Built for compliance from day one
Comprehensive compliance documentation covering ISO 27001:2022 certification, the Australian Privacy Act 1988, ASD Essential Eight Maturity Level 3, PSPF, and industry-specific requirements.
ShieldBox is built to ISO/IEC 27001:2022 standards and our ISMS is fully operational. Formal third-party certification by an accredited body is actively underway, with the certification audit scheduled for Q4 2026. Documentation of our alignment is available on request at compliance@shieldbox.com.au.
Compliance Reports & Documents
Need the full verified compliance package?
Government agencies, enterprise procurement teams, and regulated entities can request the complete documentation package including original signed certificates and assessor reports.
ASD Essential Eight — Maturity Level 3
What is the ASD Essential Eight?
The ASD Essential Eight is a set of baseline mitigation strategies developed by the Australian Signals Directorate (ASD) to help organisations protect against cyber threats. It covers application control, patching, macro settings, user application hardening, admin privilege restriction, multi-factor authentication, regular backups, and OS patching — each assessed at Maturity Levels 0–3.
ShieldBox's ASD Essential Eight status
ShieldBox has achieved ASD Essential Eight Maturity Level 3 across all eight mitigation strategies. Our email platform has been assessed against ISM controls applicable to cloud email hosting. Assessment documentation is available to government agencies and regulated entities on request by contacting compliance@shieldbox.com.au.
Applicable ISM controls
Key ISM control families covered in ShieldBox's ASD Essential Eight assessment include: Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), Incident Response (IR), Risk Assessment (RA), System and Communications Protection (SC), and System and Information Integrity (SI).
PSPF alignment
The Protective Security Policy Framework (PSPF) is the Australian Government's overarching security framework. ShieldBox supports PSPF compliance by providing an email platform capable of handling documents and communications at OFFICIAL and OFFICIAL: Sensitive classifications, with a pathway to PROTECTED. All data handling meets PSPF information security requirements.
Who needs ASD Essential Eight aligned email?
Australian Government agencies (APS, state/territory), entities handling government-classified information, defence industry suppliers, intelligence community contractors, and any organisation required to demonstrate compliance with the ISM or PSPF.
Privacy Act 1988 & Australian Privacy Principles
Privacy Act 1988 and the 13 APPs
The Privacy Act 1988 (Cth) contains 13 Australian Privacy Principles (APPs) that govern how organisations collect, use, disclose, and store personal information. ShieldBox is fully compliant with all 13 APPs, with particular focus on APP 8 (cross-border disclosure) — we guarantee your data never leaves Australia.
APP 8: Cross-border disclosure explained
APP 8 requires that before disclosing personal information to overseas recipients, an organisation must take reasonable steps to ensure the overseas recipient will not breach the APPs. The most robust way to comply with APP 8 is to never transfer personal information offshore in the first place — which is exactly what ShieldBox does. All data is stored and processed exclusively in Australia.
The 2022 Australian Privacy Act Review
The Australian Government is implementing reforms to the Privacy Act 1988 following the 2022 review. Key changes include: mandatory privacy impact assessments for high-risk activities, strengthened individual rights (right to erasure, right to object to targeting), direct right of action, and increased penalties up to $50 million. ShieldBox's architecture is designed to meet these enhanced requirements.
OAIC and regulatory enforcement
The Office of the Australian Information Commissioner (OAIC) is the independent national regulator for privacy and freedom of information. The OAIC can conduct investigations, accept privacy complaints, and issue determinations. Since the 2022 breaches, OAIC enforcement has significantly increased. Using Australian-hosted infrastructure eliminates a major category of APP 8 risk.
Healthcare: My Health Records Act 2012
Healthcare providers handling My Health Record data must ensure that record system operators meet specific security requirements under the My Health Records Act 2012 and related rules. ShieldBox's ISO 27001-aligned, Australian-sovereign infrastructure provides a compliant foundation for healthcare organisations communicating clinical information.
Financial services: APRA CPS 234
APRA Prudential Standard CPS 234 requires APRA-regulated entities to maintain information security capabilities to protect information assets. ShieldBox provides APRA-regulated financial institutions with an email infrastructure that demonstrates alignment with CPS 234's requirements for information security management.
Maturity Level 3 — All Eight Strategies
ShieldBox has achieved Maturity Level 3 across all eight ASD Essential Eight mitigation strategies — the highest achievable level. Verified by an independent security assessor.
Only approved applications can execute. ShieldBox implements strict application whitelisting across all server infrastructure.
Applications patched within 48 hours of critical vulnerability release, 2 weeks for non-critical.
ShieldBox's platform does not use Microsoft Office macros. Not applicable for SaaS email.
Web-based interfaces are hardened against common client-side vulnerabilities including XSS, CSRF, and clickjacking.
Administrative access is restricted, just-in-time provisioned, and fully logged. No standing admin access.
Server OS patched within 48 hours of critical patch release. Automated patching with zero-downtime deployment.
MFA is enforced for all user accounts, administrative access, and service-to-service authentication.
Data backed up daily to a geographically separate Australian data centre. Backups tested quarterly.
PSPF — Protective Security Policy Framework
ShieldBox fully supports OFFICIAL classification handling for government agencies and contractors.
ASD Essential Eight Maturity Level 3 achieved across all eight mitigation strategies. Suitable for sensitive government communications and legal matters.
Built to ISO 27001:2022 standards. Internationally recognised information security management framework. Formal certification in progress.
Notifiable Data Breaches (NDB) Scheme
ShieldBox's NDB obligations
ShieldBox complies with the NDB scheme under Part IIIC of the Privacy Act 1988. We maintain a documented Data Breach Response Plan (DBRP), tested annually, and will notify affected individuals and the OAIC within 30 days of becoming aware of an eligible data breach.
Your NDB compliance with ShieldBox
Australian-hosted email significantly reduces your NDB exposure. When your email is stored offshore, a breach of the overseas provider may trigger your own NDB obligations — even if your own systems are secure. ShieldBox eliminates this category of risk entirely.
Request compliance documentationIndustry-specific compliance
ISO 27001 aligned infrastructure suitable for clinical communications and ADHA requirements.
Alignment with APRA CPS 234 information security requirements documented and available.
End-to-end encryption with Australian key management supports Legal Professional Privilege claims.
ASD Essential Eight Maturity Level 3. Suitable for APS agencies and defence industry suppliers.
Suitable for universities, schools, and TAFEs handling student personal information.
For accounting, consulting, engineering, and other professional services firms handling client data.
Compliance milestone timeline
Need compliance documentation?
ISO 27001 alignment documentation, ASD Essential Eight Maturity Level 3 verification, and industry-specific documentation available on request for qualified organisations.