Australian Government protective security policy across six domains, administered by Home Affairs. Mandatory for entities and flowed down to their suppliers.
The Protective Security Policy Framework is the Australian Government's core protective security policy, administered by the Department of Home Affairs. It prescribes what government entities must do to protect their people, information and resources, domestically and internationally.
It is organised across six security domains: governance, risk, information, technology, personnel and physical. The November 2024 release was the structural turning point, expanding the framework from four domains to six by adding dedicated risk and technology domains. The July 2025 release put technology at the centre — embedding Zero Trust principles, lifting gateway security requirements, requiring a stocktake of internet-facing technology assets, and drawing ASD further into the framework. PSPF Release 2026 is the current release and took effect on 1 July 2026.
The framework operates on an annual release cycle with entity self-assessment and reporting. Applicable Commonwealth entities report each financial year on the maturity of their security capability and the effectiveness of their implementation.
It also carries a Directions mechanism. The Secretary of Home Affairs may issue a Direction at any point in the year requiring entities to act on a specific, present risk — recent Directions have addressed particular vendor products and Commonwealth technology management. Directions do not wait for the annual release, and entities must adhere to them.
Compliance is mandatory for non-corporate Commonwealth entities. Corporate Commonwealth entities and wholly-owned Commonwealth companies are expected to treat it as better practice.
Most departments and agencies. For these organisations PSPF compliance is mandatory government policy, with annual reporting to their minister and to Home Affairs.
Expected to treat the framework as better practice rather than binding policy.
The largest population in practice. Service providers of every kind — cloud hosts, software vendors, facilities managers, consultancies — must implement the relevant controls wherever a contract, deed, panel head agreement or Direction requires it. That reaches most organisations handling Commonwealth information.
Usually an annual reporting deadline for entities, or a contract clause and an accompanying assurance request for suppliers.
The PSPF runs on an annual cycle of self-assessment and reporting rather than external certification.
Entities determine their obligations under the current release. Suppliers work the other direction — establishing which requirements flow to them through their specific contract, which is rarely the whole framework and is often misjudged in both directions.
Governance, risk, information, technology, personnel and physical. Recent releases have weighted the technology domain heavily.
Security plans covering all six domains, appointment of a Chief Security Officer and CISO with appropriate authority, a technology asset stocktake covering internet-facing systems, incident reporting procedures, and a cyber security strategy and uplift plan aligned to the ISM.
Close the gaps, including Essential Eight Maturity Level Two, which the framework sets as the mandatory baseline for applicable entities.
Applicable entities report each financial year on the maturity of their security capability and the effectiveness of implementation. Reports are approved by the Accountable Authority.
Directions are issued outside the annual cycle and must be adhered to when made. Tracking them is an ongoing obligation, not an annual one.
For entities, Soveriq assesses against the current release across all six domains, builds the security plans and supporting artefacts, and prepares the annual reporting position.
For suppliers, we work the other direction: establishing precisely which requirements flow to you through your contract, and building evidence that satisfies them without over-building against a framework that was never yours to meet in full. Over-scoping here is a common and expensive mistake.
Where ISO 27001 exists, we map the ISMS across rather than starting again.
On internal review. Where Soveriq has built your security framework, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.
What we will not do. Soveriq does not approve PSPF reporting, does not speak for Home Affairs, and does not promise an assessment outcome.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
A note on our current position. Soveriq is not currently a DISP member. Our route into this work is advisory and readiness for entities, and direct delivery for suppliers carrying flow-down obligations.
Not directly — the framework binds entities, not their vendors. In practice it reaches suppliers through contracts, deeds and panel head agreements, which require you to implement the relevant controls. So the obligation is real, but it lives in your contract rather than in the policy.
Annually, with a release each cycle. Release 2026 is current and took effect 1 July 2026. Separately, the Secretary of Home Affairs can issue Directions at any time to address a specific present risk — recent examples have covered particular vendors and product categories — and those must be adhered to when issued.
The PSPF sets the policy obligation; the ISM supplies the technical controls and the Essential Eight the prioritised baseline. The PSPF requires Essential Eight Maturity Level Two for applicable entities.
No. The PSPF operates on entity self-assessment and annual reporting rather than third-party certification. Any provider offering PSPF certification is describing something that does not exist.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope