Certifications & compliance

Certifications and compliance frameworks

The credentials our team holds, and the frameworks we help you achieve.

Frameworks we help you achieve

Filter by:
essential-eight-clean-100

01/10/2024

Essential Eight

ACSC baseline mitigation strategies for Australian organizations.

View framework
apra-cps-234

01/10/2024

APRA CPS 234

Information security requirements for APRA-regulated entities (current standard, unamended since 2019).

View framework
ism

01/10/2024

ISM

Australian Government Information Security Manual alignment.

View framework
irap

01/10/2024

IRAP

Independent security assessment against the ISM, delivered with a partner IRAP assessor.

View framework
iso-27001

01/10/2024

ISO 27001

Information security management system implementation and certification support.

View framework
soc-2

01/10/2024

SOC 2

Trust services criteria for security, availability and confidentiality (2017, updated 2022).

View framework
nist-csf

01/10/2024

NIST CSF

A holistic approach to managing cyber risk across your organization.

View framework
idam

01/10/2024

IDAM

Identity and access management assessments, delivered with our Melbourne-based partner.

View framework
pci-dss

01/07/2026

PCI DSS

Cardholder data protection for merchants that process card payments.

View framework

Certifications and accreditations we hold

Individual and company credentials held by the StickmanCyber team.

Penetration testing certified Security operations certified Incident response certified PCI DSS QSA company CREST ANZ member ISO 27001 lead auditor ISO 27001 lead implementer CISSP CEH CISA OSCP (Offensive Security Certified Professional) NSW Government approved ICT provider

Frequently asked questions

A licence platform monitors your controls and generates evidence for an auditor to review. StickmanCyber is a managed service: our own analysts, GRC consultants and certified assessors do the actual security work behind the certificate, gap assessments, policy writing, penetration testing, incident response, not just the dashboard around it.

We also run our own GRC platform, StickSecure, so you can have the software and the specialists who use it on your behalf, not just one or the other.

Yes. We regularly work alongside a client's existing GRC tooling, and we also run our own platform, StickSecure, if you'd rather consolidate.

Either way, we close the gaps the platform flags, whether that's a missing policy, an unpatched control, or a process that only a person can put in place, so the evidence you're collecting actually reflects a secure environment.

A named specialist from our team, not an algorithm. Depending on the framework, that's a PCI QSA, an ISO 27001 lead auditor or lead implementer, or a CISSP or CISA-certified consultant.

You get direct access to the person doing the work, not a support ticket queue.

No, we extend it. Whether you have no dedicated security hire yet or a small team stretched thin, we plug in as the specialist capacity and expertise you need, from a Virtual CISO to hands-on assessors, for as long as you need it.

It depends on where your business is starting from and which framework you need. A mature environment with existing policies can be audit ready in a couple of months, we've taken a business to ISO 27001 in as little as 3 months, and a large organization in around 6.

A business starting from scratch usually takes longer. We scope a realistic timeline with you before any work begins.

A certification, like ISO 27001, is issued by an accredited certification body after a formal audit. An attestation, like SOC 2, is a report from an independent auditor on how your controls held up over a period, not a pass or fail.

A framework, like NIST CSF or the Essential Eight, is a set of practices to align with rather than something you're certified against, though a maturity assessment can measure how well you meet it.

For a certification like ISO 27001, the certificate comes from an accredited, independent certification body, not from us. Our job is the work that gets you ready to pass that audit: gap assessments, implementation, documentation and staff training.

Our team includes ISO 27001 lead auditors and lead implementers, and for PCI DSS we're a QSA company, so we can perform that assessment directly.

We work across sectors including finance, government, healthcare and critical infrastructure, and other regulated industries with strict data and security obligations.

Our approved status with NSW Government procurement reflects the kind of regulated, security-sensitive environments we're used to working in.

For a certification like ISO 27001, the certificate comes from an accredited, independent certification body, not from us.

Our job is the work that gets you ready to pass that audit: gap assessments, implementation, documentation and staff training.

Our team includes ISO 27001 lead auditors and lead implementers, and for PCI DSS we're a QSA company, so we can perform that assessment directly.

No. Most of these frameworks need ongoing maintenance, monitoring or periodic reassessment to stay certified or compliant, it isn't a one-time project.

We run a continuous cybersecurity uplift maturity framework, five phases that loop rather than end, so at any point you know exactly where you stand and what the next step is.

Our CSaaS engagement is built around that ongoing work, or we can hand over a clear plan for your team to run it themselves.

 

Not sure which framework applies to you?

Talk to an expert about the right path for your business.