CMaaS · Compliance Management as a Service

Every framework.
One partner.

Outplat delivers Compliance Management as a Service (CMaaS) — what some call Compliance as a Service (CaaS) — as a fixed monthly retainer managed by senior practitioners. The only Australian CMaaS practice purpose-built for mining contractors, defence suppliers, independent schools, and product companies. Scales from a 50-person contractor to multi-site enterprise operations across multiple frameworks. Fixed price, fixed scope — no billable-hour surprises, ever.

Book a scoping call

Compliance without
the overhead

CMaaS replaces expensive project teams and billable hours with a single monthly engagement where our practice manages everything on your behalf — senior-led, with specialist associates engaged where the work demands it.

01
Readiness assessment
We establish your current state against the applicable framework, identify gaps, and scope your monthly engagement. Delivered in 3 weeks.
02
Remediation & implementation
We manage the uplift — policies, controls, technical configurations, evidence collection. You remain informed without being burdened.
03
Ongoing managed compliance
Monthly retainer keeps controls current, evidence fresh, and reporting ready. When audits or questionnaires arrive, you're already prepared.

Compliance managed
across every obligation

Whether you're facing a supply chain questionnaire, a Defence contract requirement, a SOCI Act obligation, a Privacy Act audit, or a customer security review — we have a managed service built for it.

Resources & Energy Defence Schools
Essential Eight
The Australian Signals Directorate's Essential Eight is the baseline cybersecurity standard for Australian government contractors — and is now mandatory for DISP membership and increasingly required by Tier 1 mining and energy supply chains including BHP, Rio Tinto, Fortescue, and Woodside. Outplat manages your Essential Eight controls, evidence, and maturity uplift from ML1 through to ML3 on a fixed monthly retainer. Our technical team can assess controls hands-on — not just advise on them.
What we deliver

⚠ Note: The ASD announced in June 2026 that the Essential Eight will be retired over approximately 24 months and replaced by the domain-based Essentials series. Outplat monitors this transition and will manage clients through the change — no disruption to your compliance program.

  • Current-state gap assessment against ML1, ML2, or ML3
  • Remediation roadmap and implementation support
  • Ongoing control monitoring and evidence maintenance
  • Audit-ready reporting and questionnaire response support
Resources & Energy Defence Product Companies
ISO 27001
International information security management standard. Required by enterprise clients, government tenders, and product companies pursuing enterprise sales or export markets. High control overlap with Essential Eight and DISP — significant efficiency gains when bundled.
What we deliver
  • Scoped ISMS design and implementation
  • Risk register and treatment plan development
  • Policy and procedure library
  • Certification readiness and audit preparation
Defence AUKUS Supply Chain
DISP
Defence Industry Security Program membership is mandatory to win and hold Defence contracts in Australia. Outplat manages the full DISP pathway — application preparation and submission support, Essential Eight ML2 implementation (a mandatory DISP requirement), Facility Security Officer advisory, personnel security guidance, and ongoing DISP obligations management on a fixed monthly retainer. Our team has direct hands-on experience with DISP applications for WA-based SME defence suppliers and AUKUS supply chain contractors.
What we deliver
  • DISP application preparation and submission support
  • Essential Eight ML2 implementation required for DISP
  • Facility Security Officer (FSO) advisory and support
  • Ongoing DISP obligations management
Resources & Energy Critical Infrastructure
AESCSF
The Australian Energy Sector Cyber Security Framework — mandatory for energy sector organisations designated as critical infrastructure assets under the SOCI Act. Outplat is a specialist GRC advisory for WA mining and energy contractors, with direct experience managing AESCSF obligations for LNG, offshore, pipeline, and hard rock mining operators across the WA supply chain. No other Australian CMaaS provider focuses this specifically on the resources sector.
What we deliver
  • AESCSF maturity self-assessment and gap analysis
  • IT/OT convergence compliance scoping
  • SOCI Act obligations mapping and incident response planning
  • Maturity uplift program and evidence management
Schools Product Companies All Segments
Privacy Act / APP
Australian Privacy Principles compliance — mandatory for any organisation handling personal information. Critical for schools managing student data and product companies handling customer data. 2024 reforms increased maximum penalties to $50M for serious breaches.
What we deliver
  • Privacy Act obligations assessment and gap analysis
  • Privacy management framework and policy development
  • Data mapping and third-party risk assessment
  • Breach response procedures and staff awareness
Defence Federal Govt Contractors
PSPF
Protective Security Policy Framework — mandatory for Federal government agencies and their service providers. Pairs directly with Essential Eight for defence contractors and is a core component of DISP compliance.
What we deliver
  • PSPF maturity assessment across all four outcomes
  • Personnel, physical, and information security controls
  • PSPF reporting framework and evidence collection
  • Integration with DISP and Essential Eight programs
Product Companies US Market Entry
SOC 2
Trust Services Criteria attestation — required by US enterprise buyers and increasingly by Australian enterprise procurement teams. 65–70% control overlap with ISO 27001 means significant efficiency gains for companies pursuing both. We manage readiness through to Type II report.
What we deliver
  • SOC 2 readiness assessment and gap analysis
  • Trust Services Criteria control design and implementation
  • Evidence collection and continuous monitoring program
  • Auditor liaison and Type I / Type II report preparation
Schools Product Companies Resources & Energy
PCI DSS
Payment Card Industry Data Security Standard — mandatory for any organisation that stores, processes, or transmits cardholder data. Applies to schools collecting fees and donations, product companies with payment surfaces, and larger contractors with procurement portals. We manage SAQ preparation through to RoC readiness.
What we deliver
  • Merchant level assessment and SAQ scope determination
  • Cardholder data environment (CDE) scoping and reduction
  • Control gap remediation and evidence management
  • SAQ completion support and QSA liaison
Product Companies Defence Resources & Energy
ISO 42001
The AI Management System standard — the emerging benchmark for organisations developing, deploying, or procuring AI systems. Enterprise buyers and government agencies are beginning to require it. For product companies with AI in their stack, it pairs directly with ISO 27001 with significant control overlap.
What we deliver
  • AI management system design against ISO 42001 requirements
  • AI risk assessment and impact evaluation framework
  • Responsible AI policy and governance documentation
  • Certification readiness and ongoing compliance management
Product Companies Resources & Energy Defence
Australian AI Obligations
Mandatory guardrails for high-risk AI are expected in legislation by 2025–2026, covering AI used in credit decisioning, employment, critical infrastructure, and safety-critical systems. We deliver AI governance readiness now — so you're not caught reactive when obligations become law.
What we deliver
  • High-risk AI use case identification and obligation mapping
  • Voluntary AI Ethics Framework alignment assessment
  • AI governance policy and register development
  • Readiness program ahead of mandatory guardrail legislation
Resources & Energy Critical Infrastructure
SOCI Act
Security of Critical Infrastructure Act obligations for designated asset owners and operators — including mandatory incident reporting, risk management program requirements, and enhanced cyber security obligations.
What we deliver
  • Critical Infrastructure Risk Management Program (CIRMP)
  • 72-hour incident notification framework and procedures
 
  • Asset register and responsible entity documentation
  • Ongoing SOCI obligations management and reporting

Not every organisation
needs a retainer straight away

A scoped engagement gives you a defined deliverable, a clear scope, and a fixed price. No ongoing commitment required. Most clients use a scoped engagement to understand their position before moving to ongoing managed compliance.

Cyber Risk Assessment
Identify and prioritise your organisation's key cyber risk exposures. Delivered as a board-ready risk report with treatment recommendations.
Typical duration: 2–3 weeks · Fixed price
Enquire
Cybersecurity Strategy Development
A structured cybersecurity strategy aligned to your regulatory obligations, risk appetite, and operational constraints. Presented to leadership or board.
Typical duration: 3–4 weeks · Fixed price
Enquire
Essential Eight Gap Assessment
Current-state maturity assessment against ML1, ML2, or ML3. Gap analysis, prioritised remediation roadmap, and questionnaire response support.
Typical duration: 3 weeks · Fixed price
Enquire
DISP Readiness Assessment
Gap analysis against DISP application requirements. Covers Essential Eight ML2, PSPF controls, and application documentation — delivered as a readiness report with remediation priorities.
Typical duration: 3–4 weeks · Fixed price
Enquire
Privacy Act / APP Compliance Review
Assessment of your obligations under the Privacy Act and Australian Privacy Principles. Gap analysis, data mapping, and priority remediation recommendations.
Typical duration: 2–3 weeks · Fixed price
Enquire
ISO 27001 Audit Support
Preparation support for ISO/IEC 27001:2022 certification or surveillance audits. Risk register review, control evidence, clause mapping, and audit liaison.
Scoped per engagement · Fixed price
Enquire
AI Risk Assessment
Assessment of AI tool and system risks against Privacy Act obligations, ISO 42001, and Australian AI governance requirements. Delivered as a risk report with governance recommendations.
Typical duration: 2–3 weeks · Fixed price
Enquire
IR Plan Development
Incident Response plan tailored to your environment, regulatory obligations, and notification requirements. Includes playbook development and optional tabletop exercise facilitation.
Typical duration: 2–3 weeks · Fixed price
Enquire
CIRMP / SOCI Readiness
Critical Infrastructure Risk Management Program scoping and gap analysis for SOCI Act designated entities. Covers hazard identification, risk assessment, and 72-hour notification obligations.
Scoped per engagement · Fixed price
Enquire
Most scoped engagements become the foundation for an ongoing CMaaS retainer. Talk to our team

From scoping call
to always audit-ready

Every engagement follows the same four-phase model — no matter your framework or segment.

01
Discovery call
30-minute scoping call. We identify which frameworks apply, your current exposure, and what a fixed-price engagement would cover. No obligation.
02
Readiness assessment
3-week current-state assessment against your applicable frameworks. Gap analysis, risk profile, and fixed-price proposal delivered at conclusion.
03
Remediation program
We implement the controls, policies, and evidence structures needed to reach your target maturity. You remain informed, not burdened.
04
Managed compliance
Monthly retainer. Controls stay current, evidence stays fresh, reporting stays ready. When audits or questionnaires arrive, you're already prepared.

Priority access
when it matters most

Guaranteed SLA response, pre-agreed rates, and annual IR plan maintenance. Recommended as an add-on for all CMaaS clients.

Standard
Essentials
  • 8 business hour response SLA
  • Annual IR plan review and update
  • One tabletop exercise per year
  • Pre-agreed activation rates
  • Recommended for Essential Eight / Privacy clients
Enterprise
Enterprise
  • 2 hour response SLA — 24/7
  • Annual IR plan review and playbook update
  • Two tabletop exercises per year
  • Priority escalation path
  • Recommended for DISP / SOCI / AESCSF clients

For MSSPs and technology partners
looking to extend their GRC capability

If your clients ask compliance questions you currently can't answer — DISP, Essential Eight, ISO 27001, Privacy Act — Outplat can sit alongside your managed service as the specialist GRC layer. Two partnership models, designed to work with how you already operate.

Referral Partner
Referral & Co-Delivery
When a client raises a compliance requirement outside your technical scope, you refer to Outplat. We deliver under our brand, keep you informed, and pay a referral fee. Simple, no contractual complexity, no delivery obligation on your side.
  • Refer compliance conversations you can't currently answer
  • Fixed referral fee per engagement — no revenue share complexity
  • We deliver, report back, and keep you in the loop
  • Your client relationship stays with you
  • Option to co-brand proposals for larger opportunities
  • Suitable for IT consultants, accountants, and legal advisors
Managed Service Providers
MSSPs serving mining, defence, or education clients who receive compliance questions beyond their technical scope — Essential Eight self-attestations, DISP applications, Privacy Act obligations.
IT Consultants & Integrators
Technology consultants who implement systems for mining contractors, defence suppliers, or schools and need a compliance partner to complete the client's security posture without building the capability internally.
Accountants & Legal Advisors
Professional services firms whose SME clients receive Essential Eight questionnaires or Privacy Act obligations they can't navigate alone — a referral to Outplat closes the gap without you carrying delivery risk.
Get Started

Ready to be
always audit-ready?

All engagements begin with a no-obligation discovery call. We confirm your applicable frameworks, define scope, and provide a fixed-price proposal within 48 hours.

Book a free discovery call Call 1300 171 853
✉ sales@outplat.com.au ✆ 1300 171 853