HCF — Hosting Certification Framework

The Australian Government's data sovereignty and security requirements for providers hosting government data. Currently under reform.

Australian Government, through the Department of Home Affairs and Commonwealth digital and technology policy. The framework is under reform.

What it is

The Hosting Certification Framework sets the Australian Government's requirements for data centre and hosting providers that store or process government data. Its purpose is data sovereignty: ensuring Commonwealth data is hosted in facilities whose ownership, control and location the Government can be confident about.

The framework certifies hosting providers and facilities across tiers reflecting the sensitivity of the data hosted, with the higher tiers requiring greater assurance over ownership and control of the provider entity itself — not just its technical controls.

An important caveat on currency. The published framework dates from March 2021 and has been under reform, with hosting and data sovereignty policy sitting inside the broader modernisation of Commonwealth technology and protective security policy. Requirements have been moving. Any organisation planning a programme against it should confirm the current position with the contracting entity before committing budget, rather than building against the 2021 document.

Certification is granted by the Australian Government. No consultancy certifies anyone under this framework.

Who it's for

Data centre and hosting providers

Organisations providing facilities or hosting services to Australian Government entities, where certification attaches to the provider and the facility.

Cloud and managed service providers

Where Commonwealth data is stored or processed, and the contracting entity requires assurance about where it sits and who controls it.

Software vendors hosting on certified infrastructure

The largest group in practice. Most vendors are not seeking certification themselves — their obligation is to evidence that they host on a certified provider and to document the controls they operate on top of that arrangement.

What triggers the work

Usually a Commonwealth contract or panel condition asking where the data lives and who can reach it.

Why implement it

  • It is a condition of hosting Commonwealth data. Where a contract requires certified hosting, an uncertified arrangement ends the conversation.
  • Data sovereignty is a live procurement question well beyond this framework, and the documentation produced answers it for commercial buyers too.
  • It forces clarity on ownership and control. Many organisations cannot readily evidence who ultimately owns and controls their hosting chain, and that is precisely what is being asked.
  • It pairs with cloud controls. ISO 27017 and 27018 cover data location transparency and the shared responsibility boundary, doing much of the same work in a commercially recognised form.

How implementation works

Establish the current requirement before designing anything, because this framework is mid-reform.

1. Confirm the applicable requirement

The published framework dates from 2021 and is under reform. What binds you is what your contract or the contracting entity specifies today. Confirm that first rather than building against a document that may be superseded.

2. Establish your position in the chain

Hosting provider, facility operator, or software vendor hosting on someone else's certified infrastructure. The obligations differ substantially, and most organisations are in the third category.

3. Data sovereignty documentation

Where Commonwealth data physically resides, who can access it, and how ownership and control of the hosting entity is evidenced. This is the substance of the framework.

4. Control implementation

Security controls proportionate to the classification of hosted data, typically drawing on the ISM.

5. Evidence and maintain

Ownership and control arrangements change. So does the framework. Both need tracking.

How Soveriq helps

Soveriq works on hosting and data sovereignty as a readiness and evidence exercise: establishing which requirements actually bind you today, documenting data location and access, and building the control set proportionate to the data being hosted.

Where ISO 27017 and 27018 are in scope, the cloud control extensions and the data location transparency obligations do much of this work and are worth scoping together.

Being direct about this one. The HCF is mid-reform and Soveriq is not a certification body for it. We describe our work here as readiness rather than certification, and we would rather tell you the requirement is unsettled than sell you a programme against a document that may change.

What we will not do. Soveriq does not certify hosting providers, does not speak for the Commonwealth, and does not promise a certification outcome.

What the engagement looks like

  • Module 01 — Gap analysis against hosting and data sovereignty requirements as they apply to your arrangement.
  • Module 02 — Build. Sovereignty controls, data location documentation, ownership and control evidence, and the supporting management system.
  • Module 05 — Continuous compliance, including tracking the reform as it lands.

Modules 03 and 04 apply where the work supports an ISM or ISO 27001 assessment. Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

Can Soveriq certify us under the HCF?

No. Certification is granted by the Australian Government, not by a consultancy. What we provide is readiness: the controls, the documentation and the evidence of data sovereignty. Any provider claiming to certify you under the HCF is describing something that does not exist.

Is the framework changing?

Yes. The published framework dates from March 2021 and has been under reform, with hosting and data sovereignty policy sitting inside the broader Commonwealth technology and PSPF modernisation programme. Anyone telling you the requirements are settled is overstating the position — confirm the current requirement with the contracting entity before committing to a programme.

Does this apply to us if we only use a certified provider?

The certification attaches to the hosting provider and facility. If you are a software vendor hosting on a certified provider, your obligation is typically to evidence that arrangement and the controls you operate on top of it, not to seek certification yourself.

What matters most in practice?

Being able to answer, with documents rather than assurances, where Commonwealth data physically resides and who can access it — including through ownership and control of the hosting entity.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope