Enterprise & Framework Assessments

Comprehensive maturity assessments for organisations requiring structured evaluation against recognised cybersecurity and privacy frameworks.

Information Security

ISO 27001 Maturity Assessment

Evaluate your Information Security Management System against the ISO/IEC 27001:2022 standard. Covers all ISMS clauses (4–10) and Annex A controls with structured maturity scoring.

Best suited for: Organisations preparing for or maintaining ISMS certification

Learn more
Cybersecurity Framework

NIST CSF v2.0 Maturity Assessment

Evaluate your cybersecurity program against the NIST Cybersecurity Framework 2.0. Comprehensive coverage of all six functions: Govern, Identify, Protect, Detect, Respond, and Recover.

Best suited for: Organisations seeking a globally recognised cybersecurity baseline

Learn more
Service Organisations

SOC 2 Readiness Assessment

Prepare for SOC 2 examination with a structured evaluation against the Trust Services Criteria. Covers Security, Availability, Processing Integrity, Confidentiality, and Privacy.

Best suited for: SaaS providers and service organisations with enterprise customers

Learn more
Payment Security

PCI DSS Maturity Assessment

Assess your organisation's readiness against the Payment Card Industry Data Security Standard. Comprehensive coverage of all PCI DSS requirements with SAQ-type filtering and maturity-based evaluation.

Best suited for: Organisations handling cardholder data or preparing for QSA audit

Learn more
Energy Sector • SOCI Act Aligned

AESCSF v2 Cyber Security Maturity Assessment

Evaluate cybersecurity maturity against the Australian Energy Sector Cyber Security Framework v2 with SP1/SP2/SP3 Security Profile targeting. 122 questions across 11 domains. 100% local—no data leaves your device.

Best suited for: Australian energy sector entities with AEMO reporting obligations

Data Privacy

GDPR Compliance Maturity Assessment

Assess organisational compliance maturity against the General Data Protection Regulation. Covers data protection principles, individual rights, accountability requirements, and international transfers.

Best suited for: Organisations processing EU personal data or serving EU customers

Learn more
Third-Party Risk

Third-Party & Supply Chain Security Assessment

Evaluate third-party and supply chain cybersecurity risks. A comprehensive framework for assessing vendor security posture and managing supply chain risk across the full vendor lifecycle.

Best suited for: Organisations managing vendor and supply chain security risk

Learn more
Critical Infrastructure • SOCI Act

ECSO Readiness Assessment

Assess readiness for the six Enhanced Cyber Security Obligations under SOCI Act Part 2C. Covers incident response plans, cyber exercises, vulnerability assessments, and government direction compliance. 100% local—no data leaves your device.

Best suited for: Australian critical infrastructure entities designated as Systems of National Significance (SoNS)

Learn more

Assessments Work Together

Many organisations use multiple assessments together. For example, NIST CSF provides a broad cybersecurity baseline while ISO 27001 addresses management system certification. Third-Party assessments complement any primary framework when vendor risk is material. See individual product pages for related assessments.

Small Business Cyber Security Health Checks

Practical, industry-specific assessments designed for Australian small businesses. Plain language guidance tailored to your sector's unique risks and compliance requirements.

Any Industry

Small Business Cyber Security Assessment

A comprehensive cyber security health check suitable for any small business. Covers essential security controls, data protection, and incident readiness in plain language.

84 questions across 12 domains

Learn more
Professional Services

Accounting Practice Health Check

Tailored for accounting firms handling sensitive financial data. Covers ATO requirements, client financial records protection, tax agent obligations, and practice-specific risks.

84 questions across 12 domains

Learn more
Financial Services

Financial Planning Health Check

Designed for financial planners and advisers. Addresses AFSL compliance obligations, client portfolio protection, advice document security, and regulatory requirements.

62 questions across 12 domains

Learn more
Healthcare

GP Clinic Health Check

Built for general practices and medical clinics. Covers patient health information protection, clinical systems security, My Health Record obligations, and healthcare-specific compliance.

85 questions across 12 domains

Learn more
Financial Services

Mortgage Broking Health Check

Tailored for mortgage brokers and finance professionals. Covers ACL compliance, aggregator requirements, lender portal security, settlement fraud prevention, and client data protection.

56 questions across 7 domains

Learn more
Property

Real Estate Agency Health Check

Designed for real estate agencies and property managers. Addresses trust account security, vendor and buyer data protection, property listing systems, and settlement process risks.

84 questions across 12 domains

Learn more

View All Small Business Assessments

Frequently Asked Questions

Does this website collect my assessment responses?

No. This site is informational and does not collect assessment responses. All assessments are self-contained tools that you download and use locally.

What format are the assessments delivered in?

Assessments are delivered as self-contained HTML files that run entirely in your browser. No installation, account creation, or internet connection is required after download.

Who are these assessments designed for?

Our enterprise assessments are designed for CISOs, Heads of GRC, and senior security, risk, and compliance leaders who need structured, framework-aligned tools for evaluating organisational maturity. Our small business assessments are designed for business owners and managers without specialist security expertise.

Are these assessments a substitute for formal certification or audit?

No. These assessments are self-assessment tools designed to help organisations understand their current maturity level. They do not constitute formal audits, certifications, or attestations.

How is payment processed?

All payments are securely processed through a third-party payment provider. CyberAssure does not directly handle payment information.

Questions about our assessments?

Contact us to discuss which assessment is right for your organisation.

Get in Touch