The ACT Government's protective security arrangements for directorates and their suppliers, covering governance, information, personnel and physical security.
The ACT Government's protective security arrangements set how territory directorates and agencies protect their information, people and assets. They follow the standard Australian protective security structure — governance, information, personnel and physical security — and are administered through the Chief Minister, Treasury and Economic Development Directorate.
The ACT sits in an unusual position. Territory entities operate alongside a dense concentration of Commonwealth agencies, and many ACT-based suppliers hold both territory and Commonwealth work. In practice that means Commonwealth expectations exert real gravitational pull — the PSPF, the ASD ISM and the Essential Eight are common reference points for organisations working in Canberra regardless of which government is contracting.
They are still separate instruments, though. A Commonwealth PSPF position does not automatically satisfy an ACT requirement, and assuming otherwise is a mistake worth avoiding.
A note on sourcing. The ACT publishes less of its detailed security policy material publicly than the larger jurisdictions. For a supplier, the binding document is your contract and the directorate is the authority on what it requires.
This is not a certification scheme. There is no ACT protective security certificate.
For whom protective security requirements are mandatory territory policy.
Where obligations reach you through your contract. In Canberra this frequently sits alongside Commonwealth obligations for the same organisation.
The most common situation, and the one where mapping between territory and Commonwealth requirements saves the most effort.
A contract clause and an assurance request, usually alongside an existing Commonwealth obligation.
For suppliers, a contract-reading exercise before a security exercise. ACT requirements are not published as extensively as those of the larger jurisdictions, so the specific obligations come from the directorate and the contract.
Governance, information, personnel and physical security.
Access control, personnel screening appropriate to the information handled, information handling and classification, and physical security.
The Essential Eight is the common technical reference across Australian jurisdictions, and ACT entities frequently benchmark against it alongside the ASD ISM and NIST CSF.
In the form the directorate requires.
Soveriq's first step for ACT engagements is establishing what your contract actually requires and who confirms it. That is not a formality — building against an assumed standard is the most common way suppliers overspend on territory work.
From there we assess across the protective security domains, build proportionate controls, and prepare evidence in the form the directorate expects.
Because ACT organisations frequently work with Commonwealth entities as well, we map PSPF and ISM work across rather than running two programmes. In Canberra that overlap is usually the largest available saving.
Being straight about the limits. ACT requirements are less publicly documented than those of the larger states. We will tell you where we are working from published material and where the directorate needs to confirm the requirement.
On internal review. Where Soveriq has built your security framework, we provide readiness validation labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
No. They share a structure and a lineage, and the ACT sits geographically inside the Commonwealth's centre of gravity, but they are separate instruments with separate governance. A Commonwealth PSPF position does not automatically satisfy an ACT requirement.
For suppliers, in your contract and from the directorate that issued it. Detailed ACT security policy material is largely published to directorates rather than publicly.
No. Like every Australian jurisdiction's protective security arrangements, this runs on self-assessment and internal assurance rather than third-party certification.
Considerably. The control expectations overlap heavily, and evidence built for Commonwealth PSPF or ISM obligations usually transfers with modest adaptation. It is a mapping exercise rather than a new programme.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope