Compliance · guidance built in

    Compliance you can keep on top of - technical or not.

    Security frameworks, regulatory obligations, internal policies - most of it lives in spreadsheets and good intentions. 1ST2 turns any framework into a tracked, evidenced, plain-English compliance programme, with a virtual CISO guiding you on what each obligation actually means and how to meet it.

    Compliance AdvisorGrounded in your frameworks
    “Does our current setup meet Essential Eight Maturity Level 2 for patch management?”
    Patch management
    Guidance, built in

    A compliance module that actually explains your obligations - IT and non-IT alike.

    Independent security, audit, and legal consultants are - and will remain - genuinely valuable, and we'd always encourage bringing one in for the judgment calls that need a human. 1ST2's compliance module sits alongside that, keeping you informed day to day: explaining what each requirement actually means in plain English, recommending the next best action, and coaching your programme forward, month after month, so you always have a finger on the pulse between engagements. Not just a dashboard of red and green. Actual guidance - including on information security obligations, covered in more depth on the Security page.

    Guidance is generated from your uploaded frameworks and live environment data for informational purposes. It is not a substitute for independent professional security, audit, or legal advice - including advice on your obligations under South Australian and Commonwealth law where required.

    Essential Eight
    The Australian Government's baseline framework - every strategy mapped to your obligations and tracked, not left in a spreadsheet.
    Australian Cyber Security Centre
    1 in 5
    Australian businesses had a cyber incident in the past year, yet fewer than half hold a documented improvement plan. 1ST2 gives you one from day one.
    ACSC Annual Cyber Threat Report · 2023–24
    Any framework
    ISO 27001, the Privacy Act, an industry code or your own internal policy - one workspace, one source of truth, technical and non-technical alike.
    Bring what you're measured against

    Upload your framework. The platform does the rest.

    No manual mapping. No spreadsheets. No consultant required to get started.

    1

    Upload

    Drop in any framework or policy document - a security standard, a regulatory obligation, your own internal policy. One or many.

    2

    Extracted & mapped

    The platform reads every obligation, breaks it into trackable items, and maps each one to the evidence that proves it - technical or documentary.

    3

    Tracked, evidenced, guided

    Met items are marked with a date and evidence. Gaps are shown in plain English with the next step to close them - and the compliance module explains why it matters.

    IT and non-IT

    Every obligation - not just the technical ones.

    Compliance rarely sits neatly inside the IT department. 1ST2 tracks both kinds of obligation in one place, so nothing falls through the gap between technology and the rest of the business.

    Technical controls

    Proven from your environment

    Obligations that map to a control already running in your environment - multi-factor authentication, patching, backups, access restrictions - are cross-referenced against what's actually in place and marked met, with the evidence recorded for you.

    • Checked against your live controls, continuously
    • Evidence captured with dates
    • No screenshots, no manual collection
    Compliance Workspace · Obligation
    Multi-factor authentication enforced - all users
    Essential Eight · ML1Evidence captured 3 Mar 2026Status: Met
    Non-technical obligations

    Tracked against policy, process and evidence

    Obligations that live in policy and process - a data breach response plan, staff training records, a risk register, a board sign-off, a supplier agreement - are tracked against the documents and evidence you provide, with reminders so nothing lapses.

    • Upload a policy or record and link it to the obligation
    • Renewal and review reminders so nothing expires
    • Owners assigned, progress visible to leadership

    Bring the standards you're measured against.

    Whether it's mandated, expected by an insurer, or simply good practice - upload it and the platform builds the programme around it.

    Essential Eight

    The ACSC's baseline mitigation strategies, tracked to maturity level.

    ISO 27001

    The international information-security management standard.

    SOC 2

    Trust-services criteria for security, availability and confidentiality.

    Privacy Act 1988

    Australian privacy obligations and breach-response requirements.

    Industry requirements

    Sector codes and regulator expectations specific to your field.

    Cyber insurance

    The controls and evidence your insurer asks you to maintain.

    Internal policies

    Your own security, conduct and operational policies.

    Custom frameworks

    Anything you're held to - upload it and we'll map it. If your cyber insurer sends you a questionnaire, upload it and the platform maps every question to the evidence you already hold.

    Compliance Advisor

    Ask your obligations a question. Get a straight answer.

    Not sure what a requirement actually demands, or whether your current setup meets it? Ask the Compliance Advisor in plain English. It answers from your uploaded frameworks and your live status - real vCISO guidance, on demand, with the next step spelled out.

    • Grounded in your frameworks - never generic advice
    • Explains the requirement in plain English
    • Tells you whether you're currently meeting it
    • Recommends the next action to close the gap
    Evidence & reporting

    Audit-ready, the day they ask.

    Evidence pack on demand

    Generate a structured, audit-ready evidence pack in a click - every obligation, its status, and the evidence behind it. Ready for an auditor, an insurer, or a regulator, without a week of preparation.

    Monthly compliance digest

    On the first of every month, a plain-English summary of what changed, what progressed, and what's outstanding - shareable with leadership or a board as evidence of a programme that's actually moving.

    Get in touch

    See your obligations become a programme. 20 minutes.

    We'll walk you through our live demo environment - uploading a framework, watching obligations map out, asking the Compliance Advisor a question, and generating an evidence pack. See it for yourself, with no connection to your own systems required.