Define the assessment scope
Create a project from the wizard, an SSP Annex or a CCM import. Set classification, ISM version and system context, then tailor control applicability and responsibilities.
Australian ISM and IRAP compliance software
Prepare Essential Eight reports, generate ISM-aligned documentation, and bring assessors into the workflow when the engagement needs it.
Who it is for
Different teams come to SecBoost for different reasons. Some need a report and a document pack. Others need an assessor workspace, or a way to run assurance across multiple customers and systems.
Starter
For small teams that need to produce an Essential Eight compliance report and build the documentation they do not yet have.
Starter or Standard
For SaaS vendors, cloud providers and defence contractors responding to procurement, DISP or customer assurance requirements.
Standard or Enterprise
For IRAP assessors and consultants who want clients to manage scope, evidence and assessment records in one place.
Enterprise
For teams running multiple customer projects with analysts, auditors, task ownership and repeatable delivery workflows.
Enterprise
For agencies and larger organisations managing multiple assessed systems, separate projects and internal assurance teams.
Product
SecBoost is built around Australian security assurance work: ISM controls, Essential Eight maturity, SSP Annex records, generated documentation, evidence and assessor review.
Create a project from the wizard, an SSP Annex or a CCM import. Set classification, ISM version and system context, then tailor control applicability and responsibilities.
Create 20+ ISM-aligned policies, plans, standards, registers and reports from the same system profile and control records.
Record control implementation, maturity progress, blockers, alternate controls, no-visibility gaps and residual risk for Maturity Level 1, 2 or 3.
Upload screenshots, PDFs, exports and supporting records directly against the control implementation and assessment record.
Standard and Enterprise let assessors work inside SecBoost: review evidence, record assessment outcomes, return controls to editing when more information is needed, and finish with OSCAL and completed CCM outputs.
Structured context questions power AI implementation suggestions aligned to your actual system profile and the relevant ISM control.
Recent product coverage
SecBoost keeps pace with the practical outputs teams need for Essential Eight, ISM documentation, evidence management and assessment preparation.
New in Apr 2026
Generate target progress and portfolio executive reports covering maturity achievement, blockers, alternate controls, no-visibility gaps and residual risk.
New in Mar 2026
Use the March 2026 ISM release across project setup, SSP Annex, generated matrices and generated documentation.
New in Mar 2026
Attach implementation evidence directly to controls with drag-and-drop upload and virus scanning during processing.
New in Feb 2026
Export OSCAL 1.1.2 System Security Plan and Assessment Results JSON for use in OSCAL-aware tooling.
Pricing
Starter covers documentation and Essential Eight reporting. Standard adds assessor collaboration. Enterprise adds Teams, tasks and multiple organisations.
$7k/year + GST
Best for SMBs and small teams starting Essential Eight or ISM documentation work.
$12k/year + GST
Best when an assessor needs to log in and perform assessment work inside SecBoost.
Contact us
Best for multiple organisations, multiple systems, delivery teams and portfolio assurance.
Contact
Tell us about your organisation, system count, target maturity level, assessment timing and whether an assessor needs to work inside SecBoost.
We work with Australian organisations preparing Essential Eight reports, ISM document packs and IRAP assessments.