Plain English — promise — current as at 14 August 2026
The ISM controls that matter for your documents
The ASD's Information Security Manual (ISM) is written for systems, but a handful of its controls decide how documents must be signed, protected and carried into the post-quantum era. Here they are in plain English — with control numbers, so you can check us. General information, not legal advice — current as at 14 August 2026.
The cryptography transition controls
ISM-1917
ISM-governed systems must support the post-quantum algorithms — ML-DSA-87 and SHA-384/512 — well before the end-2030 transition deadline.
ISM-1990
Validated cryptographic modules are preferred: implementations should carry independent scrutiny, not just good intentions.
ISM-1992 & ISM-1994
Use the hedged ML-DSA variant, and keep digest agility — SHA-512 where pre-hashing is used — so one weakened primitive never strands a document.
ISM-1996 & ISM-2073
Hybrid classical+post-quantum composition must follow defined rules, and vendors must publish and maintain a transition plan you can hold them to.
How Omitly maps to them, today
Today, every Omitly seal is Ed25519 over a SHA-256 digest — real and shipped, but not on the ISM's approved list. Hybrid seals (ML-DSA-87 + ECDSA P-384) with SHA-384/512 digests, a module admission bar and a published transition plan are on our roadmap, not shipped yet. The full mapping — control by control, including what's shipped versus roadmap — is in our answers to ASD's vendor questionnaire.
This page is general information, not legal advice. It explains ISM controls in plain English and does not determine whether any control applies to your organisation. Cite the primary source — the ASD's Information Security Manual — and take your own advice. Current as at 14 August 2026.
Check the mapping yourself
Every claim on this page cites a control number — and our vendor-questionnaire answers put the artifacts behind them on the record.