Know where you stand
before your IRAP assessor does

Connect your security tools, map findings to ISM controls, and generate your Statement of Applicability — so you walk into assessment day with evidence, not spreadsheets.

app.quantsecurity.io/dashboard/compliance
614
Compliant
203
Partial
47
Gap
78%
Readiness
COMPLIANT ISM-1402 — Multi-factor authentication for privileged access Access Control
PARTIAL ISM-1490 — Application patching within two weeks of release System Management
GAP ISM-1059 — Event logs protected from unauthorised modification System Monitoring

Pulls from the tools you already run

AWS
GitHub
Mosyle
Google Workspace

From connected tools to assessment-ready

QuantAssure connects your security tooling to the ISM. AI maps findings to controls, generates your SOA, and tracks what's changed since your last review.

ISM Control Catalog

All 992 ISM controls, sourced from ASD's official OSCAL publication. Updated when ASD publishes new revisions.

AI-Powered Assessment

AI evaluates your environment against applicable ISM controls and explains its reasoning — so you can review the logic, not just the result.

Statement of Applicability

Your SOA builds itself from scan data and AI assessments. Export as CSV in the format your assessor expects.

Essential Eight Scoring

Track maturity levels across all eight strategies. See what's needed to reach the next level.

IRAP Readiness Dashboard

Readiness score with topic-level breakdown. Know your gaps before your assessor does.

Evidence Management

Link findings, policies, and manual evidence to controls. Freshness tracking flags when evidence goes stale.

Four steps to assessment-ready

Most of the work is connecting your tools. QuantAssure handles the ISM mapping from there.

1

Connect Your Tools

GitHub, AWS, Google Workspace, Mosyle — connect in minutes.

2

AI Maps to ISM

AI maps findings to ISM controls and shows its reasoning for each.

3

SOA Generated

SOA generated from your data. Review, refine, export.

4

Assessment Ready

Walk in with a readiness score, evidence for every control, and a complete SOA.

"Built in Australia for organisations navigating IRAP. We got tired of mapping security data to ISM controls in spreadsheets — so we built something better."

Also supports Essential Eight, SOC 2, and ISO 27001

Ready for your IRAP assessment?

See how QuantAssure maps your security posture to the ISM. Request a trial and we'll walk you through it with your controls.