Sector · MSPs & IT providers
Run compliance for every client from one screen, with hard walls between them.
Clients ask their MSP for Essential Eight evidence and ISO readiness. Doing it per client in separate tools does not scale, and mixing client data is a breach.
What gets asked
The stack.
The standards this sector is asked for, and why.
ACSC Essential Eight
The Australian Signals Directorate's eight mitigation strategies, assessed at maturity levels 1–3.
ISO/IEC 27001:2022
The international standard for an information security management system (ISMS).
- Client requests for E8 maturity reports
- A compliance service line
- Your own 27001 for enterprise clients
The first eight weeks
A worked plan.
What a typical programme looks like on ISO Assist. Scope and existing evidence move the dates; the shape holds.
- WEEK 1
MSP workspace with your first three client tenants. Per-tenant isolation enforced at the database layer.
- WEEK 2–4
E8 assessment per client, evidence linked from your existing tooling exports.
- WEEK 5–6
Client-facing maturity reports; exceptions and remediation actions assigned.
- WEEK 7–8
Your own 27001 adopted in the parent tenant; shared policies distributed.
Registers that matter
What you will actually maintain.
Registers are data on a generic engine: pack-defined columns, CSV in and out, evidence links per row.
Example
Illustrative, a typical programme, not a named customer.
An MSP with 25 SMB clients standardising on quarterly E8 maturity reports, each generated from the client's own tenant.
Reading
From the blog.
ESSENTIAL EIGHT · 24 AUGUST 2026
The Essential Eight, explained for Australian businesses
ReadCYBER SECURITY · 10 AUGUST 2026
ISO 27001 when you run on Google Workspace, not a cloud-native stack
ReadCYBER SECURITY · 3 AUGUST 2026
Cyber hygiene for Australian SMBs in 2026: the eight things that still matter
ReadBook the MSPs demo.
Bring your tender clause or client request. We adopt the standards it names, live.