act 1988, including the Notifiable Data Breaches scheme. Anything a gap review surfaces lands in your report.
What do we receive, and who owns it?
A written deliverable specific to the framework, and all of it is yours: the reports, the policies, and the evidence pack belong to the business. Every gap comes back in plain English with a concrete fix, so your team can close it without a translator, and the evidence pack is built to be handed straight to the assessor.
What happens after delivery?
The finish line is the audit, not a report that arrives and sits. And a certificate is a snapshot the day it is issued. What keeps it honest between renewals is operating discipline: the patching, access reviews, and evidence habits the uplift put in place. Frameworks move as well; the 2026 Privacy Act reforms are the working example. Where a business wants a standing owner for that discipline, our security advisory and vCISO work covers it: a named security lead on a regular cadence.
Do you deliver outside Brisbane?
Yes. We are a national firm, head office in Brisbane, delivering Australia-wide. Most of the work runs against your environment and your documentation rather than your floor space, so location changes nothing about a gap review or an evidence pack.
How is the cost set?
Scope first, then the number. Compliance work runs as a defined program with milestones toward your certification or audit date, or as a fixed-scope engagement with a clear target, timeframe, and deliverable. What drives the scope: the framework and your target tier or maturity level, the number of environments and tenancies in scope, and how much of the evidence trail already exists. We do not publish rate cards or indicative ranges, because a number quoted before scoping is a guess. Send a brief through the contact page with the framework you are targeting and the date you need to be ready.

Walk into the audit with the evidence in hand.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a brief[email protected]