ATO Digital Service Provider (DSP) Operational Security Framework
The Australian Taxation Office's security framework for software developers whose products send tax, accounting, payroll, business registry or superannuation data to the ATO: audit logging, multi-factor authentication and session limits, onshore hosting, key management, encryption at rest and TLS 1.3 in transit, customer entity validation, personnel security, security monitoring, supply chain and add-on marketplace controls, independent certification or self-assessment by risk category, annual reviews, change notices and reporting data breaches to the ATO within one business day, as a condition of access to ATO APIs and digital services.
ATO Digital Service Provider (DSP) Operational Security Framework is a compliance framework from Australia with 3 domains and 26 controls that map to 3 other frameworks. The largest domains are Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework (15 controls), Registration, maintaining compliance and data breach reporting – ATO Digital Service Provider (DSP) Operational Security Framework (8 controls), Certification and self-assessment – ATO Digital Service Provider (DSP) Operational Security Framework (3 controls). Every control below carries what it requires and what an assessor expects to see.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit softwaredevelopers.ato.gov.auFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (3)
Certification and self-assessment – ATO Digital Service Provider (DSP) Operational Security Framework
| Code | Title |
|---|---|
| ato-digital-service-provider-dsp-operational-security-framework::CERT.GAP | Explain gaps against the chosen standard and resubmit after significant change |
| ato-digital-service-provider-dsp-operational-security-framework::CERT.IND | Independent certification (iRAP or ISO/IEC 27001) where the category requires it |
| ato-digital-service-provider-dsp-operational-security-framework::CERT.SELF | Self-assessment against an approved standard, renewed every two years |
Registration, maintaining compliance and data breach reporting – ATO Digital Service Provider (DSP) Operational Security Framework
| Code | Title |
|---|---|
| ato-digital-service-provider-dsp-operational-security-framework::PROC.ANNUAL | Annual assurance review |
| ato-digital-service-provider-dsp-operational-security-framework::PROC.BREACH | Report data breaches to the ATO within one business day |
| ato-digital-service-provider-dsp-operational-security-framework::PROC.CHANGE | Notify the DPO of significant changes to the business or product |
| ato-digital-service-provider-dsp-operational-security-framework::PROC.HOSTED | Isolate hosted client instances and limit DSP access to support with consent |
| ato-digital-service-provider-dsp-operational-security-framework::PROC.PRODUCTID | Keep ATO product IDs confidential and use them only as intended |
| ato-digital-service-provider-dsp-operational-security-framework::PROC.REGISTER | Register, complete the OSF questionnaire and evidence every control |
| ato-digital-service-provider-dsp-operational-security-framework::PROC.SSP | Describe the sending service provider model and value chain |
| ato-digital-service-provider-dsp-operational-security-framework::PROC.TRUE | Give the ATO true and correct information and keep details current |
Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework
Your Compliance Coverage
If you comply with ATO Digital Service Provider (DSP) Operational Security Framework, you already cover:
Maps to 3 other frameworks
Coverage is not the same as your position
This page shows what ATO Digital Service Provider (DSP) Operational Security Framework overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is ATO Digital Service Provider (DSP) Operational Security Framework and who does it apply to?
ATO Digital Service Provider (DSP) Operational Security Framework is a compliance framework from Australia with 3 domains and 26 controls. The Australian Taxation Office's security framework for software developers whose products send tax, accounting, payroll, business registry or superannuation data to the ATO: audit logging, multi-factor authentication and session limits, onshore hosting, key management, encryption at rest and TLS 1.3 in transit, customer entity validation, personnel security, security monitoring, supply chain and add-on marketplace controls, independent certification or self-assessment by risk category, annual reviews, change notices and reporting data breaches to the ATO within one business day, as a condition of access to ATO APIs and digital services. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ATO Digital Service Provider (DSP) Operational Security Framework actually require?
ATO Digital Service Provider (DSP) Operational Security Framework has 26 controls organised across 3 domains. The largest domains are Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework (15 controls), Registration, maintaining compliance and data breach reporting – ATO Digital Service Provider (DSP) Operational Security Framework (8 controls), Certification and self-assessment – ATO Digital Service Provider (DSP) Operational Security Framework (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ATO Digital Service Provider (DSP) Operational Security Framework do I already cover?
ATO Digital Service Provider (DSP) Operational Security Framework maps to 3 other compliance frameworks. The top mapping partners are ISO 27002:2022 (73% coverage), Australian Information Security Manual (35% coverage), ACSC Essential Eight (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ATO Digital Service Provider (DSP) Operational Security Framework?
Start your ATO Digital Service Provider (DSP) Operational Security Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ATO Digital Service Provider (DSP) Operational Security Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 26 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.
Get Started Free →Free forever — no credit card required