Back to Frameworks

ATO Digital Service Provider (DSP) Operational Security Framework

Australia
vWeb edition on the ATO Software Developers site (requirements and further guidance modified 16 April 2025; meeting the requirements 9 September 2025; security events and data breaches 7 May 2026) with DSP OSF Questionnaire v3.2 (September 2025); succeeds the PDF editions v6.0 (August 2021) and v6.05 (April 2023)
3 domains
26 controls

The Australian Taxation Office's security framework for software developers whose products send tax, accounting, payroll, business registry or superannuation data to the ATO: audit logging, multi-factor authentication and session limits, onshore hosting, key management, encryption at rest and TLS 1.3 in transit, customer entity validation, personnel security, security monitoring, supply chain and add-on marketplace controls, independent certification or self-assessment by risk category, annual reviews, change notices and reporting data breaches to the ATO within one business day, as a condition of access to ATO APIs and digital services.

Verified

ATO Digital Service Provider (DSP) Operational Security Framework is a compliance framework from Australia with 3 domains and 26 controls that map to 3 other frameworks. The largest domains are Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework (15 controls), Registration, maintaining compliance and data breach reporting – ATO Digital Service Provider (DSP) Operational Security Framework (8 controls), Certification and self-assessment – ATO Digital Service Provider (DSP) Operational Security Framework (3 controls). Every control below carries what it requires and what an assessor expects to see.

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit softwaredevelopers.ato.gov.au

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (3)

Certification and self-assessment – ATO Digital Service Provider (DSP) Operational Security Framework

3 controls
Controls in the Certification and self-assessment – ATO Digital Service Provider (DSP) Operational Security Framework domain of ATO Digital Service Provider (DSP) Operational Security Framework — 3 controls
CodeTitle
ato-digital-service-provider-dsp-operational-security-framework::CERT.GAPExplain gaps against the chosen standard and resubmit after significant change
ato-digital-service-provider-dsp-operational-security-framework::CERT.INDIndependent certification (iRAP or ISO/IEC 27001) where the category requires it
ato-digital-service-provider-dsp-operational-security-framework::CERT.SELFSelf-assessment against an approved standard, renewed every two years

Registration, maintaining compliance and data breach reporting – ATO Digital Service Provider (DSP) Operational Security Framework

8 controls
Controls in the Registration, maintaining compliance and data breach reporting – ATO Digital Service Provider (DSP) Operational Security Framework domain of ATO Digital Service Provider (DSP) Operational Security Framework — 8 controls
CodeTitle
ato-digital-service-provider-dsp-operational-security-framework::PROC.ANNUALAnnual assurance review
ato-digital-service-provider-dsp-operational-security-framework::PROC.BREACHReport data breaches to the ATO within one business day
ato-digital-service-provider-dsp-operational-security-framework::PROC.CHANGENotify the DPO of significant changes to the business or product
ato-digital-service-provider-dsp-operational-security-framework::PROC.HOSTEDIsolate hosted client instances and limit DSP access to support with consent
ato-digital-service-provider-dsp-operational-security-framework::PROC.PRODUCTIDKeep ATO product IDs confidential and use them only as intended
ato-digital-service-provider-dsp-operational-security-framework::PROC.REGISTERRegister, complete the OSF questionnaire and evidence every control
ato-digital-service-provider-dsp-operational-security-framework::PROC.SSPDescribe the sending service provider model and value chain
ato-digital-service-provider-dsp-operational-security-framework::PROC.TRUEGive the ATO true and correct information and keep details current

Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

15 controls
Controls in the Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework domain of ATO Digital Service Provider (DSP) Operational Security Framework — 15 controls
CodeTitle
ato-digital-service-provider-dsp-operational-security-framework::SEC.ADDONReasonable care over third-party add-on partners
ato-digital-service-provider-dsp-operational-security-framework::SEC.AUDITAudit logging of user access and actions, kept 12 months
ato-digital-service-provider-dsp-operational-security-framework::SEC.AUTH.MFAMulti-factor authentication for all staff and end users (DSP-controlled products)
ato-digital-service-provider-dsp-operational-security-framework::SEC.AUTH.SESSIONSession, lockout, remember-me and token limits
ato-digital-service-provider-dsp-operational-security-framework::SEC.AUTH.SSOEnterprise single sign-on only on DPO advice and within set limits
ato-digital-service-provider-dsp-operational-security-framework::SEC.AUTH.UNIQUEUnique user logins, shared logins blocked
ato-digital-service-provider-dsp-operational-security-framework::SEC.EAREncryption at rest of in-scope data, or the four compensating controls
ato-digital-service-provider-dsp-operational-security-framework::SEC.EITEncryption in transit with TLS 1.3 at minimum
ato-digital-service-provider-dsp-operational-security-framework::SEC.ENTITYEntity validation of customers against an independent source
ato-digital-service-provider-dsp-operational-security-framework::SEC.HOSTOnshore data hosting with hosting provider details given to the ATO
ato-digital-service-provider-dsp-operational-security-framework::SEC.HOST.OFFSHOREOffshore hosting only by exception, after consulting the ATO
ato-digital-service-provider-dsp-operational-security-framework::SEC.KEYEncryption key management policy covering the key lifecycle
ato-digital-service-provider-dsp-operational-security-framework::SEC.MONITORSecurity monitoring at network, application and transaction layers
ato-digital-service-provider-dsp-operational-security-framework::SEC.PERSONNELPersonnel security for hiring, managing and terminating staff and contractors
ato-digital-service-provider-dsp-operational-security-framework::SEC.SUPPLYSupply chain overview with the functional role of each participant

Maps to 3 other frameworks

26 total controls
ISO 27002:2022
19 source controls mapped|20 target controls covered
73%
Australian Information Security Manual
9 source controls mapped|16 target controls covered
35%
ACSC Essential Eight
1 source controls mapped|1 target controls covered
4%

Coverage is not the same as your position

This page shows what ATO Digital Service Provider (DSP) Operational Security Framework overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is ATO Digital Service Provider (DSP) Operational Security Framework and who does it apply to?

ATO Digital Service Provider (DSP) Operational Security Framework is a compliance framework from Australia with 3 domains and 26 controls. The Australian Taxation Office's security framework for software developers whose products send tax, accounting, payroll, business registry or superannuation data to the ATO: audit logging, multi-factor authentication and session limits, onshore hosting, key management, encryption at rest and TLS 1.3 in transit, customer entity validation, personnel security, security monitoring, supply chain and add-on marketplace controls, independent certification or self-assessment by risk category, annual reviews, change notices and reporting data breaches to the ATO within one business day, as a condition of access to ATO APIs and digital services. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ATO Digital Service Provider (DSP) Operational Security Framework actually require?

ATO Digital Service Provider (DSP) Operational Security Framework has 26 controls organised across 3 domains. The largest domains are Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework (15 controls), Registration, maintaining compliance and data breach reporting – ATO Digital Service Provider (DSP) Operational Security Framework (8 controls), Certification and self-assessment – ATO Digital Service Provider (DSP) Operational Security Framework (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ATO Digital Service Provider (DSP) Operational Security Framework do I already cover?

ATO Digital Service Provider (DSP) Operational Security Framework maps to 3 other compliance frameworks. The top mapping partners are ISO 27002:2022 (73% coverage), Australian Information Security Manual (35% coverage), ACSC Essential Eight (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ATO Digital Service Provider (DSP) Operational Security Framework?

Start your ATO Digital Service Provider (DSP) Operational Security Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ATO Digital Service Provider (DSP) Operational Security Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 26 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.

Get Started Free →

Free forever — no credit card required