The mandatory cyber security policy for NSW Government agencies, administered by Cyber Security NSW, with annual assurance reporting and attestation.
The NSW Cyber Security Policy sets the mandatory cyber security requirements for NSW Government agencies. It is administered by Cyber Security NSW within the Department of Customer Service, and it is reviewed and reissued regularly — the current edition is the 2026–27 policy.
The policy sets out mandatory requirements, reporting obligations, threat-based cyber risk management principles, and the roles and responsibilities that agencies must assign. It is deliberately risk-based rather than purely prescriptive, and it leans on the Essential Eight as its technical baseline.
The cycle that matters is annual. By 31 October each year, agencies must report to Cyber Security NSW, either through their portfolio Chief Information Security Officer or directly, providing:
Alongside the policy, Cyber Security NSW issues directives that carry their own mandatory requirements — recent examples have covered targeted uplift initiatives and the handling of 'limited use' cyber security incident information under the Commonwealth Cyber Security Act 2024.
This is not a certification scheme. There is no NSW CSP certificate.
Departments, executive agencies, separate agencies and statutory authorities. For these organisations the policy is mandatory and the reporting deadline is fixed.
The policy requires agencies to manage cyber security risks arising from third-party providers — including ICT providers such as NSW Government shared service providers, and any party that processes or stores an agency's sensitive information. In practice that obligation lands on suppliers through their contracts.
Where you hold or process NSW Government sensitive information, expect to be asked to evidence controls, incident responsibilities and breach notification arrangements.
For agencies, the October reporting deadline. For suppliers, a contract clause and an accompanying assurance request.
The cycle is annual, built around assurance assessment and attestation.
Agencies determine which mandatory requirements apply. Requirements may be assessed as not applicable, but each must be explained in the attestation letter with any compensating controls noted. A formal exemption request is not needed for this, though a portfolio CISO should be consulted where applicability is unclear.
An assurance assessment covering all mandatory requirements for the financial year. This is evidence-based rather than a self-rating exercise.
Information security management system, defined cyber security roles and responsibilities, Essential Eight implementation and maturity reporting, and third-party risk management covering ICT providers and anyone processing or storing agency sensitive information.
The inventory of assets whose compromise would matter most. Agencies frequently find this harder than expected, because it forces a prioritisation nobody has previously written down.
Maintain a register of residual risks rated high or extreme, with treatment and review mechanisms, and report them.
Reporting goes to Cyber Security NSW, either through the portfolio CISO or directly, and includes the assurance assessment, high and extreme residual risks, the crown jewel inventory, an assessment against all-of-government cyber security risks, and a signed attestation on cyber security posture.
For agencies, Soveriq assesses against the mandatory requirements, builds the underlying management system and crown jewel inventory, and prepares the assurance assessment and attestation position ahead of the October deadline.
For suppliers, we establish precisely which obligations flow to you through your agency contract and build evidence that satisfies them — without building against the whole policy, which was never yours to meet.
Where ISO 27001 is held or in progress, we map it across rather than starting again. The policy's ISMS expectations align closely.
On internal review. Where Soveriq has built your security framework, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.
What we will not do. Soveriq does not approve attestations, does not speak for Cyber Security NSW, and does not promise an assessment outcome.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
By 31 October each year, covering the previous financial year. Extensions must be requested in writing to Cyber Security NSW before 31 October, in line with the reporting guidance — they are not granted retrospectively.
Agencies may assess a mandatory requirement as not applicable. You must clearly explain each 'not applicable' response in the attestation letter, including any compensating controls. A formal exemption request is not required for this, though agencies unsure whether a requirement applies should consult their portfolio CISO.
Not directly. The policy binds agencies. It reaches suppliers through contracts, because agencies must manage cyber security risks from third-party providers — including ICT providers and anyone processing or storing agency sensitive information.
No. The policy runs on agency self-assessment, assurance assessment and signed attestation. There is no third-party certification and nobody can issue you one.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope