Adelaide · South Australia · Australia-Wide

DISP, Essential Eight & compliance consulting for Adelaide businesses.

Adelaide is Australia's defence industry capital. With AUKUS driving hundreds of new supply chain entrants and the Australian Space Agency headquartered in the city, demand for DISP, Essential Eight ML2, ISO 27001, and ISO 42001 has never been higher. We help Adelaide businesses get compliant — fixed-price, no surprises.

What drives compliance demand in Adelaide

Adelaide has a distinct compliance landscape shaped by defence, space, SA Government procurement, and a growing healthcare and medical device sector. Each brings its own regulatory requirements — and significant overlap where a single engagement can satisfy multiple frameworks.

Defence & AUKUS supply chain

Adelaide is home to the Australian Submarine Corporation (the centrepiece of SSN-AUKUS), BAE Systems, Hanwha, Saab, Thales, and Lockheed Martin. The AUKUS submarine programme will draw hundreds of South Australian SMEs into the defence supply chain over the next decade — most for the first time. Every new entrant needs DISP membership, which requires Essential Eight Maturity Level 2 as its information security baseline. Many also need ISO 27001 to satisfy prime contractor procurement requirements.

Space sector

The Australian Space Agency is headquartered in Adelaide, alongside a growing cluster of space technology companies — Myriota, Fleet Space Technologies, Southern Launch, and Inovor Technologies among them. Space businesses pursuing Australian Government contracts or international partnerships need ISO 27001 for information security assurance, and increasingly ISO 42001 for AI governance as AI-driven autonomy and data processing become central to space operations.

SA Government ICT procurement

SA Government agencies — including the Department for Industry & Trade (DIT), SA Ambulance Service (SAAS), and SA Health — require ISO 27001 from ICT and technology suppliers as a procurement standard. The SA Government Cyber Security Framework aligns closely with the ASD Essential Eight, making Essential Eight ML2 a practical prerequisite for government ICT work across the state.

Healthcare & medical devices

Adelaide has a growing medtech and biotech sector, including Signostics, Scinai Immunotherapeutics, and spinouts from Flinders University and the University of Adelaide. Medical device manufacturers and digital health businesses handling patient data need ISO 27001 for clinical data protection obligations, and ISO 27701 where the Privacy Act 1988 and health information handling requirements apply.

Services for Adelaide businesses

Essential Eight (DISP prerequisite)

Essential Eight Maturity Level 2 is the information security baseline required for DISP membership and most defence prime procurement. We build your ML2 controls inside your existing Microsoft 365 environment — Entra ID, Intune, Defender — with evidence mapped to DISP assessor expectations. Typically 8–12 weeks for a focused Adelaide SME engagement.

Learn more →

ISO 27001 Certification

Full ISMS build and Stage 1/Stage 2 audit support. Required by SA Government ICT procurement, defence primes, and space sector customers. Evidence managed in SharePoint with controls via Entra, Intune, and Defender. 10–14 weeks for most Adelaide mid-market organisations. No ongoing third-party platform licence fees.

Learn more →

ISO 42001 AI Governance

AI Management System for Adelaide's space and defence technology businesses. Space sector organisations using AI for satellite operations, earth observation analytics, or autonomous systems face growing customer and government expectations around AI governance. ISO 42001 is the internationally recognised standard — and pairs naturally with ISO 27001.

Learn more →

ISO 27701 Privacy

Privacy Information Management System aligned to the Australian Privacy Act 1988. Relevant for Adelaide healthcare, medical device, and SA Government suppliers handling patient data or personal information. Extends ISO 27001 with a privacy overlay — most clients complete both in a single engagement.

Learn more →

SOC 2 Type II

SOC 2 readiness and audit coordination for Adelaide technology and SaaS companies with US enterprise customers. Space sector businesses and defence technology firms with US Government or US prime contractor relationships often need SOC 2 alongside ISO 27001 — one evidence set, two certifications.

Learn more →

NIST CSF 2.0

NIST Cybersecurity Framework implementation for Adelaide defence and space businesses with US partners, US Government contracts, or US prime contractor requirements. NIST CSF aligns closely with DISP's information security expectations and can satisfy both simultaneously in a combined engagement.

Learn more →

Common questions from Adelaide clients

Do you deliver compliance consulting in Adelaide?

Both remotely and on-site. Most work is delivered remotely. For Adelaide clients we can travel for kickoff workshops, leadership briefings, and internal audit sessions where in-person presence adds value. No interstate travel cost premium — engagements are fixed-price.

What do defence suppliers in Adelaide need for AUKUS work?

Most Adelaide businesses joining the AUKUS supply chain for the first time need DISP membership as a minimum requirement from the prime contractor. DISP requires Essential Eight Maturity Level 2 as its information security baseline. Beyond DISP, primes like ASC, BAE Systems, and Lockheed Martin typically require ISO 27001 certification from their tier-2 and tier-3 suppliers for any contract involving sensitive defence information. We help businesses work through DISP and ISO 27001 together where scope allows — significantly more efficient than sequential engagements.

What's involved in DISP for a first-time applicant?

DISP (Defence Industry Security Program) is administered by the Department of Defence and requires demonstrated governance across physical security, personnel security, and information security. For most first-time Adelaide applicants, the information security workstream is the most substantive — Essential Eight ML2 controls must be implemented and evidenced before assessment. You also need a documented security policy framework, a nominated Facility Security Officer (FSO), and personnel clearance arrangements appropriate to the work you will be doing. We handle the information security workstream end-to-end and coordinate with your FSO on the broader DISP application.

How does Essential Eight ML2 relate to DISP?

Essential Eight Maturity Level 2 is effectively a non-negotiable prerequisite for DISP membership. DISP assessors use the Essential Eight as their primary lens for evaluating information security maturity. An organisation without ML2 controls in place will not pass a DISP assessment. We build ML2 controls inside your existing Microsoft 365 environment — application control, patching, macro restrictions, MFA, and the remaining strategies — with evidence structured to satisfy DISP assessors directly. Most Adelaide SMEs reach ML2 in 8–12 weeks.

We also work with clients in

Brisbane Our HQ — Queensland Sydney Enterprise & fintech Melbourne Healthcare & financial services Canberra Federal government & defence Perth Resources & defence

Ready to scope your Adelaide engagement?

Whether you're a defence supplier preparing for DISP, a space sector business pursuing ISO 27001, or an SA Government ICT supplier facing a certification requirement — a free 30-minute call gives you a realistic scope, timeline, and fixed-price estimate.

Microsoft Teams