Free Resources

Practical compliance resources for Australian organisations

Guides, interactive readiness checklists, and insights — built around what auditors actually look for, not what makes compliance seem harder than it is. Everything here is free.

Interactive checklists

Answer questions, see your score, download a prioritised PDF roadmap. Takes 12–15 minutes. Gives you an honest baseline and the most important gaps to close first.

§
Deep-dive guides

Practitioner-level guides on specific topics — what auditors look for, how to build it, what good looks like. Written for CISOs, compliance owners, and technical leads.

Insights & articles

Practical articles on compliance strategy, enterprise sales, and implementation — written for teams that need to make compliance decisions, not just read about them.

Interactive readiness checklists

Answer the questions, see your score, and download a prioritised PDF roadmap. Each checklist is mapped to the relevant framework's maturity criteria so the output tells you exactly where you stand — not just whether you pass or fail.

How the checklists work: Answer yes / partial / no for each control area → your score updates in real time → download a branded PDF with domain breakdown, top gaps, and next-step guidance. Free, no sign-up required.

Deep-dive guides

Practitioner-level guides on specific compliance topics. Each one covers the standard, what auditors actually check, how to implement it, and what good evidence looks like.

The Essential Eight Explained — Australia's Complete Cyber Security Guide
Featured Essential Eight · ASD 20 min read

The Essential Eight Explained — Australia's Complete Cyber Security Guide

What the Essential Eight is, the maturity model (ML1/ML2/ML3), all eight controls in detail, who needs it, how to achieve ML2, and what evidence auditors expect. Updated June 2026.

Read guide →
IS18 Compliance for Queensland Government ICT Suppliers — Complete Guide
IS18 · Queensland Government 18 min read

IS18 Compliance for Queensland Government ICT Suppliers — Complete Guide

What IS18 requires, how it maps to Essential Eight and ISO 27001, what an IS18 Compliance Statement must contain, and how to achieve compliance in 4–12 weeks. Essential reading for any QLD Government ICT supplier.

Read guide →
ASD Essentials Series: What Replaces the Essential Eight?
Essential Eight · ASD · Transition 10 min read

ASD Essentials Series: What Replaces the Essential Eight?

ASD is retiring the Essential Eight and replacing it with the Essentials series — a broader framework covering enterprise IT, OT, cloud and agentic AI. Understand what's changing, when, and what to do now.

Read guide →
The RFFR SoA Control Library — Every ISM Control, and What Automates
RFFR · ISM · DEWR Reference

The RFFR SoA Control Library — Every ISM Control, and What Automates

Browse the complete Right Fit For Risk Statement of Applicability: all 989 ISM (June 2026) controls plus the 7 program-deed obligations, filterable by guideline, with Essential Eight maturity and Microsoft 365 automation coverage marked on every control.

Read guide →
Inside a Statement of Applicability (SoA)
ISO 27001 · ISO 27701 · ISO 42001 12 min read

Inside a Statement of Applicability (SoA)

What auditors expect, how risk links to Annex A, and how to build an integrated SoA across ISO 27001, ISO 27701, and ISO 42001 in Microsoft 365.

Read guide →
What a Good ROPA Looks Like — and Common Mistakes
ISO 27701 · Privacy Act 10 min read

What a Good ROPA Looks Like — and Common Mistakes

The anatomy of a useful Record of Processing Activities with worked examples, common gaps that trigger regulatory enquiries, and a SharePoint-based implementation guide.

Read guide →
AI Governance Readiness — ISO 42001 Explained
ISO 42001 · AI Governance 10 min read

AI Governance Readiness — ISO 42001 Explained

Model inventory, AI risk and impact assessments, human oversight, and monitoring — a practical guide to building an AI Management System inside Microsoft 365.

Read guide →
Automating Compliance in Microsoft 365, Azure & AWS
Microsoft 365 · Azure · AWS 8 min read

Automating Compliance in Microsoft 365, Azure & AWS

How to turn evidence collection, access reviews, and security posture into continuous assurance using tools you already own — no third-party GRC platform required.

Read guide →
How to Build a Risk Register in SharePoint
ISO 27001 · ISO 27701 · ISO 42001 14 min read

How to Build a Risk Register in SharePoint

Full column schema, conditional formatting JSON, Power Automate flows, and views — one SharePoint List covering ISO 27001, ISO 27701, and ISO 42001. No third-party GRC platform required.

Read guide →

Insights & articles

Practical articles on compliance strategy, enterprise sales, and implementation guidance for Australian organisations.

View all articles →

Real outcomes from Australian organisations

See how organisations like yours achieved certification, improved maturity, and unlocked enterprise contracts — with specific timelines and outcomes.

View all case studies →

Free monthly digest

Get the monthly Australian compliance digest

Practical updates on Privacy Act changes, Essential Eight revisions, ISO 27001 news, and real implementation tips — once a month, no spam.

No spam. Unsubscribe any time. We never share your email.

Not sure which resource to start with?

A free 30-minute call will tell you which framework applies to your situation, what your most important gaps are, and what the fastest path to audit-ready looks like. No obligation.

Microsoft Teams