ACT Government Protective Security

The ACT Government's protective security arrangements for directorates and their suppliers, covering governance, information, personnel and physical security.

ACT Government, through the Chief Minister, Treasury and Economic Development Directorate.

What it is

The ACT Government's protective security arrangements set how territory directorates and agencies protect their information, people and assets. They follow the standard Australian protective security structure — governance, information, personnel and physical security — and are administered through the Chief Minister, Treasury and Economic Development Directorate.

The ACT sits in an unusual position. Territory entities operate alongside a dense concentration of Commonwealth agencies, and many ACT-based suppliers hold both territory and Commonwealth work. In practice that means Commonwealth expectations exert real gravitational pull — the PSPF, the ASD ISM and the Essential Eight are common reference points for organisations working in Canberra regardless of which government is contracting.

They are still separate instruments, though. A Commonwealth PSPF position does not automatically satisfy an ACT requirement, and assuming otherwise is a mistake worth avoiding.

A note on sourcing. The ACT publishes less of its detailed security policy material publicly than the larger jurisdictions. For a supplier, the binding document is your contract and the directorate is the authority on what it requires.

This is not a certification scheme. There is no ACT protective security certificate.

Who it's for

ACT Government directorates and agencies

For whom protective security requirements are mandatory territory policy.

Suppliers to ACT Government

Where obligations reach you through your contract. In Canberra this frequently sits alongside Commonwealth obligations for the same organisation.

Canberra-based organisations working across both governments

The most common situation, and the one where mapping between territory and Commonwealth requirements saves the most effort.

What triggers the work

A contract clause and an assurance request, usually alongside an existing Commonwealth obligation.

Why implement it

  • For directorates it is mandatory policy, covering the full protective security span.
  • For suppliers it protects the contract, with the same commercial dynamic as every other jurisdiction.
  • The Commonwealth overlap is a genuine saving. Organisations holding both territory and Commonwealth work can build one control set and evidence it twice, provided the mapping is done deliberately.
  • Personnel and physical security are in scope, so a purely technical programme will not satisfy the requirement.
  • ISO 27001 does much of it. A functioning ISO 27001 system covers a substantial share of the governance and information expectations.

How implementation works

1. Establish what binds you

For suppliers, a contract-reading exercise before a security exercise. ACT requirements are not published as extensively as those of the larger jurisdictions, so the specific obligations come from the directorate and the contract.

2. Assess across the security domains

Governance, information, personnel and physical security.

3. Build proportionate controls

Access control, personnel screening appropriate to the information handled, information handling and classification, and physical security.

4. Address the technical baseline

The Essential Eight is the common technical reference across Australian jurisdictions, and ACT entities frequently benchmark against it alongside the ASD ISM and NIST CSF.

5. Evidence and report

In the form the directorate requires.

How Soveriq helps

Soveriq's first step for ACT engagements is establishing what your contract actually requires and who confirms it. That is not a formality — building against an assumed standard is the most common way suppliers overspend on territory work.

From there we assess across the protective security domains, build proportionate controls, and prepare evidence in the form the directorate expects.

Because ACT organisations frequently work with Commonwealth entities as well, we map PSPF and ISM work across rather than running two programmes. In Canberra that overlap is usually the largest available saving.

Being straight about the limits. ACT requirements are less publicly documented than those of the larger states. We will tell you where we are working from published material and where the directorate needs to confirm the requirement.

On internal review. Where Soveriq has built your security framework, we provide readiness validation labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What the engagement looks like

  • Module 01 — Gap analysis against your contract obligations and the applicable ACT requirements, beginning with establishing what those are.
  • Module 02 — Build. Governance, information, personnel and physical security controls proportionate to what you hold.
  • Module 03 — Internal review, subject to the impartiality position above.
  • Module 04 — Representation where a directorate client engages directly.
  • Module 05 — Continuous compliance.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

Is the ACT framework the same as the Commonwealth PSPF?

No. They share a structure and a lineage, and the ACT sits geographically inside the Commonwealth's centre of gravity, but they are separate instruments with separate governance. A Commonwealth PSPF position does not automatically satisfy an ACT requirement.

Where do we find the specific requirements?

For suppliers, in your contract and from the directorate that issued it. Detailed ACT security policy material is largely published to directorates rather than publicly.

Is there an ACT security certificate?

No. Like every Australian jurisdiction's protective security arrangements, this runs on self-assessment and internal assurance rather than third-party certification.

We already work with Commonwealth agencies. Does that help?

Considerably. The control expectations overlap heavily, and evidence built for Commonwealth PSPF or ISM obligations usually transfers with modest adaptation. It is a mapping exercise rather than a new programme.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope