Protective Security Policy Framework (PSPF) Release 2026
The Australian Government's Protective Security Policy Framework as issued on 1 July 2026: the 220 mandatory requirements across governance, risk, information, technology, personnel and physical security that non-corporate Commonwealth entities report against each year and that contracts pass to suppliers, from the security plan and incident reporting to foreign ownership checks in procurement, the handling tables, system authorisation, Essential Eight Maturity Level Two, hosting and gateway certification, clearance vetting and waivers, and Security Zone certification. Every leaf read against the Release 2026 text.
Protective Security Policy Framework (PSPF) Release 2026 is a compliance framework from Australia (Commonwealth); administered by the Department of Home Affairs with 6 domains and 220 controls that map to 225 other frameworks. The largest domains are Part Five: Personnel (sections 16 to 22) – Protective Security Policy Framework (PSPF) Release 2026 (74 controls), Part Four: Technology (sections 13 to 15) – Protective Security Policy Framework (PSPF) Release 2026 (39 controls), Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026 (36 controls). Every control below carries what it requires and what an assessor expects to see.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit protectivesecurity.gov.auFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Part Five: Personnel (sections 16 to 22) – Protective Security Policy Framework (PSPF) Release 2026
| Code | Title |
|---|---|
| protective-security-policy-framework-pspf-release-2026::0116 | 0116 Ensure eligibility and suitability of personnel with access |
| protective-security-policy-framework-pspf-release-2026::0117 | 0117 Identity check to National Identity Proofing Guidelines Level 3 |
| protective-security-policy-framework-pspf-release-2026::0118 | 0118 Verify biographic information against the original record |
| protective-security-policy-framework-pspf-release-2026::0119 | 0119 Eligibility check to work in Australia and for the Government |
| protective-security-policy-framework-pspf-release-2026::0120 | 0120 Assurance of suitability and agreement to comply with protective policies |
| protective-security-policy-framework-pspf-release-2026::0121 | 0121 Complete pre-employment checks before temporary access; NV1 for TOP SECRET |
| protective-security-policy-framework-pspf-release-2026::0122 | 0122 Risk assessment decides temporary access |
| protective-security-policy-framework-pspf-release-2026::0123 | 0123 Supervise temporary access |
| protective-security-policy-framework-pspf-release-2026::0124 | 0124 Limit short-term temporary access to three months in twelve |
| protective-security-policy-framework-pspf-release-2026::0125 | 0125 AVA confirms clearance pack and no initial concerns before provisional access |
| protective-security-policy-framework-pspf-release-2026::0126 | 0126 No temporary access to caveated information except exceptionally |
| protective-security-policy-framework-pspf-release-2026::0127 | 0127 Obtain an undertaking before temporary access |
| protective-security-policy-framework-pspf-release-2026::0128 | 0128 Obtain other entities' agreement before temporary access to their material |
| protective-security-policy-framework-pspf-release-2026::0129 | 0129 Facilitate access to official information |
| protective-security-policy-framework-pspf-release-2026::0130 | 0130 Control access to systems, networks, infrastructure, devices and applications |
| protective-security-policy-framework-pspf-release-2026::0131 | 0131 Need-to-know for classified access |
| protective-security-policy-framework-pspf-release-2026::0132 | 0132 Personnel with ongoing classified access are cleared to the right level |
| protective-security-policy-framework-pspf-release-2026::0133 | 0133 Meet caveat clearance and suitability requirements |
| protective-security-policy-framework-pspf-release-2026::0134 | 0134 Unique identification, authentication and authorisation for classified systems |
| protective-security-policy-framework-pspf-release-2026::0135 | 0135 Risk-assess working in another government entity's facilities |
| protective-security-policy-framework-pspf-release-2026::0136 | 0136 Agreement managing risks of working in another entity's facilities |
| protective-security-policy-framework-pspf-release-2026::0137 | 0137 ASD approval for remote TOP SECRET access internationally |
| protective-security-policy-framework-pspf-release-2026::0138 | 0138 Risk-assess international remote work |
| protective-security-policy-framework-pspf-release-2026::0139 | 0139 No remote work where foreign extrajudicial directions apply, unless CSO-approved |
| protective-security-policy-framework-pspf-release-2026::0140 | 0140 Use AGSVA or TS-PA Vetting Authority, or vet consistently when authorised |
| protective-security-policy-framework-pspf-release-2026::0141 | 0141 Vetting personnel attain and maintain competencies |
| protective-security-policy-framework-pspf-release-2026::0142 | 0142 Set new clearance conditions before assuming sponsorship of a conditional clearance |
| protective-security-policy-framework-pspf-release-2026::0143 | 0143 Repeat exceptional business requirement and risk assessment before transferring a waived clearance |
| protective-security-policy-framework-pspf-release-2026::0144 | 0144 AVA issues clearances only when sponsored or authorised |
| protective-security-policy-framework-pspf-release-2026::0145 | 0145 Identify positions requiring a clearance and document the level |
| protective-security-policy-framework-pspf-release-2026::0146 | 0146 Everyone in an identified position holds a valid clearance |
| protective-security-policy-framework-pspf-release-2026::0147 | 0147 Confirm citizenship and complete screening before seeking a clearance |
| protective-security-policy-framework-pspf-release-2026::0148 | 0148 Exceptional business need and risk assessment before a citizenship waiver |
| protective-security-policy-framework-pspf-release-2026::0149 | 0149 Approve citizenship waivers, confirm no concurrent waiver, keep a record |
| protective-security-policy-framework-pspf-release-2026::0150 | 0150 Exceptional business need and risk assessment before a checkable background waiver |
| protective-security-policy-framework-pspf-release-2026::0151 | 0151 Approve checkable background waivers, confirm no concurrent waiver, keep a record |
| protective-security-policy-framework-pspf-release-2026::0152 | 0152 AVA informs the sponsor and clears uncheckable subjects only with a waiver copy |
| protective-security-policy-framework-pspf-release-2026::0153 | 0153 Informed consent to collect, use and disclose personal information for vetting |
| protective-security-policy-framework-pspf-release-2026::0154 | 0154 Assess integrity under the Adjudicative Standard (Baseline to PV) |
| protective-security-policy-framework-pspf-release-2026::0155 | 0155 Assess TS-PA suitability under the TS-PA Standard |
| protective-security-policy-framework-pspf-release-2026::0156 | 0156 Conduct minimum personnel security checks for the level |
| protective-security-policy-framework-pspf-release-2026::0157 | 0157 Resolve any doubt in the national interest |
| protective-security-policy-framework-pspf-release-2026::0158 | 0158 Conditional clearances: identify conditions, inform the sponsor, issue only on acceptance |
| protective-security-policy-framework-pspf-release-2026::0159 | 0159 AVA shares information of concern with the sponsor at outcome |
| protective-security-policy-framework-pspf-release-2026::0160 | 0160 Procedural fairness in adverse clearance decisions |
| protective-security-policy-framework-pspf-release-2026::0161 | 0161 AVA reviews conditional clearance conditions annually |
| protective-security-policy-framework-pspf-release-2026::0162 | 0162 AVA conducts reviews for cause |
| protective-security-policy-framework-pspf-release-2026::0163 | 0163 TS-PA Vetting Agency implements the TS-PA Standard for ongoing assessment |
| protective-security-policy-framework-pspf-release-2026::0164 | 0164 Sponsor actively manages ongoing suitability |
| protective-security-policy-framework-pspf-release-2026::0165 | 0165 Monitor conditional clearance compliance and report non-compliance |
| protective-security-policy-framework-pspf-release-2026::0166 | 0166 Monitor clearance maintenance obligations |
| protective-security-policy-framework-pspf-release-2026::0167 | 0167 Share relevant information of concern |
| protective-security-policy-framework-pspf-release-2026::0168 | 0168 Annual security check with all cleared personnel |
| protective-security-policy-framework-pspf-release-2026::0169 | 0169 Review eligibility waivers annually, before revalidation and before transfer |
| protective-security-policy-framework-pspf-release-2026::0170 | 0170 Sponsor manages TS-PA holders under the TS-PA Standard |
| protective-security-policy-framework-pspf-release-2026::0171 | 0171 AVA revalidates minimum checks |
| protective-security-policy-framework-pspf-release-2026::0172 | 0172 AVA reassesses integrity at revalidation (Baseline to PV) |
| protective-security-policy-framework-pspf-release-2026::0173 | 0173 TS-PA Authority reassesses trustworthiness at revalidation |
| protective-security-policy-framework-pspf-release-2026::0174 | 0174 AVA resolves doubt in the national interest at revalidation |
| protective-security-policy-framework-pspf-release-2026::0175 | 0175 AVA starts revalidation in time to avoid lapse |
| protective-security-policy-framework-pspf-release-2026::0176 | 0176 AVA shares concerns so the sponsor can suspend or limit access |
| protective-security-policy-framework-pspf-release-2026::0177 | 0177 Sponsor shares information of security concern with the AVA |
| protective-security-policy-framework-pspf-release-2026::0178 | 0178 AVA shares information of security concern with the sponsor |
| protective-security-policy-framework-pspf-release-2026::0179 | 0179 AVA assesses and responds to information of security concern |
| protective-security-policy-framework-pspf-release-2026::0180 | 0180 Travel briefings for NV2 and higher holders |
| protective-security-policy-framework-pspf-release-2026::0181 | 0181 Advise the CSO or CISO before adverse separations |
| protective-security-policy-framework-pspf-release-2026::0182 | 0182 Inform separating personnel of ongoing obligations and debrief cleared staff |
| protective-security-policy-framework-pspf-release-2026::0183 | 0183 Provide security information to the receiving entity on request |
| protective-security-policy-framework-pspf-release-2026::0184 | 0184 Report security concerns about transferring personnel to ASIO |
| protective-security-policy-framework-pspf-release-2026::0185 | 0185 Risk-assess when separation procedures cannot be completed |
| protective-security-policy-framework-pspf-release-2026::0186 | 0186 Withdraw access on separation or transfer |
| protective-security-policy-framework-pspf-release-2026::0187 | 0187 Advise the AVA of a clearance holder's separation and any concerns |
| protective-security-policy-framework-pspf-release-2026::0188 | 0188 AVA records clearance status changes and transfers files |
| protective-security-policy-framework-pspf-release-2026::0218 | 0218 No temporary or provisional access for waiver subjects until vetting completes |
Part Four: Technology (sections 13 to 15) – Protective Security Policy Framework (PSPF) Release 2026
| Code | Title |
|---|---|
| protective-security-policy-framework-pspf-release-2026::0084 | 0084 Apply ISM cyber security principles across the system lifecycle |
| protective-security-policy-framework-pspf-release-2026::0085 | 0085 Apply ISM controls and guidelines on a risk basis |
| protective-security-policy-framework-pspf-release-2026::0086 | 0086 Authorise each system to operate before it handles government information |
| protective-security-policy-framework-pspf-release-2026::0087 | 0087 Base authorisation decisions on the ISM risk-based approach |
| protective-security-policy-framework-pspf-release-2026::0088 | 0088 Authorise at the highest classification the system will handle |
| protective-security-policy-framework-pspf-release-2026::0089 | 0089 Register of authorised technology systems |
| protective-security-policy-framework-pspf-release-2026::0090 | 0090 Reassess authorisation on significant change |
| protective-security-policy-framework-pspf-release-2026::0093 | 0093 Apply ASD temporary mitigations to legacy IT |
| protective-security-policy-framework-pspf-release-2026::0094 | 0094 Store SECRET-and-below technology assets in the right Security Zone |
| protective-security-policy-framework-pspf-release-2026::0095 | 0095 Store TOP SECRET technology assets in SCEC racks in accredited Zone 5 |
| protective-security-policy-framework-pspf-release-2026::0096 | 0096 ASIO-T4 certify and ASD accredit outsourced catastrophic-impact facilities |
| protective-security-policy-framework-pspf-release-2026::0097 | 0097 Dispose of technology assets per the ISM |
| protective-security-policy-framework-pspf-release-2026::0098 | 0098 Cyber security strategy and uplift plan with a Zero Trust Culture |
| protective-security-policy-framework-pspf-release-2026::0099 | 0099 Essential Eight: patch applications to Maturity Level Two |
| protective-security-policy-framework-pspf-release-2026::0100 | 0100 Essential Eight: patch operating systems to Maturity Level Two |
| protective-security-policy-framework-pspf-release-2026::0101 | 0101 Essential Eight: multi-factor authentication to Maturity Level Two |
| protective-security-policy-framework-pspf-release-2026::0102 | 0102 Essential Eight: restrict administrative privileges to Maturity Level Two |
| protective-security-policy-framework-pspf-release-2026::0103 | 0103 Essential Eight: application control to Maturity Level Two |
| protective-security-policy-framework-pspf-release-2026::0104 | 0104 Essential Eight: restrict Microsoft Office macros to Maturity Level Two |
| protective-security-policy-framework-pspf-release-2026::0105 | 0105 Essential Eight: user application hardening to Maturity Level Two |
| protective-security-policy-framework-pspf-release-2026::0106 | 0106 Essential Eight: regular backups to Maturity Level Two |
| protective-security-policy-framework-pspf-release-2026::0107 | 0107 Consider and implement the remaining Strategies to Mitigate Cyber Security Incidents |
| protective-security-policy-framework-pspf-release-2026::0108 | 0108 Protective DNS or equivalent blocks known malicious endpoints |
| protective-security-policy-framework-pspf-release-2026::0109 | 0109 Use cloud providers with an IRAP assessment in the last 24 months |
| protective-security-policy-framework-pspf-release-2026::0110 | 0110 Act on IRAP recommendations on a risk basis |
| protective-security-policy-framework-pspf-release-2026::0111 | 0111 Host classified and SoGS data only with Hosting Certification Framework certified services |
| protective-security-policy-framework-pspf-release-2026::0112 | 0112 Use the Data Centre Facilities Supplies Panel |
| protective-security-policy-framework-pspf-release-2026::0114 | 0114 Use gateways with an IRAP (or ASD) assessment in the last 24 months |
| protective-security-policy-framework-pspf-release-2026::0115 | 0115 Vulnerability disclosure program |
| protective-security-policy-framework-pspf-release-2026::0211 | 0211 Technology Asset Stocktake and Technology Security Risk Management Plan |
| protective-security-policy-framework-pspf-release-2026::0212 | 0212 Newly procured cryptographic equipment and software supports approved post-quantum algorithms |
| protective-security-policy-framework-pspf-release-2026::0213 | 0213 CISO reports cyber risk to each Audit Committee meeting |
| protective-security-policy-framework-pspf-release-2026::0214 | 0214 Protect digital infrastructure with a gateway capability |
| protective-security-policy-framework-pspf-release-2026::0215 | 0215 Participate in ASD's Cyber Security Partnership Program |
| protective-security-policy-framework-pspf-release-2026::0216 | 0216 Connect to ASD's Cyber Threat Intelligence Sharing platform |
| protective-security-policy-framework-pspf-release-2026::0217 | 0217 Protect declared Systems of Government Significance |
| protective-security-policy-framework-pspf-release-2026::0221 | 0221 Apply the Commonwealth Technology Standard when authorising systems up to SECRET |
| protective-security-policy-framework-pspf-release-2026::0222 | 0222 Policy on sharing risk assessments to the Centralised Risk Sharing Capability |
| protective-security-policy-framework-pspf-release-2026::0223 | 0223 Post-quantum cryptography transition plan |
Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026
| Code | Title |
|---|---|
| protective-security-policy-framework-pspf-release-2026::0001 | 0001 Department of State supports portfolio entities |
| protective-security-policy-framework-pspf-release-2026::0002 | 0002 Comply with all Protective Security Directions |
| protective-security-policy-framework-pspf-release-2026::0003 | 0003 Technical Authority Entity provides technical advice |
| protective-security-policy-framework-pspf-release-2026::0004 | 0004 Shared Service Provider Entity supplies security services |
| protective-security-policy-framework-pspf-release-2026::0005 | 0005 Shared Service Provider Entity documents responsibilities and accountabilities |
| protective-security-policy-framework-pspf-release-2026::0006 | 0006 Accountable Authority answerable to the minister |
| protective-security-policy-framework-pspf-release-2026::0007 | 0007 Accountable Authority manages the entity's security risks |
| protective-security-policy-framework-pspf-release-2026::0008 | 0008 Appoint and empower a Chief Security Officer |
| protective-security-policy-framework-pspf-release-2026::0009 | 0009 CSO is an SES officer holding at least NV1 |
| protective-security-policy-framework-pspf-release-2026::0010 | 0010 CSO accountable to the Accountable Authority |
| protective-security-policy-framework-pspf-release-2026::0011 | 0011 Appoint a Chief Information Security Officer |
| protective-security-policy-framework-pspf-release-2026::0012 | 0012 CISO capability, experience and NV1 clearance |
| protective-security-policy-framework-pspf-release-2026::0013 | 0013 CISO accountable for cyber security risk |
| protective-security-policy-framework-pspf-release-2026::0014 | 0014 Security practitioners skilled, empowered and resourced |
| protective-security-policy-framework-pspf-release-2026::0015 | 0015 Security practitioners have access to training |
| protective-security-policy-framework-pspf-release-2026::0016 | 0016 Accountable Authority approves tailored security governance |
| protective-security-policy-framework-pspf-release-2026::0017 | 0017 Dedicated, monitored security email address |
| protective-security-policy-framework-pspf-release-2026::0018 | 0018 Develop and maintain a security plan with the mandatory elements |
| protective-security-policy-framework-pspf-release-2026::0019 | 0019 Accountable Authority approves the security plan |
| protective-security-policy-framework-pspf-release-2026::0020 | 0020 Consider the security plan annually and review it at least every two years |
| protective-security-policy-framework-pspf-release-2026::0021 | 0021 Procedures to achieve every element of the security plan |
| protective-security-policy-framework-pspf-release-2026::0022 | 0022 Security monitoring and continuous improvement |
| protective-security-policy-framework-pspf-release-2026::0023 | 0023 Positive security culture program |
| protective-security-policy-framework-pspf-release-2026::0024 | 0024 Security awareness training at engagement and annually |
| protective-security-policy-framework-pspf-release-2026::0025 | 0025 Targeted training for specialist or high-risk positions |
| protective-security-policy-framework-pspf-release-2026::0026 | 0026 Procedures to respond to and manage security incidents |
| protective-security-policy-framework-pspf-release-2026::0027 | 0027 Incident response plans in business continuity arrangements |
| protective-security-policy-framework-pspf-release-2026::0028 | 0028 Report significant and externally reportable incidents within timeframes |
| protective-security-policy-framework-pspf-release-2026::0029 | 0029 Investigate incidents under the Australian Government Investigations Standards |
| protective-security-policy-framework-pspf-release-2026::0030 | 0030 Procedural fairness in security investigations |
| protective-security-policy-framework-pspf-release-2026::0031 | 0031 Provide the annual protective security report to the minister |
| protective-security-policy-framework-pspf-release-2026::0032 | 0032 Submit the annual protective security report to Home Affairs |
| protective-security-policy-framework-pspf-release-2026::0033 | 0033 Accountable Authority approves and verifies the annual report |
| protective-security-policy-framework-pspf-release-2026::0034 | 0034 Cooperate with Home Affairs assurance activities |
| protective-security-policy-framework-pspf-release-2026::0035 | 0035 Submit the annual Cyber Security Survey to ASD |
| protective-security-policy-framework-pspf-release-2026::0219 | 0219 Training covers foreign interference, espionage, cultivation and exploitation |
Part Six: Physical (sections 23 to 25) – Protective Security Policy Framework (PSPF) Release 2026
| Code | Title |
|---|---|
| protective-security-policy-framework-pspf-release-2026::0189 | 0189 Integrate protective security in facility planning, selection, design and modification |
| protective-security-policy-framework-pspf-release-2026::0190 | 0190 Facility security plan for new, under-construction or refurbished facilities |
| protective-security-policy-framework-pspf-release-2026::0191 | 0191 Site selection informed by the site selection factors |
| protective-security-policy-framework-pspf-release-2026::0192 | 0192 Design access control to meet Security Zone definitions |
| protective-security-policy-framework-pspf-release-2026::0193 | 0193 Construct facilities to ASIO Technical Notes for public and non-classified areas |
| protective-security-policy-framework-pspf-release-2026::0194 | 0194 Construct Zones Two to Five to ASIO Technical Notes 1/15 and 5/12 |
| protective-security-policy-framework-pspf-release-2026::0195 | 0195 Operate and maintain facilities per Security Zones and measures |
| protective-security-policy-framework-pspf-release-2026::0196 | 0196 Certify Zones One to Four before operational use |
| protective-security-policy-framework-pspf-release-2026::0197 | 0197 ASIO-T4 certifies Zone Five TOP SECRET or catastrophic-aggregation areas |
| protective-security-policy-framework-pspf-release-2026::0198 | 0198 Accredit Zones One to Five before operational use |
| protective-security-policy-framework-pspf-release-2026::0199 | 0199 ASD accredits SCIFs under the National SCIF Accreditation Program |
| protective-security-policy-framework-pspf-release-2026::0200 | 0200 Physical measures against loss of availability and unauthorised access or removal |
| protective-security-policy-framework-pspf-release-2026::0201 | 0201 Physical measures commensurate with business impact level |
| protective-security-policy-framework-pspf-release-2026::0202 | 0202 Physical measures against harm to people |
| protective-security-policy-framework-pspf-release-2026::0203 | 0203 Use the appropriate container, safe, vault or room |
| protective-security-policy-framework-pspf-release-2026::0204 | 0204 Perimeter doors and hardware to Table 43 |
| protective-security-policy-framework-pspf-release-2026::0205 | 0205 Control personnel, vehicle and equipment access to Zones One to Five per Table 44 |
| protective-security-policy-framework-pspf-release-2026::0206 | 0206 Control visitor access per Table 45 |
| protective-security-policy-framework-pspf-release-2026::0207 | 0207 Approve ongoing third-party access with clearance and a business case |
| protective-security-policy-framework-pspf-release-2026::0208 | 0208 Security alarm systems per Table 46 |
| protective-security-policy-framework-pspf-release-2026::0209 | 0209 Security guard arrangements per Table 47 |
| protective-security-policy-framework-pspf-release-2026::0210 | 0210 Technical surveillance countermeasures per Table 48 |
Part Three: Information (sections 9 to 12) – Protective Security Policy Framework (PSPF) Release 2026
| Code | Title |
|---|---|
| protective-security-policy-framework-pspf-release-2026::0058 | 0058 Originator controls sanitisation, reclassification and declassification |
| protective-security-policy-framework-pspf-release-2026::0059 | 0059 Assess value, importance and sensitivity by potential damage |
| protective-security-policy-framework-pspf-release-2026::0060 | 0060 Classify at the lowest reasonable level |
| protective-security-policy-framework-pspf-release-2026::0061 | 0061 Mark classified information with text-based markings |
| protective-security-policy-framework-pspf-release-2026::0062 | 0062 Apply the minimum protections and handling requirements |
| protective-security-policy-framework-pspf-release-2026::0063 | 0063 Apply the Security Caveat Standard and controlling authority requirements |
| protective-security-policy-framework-pspf-release-2026::0064 | 0064 Mark caveats as text with a classification |
| protective-security-policy-framework-pspf-release-2026::0065 | 0065 Page and reference numbering on accountable material |
| protective-security-policy-framework-pspf-release-2026::0066 | 0066 Handle accountable material per originator and caveat owner requirements |
| protective-security-policy-framework-pspf-release-2026::0067 | 0067 Apply the Email Protective Marking Standard |
| protective-security-policy-framework-pspf-release-2026::0068 | 0068 Apply the Recordkeeping Metadata Standard classification sub-property |
| protective-security-policy-framework-pspf-release-2026::0069 | 0069 Apply the metadata Rights property where restrictions are categorised |
| protective-security-policy-framework-pspf-release-2026::0070 | 0070 Hold classified discussions only in approved locations |
| protective-security-policy-framework-pspf-release-2026::0071 | 0071 Operational controls for information holdings proportional to value |
| protective-security-policy-framework-pspf-release-2026::0072 | 0072 Auditable register for TOP SECRET and accountable material |
| protective-security-policy-framework-pspf-release-2026::0073 | 0073 Dispose of information securely |
| protective-security-policy-framework-pspf-release-2026::0074 | 0074 Destroy classified information when retention ends |
| protective-security-policy-framework-pspf-release-2026::0075 | 0075 Share classified information outside the entity only with clearance and need-to-know |
| protective-security-policy-framework-pspf-release-2026::0076 | 0076 Apply the Commonwealth-State MOU when sharing with states and territories |
| protective-security-policy-framework-pspf-release-2026::0077 | 0077 Agreement in place before sharing classified information outside government |
| protective-security-policy-framework-pspf-release-2026::0078 | 0078 Meet provisions of international agreements and arrangements |
| protective-security-policy-framework-pspf-release-2026::0079 | 0079 Share classified information with foreign entities only under a legal provision, agreement or arrangement |
| protective-security-policy-framework-pspf-release-2026::0080 | 0080 Never share AUSTEO with non-citizens without an exemption |
| protective-security-policy-framework-pspf-release-2026::0081 | 0081 Share AGAO only with citizens or listed-entity secondees |
| protective-security-policy-framework-pspf-release-2026::0082 | 0082 Safeguard foreign classified information per the agreement |
| protective-security-policy-framework-pspf-release-2026::0083 | 0083 Share with foreign non-government stakeholders only under a legal basis |
Part Two: Risk (sections 5 to 8) – Protective Security Policy Framework (PSPF) Release 2026
| Code | Title |
|---|---|
| protective-security-policy-framework-pspf-release-2026::0036 | 0036 Determine and document security risk tolerance |
| protective-security-policy-framework-pspf-release-2026::0037 | 0037 Risk steward for each security risk, including shared risks |
| protective-security-policy-framework-pspf-release-2026::0038 | 0038 Consider impacts of risk decisions on other entities and share risk information |
| protective-security-policy-framework-pspf-release-2026::0039 | 0039 Manage security risks from procurement |
| protective-security-policy-framework-pspf-release-2026::0040 | 0040 Proportionate security terms in contracts and outsourcing |
| protective-security-policy-framework-pspf-release-2026::0041 | 0041 Ensure providers and subcontractors comply with relevant PSPF requirements |
| protective-security-policy-framework-pspf-release-2026::0042 | 0042 Contracts require incident reporting and compliance with directions |
| protective-security-policy-framework-pspf-release-2026::0043 | 0043 Government service providers share IRAP reports |
| protective-security-policy-framework-pspf-release-2026::0044 | 0044 Monitor contract security terms over the contract life |
| protective-security-policy-framework-pspf-release-2026::0045 | 0045 Security arrangements for contract completion or termination |
| protective-security-policy-framework-pspf-release-2026::0046 | 0046 Consider foreign ownership, control or influence risks in procurement |
| protective-security-policy-framework-pspf-release-2026::0047 | 0047 Manage and reassess contractual security risk over the contract life |
| protective-security-policy-framework-pspf-release-2026::0048 | 0048 Use secure and verifiable vendors; CISO approves residual risk |
| protective-security-policy-framework-pspf-release-2026::0049 | 0049 Manage security risks of engaging with foreign partners |
| protective-security-policy-framework-pspf-release-2026::0050 | 0050 Personnel do not publicise their security clearance online |
| protective-security-policy-framework-pspf-release-2026::0051 | 0051 Insider threat program for entities managing Baseline to PV clearance subjects |
| protective-security-policy-framework-pspf-release-2026::0052 | 0052 Vary application in exceptional circumstances |
| protective-security-policy-framework-pspf-release-2026::0053 | 0053 Document variations in the security plan |
| protective-security-policy-framework-pspf-release-2026::0054 | 0054 Review and report alternative mitigations annually |
| protective-security-policy-framework-pspf-release-2026::0055 | 0055 Business continuity plan for critical services and assets |
| protective-security-policy-framework-pspf-release-2026::0056 | 0056 Emergency plans integrated in business continuity |
| protective-security-policy-framework-pspf-release-2026::0057 | 0057 Notify personnel of heightened emergency risk |
| protective-security-policy-framework-pspf-release-2026::0220 | 0220 Policy prohibiting online publication of clearance information |
Your Compliance Coverage
If you comply with Protective Security Policy Framework (PSPF) Release 2026, you already cover:
API 1164
2%
4 controls mapped
Compare →Annex 11 to EU GMP - Computerised Systems
2%
4 controls mapped
Compare →ISO/IEC 27010:2015
2%
4 controls mapped
Compare →+ 222 more: ISO/IEC 27011:2024 (2%), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (2%)
See all 225 mapped frameworks ↓Maps to 225 other frameworks
Coverage is not the same as your position
This page shows what Protective Security Policy Framework (PSPF) Release 2026 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is Protective Security Policy Framework (PSPF) Release 2026 and who does it apply to?
Protective Security Policy Framework (PSPF) Release 2026 is a compliance framework from Australia (Commonwealth); administered by the Department of Home Affairs with 6 domains and 220 controls. The Australian Government's Protective Security Policy Framework as issued on 1 July 2026: the 220 mandatory requirements across governance, risk, information, technology, personnel and physical security that non-corporate Commonwealth entities report against each year and that contracts pass to suppliers, from the security plan and incident reporting to foreign ownership checks in procurement, the handling tables, system authorisation, Essential Eight Maturity Level Two, hosting and gateway certification, clearance vetting and waivers, and Security Zone certification. Every leaf read against the Release 2026 text. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Protective Security Policy Framework (PSPF) Release 2026 actually require?
Protective Security Policy Framework (PSPF) Release 2026 has 220 controls organised across 6 domains. The largest domains are Part Five: Personnel (sections 16 to 22) – Protective Security Policy Framework (PSPF) Release 2026 (74 controls), Part Four: Technology (sections 13 to 15) – Protective Security Policy Framework (PSPF) Release 2026 (39 controls), Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026 (36 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Protective Security Policy Framework (PSPF) Release 2026 do I already cover?
Protective Security Policy Framework (PSPF) Release 2026 maps to 225 other compliance frameworks. The top mapping partners are API 1164 (2% coverage), Annex 11 to EU GMP - Computerised Systems (2% coverage), ISO/IEC 27010:2015 (2% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Protective Security Policy Framework (PSPF) Release 2026?
Start your Protective Security Policy Framework (PSPF) Release 2026 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Protective Security Policy Framework (PSPF) Release 2026 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 220 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 703 frameworks.
Get Started Free →Free forever — no credit card required