Purpose-built for IRAP, CSP, Essential 8, NIST CSF & more
Execute formal security assessments with a structured methodology, from scoping through to audit-ready report delivery. One platform replacing spreadsheets, email chains, and disconnected tools.
Australian made and owned by Reckon Security
Assessment progress, control metrics, and implementation status at a glance.
IRAP-2026-AUS-GOV
Plan & prepare
100%
Define boundary
100%
Assess controls
25%
Produce report
0%
Next Activities
Patch applications
Assess the Controls
Multi-factor authentication
Assess the Controls
Completed
261
Pending
458
Open RFIs
60
Tasks
7
Guideline Progress
Framework aligned
ISM (IRAP, CSP), Essential 8, NIST & more
Purpose-built for assessors
Government, consultancies & independents
Per-assessment isolation
Ephemeral infrastructure per engagement
Deploy your way
Cloud, on-premises, or air-gapped
THE PROBLEM
Today's assessment reality
Five phases, five sets of tools, and nothing carries between them.
Phase
Where the work lives
What breaks at the handoff
What it costs
01Scope
Excel, Email
Boundary agreed on a call, typed up later
Manual boundary definition
02Collect
Email, Shared drive
Attachments re-filed by hand
Evidence in 4+ locations
03Evaluate
Spreadsheet, PDF viewer
Verdicts re-keyed from notes
No per-asset-group tracking
04Report
Word, Excel
Counts copied between two documents
Days of manual formatting
05Deliver
Email, PDF
Version history ends at the outbox
No audit trail
Every row above is a handoff between two tools that do not know about each other. Nothing validates that what left one arrived in the next, and nothing records that the move happened.
Why current tools fall short
Control evaluations in Excel. Evidence scattered across shared drives. Information requests handled over email. Reports assembled manually, section by section.
It works, until someone misses a control, loses an evidence trail, or spends days formatting a deliverable.
Compliance automation platforms are built for ongoing monitoring: automated scans, integration-driven evidence collection, posture dashboards. They answer "are we compliant right now?" They don't model phased assessment execution, structured test methods, or government-grade report generation. Different problem. Different tool.
Risk registers and control libraries with pass/fail outcomes. Every framework flattened into a checklist. No per-asset-group evaluation. No structured test methods with quality ratings. No assessment methodology. They manage risk posture. They don't execute formal assessments.
HOW IT WORKS
Define the assessment boundary. Select frameworks, environments, and asset groups. Configure the workflow phases your assessment requires.
Define the boundary, select frameworks and asset groups
Framework
Asset Groups
4 of 12 selectedAssessment Phases
THE PLATFORM
Three purpose-built applications: Framework Manager, Portfolio Manager, and Secure Assessment Workspace, working as one integrated platform.
Framework Manager
Configure
The single source of truth for security frameworks. Manages control hierarchies, asset group definitions, test methods, workflow templates, and report structures across ISM (IRAP, CSP), Essential 8, NIST CSF, and more.
Portfolio Manager
Coordinate
Your organisation’s hub for managing the full assessment lifecycle. Create assessments, maintain system inventories, assign teams, and provision isolated assessment environments, with complete portfolio oversight.
Secure Assessment Workspace
Execute
An isolated, ephemeral environment provisioned for every assessment. Where assessors execute structured workflows, evaluate controls per asset group, manage evidence with chain of custody, generate audit-ready reports, and collaborate with clients through a dedicated portal.
Structured Workflows
Phased methodology from scoping to delivery
Control Evaluation
Per-asset-group with quality ratings
Evidence Management
Upload, annotate, link & verify integrity
Report Generation
Framework-specific, audit-ready output
Client Portal
Structured RFIs & evidence submission
WHY CYBERFRAME
Every assessment follows a framework-tailored workflow with phases, objectives, and activities defined by the framework you’re assessing against. Junior assessors follow a clear path that ensures nothing is missed. Senior assessors move faster with a methodology they trust.
Phases lock when complete. Approval workflows enforce quality at every step. The result: consistent, defensible assessments regardless of who’s on the team.
ISM Assessment Workflow
Framework-definedMost platforms reduce control evaluation to a single status per control. CyberFrame evaluates each control against every applicable asset group, with individual test methods per pairing and a quality-of-evidence rating for each.
The result is a three-dimensional evaluation matrix: Control × Asset Group × Quality Level. This is how IRAP assessors actually work. Most platforms don’t model it.
| ISM-0421 | ISM-1234 | ISM-0843 | ISM-1526 | ISM-0974 | |
|---|---|---|---|---|---|
| Cloud Infrastructure | |||||
| End User Devices | |||||
| Network Devices |
ISM-1234
End User Devices
Test methods: 3 of 4 complete
Quality rating: Sufficient
View PDFs directly within the platform. Place positional annotations on specific pages, paragraphs, and configuration screenshots, colour-coded by type.
Every evidence item is SHA-256 hashed at the point of upload. A tamper-proof chain of custody records every access, transfer, and verification event. Integrity verification detects any retroactive tampering.
Evidence Chain of Custody
Network Architecture.pdf
SHA-256: a3f8...c912
Access Policy v3.docx
SHA-256: 7b2e...d4a1
Vulnerability Scan.pdf
SHA-256: e1c5...8f3b
Incident Response Plan.pdf
SHA-256: 4d9a...1e7c
3 annotation types · Positional tracking · Page-level linking
IRAP and government assessment reports follow strict formatting requirements. Assembling them manually takes days. CyberFrame generates reports from framework-specific templates where the report structure, section headings, and data-driven content are all tailored to the framework used for your assessment.
Control evaluation summaries, evidence inventories, and compliance statistics populate automatically. Assessors author the narrative sections. The platform handles everything else.
IRAP Report: Auto-assembly
ASD template v1.0Clients get their own isolated interface to respond to information requests, upload evidence, and track assessment progress. Every submission is logged, hashed, and linked to the relevant controls.
Assessors see exactly what clients see. No more chasing attachments across email threads, shared drives, and Teams channels. One structured channel from request to closure.
Assessor–Client Collaboration
FRAMEWORKS
ISM (IRAP, CSP)
Information Security Manual
Essential 8
Maturity-based mitigation strategies
SACSF
SA Cyber Security Framework
NIST CSF
Cybersecurity Framework
Custom
Define your own frameworks
SECURITY & TRUST
Per-assessment isolation
Every assessment runs in its own isolated environment with dedicated database, authentication, and file storage. Data never co-mingles between engagements.
Tamper-proof audit trail
Every significant action is hash-chained so any retroactive modification is immediately detectable. Full event tracking across authentication, workflow, evidence, and approvals.
Granular access control
Role-based permissions across every entity type with phase-specific restrictions. Formal approval workflows with delegation authority and governance controls.
Deploy your way
Fully managed cloud, on-premises for data sovereignty, or air-gapped for classified and restricted networks. You control where assessment data lives.
WHO IT'S FOR
Navigate government frameworks including IRAP, CSP, and Essential 8 with confidence. Per-assessment isolation, tamper-proof audit trails, and air-gapped deployment options for classified networks.
Australian sovereign hosting
Manage assessments across multiple frameworks without expanding your security team. Structured workflows guide your team through every phase, and framework-specific report templates ensure audit-ready deliverables every time.
Enterprise-grade, zero overhead
Scale your engagement capacity while increasing quality of outcomes. Standardise your methodology across every assessor, from junior to senior. Every deliverable meets the same standard, every assessment follows the same rigour.
Consistent quality at scale
Access enterprise-grade assessment tools without the overhead of large consulting firms. Structured workflows, deep control evaluation, evidence management, and audit-ready reporting, purpose-built for practices of any size.
Professional-grade tools, zero bloat
Request a personalised demo with your assessment team.
Australian owned | No credit card required | Australian sovereign hosting