DrochaidHorizon3.ai
NodeZero/Industries/Defence & DISP/AUKUS readiness
Defence & DISP — AUKUS readiness

Essential Eight is the floor. AUKUS is where the bar is heading.

AUKUS is reshaping the Defence industrial base across Australia, the UK, and the United States. For Australian contractors, participation in AUKUS programmes means handling US-controlled Defence technology — submarine designs, weapons software, space systems — and proving your cyber security posture to all three nations. Essential Eight ML2 is the mandatory Australian baseline, but AUKUS interoperability requires alignment with US standards including NIST 800-171 and the Cybersecurity Maturity Model Certification (CMMC). The organisations that start building toward both now will be the ones invited to the table.

Your specific challenges

Two compliance regimes, one environment

Australian DISP membership requires Essential Eight ML2. AUKUS participation increasingly requires NIST 800-171 alignment and future CMMC certification. These aren't separate problems — they apply to the same IT environment, and you need to satisfy both.

The ITAR exemption raised the stakes

Since December 2025, Australian contractors can handle US-controlled Defence technology directly under the AUKUS ITAR exemption. This expands both the attack surface and the compliance requirements. US partners expect assurance mapped to their own standards — NIST 800-171 and CMMC — from their Australian supply chain.

CMMC is coming for Australian contractors

US Cybersecurity Maturity Model Certification is expected to cascade to Australian contractors handling US Defence information from 2026-2027. Companies bidding on US DoD subcontracts — directly or through primes — will need to demonstrate CMMC readiness. The time to prepare is now, not when the requirement lands.

No harmonised standard yet

AUKUS nations are actively working to harmonise cyber security standards, but the process isn't complete. Australian contractors need to navigate Essential Eight, NIST 800-171, and potentially UK Cyber Essentials Plus simultaneously — with no single framework covering all three.

How NodeZero helps

Built for your situation

01

One platform, both sides of the compliance equation

NodeZero powers the NSA Cybersecurity Collaboration Center's Continuous Autonomous Penetration Testing (CAPT) programme for US Defence industrial base suppliers. CAPT is a US programme for US contractors, not something you enrol in, but the pedigree travels: the platform behind continuous testing of US Defence suppliers is proven enough for ours. The same platform maps directly to Essential Eight ML2, so you build evidence for both regimes at once.

02

Essential Eight as your AUKUS foundation

Essential Eight ML2 isn't just an Australian obligation — it's the practical foundation for AUKUS readiness. The eight strategies cover the same security domains as NIST 800-171: access control, system hardening, vulnerability management, and monitoring. Proving ML2 gets you most of the way to NIST 800-171 alignment.

03

NIST 800-171 control mapping

NodeZero maps findings to NIST 800-171 control families that underpin CMMC. As AUKUS harmonisation progresses, your testing evidence will already be structured for the frameworks that matter on both sides of the Pacific.

04

Credentialled where it counts

When US and UK partners ask about your security posture, NodeZero's pedigree speaks their language. NodeZero's role powering the NSA's CAPT programme for US Defence industrial base suppliers, and its NIST 800-171 mapping, are benchmarks US Defence partners recognise — not just an Australian self-assessment.

NSA CAPT
powered by NodeZero for US defence industrial base suppliers
NIST 800-171
control family mapping for CMMC readiness
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Build your AUKUS readiness now

See how NodeZero bridges Essential Eight and NIST 800-171 — one platform, both compliance regimes