NSW Cyber Security Policy

The mandatory cyber security policy for NSW Government agencies, administered by Cyber Security NSW, with annual assurance reporting and attestation.

Cyber Security NSW, within the Department of Customer Service.

What it is

The NSW Cyber Security Policy sets the mandatory cyber security requirements for NSW Government agencies. It is administered by Cyber Security NSW within the Department of Customer Service, and it is reviewed and reissued regularly — the current edition is the 2026–27 policy.

The policy sets out mandatory requirements, reporting obligations, threat-based cyber risk management principles, and the roles and responsibilities that agencies must assign. It is deliberately risk-based rather than purely prescriptive, and it leans on the Essential Eight as its technical baseline.

The cycle that matters is annual. By 31 October each year, agencies must report to Cyber Security NSW, either through their portfolio Chief Information Security Officer or directly, providing:

  • an assurance assessment against all mandatory requirements for the previous financial year
  • any cyber security risks with a residual rating of high or extreme
  • a signed attestation on cyber security posture
  • an assessment against all-of-government cyber security risks
  • a crown jewel asset inventory

Alongside the policy, Cyber Security NSW issues directives that carry their own mandatory requirements — recent examples have covered targeted uplift initiatives and the handling of 'limited use' cyber security incident information under the Commonwealth Cyber Security Act 2024.

This is not a certification scheme. There is no NSW CSP certificate.

Who it's for

NSW Government agencies

Departments, executive agencies, separate agencies and statutory authorities. For these organisations the policy is mandatory and the reporting deadline is fixed.

Third-party service providers to NSW agencies

The policy requires agencies to manage cyber security risks arising from third-party providers — including ICT providers such as NSW Government shared service providers, and any party that processes or stores an agency's sensitive information. In practice that obligation lands on suppliers through their contracts.

Suppliers holding agency sensitive information

Where you hold or process NSW Government sensitive information, expect to be asked to evidence controls, incident responsibilities and breach notification arrangements.

What triggers the work

For agencies, the October reporting deadline. For suppliers, a contract clause and an accompanying assurance request.

Why implement it

  • For agencies it is mandatory, with a fixed annual deadline and a signed attestation by the agency head. This is not a framework you can quietly defer.
  • For suppliers it protects the contract. Agencies must manage third-party cyber risk, and they discharge that by requiring evidence from you.
  • The crown jewel inventory is genuinely useful. Identifying which assets matter most is the prerequisite for spending security budget sensibly, and most organisations have never done it formally.
  • It forces residual risk into the open. Reporting high and extreme residual risks with treatment plans means they get executive attention rather than sitting unowned in a register.
  • It aligns with what you may already hold. The ISMS expectations map closely onto ISO 27001, and the technical baseline runs through the Essential Eight.

How implementation works

The cycle is annual, built around assurance assessment and attestation.

1. Establish scope and applicability

Agencies determine which mandatory requirements apply. Requirements may be assessed as not applicable, but each must be explained in the attestation letter with any compensating controls noted. A formal exemption request is not needed for this, though a portfolio CISO should be consulted where applicability is unclear.

2. Assess against the mandatory requirements

An assurance assessment covering all mandatory requirements for the financial year. This is evidence-based rather than a self-rating exercise.

3. Build the underlying capability

Information security management system, defined cyber security roles and responsibilities, Essential Eight implementation and maturity reporting, and third-party risk management covering ICT providers and anyone processing or storing agency sensitive information.

4. Identify crown jewel assets

The inventory of assets whose compromise would matter most. Agencies frequently find this harder than expected, because it forces a prioritisation nobody has previously written down.

5. Manage and report risk

Maintain a register of residual risks rated high or extreme, with treatment and review mechanisms, and report them.

6. Report and attest by 31 October

Reporting goes to Cyber Security NSW, either through the portfolio CISO or directly, and includes the assurance assessment, high and extreme residual risks, the crown jewel inventory, an assessment against all-of-government cyber security risks, and a signed attestation on cyber security posture.

How Soveriq helps

For agencies, Soveriq assesses against the mandatory requirements, builds the underlying management system and crown jewel inventory, and prepares the assurance assessment and attestation position ahead of the October deadline.

For suppliers, we establish precisely which obligations flow to you through your agency contract and build evidence that satisfies them — without building against the whole policy, which was never yours to meet.

Where ISO 27001 is held or in progress, we map it across rather than starting again. The policy's ISMS expectations align closely.

On internal review. Where Soveriq has built your security framework, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What we will not do. Soveriq does not approve attestations, does not speak for Cyber Security NSW, and does not promise an assessment outcome.

What the engagement looks like

  • Module 01 — Gap analysis against the mandatory requirements, or against the subset flowing to you by contract.
  • Module 02 — Build. ISMS, crown jewel inventory, risk register, Essential Eight uplift and the third-party risk process.
  • Module 03 — Internal review ahead of the assurance assessment, subject to the impartiality position above.
  • Module 04 — Representation where Cyber Security NSW or an agency client engages directly.
  • Module 05 — Continuous compliance, including the annual reporting cycle.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

When is reporting due?

By 31 October each year, covering the previous financial year. Extensions must be requested in writing to Cyber Security NSW before 31 October, in line with the reporting guidance — they are not granted retrospectively.

What if a requirement does not apply to us?

Agencies may assess a mandatory requirement as not applicable. You must clearly explain each 'not applicable' response in the attestation letter, including any compensating controls. A formal exemption request is not required for this, though agencies unsure whether a requirement applies should consult their portfolio CISO.

Does this apply to us as a supplier?

Not directly. The policy binds agencies. It reaches suppliers through contracts, because agencies must manage cyber security risks from third-party providers — including ICT providers and anyone processing or storing agency sensitive information.

Is there a NSW CSP certificate?

No. The policy runs on agency self-assessment, assurance assessment and signed attestation. There is no third-party certification and nobody can issue you one.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope