PSPF — Protective Security Policy Framework

Australian Government protective security policy across six domains, administered by Home Affairs. Mandatory for entities and flowed down to their suppliers.

Department of Home Affairs. Directions are issued by the Secretary of the Department.

What it is

The Protective Security Policy Framework is the Australian Government's core protective security policy, administered by the Department of Home Affairs. It prescribes what government entities must do to protect their people, information and resources, domestically and internationally.

It is organised across six security domains: governance, risk, information, technology, personnel and physical. The November 2024 release was the structural turning point, expanding the framework from four domains to six by adding dedicated risk and technology domains. The July 2025 release put technology at the centre — embedding Zero Trust principles, lifting gateway security requirements, requiring a stocktake of internet-facing technology assets, and drawing ASD further into the framework. PSPF Release 2026 is the current release and took effect on 1 July 2026.

The framework operates on an annual release cycle with entity self-assessment and reporting. Applicable Commonwealth entities report each financial year on the maturity of their security capability and the effectiveness of their implementation.

It also carries a Directions mechanism. The Secretary of Home Affairs may issue a Direction at any point in the year requiring entities to act on a specific, present risk — recent Directions have addressed particular vendor products and Commonwealth technology management. Directions do not wait for the annual release, and entities must adhere to them.

Compliance is mandatory for non-corporate Commonwealth entities. Corporate Commonwealth entities and wholly-owned Commonwealth companies are expected to treat it as better practice.

Who it's for

Non-corporate Commonwealth entities

Most departments and agencies. For these organisations PSPF compliance is mandatory government policy, with annual reporting to their minister and to Home Affairs.

Corporate Commonwealth entities and Commonwealth companies

Expected to treat the framework as better practice rather than binding policy.

Contractors and suppliers

The largest population in practice. Service providers of every kind — cloud hosts, software vendors, facilities managers, consultancies — must implement the relevant controls wherever a contract, deed, panel head agreement or Direction requires it. That reaches most organisations handling Commonwealth information.

What triggers the work

Usually an annual reporting deadline for entities, or a contract clause and an accompanying assurance request for suppliers.

Why implement it

  • For entities it is mandatory policy, with annual reporting to the minister and to Home Affairs approved by the Accountable Authority.
  • For suppliers it protects the contract. Where PSPF-derived obligations flow down, failing to evidence them puts the engagement at risk.
  • It is the gateway to Commonwealth work. Demonstrable alignment is a practical prerequisite for competing for contracts involving Commonwealth information.
  • It forces a technology asset stocktake. Recent releases require entities to know and maintain a record of their internet-facing systems — something most organisations cannot produce on request, and the absence of which is a live security risk in itself.
  • It aligns with what you may already hold. The governance expectations map closely onto ISO 27001, and the technical layer runs through the ISM and Essential Eight.

How implementation works

The PSPF runs on an annual cycle of self-assessment and reporting rather than external certification.

1. Establish what applies

Entities determine their obligations under the current release. Suppliers work the other direction — establishing which requirements flow to them through their specific contract, which is rarely the whole framework and is often misjudged in both directions.

2. Assess against the six domains

Governance, risk, information, technology, personnel and physical. Recent releases have weighted the technology domain heavily.

3. Build the security plan and supporting artefacts

Security plans covering all six domains, appointment of a Chief Security Officer and CISO with appropriate authority, a technology asset stocktake covering internet-facing systems, incident reporting procedures, and a cyber security strategy and uplift plan aligned to the ISM.

4. Uplift

Close the gaps, including Essential Eight Maturity Level Two, which the framework sets as the mandatory baseline for applicable entities.

5. Report

Applicable entities report each financial year on the maturity of their security capability and the effectiveness of implementation. Reports are approved by the Accountable Authority.

6. Track Directions

Directions are issued outside the annual cycle and must be adhered to when made. Tracking them is an ongoing obligation, not an annual one.

How Soveriq helps

For entities, Soveriq assesses against the current release across all six domains, builds the security plans and supporting artefacts, and prepares the annual reporting position.

For suppliers, we work the other direction: establishing precisely which requirements flow to you through your contract, and building evidence that satisfies them without over-building against a framework that was never yours to meet in full. Over-scoping here is a common and expensive mistake.

Where ISO 27001 exists, we map the ISMS across rather than starting again.

On internal review. Where Soveriq has built your security framework, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What we will not do. Soveriq does not approve PSPF reporting, does not speak for Home Affairs, and does not promise an assessment outcome.

What the engagement looks like

  • Module 01 — Gap analysis against the requirements that apply to you, whether as an entity or through a contract.
  • Module 02 — Build. Security plans across the six domains, technology asset stocktake, incident procedures and the supporting control work.
  • Module 03 — Internal review ahead of reporting, subject to the impartiality position above.
  • Module 04 — Representation where an agency or assessor engages directly.
  • Module 05 — Continuous compliance, including tracking annual releases and Directions.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

A note on our current position. Soveriq is not currently a DISP member. Our route into this work is advisory and readiness for entities, and direct delivery for suppliers carrying flow-down obligations.

Common questions

Does the PSPF apply to us as a supplier?

Not directly — the framework binds entities, not their vendors. In practice it reaches suppliers through contracts, deeds and panel head agreements, which require you to implement the relevant controls. So the obligation is real, but it lives in your contract rather than in the policy.

How often does it change?

Annually, with a release each cycle. Release 2026 is current and took effect 1 July 2026. Separately, the Secretary of Home Affairs can issue Directions at any time to address a specific present risk — recent examples have covered particular vendors and product categories — and those must be adhered to when issued.

What is the relationship with the ISM and Essential Eight?

The PSPF sets the policy obligation; the ISM supplies the technical controls and the Essential Eight the prioritised baseline. The PSPF requires Essential Eight Maturity Level Two for applicable entities.

Is there a PSPF certificate?

No. The PSPF operates on entity self-assessment and annual reporting rather than third-party certification. Any provider offering PSPF certification is describing something that does not exist.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope