Western Australia's baseline cyber security policy for government entities, built on the Essential Eight, the Further Five, NIST CSF and the ASD ISM.
The WA Government Cyber Security Policy prescribes the baseline for cyber security capabilities and practices across the Western Australian Government. The current published version dates from 2024.
What distinguishes it from other state policies is how explicitly it borrows from established frameworks rather than inventing its own control set. It mandates the Essential Eight at Maturity Level One as a minimum, and integrates that with the NIST Cybersecurity Framework, the ASD Information Security Manual, and ASD's Further Five mitigation strategies — additional strategies beyond the eight.
Maturity Level One as the mandated floor is worth understanding correctly. It is a baseline, not a target. An entity holding significant personal information or operating critical services should be able to explain why Level One is where it stopped, because the policy is risk-based and the floor is a starting point rather than an answer.
Compliance is demonstrated through annual reporting rather than certification. There is no WA Cyber Security Policy certificate.
Public sector entities to which the policy applies, for whom it sets the mandatory baseline and the annual reporting obligation.
Where cyber security obligations flow down through contracts. As with every state framework, the binding document for a supplier is the contract rather than the policy itself.
Because the policy integrates both, existing work under either maps across substantially rather than needing to be redone.
The annual reporting cycle for entities, or a contract clause and assurance request for suppliers.
The policy is a baseline, so the first question is where you sit against it and the second is whether the baseline is sufficient for your risk.
Establish which entities and systems the policy covers in your context, and where obligations flow to suppliers.
Including current Essential Eight maturity, assessed against evidence rather than self-assertion. Maturity Level One is a floor, not a target for an entity holding significant sensitive information.
The additional mitigation strategies the policy incorporates alongside the eight. These are frequently overlooked because they sit outside the more familiar Essential Eight framing.
The policy draws on both. Where an entity already works to the NIST Cybersecurity Framework or the ASD ISM, that work maps across rather than being duplicated.
Roles, accountability and the records that make a reporting position defensible.
Against the policy requirements, with the evidence to support the position taken.
Soveriq assesses against the policy baseline using evidence rather than self-rating, covers the Further Five alongside the Essential Eight — which is the part most commonly missed — and maps existing NIST CSF or ISM work across instead of duplicating it.
For suppliers, we establish which obligations flow through your contract with a WA entity and build proportionate evidence.
We will also tell you plainly if Maturity Level One is not adequate for what you hold. A policy floor is not the same as an appropriate risk position, and treating it as one is how organisations end up compliant and breached.
On internal review. Where Soveriq has performed the uplift, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.
What we will not do. Soveriq does not approve reporting, does not speak for the Office of Digital Government, and does not promise an assessment outcome.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
It is the policy baseline, not a ceiling. Whether it is enough depends on what the entity holds and what it is exposed to. An entity handling significant personal information with only Maturity Level One should be able to explain that decision, because the policy is risk-based and a baseline is a floor rather than an answer.
Additional mitigation strategies beyond the eight, drawn from ASD's broader mitigation strategy guidance. WA's policy incorporates them alongside the Essential Eight, which is one of the ways it goes past a straight Essential Eight adoption.
The policy references the Essential Eight, so as ASD moves to the Essentials series the WA policy will need to follow. Nothing changes immediately — the Essential Eight remains live — but entities should expect the reference to be updated in a future policy revision.
The policy is directed at WA public sector entities. Local government arrangements differ, and the practical answer for any specific body is in its own governing arrangements rather than the policy itself.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope