Compliance Frameworks
Independent guidance across the frameworks that shape your cyber and compliance posture.
The list of compliance frameworks we support.
Align your cybersecurity posture to meet the recognised standards that will protect you now and into the future. These frameworks provide the structure for our assessments and reporting. Whether you need a single framework or a combined approach, we help you understand where you stand and what to prioritise next.
ASD Essential 8
Australia’s baseline model for cyber resilience, focused on practical, high‑impact controls. Assessments include maturity scoring across application control, patching, MFA, backups, and other core safeguards.
Best for: Australian organisations seeking a defensible, insurer‑aligned uplift path.
CIS Controls v8
A globally recognised, prioritised set of technical safeguards. Assessments map vulnerabilities, configurations, identity risks, and endpoint findings to CIS Controls to provide a clear, actionable roadmap.
Best for: Organisations wanting a practical, internationally aligned control framework.
NIST CSF
A high‑level framework that organises security activities into five functions: Identify, Protect, Detect, Respond, and Recover. Provides a simple, strategic view of cyber maturity without requiring a full governance audit.
Best for: Organisations wanting a clear, insurer‑friendly maturity snapshot.
SMB1001
A streamlined control set designed specifically for small and medium businesses. Focuses on essential technical safeguards, identity hygiene, configuration hardening, and basic operational practices.
Best for: SMB all-rounder, great for improving cyber posture, with the option to progress toward formal SMB1001 verification.
Cyber Essentials
A foundational security standard focused on five core technical controls: firewalls, secure configuration, access control, malware protection, and patch management. Provides a simple, practical baseline for reducing common cyber threats.
Best for: Organisations wanting a lightweight, internationally recognised security baseline.
NIS2
An EU cybersecurity standard that sets mandatory requirements for risk management, incident reporting, access control, and operational resilience. Assessments highlight gaps against NIS2’s core security measures.
Best for: Organisations operating in or supporting EU markets that need to demonstrate alignment with NIS2 expectations.
PCI DSS
Technical assessments aligned to PCI DSS requirements, including vulnerabilities, configurations, and identity‑related risks.
Best for: Organisations handling cardholder data that require technical evidence for PCI compliance.
HIPAA
Technical assessments aligned to HIPAA safeguard requirements, supporting organisations that handle or process health‑related information.
Best for: Software vendors, clinics, and service providers working with health data.
Australian Privacy Act & Notifiable Data Breaches (NDB)
The Privacy Act 1988 sets out how Australian businesses must handle personal information, including requirements for secure storage, access controls, and breach notification. Our assessments identify PII exposure risks, configuration gaps, and areas where your environment may fall short of NDB obligations — helping you avoid penalties and maintain trust with customers and regulators.
Other Frameworks
- NIST SP 800‑53
- NIST SP 800‑171
- GDPR
- and more...
If a framework isn’t listed, please reach out — we can confirm whether it’s something we support and guide you on the best assessment pathway.
Build a Compliance Pathway That Works for You
Whether you need one framework or a tailored combination, we guide you with structured assessments, clear reporting, and the Blinx Security Portal to help your IT team or MSP manage evidence and track progress.
We use essential cookies to help keep your experience secure.
