Security & Compliance Certification

Security compliance, done for you

ComplyZone manages the full compliance and certification process for your business — from evidence collection to attestation — so you can stay focused on running it.

Get started free See what's included
ATO OSF specialists
Powered by Microsoft Azure
ISO 27001 & SOC 2 ready
End-to-end managed service
No compliance background needed
Early access · Limited onboarding

Be one of the first DSPs to try ComplyZone

We're onboarding an initial group of Digital Service Providers ahead of full launch. Register your interest and we'll reach out as spots open up — no cost or obligation to join the list, and no need to already know your OSF category.

By submitting, you agree to our Privacy Policy. We'll only use your details to contact you about ComplyZone early access.

Your compliance team — without the overhead

ComplyZone takes on the burden of security certification so you don't have to. By outsourcing your compliance requirements to us, you eliminate the stress, confusion, and resource drain of navigating complex security standards on your own.

Our AI-powered platform streamlines evidence collection, validation, and certification — accelerating your path across the ATO's Operational Security Framework (OSF) and a broad range of global standards.

Whether you need full end-to-end management or support at specific stages, ComplyZone acts on your behalf through the entire certification process. Powered by Microsoft Azure, your data is protected at every step.

Why DSPs choose us

Faster to OSF attestation than going it alone
100%
Azure-hosted infrastructure with multi-layer security
Full
Managed service — we handle paperwork, you handle business

Everything your compliance programme needs

From incident readiness to personnel security, we cover the full scope of the ATO OSF questionnaire — and beyond.

🛡️

ATO OSF Questionnaire compliance

Our core speciality. We guide DSPs through every section of the ATO's yearly OSF attestation, from gap analysis to final submission.

  • Gap analysis against OSF requirements
  • Evidence collection & formatting
  • Questionnaire completion support
  • Yearly re-attestation management
🚨

Incident response

Be ready before a breach happens. We build your incident response capability with structured templates, runbooks, and testing plans.

  • Incident response plan templates
  • Breach notification procedures
  • Tabletop exercise facilitation
🏗️

Security design

We embed secure-by-design principles into your architecture and technology choices from the ground up.

  • Architecture review & threat modelling
  • Secure-by-design documentation
  • Technology alignment reports
👥

Personnel security

Controls for your people — from MFA enforcement to onboarding checklists and access revocation on offboarding.

  • MFA & role-based access controls
  • Onboarding / offboarding procedures
  • Security awareness training support
🔗

Third-party risk management

Map and manage your supply chain risk. We trace controls and evidence across your vendor ecosystem.

  • Supplier register & risk ratings
  • Third-party questionnaires
  • Supply chain control evidence
🌐

ISO 27001 & SOC 2 alignment

Already pursuing OSF? We map your existing evidence to ISO 27001 or SOC 2, so you get more out of every compliance effort.

  • OSF-to-ISO 27001 evidence mapping
  • SOC 2 readiness assessment
  • Dual-certification planning

Trusted by DSPs across Australia

Here's what organisations like yours say after working with ComplyZone.

★★★★★

"We had no idea where to start with OSF. ComplyZone walked us through every section, handled the evidence collection, and submitted on our behalf. We passed first time."

JM
James M.
CTO, mid-size payroll DSP
★★★★★

"The ISO alignment feature was a game-changer. We got OSF compliance and a clear path to ISO 27001 from the same engagement. Incredible value."

SR
Sarah R.
Head of Security, SaaS provider
★★★★★

"Switched to ComplyZone after struggling with internal resources. The Premium plan gave us direct expert access — they responded same-day every time."

DK
David K.
Founder, accounting software DSP

Priced around how OSF compliance actually works

OSF is an annual obligation, not a monthly one. Our pricing reflects that — a free starting point, annual tools access, or a fixed-fee engagement when you need expert support.

Core tiers
Free
$0

Start here. Find out your OSF category and exactly what evidence you need — no account required.

  • OSF Category Calculator
  • Evidence checklist by email
  • Downloadable category report
  • ATO questionnaire link & guide
  • Evidence templates
  • Expert support
  • Questionnaire review
Use the calculator
DIY Toolkit
$495/year

For DSPs who know what's required and want the right templates and workbooks to do it efficiently.

  • Everything in Free
  • Evidence templates — all categories
  • Taxonomy diagram template
  • Policy document library
  • Self-assessment workbooks
  • Annual review checklist
  • OSF update notifications
  • Expert review or sign-off
  • Questionnaire submission support
Get started
Done for you
From $4,500/year

We own the entire process. Initial submission plus ongoing annual reviews — fully managed, scoped to your category and number of products.

  • Everything in Guided submission
  • We complete the questionnaire
  • We compile & format all evidence
  • Taxonomy diagram produced for you
  • DPO liaison on your behalf
  • Annual review managed automatically
  • OSF change monitoring & alerts
  • ISO 27001 / SOC 2 mapping included
  • Breach notification support
  • Named account manager
  • Priority response (same business day)
Pricing is scoped on enquiry Category B–E starts from $4,500/year. Category A engagements — which require independent iRAP or ISO 27001 certification and up to twelve evidence items — are priced on application following a scoping call.
Talk to us
Multiple products? Each ATO product ID requires its own OSF submission. Add additional product submissions to any engagement from $400 per product where infrastructure and architecture are shared.
Add-on services

Available alongside any tier. Priced as fixed-fee deliverables so you know exactly what you're getting.

$750

Rapid attestation

Prioritised 30-day turnaround for urgent or overdue OSF submissions.

$1,200

Taxonomy diagram

Professionally produced data-flow diagram showing your full ATO supply chain — a mandatory requirement for all categories.

$950

ISO 27001 gap analysis

Map your existing OSF evidence to ISO 27001 controls — maximise what you've already built.

$600

PCI DSS self-assessment support

Templates, evidence kits, and guided preparation for PCI DSS self-assessment questionnaires.

$1,500

Personnel security pack

Complete policy templates, pre-employment screening process, NDA kit, and offboarding checklist — ready to implement.

$800

Supply chain audit

Full vendor mapping with ABN verification and functional role documentation for each participant in your supply chain.

$350/hr

Ad-hoc expert advisory

DPO query support, breach notification guidance, OSF framework interpretation, or any compliance question that comes up.

$400

Additional product submission

Each ATO product ID requires its own submission. Discounted rate where infrastructure and architecture are shared.

$950

Peppol eInvoicing readiness assessment Coming soon

Gap analysis against the A-NZ Peppol specification, help selecting and integrating with an accredited Access Point, invoice field mapping to the required UBL schema, and a written readiness report — useful ahead of the Commonwealth's 2026 Peppol adoption deadlines.

OSF Category Calculator

Answer a few questions about your product and we'll tell you exactly which OSF category applies — and what evidence you need to collect. Takes under 2 minutes.

0 of 0

Common questions

New to OSF compliance? Here are the questions we hear most often.

What is the ATO Operational Security Framework (OSF)?
The ATO's Operational Security Framework is a set of security requirements that Digital Service Providers (DSPs) must meet to connect to ATO systems and handle taxpayer data. DSPs must attest compliance annually. The OSF covers areas including access control, incident management, personnel security, and third-party risk.
Who is a Digital Service Provider (DSP)?
A DSP is any business that develops software or provides digital services that interact with the ATO — for example, accounting software, payroll platforms, tax lodgement tools, or API-connected SaaS products. If your product connects to ATO systems, you are likely a DSP and subject to OSF requirements.
How long does OSF certification take?
Timelines vary depending on how mature your existing security practices are. With ComplyZone managing the process, most DSPs complete initial attestation within 4–8 weeks. Organisations with existing security programmes may complete it faster.
Do I need a security background to use ComplyZone?
No. ComplyZone is designed specifically for business owners, IT managers, and operations teams who need to meet compliance requirements without specialist security knowledge. Our tools, templates, and experts guide you through every step in plain language.
Can ComplyZone help with ISO 27001 or SOC 2 as well?
Yes. Our Standard and Premium plans include tooling to map your OSF evidence to ISO 27001 and SOC 2 requirements, so you can pursue multiple certifications without duplicating effort. This is especially valuable for DSPs serving enterprise customers who require ISO or SOC 2 certification.
Is my data secure with ComplyZone?
Yes. ComplyZone is powered by Microsoft Azure, providing enterprise-grade infrastructure, encryption at rest and in transit, and multilayered security controls. We are aligned to the same security standards we help our clients achieve.

Let's get your compliance sorted

Tell us about your situation and we'll get back to you within one business day. Not sure which plan you need? Just ask — we'll help you figure it out.

📧 hello@complyzone.com.au
📍 Australia-based team
🕐 Response within 1 business day

Not sure? Use the free calculator to find out in under 2 minutes.

By submitting this form, you agree to our Privacy Policy. We'll only use your details to respond to your enquiry.

✓ Message sent! We'll be in touch within one business day.