A report written to be shown
The same document answers a procurement questionnaire, a prime's security annex, and a board paper.
A fixed scope, fixed fee space cyber assessment for Australian space companies. Four to six weeks from start to a report you can hand to a customer, a prime, or a board.
Start a conversation What it answers
Founded by Bradley Busch, author of An Australian Guide to Space Cybersecurity, published by the ISACA Sydney Chapter, with Janis Lesinskis advising, who built wildfire detection pipelines under FUEGO at the UC Berkeley Space Sciences Laboratory.
The same document answers a procurement questionnaire, a prime's security annex, and a board paper.
Scoped by payload class, bus model, and orbital layer, then mapped to NIST SP 800-171 Rev 2, the same 110 controls under CMMC Level 2. Ground segment controls apply to the ground segment. You are not answering for a constellation you do not fly.
Findings arrive graded U1 to U5: irrecoverable breaches first, then design freeze controls while the freeze is still open. Everyone finds problems. The order to close them is the useful part.
Each finding carries a consequence level and the reason it sits there, in language a director reads once and understands.
The control set comes from the ISACA Sydney Chapter space cybersecurity guide and a nine stage enterprise architecture ending in 53 controls. The engineering half comes from fire detection software built under FUEGO at the UC Berkeley Space Sciences Laboratory and used during Californian wildfire seasons.
Scoping and evidence request. We size the control set to your mission and list the evidence we need. Your team spends 4 to 6 hours in week 1 and about 2 hours a week after that.
Assessment against the 53 controls across 9 domains. Where evidence is thin, we run a working session before writing the finding.
Peer review, then the report and a walkthrough with whoever has to defend it. Two assessors sign every report.
Your prime's flow-down clause is DFARS 252.204-7021, and the annual affirmation behind it is a legal instrument.
Neither is a cybersecurity standard, and both assume you can show that technical data never reached someone unauthorised.
Space has no SOCI asset classes yet. Your customers' obligations already reach you.
Most of CMMC Level 2 is self-assessed and third party assessment is suspended. That leaves you as the only person who examined the score you affirm.
A 20 minute call is enough to say whether an assessment answers it, what the scope looks like against your mission, and the fee. Fixed before we start, with no variation without your sign off.