Protective Security Policy Framework (PSPF) Release 2026
Part Two: Risk (sections 5 to 8) – Protective Security Policy Framework (PSPF) Release 2026

Protective Security Policy Framework (PSPF) Release 2026 0043: 0043 Government service providers share IRAP reports

Requirement 0043 (Part Two: Risk, section 6.1.1 Third Party Risk Management; applies to All entities; dated 31 October 2024; retained from Release 2025): Government entities providing outsourced services provide IRAP assessment reports to the government entities consuming, or looking to consume, their services. Entities acting as managed or cloud service providers make IRAP assessment reports available to consuming entities, where reasonably practicable.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Part Two: Risk (sections 5 to 8) – Protective Security Policy Framework (PSPF) Release 2026

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.