The analysis your engineers and your lawyers each only half own.
Australian defence-adjacent technology firms rarely lose work for technical reasons. They lose it at an evidentiary gate — a DISP application held at the wrong level, an export classification nobody checked against the bill of materials, a sovereignty claim that survives marketing but not procurement. Those failures live in the gap between the people who build the system and the people who read the regulation. JEGASEC works in that gap, and returns a written determination you can put in front of a board, a prime, or a Commonwealth buyer.
This is JEGASEC's professional-services capability. It is distinct from the company's product mission, led by Continuity, and it is intended to help fund continued product development.
Engagements are document-based, not meeting-based.
Every engagement is fixed in scope, fixed in fee, and delivered as a written instrument. There are no discovery calls, standing check-ins, workshops or live support components. This is a methodology, not a limitation: the analysis is worth what it costs because it is produced in uninterrupted depth against a complete evidence set, rather than assembled between meetings.
Scope confirmation
You receive the engagement scope, the input manifest, and three available start dates. Nothing is negotiated by call. A written intake instrument replaces the discovery meeting entirely.
Written · 2 business daysEvidence upload and data freeze
You upload the complete input manifest to a per-engagement encrypted workspace before the agreed freeze date. From that date the evidence set and the scope are fixed, and the delivery clock starts.
Client-side · Deadline-drivenAnalysis
Uninterrupted analytical work against the frozen evidence set. You may submit up to three consolidated written query bundles during this window. Responses are within two business days.
20 to 30 business daysWritten determination
You receive the bound deliverable, plus two rounds of consolidated written comments for correction and clarification within the agreed scope. Where a walkthrough is useful, it is provided as a recorded briefing.
Deliverable · Two revision roundsThree engagements.
Each is a single written artifact addressing a single evidentiary gate. Fees are fixed and stated in full below, exclusive of GST, payable 50% on commencement and 50% on delivery.
Defence Readiness Determination — the DISP level you can actually substantiate, and what stands between you and the one you need.
Sovereign Autonomy Compliance Architecture — export classification, component provenance and autonomy assurance, reconciled in one document.
Sovereign Control Attestation Pack — what you can truthfully claim about sovereignty, evidenced, plus the extract you hand to buyers.
Defence Readiness Determination
For mid-tier cyber and ICT firms pursuing Commonwealth panels or prime subcontracts. DISP assesses membership across four separate domains — security governance, personnel, physical and ICT — and governance is pinned to the highest level sought in any other domain. One weak domain therefore caps the entire membership, and firms routinely discover this after committing a bid cycle to an application that was never going to clear at the level lodged.
This engagement returns a reasoned determination of the level your evidence currently supports, domain by domain, and the specific artifacts that stand between that position and the one your target contracts require.
- Corporate structure and beneficial ownership
- Security policy suite and governance charter
- Screening procedures and current clearance holdings
- Site plans, access control and facility arrangements
- Network architecture and Essential Eight self-assessment
- The contracts or panels you are pursuing
- Written determination, stated by domain
- Evidentiary basis for each assessed position
- Tabulated gap register with dependency order
- Phased remediation sequence and critical path
- Submission evidence-pack index
- Annexure: flow-down clause analysis
Sovereign Autonomy Compliance Architecture
For uncrewed and autonomous systems manufacturers moving from prototype into Defence programs or export markets. A platform is simultaneously a controlled good under the Defence Trade Controls Act and the Defence and Strategic Goods List, a supply-chain sovereignty question determined by component provenance, and an assurance object whose autonomy behaviour must be defensible in writing. Those three domains are usually owned by three people who never co-author a single document — which is where programs stall, at the export or due-diligence gate, after the capital is already spent.
This engagement reconciles all three into one architecture document: where the platform sits against the control lists, which components disqualify it from which programs, and whether the autonomy argument holds.
- Full performance envelope and published claims
- Complete BOM with country of design and manufacture
- Autonomy architecture, failsafe and lost-link behaviour
- Cryptographic and datalink design
- Prior export permits, decisions or classification advice
- Target programs, primes and export destinations
- Written control-classification position
- Provenance ledger graded by sovereignty risk
- Named substitution candidates for blocking components
- Structured autonomy assurance argument
- Program eligibility matrix with blocking conditions
- Annexure: marketing-claim escalation register
Sovereign Control Attestation Pack
For hosting, cloud and managed-infrastructure providers selling to Commonwealth, state and critical-infrastructure customers. Sovereignty is now an evidentiary claim rather than a marketing one. Under the Hosting Certification Framework the distinction between certification tiers turns on ownership and control, not technology. Under the Security of Critical Infrastructure regime, your customers carry risk-management-program obligations — including independent assurance and contractual management of supply-chain dependencies — that flow down onto you in writing, and that they will ask you to evidence.
This engagement returns the attestation you put in front of those buyers, and an honest internal statement of what you can and cannot currently claim.
- Ownership, control rights and board composition
- Facility register with ownership and operator status
- Topology and cross-jurisdictional data flows
- Privileged access roles, locations and clearances
- Existing assessment reports and certification scope
- Customer contracts and flow-down obligations
- Evidence-referenced sovereignty position statement
- Control and influence analysis against tier conditions
- Jurisdictional exposure map, including support paths
- Flow-down analysis of customer CIRMP obligations
- Certification pathway with the concessions each tier requires
- Annexure: customer-facing attestation extract, cleared for release
Why this analysis, from here.
The work sits at an uncommon intersection: defence engineering practice, cyber security grounding, and the regulatory literacy to read a flow-down clause and a network architecture diagram as the same document. JEGASEC is independent and founder-led, and sells rigour and operator credibility rather than certifications it does not hold.
- Former RAAF electronics engineering officer — Defence capability work, electronic-warfare simulation exposure, sensitive technical data governance
- Bachelor of Computing and Cyber Security, UNSW Canberra
- Juris Doctor, Monash University — commenced May 2026, studied alongside ongoing cyber security and technology work
- Frameworks applied: ACSC Essential Eight, OWASP, MITRE ATT&CK, Defence Security Principles Framework, DSGL, Hosting Certification Framework, SOCI
Advisory independence is a standing principle here: this practice is not a sales channel for JEGASEC's own products, and "you don't need this" is a legitimate finding. Read more about the founder.
Before you enquire.
These engagements suit a specific kind of client, and are a poor fit for others. Rather than discover that on a call neither of us wanted, here is the filter in full.
A good fit if
- Budget is approved, or approvable against a scope document
- You prefer a written determination to a series of meetings
- You can assemble the input manifest within two to six weeks
- Someone identifiable can authorise release of those documents
- There is a specific gate this needs to clear, with a date attached
A poor fit if
- You need regular check-ins or a named contact for live questions
- You are looking for someone to work alongside your team day to day
- You need help producing the underlying evidence, not analysing it
- You are collecting comparative quotes against hourly proposals
- You need hands-on testing of a live environment
If the second column describes you, say so in your enquiry and we will point you to a firm better suited to it. That referral costs us a sale and saves you a quarter.
JEGASEC is not an Australian legal practice and does not provide legal services, legal advice or legal opinions. Where a deliverable addresses legislation, control lists, standards or contractual provisions, it does so as technical and structural analysis of the requirements those instruments impose on systems, evidence and organisational design. Obtain independent advice from an admitted legal practitioner before acting on any matter bearing on your legal position.
No warranty is given that any engagement will result in a certification, membership, permit, clearance, panel position or approval being granted — those determinations rest entirely with the relevant decision-maker. Analysis states a position as at the evidence-freeze date and is prepared for the client named in the engagement, on the evidence that client supplies.
JEGASEC is an independent business and is not endorsed by, affiliated with or representing the Australian Defence Force or the Australian Government. Do not send classified, protected or operationally sensitive material to JEGASEC without a separate written agreement and appropriate handling arrangements in place.