Essential 8 for the tender. SOC 2 for the deal. NIST for the board. One platform proves all three.
A 5-minute scan checks your Microsoft 365 against all 107 Essential 8 controls, Maturity Levels 1 and 2. CARS ranks the gaps by risk. AutoFix deploys the fix to your tenant, with one-click rollback.
Works with Microsoft 365 E3 and E5 · Least-privilege OAuth · Read-only scan by default · All processing and AI stay in Australia.
Connect, scan, rank, fix. The full platform in 90 seconds.
“Send your Essential 8 ML2 attestation before we renew the tender.”
“We need SOC 2 Type II evidence before we sign.”
“Board wants a NIST AI RMF report on our Copilot rollout.”
Three frameworks. One team. No new headcount. The alternative is a consultant engagement and a spreadsheet. This is a five-minute connect.
~5 min
Scan a full M365 tenant
107
Essential 8 controls checked
Read-only
Default scan mode
100% AU
Data and AI stay onshore
See exactly what to fix first
CYBERWHITE scans your Microsoft 365 and ranks every gap by business risk with CARS, so your team fixes what actually matters, not a generic 500-item checklist.
How it works
01
Connect
5 minutesOne-click OAuth to your M365 tenant. Least-privilege, no agents on devices.
02
Gap analysis
InstantScan across Essential 8 ML1 and ML2, SMB1001 and SOC 2, with NIST CSF 2.0 and AI RMF assessments alongside. Includes ISO 27001 cross-mapping.
03
Remediation
CARS-rankedCARS ranks fixes by business impact. One-click AutoFix deploys real policies via Microsoft Graph, with approval, report-only mode and rollback.
04
Evidence
Audit-readyCollect evidence packages for auditors, insurers and enterprise buyers as you go.
05
Insights
Next stepsExport reports and a prioritised list of next actions. Repeatable, not point-in-time.
Built for teams like yours
No new headcount
Your IT team gets audit-ready without consultants or new hires. If you have a GRC team, it does their legwork.
Australian compliance expertise
Essential 8 ML1 and ML2, the framework tenders and insurers ask for.
M365-native
Connect via OAuth and see your gaps the same day. No agents, no spreadsheets.
CARS: priority, not noise
Every gap ranked by business impact, not a 500-item wall of "high priority".
Business plans, AUD
Starter
$199AUD/mo
Small teams getting audit-ready
Professional
$499AUD/mo
The full platform for one organisation
Enterprise
Custom
Larger tenants and procurement needs
Business outcomes
Win enterprise deals faster
SOC 2 and Essential 8 ML2 are table stakes in procurement. Prove compliance up front, with ISO 27001 cross-mapping to show auditors your coverage, and deal cycles shorten.
Access government tenders
Federal and state tenders increasingly require Essential 8 ML2. Move from "not qualified" to "pre-qualified".
Support better insurance terms
Insurers now ask specifically about Essential 8. Documented, deployed controls support better renewal conversations.
Build board confidence
Framework-level reporting for board packs, investor due diligence and your NIST AI RMF story.
The Essential Eight is being retired. The asks are not.
ASD is replacing the Essential Eight with a new Essentials series, and says work done under it stays relevant. Tenders, insurers and customers keep asking, whatever the standard is called next year. CYBERWHITE already runs Essential 8, SMB1001, SOC 2 and NIST CSF 2.0 side by side.
Now
ASD consultation open on the first chapter of the new Essentials series.
Year 1
Essential Eight deprecation expected to begin.
Year 2
Essential Eight expected to be retired, replaced by the Essentials series.
Frequently asked questions
Do I still need a compliance consultant?+
Many businesses use both. A consultant brings judgement and advice. CYBERWHITE does the repeatable work: it scans your tenant, prioritises the gaps with CARS, applies remediations via Microsoft Graph and keeps the evidence. Consultants and MSPs use CYBERWHITE with their own clients too.
Can we just use spreadsheets and free tools?+
Until an auditor or enterprise buyer asks for evidence. A point-in-time spreadsheet starts drifting the day you finish it. CYBERWHITE re-scans on demand and keeps the evidence current.
How long until we are audit-ready?+
A typical M365 environment reaches ML1 in 60 to 120 days depending on starting maturity. The scan itself takes about 5 minutes, so you know exactly where you stand on day one.
Can we start with Essential 8 and add SOC 2 later?+
Yes. Start with Essential 8 and add SOC 2, NIST CSF 2.0 or NIST AI RMF when you need them. Evidence maps across every framework in one platform.
What happens when our environment changes?+
Re-scan any time. Assessments are repeatable, so drift shows up the same day rather than at your next audit.
Do you work with our existing auditor?+
Yes. Export audit-ready evidence packages and hand them to any auditor or insurer. CYBERWHITE works with your existing audit relationships.
Every framework, from one platform. Start today.
See where you stand in minutes, or talk to us about a plan that fits your team.