FAQ
Short answers. If the one you need is not here, ask us directly and we will add it.
How long does an assessment take?#
Four to six weeks from start to report. Week 1 is scoping and the evidence request. Weeks 2 to 4 are the assessment itself. Weeks 5 to 6 are peer review, the report, and a walkthrough with whoever has to defend it.
How much engineering time does it cost us?#
Hours, not weeks. We size the control set to your mission first and tell you exactly what we need, so your engineers are answering specific questions rather than assembling a general evidence pack. Where the evidence is thin we run a working session rather than writing a finding from a gap in a spreadsheet.
Is the fee really fixed?#
Yes. The fee is fixed before we start, with no variation without your sign off. A 20 minute call is usually enough to scope it against your mission and quote it.
What do we actually get at the end?#
One report, written to be shown rather than filed. The same document answers a procurement questionnaire, a prime's security annex, and a board paper. Findings are graded U1 to U5 with the fix already sequenced, and each carries a consequence level and the reason it sits there.
Does this give us a CMMC certification?#
No, and be careful with anyone who says otherwise. Since Phase 1 opened on 10 November 2025 most of Level 2 is self-assessed, and the move to third party assessment was suspended in July 2026 with no replacement date set. You post your own score in SPRS and affirm it annually. What we give you is the evidence sitting behind the number you sign.
Does it make us SOCI compliant?#
No. Space is not currently a designated asset class under the Security of Critical Infrastructure Act, so there is nothing to be certified against. Anyone selling you a SOCI compliance certificate for a space asset is selling you something that does not exist yet. Parts of what you do may already be in scope through ground segment, positioning support, or data services sitting behind another operator's obligations — the control set carries three level traceability from obligation to technical control, so the evidence holds if designation arrives.
Can you tell us whether our payload is ITAR or EAR controlled?#
No. Classification is your export lawyer's call. Holding the data is ours — access control, segregation and personnel screening are what we assess, because both regimes assume you can show that technical data never reached a person who was not authorised to see it.
When in a programme is the right time to run one?#
Four moments. When a customer or prime has asked a security question you cannot answer yet. At design freeze, while a control still costs a decision instead of a redesign. At pre-launch acceptance. And at first flight, then annually after it.
Is this a penetration test?#
No. A penetration test tells you whether a specific thing can be broken today. An assessment tells you whether you can show a customer, a prime, a regulator or a board that the controls they care about exist and are working. The two answer different questions and neither substitutes for the other.
Who signs the report?#
Two named assessors sign every report, after peer review. Assessments carry professional indemnity cover.
Do you work outside Australia?#
The assessment is built for Australian space companies and the regimes they answer to — a US prime's flow-down, export control on technical data held here, and Australian critical infrastructure obligations. Ask us if your situation sits near that edge.