Back to Frameworks

Protective Security Policy Framework (PSPF) Release 2026

Australia (Commonwealth); administered by the Department of Home Affairs
vRelease 2026 (issued 1 July 2026); supersedes Release 2025 (1 July 2025) and Release 2024 (31 October 2024)
6 domains
220 controls

The Australian Government's Protective Security Policy Framework as issued on 1 July 2026: the 220 mandatory requirements across governance, risk, information, technology, personnel and physical security that non-corporate Commonwealth entities report against each year and that contracts pass to suppliers, from the security plan and incident reporting to foreign ownership checks in procurement, the handling tables, system authorisation, Essential Eight Maturity Level Two, hosting and gateway certification, clearance vetting and waivers, and Security Zone certification. Every leaf read against the Release 2026 text.

Verified

Protective Security Policy Framework (PSPF) Release 2026 is a compliance framework from Australia (Commonwealth); administered by the Department of Home Affairs with 6 domains and 220 controls that map to 225 other frameworks. The largest domains are Part Five: Personnel (sections 16 to 22) – Protective Security Policy Framework (PSPF) Release 2026 (74 controls), Part Four: Technology (sections 13 to 15) – Protective Security Policy Framework (PSPF) Release 2026 (39 controls), Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026 (36 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated Published standard

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit protectivesecurity.gov.au

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Part Five: Personnel (sections 16 to 22) – Protective Security Policy Framework (PSPF) Release 2026

74 controls
Controls in the Part Five: Personnel (sections 16 to 22) – Protective Security Policy Framework (PSPF) Release 2026 domain of Protective Security Policy Framework (PSPF) Release 2026 — 74 controls
CodeTitle
protective-security-policy-framework-pspf-release-2026::01160116 Ensure eligibility and suitability of personnel with access
protective-security-policy-framework-pspf-release-2026::01170117 Identity check to National Identity Proofing Guidelines Level 3
protective-security-policy-framework-pspf-release-2026::01180118 Verify biographic information against the original record
protective-security-policy-framework-pspf-release-2026::01190119 Eligibility check to work in Australia and for the Government
protective-security-policy-framework-pspf-release-2026::01200120 Assurance of suitability and agreement to comply with protective policies
protective-security-policy-framework-pspf-release-2026::01210121 Complete pre-employment checks before temporary access; NV1 for TOP SECRET
protective-security-policy-framework-pspf-release-2026::01220122 Risk assessment decides temporary access
protective-security-policy-framework-pspf-release-2026::01230123 Supervise temporary access
protective-security-policy-framework-pspf-release-2026::01240124 Limit short-term temporary access to three months in twelve
protective-security-policy-framework-pspf-release-2026::01250125 AVA confirms clearance pack and no initial concerns before provisional access
protective-security-policy-framework-pspf-release-2026::01260126 No temporary access to caveated information except exceptionally
protective-security-policy-framework-pspf-release-2026::01270127 Obtain an undertaking before temporary access
protective-security-policy-framework-pspf-release-2026::01280128 Obtain other entities' agreement before temporary access to their material
protective-security-policy-framework-pspf-release-2026::01290129 Facilitate access to official information
protective-security-policy-framework-pspf-release-2026::01300130 Control access to systems, networks, infrastructure, devices and applications
protective-security-policy-framework-pspf-release-2026::01310131 Need-to-know for classified access
protective-security-policy-framework-pspf-release-2026::01320132 Personnel with ongoing classified access are cleared to the right level
protective-security-policy-framework-pspf-release-2026::01330133 Meet caveat clearance and suitability requirements
protective-security-policy-framework-pspf-release-2026::01340134 Unique identification, authentication and authorisation for classified systems
protective-security-policy-framework-pspf-release-2026::01350135 Risk-assess working in another government entity's facilities
protective-security-policy-framework-pspf-release-2026::01360136 Agreement managing risks of working in another entity's facilities
protective-security-policy-framework-pspf-release-2026::01370137 ASD approval for remote TOP SECRET access internationally
protective-security-policy-framework-pspf-release-2026::01380138 Risk-assess international remote work
protective-security-policy-framework-pspf-release-2026::01390139 No remote work where foreign extrajudicial directions apply, unless CSO-approved
protective-security-policy-framework-pspf-release-2026::01400140 Use AGSVA or TS-PA Vetting Authority, or vet consistently when authorised
protective-security-policy-framework-pspf-release-2026::01410141 Vetting personnel attain and maintain competencies
protective-security-policy-framework-pspf-release-2026::01420142 Set new clearance conditions before assuming sponsorship of a conditional clearance
protective-security-policy-framework-pspf-release-2026::01430143 Repeat exceptional business requirement and risk assessment before transferring a waived clearance
protective-security-policy-framework-pspf-release-2026::01440144 AVA issues clearances only when sponsored or authorised
protective-security-policy-framework-pspf-release-2026::01450145 Identify positions requiring a clearance and document the level
protective-security-policy-framework-pspf-release-2026::01460146 Everyone in an identified position holds a valid clearance
protective-security-policy-framework-pspf-release-2026::01470147 Confirm citizenship and complete screening before seeking a clearance
protective-security-policy-framework-pspf-release-2026::01480148 Exceptional business need and risk assessment before a citizenship waiver
protective-security-policy-framework-pspf-release-2026::01490149 Approve citizenship waivers, confirm no concurrent waiver, keep a record
protective-security-policy-framework-pspf-release-2026::01500150 Exceptional business need and risk assessment before a checkable background waiver
protective-security-policy-framework-pspf-release-2026::01510151 Approve checkable background waivers, confirm no concurrent waiver, keep a record
protective-security-policy-framework-pspf-release-2026::01520152 AVA informs the sponsor and clears uncheckable subjects only with a waiver copy
protective-security-policy-framework-pspf-release-2026::01530153 Informed consent to collect, use and disclose personal information for vetting
protective-security-policy-framework-pspf-release-2026::01540154 Assess integrity under the Adjudicative Standard (Baseline to PV)
protective-security-policy-framework-pspf-release-2026::01550155 Assess TS-PA suitability under the TS-PA Standard
protective-security-policy-framework-pspf-release-2026::01560156 Conduct minimum personnel security checks for the level
protective-security-policy-framework-pspf-release-2026::01570157 Resolve any doubt in the national interest
protective-security-policy-framework-pspf-release-2026::01580158 Conditional clearances: identify conditions, inform the sponsor, issue only on acceptance
protective-security-policy-framework-pspf-release-2026::01590159 AVA shares information of concern with the sponsor at outcome
protective-security-policy-framework-pspf-release-2026::01600160 Procedural fairness in adverse clearance decisions
protective-security-policy-framework-pspf-release-2026::01610161 AVA reviews conditional clearance conditions annually
protective-security-policy-framework-pspf-release-2026::01620162 AVA conducts reviews for cause
protective-security-policy-framework-pspf-release-2026::01630163 TS-PA Vetting Agency implements the TS-PA Standard for ongoing assessment
protective-security-policy-framework-pspf-release-2026::01640164 Sponsor actively manages ongoing suitability
protective-security-policy-framework-pspf-release-2026::01650165 Monitor conditional clearance compliance and report non-compliance
protective-security-policy-framework-pspf-release-2026::01660166 Monitor clearance maintenance obligations
protective-security-policy-framework-pspf-release-2026::01670167 Share relevant information of concern
protective-security-policy-framework-pspf-release-2026::01680168 Annual security check with all cleared personnel
protective-security-policy-framework-pspf-release-2026::01690169 Review eligibility waivers annually, before revalidation and before transfer
protective-security-policy-framework-pspf-release-2026::01700170 Sponsor manages TS-PA holders under the TS-PA Standard
protective-security-policy-framework-pspf-release-2026::01710171 AVA revalidates minimum checks
protective-security-policy-framework-pspf-release-2026::01720172 AVA reassesses integrity at revalidation (Baseline to PV)
protective-security-policy-framework-pspf-release-2026::01730173 TS-PA Authority reassesses trustworthiness at revalidation
protective-security-policy-framework-pspf-release-2026::01740174 AVA resolves doubt in the national interest at revalidation
protective-security-policy-framework-pspf-release-2026::01750175 AVA starts revalidation in time to avoid lapse
protective-security-policy-framework-pspf-release-2026::01760176 AVA shares concerns so the sponsor can suspend or limit access
protective-security-policy-framework-pspf-release-2026::01770177 Sponsor shares information of security concern with the AVA
protective-security-policy-framework-pspf-release-2026::01780178 AVA shares information of security concern with the sponsor
protective-security-policy-framework-pspf-release-2026::01790179 AVA assesses and responds to information of security concern
protective-security-policy-framework-pspf-release-2026::01800180 Travel briefings for NV2 and higher holders
protective-security-policy-framework-pspf-release-2026::01810181 Advise the CSO or CISO before adverse separations
protective-security-policy-framework-pspf-release-2026::01820182 Inform separating personnel of ongoing obligations and debrief cleared staff
protective-security-policy-framework-pspf-release-2026::01830183 Provide security information to the receiving entity on request
protective-security-policy-framework-pspf-release-2026::01840184 Report security concerns about transferring personnel to ASIO
protective-security-policy-framework-pspf-release-2026::01850185 Risk-assess when separation procedures cannot be completed
protective-security-policy-framework-pspf-release-2026::01860186 Withdraw access on separation or transfer
protective-security-policy-framework-pspf-release-2026::01870187 Advise the AVA of a clearance holder's separation and any concerns
protective-security-policy-framework-pspf-release-2026::01880188 AVA records clearance status changes and transfers files
protective-security-policy-framework-pspf-release-2026::02180218 No temporary or provisional access for waiver subjects until vetting completes

Part Four: Technology (sections 13 to 15) – Protective Security Policy Framework (PSPF) Release 2026

39 controls
Controls in the Part Four: Technology (sections 13 to 15) – Protective Security Policy Framework (PSPF) Release 2026 domain of Protective Security Policy Framework (PSPF) Release 2026 — 39 controls
CodeTitle
protective-security-policy-framework-pspf-release-2026::00840084 Apply ISM cyber security principles across the system lifecycle
protective-security-policy-framework-pspf-release-2026::00850085 Apply ISM controls and guidelines on a risk basis
protective-security-policy-framework-pspf-release-2026::00860086 Authorise each system to operate before it handles government information
protective-security-policy-framework-pspf-release-2026::00870087 Base authorisation decisions on the ISM risk-based approach
protective-security-policy-framework-pspf-release-2026::00880088 Authorise at the highest classification the system will handle
protective-security-policy-framework-pspf-release-2026::00890089 Register of authorised technology systems
protective-security-policy-framework-pspf-release-2026::00900090 Reassess authorisation on significant change
protective-security-policy-framework-pspf-release-2026::00930093 Apply ASD temporary mitigations to legacy IT
protective-security-policy-framework-pspf-release-2026::00940094 Store SECRET-and-below technology assets in the right Security Zone
protective-security-policy-framework-pspf-release-2026::00950095 Store TOP SECRET technology assets in SCEC racks in accredited Zone 5
protective-security-policy-framework-pspf-release-2026::00960096 ASIO-T4 certify and ASD accredit outsourced catastrophic-impact facilities
protective-security-policy-framework-pspf-release-2026::00970097 Dispose of technology assets per the ISM
protective-security-policy-framework-pspf-release-2026::00980098 Cyber security strategy and uplift plan with a Zero Trust Culture
protective-security-policy-framework-pspf-release-2026::00990099 Essential Eight: patch applications to Maturity Level Two
protective-security-policy-framework-pspf-release-2026::01000100 Essential Eight: patch operating systems to Maturity Level Two
protective-security-policy-framework-pspf-release-2026::01010101 Essential Eight: multi-factor authentication to Maturity Level Two
protective-security-policy-framework-pspf-release-2026::01020102 Essential Eight: restrict administrative privileges to Maturity Level Two
protective-security-policy-framework-pspf-release-2026::01030103 Essential Eight: application control to Maturity Level Two
protective-security-policy-framework-pspf-release-2026::01040104 Essential Eight: restrict Microsoft Office macros to Maturity Level Two
protective-security-policy-framework-pspf-release-2026::01050105 Essential Eight: user application hardening to Maturity Level Two
protective-security-policy-framework-pspf-release-2026::01060106 Essential Eight: regular backups to Maturity Level Two
protective-security-policy-framework-pspf-release-2026::01070107 Consider and implement the remaining Strategies to Mitigate Cyber Security Incidents
protective-security-policy-framework-pspf-release-2026::01080108 Protective DNS or equivalent blocks known malicious endpoints
protective-security-policy-framework-pspf-release-2026::01090109 Use cloud providers with an IRAP assessment in the last 24 months
protective-security-policy-framework-pspf-release-2026::01100110 Act on IRAP recommendations on a risk basis
protective-security-policy-framework-pspf-release-2026::01110111 Host classified and SoGS data only with Hosting Certification Framework certified services
protective-security-policy-framework-pspf-release-2026::01120112 Use the Data Centre Facilities Supplies Panel
protective-security-policy-framework-pspf-release-2026::01140114 Use gateways with an IRAP (or ASD) assessment in the last 24 months
protective-security-policy-framework-pspf-release-2026::01150115 Vulnerability disclosure program
protective-security-policy-framework-pspf-release-2026::02110211 Technology Asset Stocktake and Technology Security Risk Management Plan
protective-security-policy-framework-pspf-release-2026::02120212 Newly procured cryptographic equipment and software supports approved post-quantum algorithms
protective-security-policy-framework-pspf-release-2026::02130213 CISO reports cyber risk to each Audit Committee meeting
protective-security-policy-framework-pspf-release-2026::02140214 Protect digital infrastructure with a gateway capability
protective-security-policy-framework-pspf-release-2026::02150215 Participate in ASD's Cyber Security Partnership Program
protective-security-policy-framework-pspf-release-2026::02160216 Connect to ASD's Cyber Threat Intelligence Sharing platform
protective-security-policy-framework-pspf-release-2026::02170217 Protect declared Systems of Government Significance
protective-security-policy-framework-pspf-release-2026::02210221 Apply the Commonwealth Technology Standard when authorising systems up to SECRET
protective-security-policy-framework-pspf-release-2026::02220222 Policy on sharing risk assessments to the Centralised Risk Sharing Capability
protective-security-policy-framework-pspf-release-2026::02230223 Post-quantum cryptography transition plan

Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026

36 controls
Controls in the Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026 domain of Protective Security Policy Framework (PSPF) Release 2026 — 36 controls
CodeTitle
protective-security-policy-framework-pspf-release-2026::00010001 Department of State supports portfolio entities
protective-security-policy-framework-pspf-release-2026::00020002 Comply with all Protective Security Directions
protective-security-policy-framework-pspf-release-2026::00030003 Technical Authority Entity provides technical advice
protective-security-policy-framework-pspf-release-2026::00040004 Shared Service Provider Entity supplies security services
protective-security-policy-framework-pspf-release-2026::00050005 Shared Service Provider Entity documents responsibilities and accountabilities
protective-security-policy-framework-pspf-release-2026::00060006 Accountable Authority answerable to the minister
protective-security-policy-framework-pspf-release-2026::00070007 Accountable Authority manages the entity's security risks
protective-security-policy-framework-pspf-release-2026::00080008 Appoint and empower a Chief Security Officer
protective-security-policy-framework-pspf-release-2026::00090009 CSO is an SES officer holding at least NV1
protective-security-policy-framework-pspf-release-2026::00100010 CSO accountable to the Accountable Authority
protective-security-policy-framework-pspf-release-2026::00110011 Appoint a Chief Information Security Officer
protective-security-policy-framework-pspf-release-2026::00120012 CISO capability, experience and NV1 clearance
protective-security-policy-framework-pspf-release-2026::00130013 CISO accountable for cyber security risk
protective-security-policy-framework-pspf-release-2026::00140014 Security practitioners skilled, empowered and resourced
protective-security-policy-framework-pspf-release-2026::00150015 Security practitioners have access to training
protective-security-policy-framework-pspf-release-2026::00160016 Accountable Authority approves tailored security governance
protective-security-policy-framework-pspf-release-2026::00170017 Dedicated, monitored security email address
protective-security-policy-framework-pspf-release-2026::00180018 Develop and maintain a security plan with the mandatory elements
protective-security-policy-framework-pspf-release-2026::00190019 Accountable Authority approves the security plan
protective-security-policy-framework-pspf-release-2026::00200020 Consider the security plan annually and review it at least every two years
protective-security-policy-framework-pspf-release-2026::00210021 Procedures to achieve every element of the security plan
protective-security-policy-framework-pspf-release-2026::00220022 Security monitoring and continuous improvement
protective-security-policy-framework-pspf-release-2026::00230023 Positive security culture program
protective-security-policy-framework-pspf-release-2026::00240024 Security awareness training at engagement and annually
protective-security-policy-framework-pspf-release-2026::00250025 Targeted training for specialist or high-risk positions
protective-security-policy-framework-pspf-release-2026::00260026 Procedures to respond to and manage security incidents
protective-security-policy-framework-pspf-release-2026::00270027 Incident response plans in business continuity arrangements
protective-security-policy-framework-pspf-release-2026::00280028 Report significant and externally reportable incidents within timeframes
protective-security-policy-framework-pspf-release-2026::00290029 Investigate incidents under the Australian Government Investigations Standards
protective-security-policy-framework-pspf-release-2026::00300030 Procedural fairness in security investigations
protective-security-policy-framework-pspf-release-2026::00310031 Provide the annual protective security report to the minister
protective-security-policy-framework-pspf-release-2026::00320032 Submit the annual protective security report to Home Affairs
protective-security-policy-framework-pspf-release-2026::00330033 Accountable Authority approves and verifies the annual report
protective-security-policy-framework-pspf-release-2026::00340034 Cooperate with Home Affairs assurance activities
protective-security-policy-framework-pspf-release-2026::00350035 Submit the annual Cyber Security Survey to ASD
protective-security-policy-framework-pspf-release-2026::02190219 Training covers foreign interference, espionage, cultivation and exploitation

Part Six: Physical (sections 23 to 25) – Protective Security Policy Framework (PSPF) Release 2026

22 controls
Controls in the Part Six: Physical (sections 23 to 25) – Protective Security Policy Framework (PSPF) Release 2026 domain of Protective Security Policy Framework (PSPF) Release 2026 — 22 controls
CodeTitle
protective-security-policy-framework-pspf-release-2026::01890189 Integrate protective security in facility planning, selection, design and modification
protective-security-policy-framework-pspf-release-2026::01900190 Facility security plan for new, under-construction or refurbished facilities
protective-security-policy-framework-pspf-release-2026::01910191 Site selection informed by the site selection factors
protective-security-policy-framework-pspf-release-2026::01920192 Design access control to meet Security Zone definitions
protective-security-policy-framework-pspf-release-2026::01930193 Construct facilities to ASIO Technical Notes for public and non-classified areas
protective-security-policy-framework-pspf-release-2026::01940194 Construct Zones Two to Five to ASIO Technical Notes 1/15 and 5/12
protective-security-policy-framework-pspf-release-2026::01950195 Operate and maintain facilities per Security Zones and measures
protective-security-policy-framework-pspf-release-2026::01960196 Certify Zones One to Four before operational use
protective-security-policy-framework-pspf-release-2026::01970197 ASIO-T4 certifies Zone Five TOP SECRET or catastrophic-aggregation areas
protective-security-policy-framework-pspf-release-2026::01980198 Accredit Zones One to Five before operational use
protective-security-policy-framework-pspf-release-2026::01990199 ASD accredits SCIFs under the National SCIF Accreditation Program
protective-security-policy-framework-pspf-release-2026::02000200 Physical measures against loss of availability and unauthorised access or removal
protective-security-policy-framework-pspf-release-2026::02010201 Physical measures commensurate with business impact level
protective-security-policy-framework-pspf-release-2026::02020202 Physical measures against harm to people
protective-security-policy-framework-pspf-release-2026::02030203 Use the appropriate container, safe, vault or room
protective-security-policy-framework-pspf-release-2026::02040204 Perimeter doors and hardware to Table 43
protective-security-policy-framework-pspf-release-2026::02050205 Control personnel, vehicle and equipment access to Zones One to Five per Table 44
protective-security-policy-framework-pspf-release-2026::02060206 Control visitor access per Table 45
protective-security-policy-framework-pspf-release-2026::02070207 Approve ongoing third-party access with clearance and a business case
protective-security-policy-framework-pspf-release-2026::02080208 Security alarm systems per Table 46
protective-security-policy-framework-pspf-release-2026::02090209 Security guard arrangements per Table 47
protective-security-policy-framework-pspf-release-2026::02100210 Technical surveillance countermeasures per Table 48

Part Three: Information (sections 9 to 12) – Protective Security Policy Framework (PSPF) Release 2026

26 controls
Controls in the Part Three: Information (sections 9 to 12) – Protective Security Policy Framework (PSPF) Release 2026 domain of Protective Security Policy Framework (PSPF) Release 2026 — 26 controls
CodeTitle
protective-security-policy-framework-pspf-release-2026::00580058 Originator controls sanitisation, reclassification and declassification
protective-security-policy-framework-pspf-release-2026::00590059 Assess value, importance and sensitivity by potential damage
protective-security-policy-framework-pspf-release-2026::00600060 Classify at the lowest reasonable level
protective-security-policy-framework-pspf-release-2026::00610061 Mark classified information with text-based markings
protective-security-policy-framework-pspf-release-2026::00620062 Apply the minimum protections and handling requirements
protective-security-policy-framework-pspf-release-2026::00630063 Apply the Security Caveat Standard and controlling authority requirements
protective-security-policy-framework-pspf-release-2026::00640064 Mark caveats as text with a classification
protective-security-policy-framework-pspf-release-2026::00650065 Page and reference numbering on accountable material
protective-security-policy-framework-pspf-release-2026::00660066 Handle accountable material per originator and caveat owner requirements
protective-security-policy-framework-pspf-release-2026::00670067 Apply the Email Protective Marking Standard
protective-security-policy-framework-pspf-release-2026::00680068 Apply the Recordkeeping Metadata Standard classification sub-property
protective-security-policy-framework-pspf-release-2026::00690069 Apply the metadata Rights property where restrictions are categorised
protective-security-policy-framework-pspf-release-2026::00700070 Hold classified discussions only in approved locations
protective-security-policy-framework-pspf-release-2026::00710071 Operational controls for information holdings proportional to value
protective-security-policy-framework-pspf-release-2026::00720072 Auditable register for TOP SECRET and accountable material
protective-security-policy-framework-pspf-release-2026::00730073 Dispose of information securely
protective-security-policy-framework-pspf-release-2026::00740074 Destroy classified information when retention ends
protective-security-policy-framework-pspf-release-2026::00750075 Share classified information outside the entity only with clearance and need-to-know
protective-security-policy-framework-pspf-release-2026::00760076 Apply the Commonwealth-State MOU when sharing with states and territories
protective-security-policy-framework-pspf-release-2026::00770077 Agreement in place before sharing classified information outside government
protective-security-policy-framework-pspf-release-2026::00780078 Meet provisions of international agreements and arrangements
protective-security-policy-framework-pspf-release-2026::00790079 Share classified information with foreign entities only under a legal provision, agreement or arrangement
protective-security-policy-framework-pspf-release-2026::00800080 Never share AUSTEO with non-citizens without an exemption
protective-security-policy-framework-pspf-release-2026::00810081 Share AGAO only with citizens or listed-entity secondees
protective-security-policy-framework-pspf-release-2026::00820082 Safeguard foreign classified information per the agreement
protective-security-policy-framework-pspf-release-2026::00830083 Share with foreign non-government stakeholders only under a legal basis

Part Two: Risk (sections 5 to 8) – Protective Security Policy Framework (PSPF) Release 2026

23 controls
Controls in the Part Two: Risk (sections 5 to 8) – Protective Security Policy Framework (PSPF) Release 2026 domain of Protective Security Policy Framework (PSPF) Release 2026 — 23 controls
CodeTitle
protective-security-policy-framework-pspf-release-2026::00360036 Determine and document security risk tolerance
protective-security-policy-framework-pspf-release-2026::00370037 Risk steward for each security risk, including shared risks
protective-security-policy-framework-pspf-release-2026::00380038 Consider impacts of risk decisions on other entities and share risk information
protective-security-policy-framework-pspf-release-2026::00390039 Manage security risks from procurement
protective-security-policy-framework-pspf-release-2026::00400040 Proportionate security terms in contracts and outsourcing
protective-security-policy-framework-pspf-release-2026::00410041 Ensure providers and subcontractors comply with relevant PSPF requirements
protective-security-policy-framework-pspf-release-2026::00420042 Contracts require incident reporting and compliance with directions
protective-security-policy-framework-pspf-release-2026::00430043 Government service providers share IRAP reports
protective-security-policy-framework-pspf-release-2026::00440044 Monitor contract security terms over the contract life
protective-security-policy-framework-pspf-release-2026::00450045 Security arrangements for contract completion or termination
protective-security-policy-framework-pspf-release-2026::00460046 Consider foreign ownership, control or influence risks in procurement
protective-security-policy-framework-pspf-release-2026::00470047 Manage and reassess contractual security risk over the contract life
protective-security-policy-framework-pspf-release-2026::00480048 Use secure and verifiable vendors; CISO approves residual risk
protective-security-policy-framework-pspf-release-2026::00490049 Manage security risks of engaging with foreign partners
protective-security-policy-framework-pspf-release-2026::00500050 Personnel do not publicise their security clearance online
protective-security-policy-framework-pspf-release-2026::00510051 Insider threat program for entities managing Baseline to PV clearance subjects
protective-security-policy-framework-pspf-release-2026::00520052 Vary application in exceptional circumstances
protective-security-policy-framework-pspf-release-2026::00530053 Document variations in the security plan
protective-security-policy-framework-pspf-release-2026::00540054 Review and report alternative mitigations annually
protective-security-policy-framework-pspf-release-2026::00550055 Business continuity plan for critical services and assets
protective-security-policy-framework-pspf-release-2026::00560056 Emergency plans integrated in business continuity
protective-security-policy-framework-pspf-release-2026::00570057 Notify personnel of heightened emergency risk
protective-security-policy-framework-pspf-release-2026::02200220 Policy prohibiting online publication of clearance information

Your Compliance Coverage

If you comply with Protective Security Policy Framework (PSPF) Release 2026, you already cover:

Maps to 225 other frameworks

248 total controls
API 1164
4 source controls mapped|10 target controls covered
2%
Annex 11 to EU GMP - Computerised Systems
4 source controls mapped|6 target controls covered
2%
ISO/IEC 27010:2015
4 source controls mapped|7 target controls covered
2%
ISO/IEC 27011:2024
4 source controls mapped|7 target controls covered
2%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
4 source controls mapped|3 target controls covered
2%
FBI CJIS Security Policy
4 source controls mapped|3 target controls covered
2%
NIST Privacy Framework
3 source controls mapped|6 target controls covered
1%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
3 source controls mapped|2 target controls covered
1%
BSI IT-Grundschutz
3 source controls mapped|7 target controls covered
1%
APPI
3 source controls mapped|3 target controls covered
1%
Bahrain PDPL
3 source controls mapped|3 target controls covered
1%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
3 source controls mapped|3 target controls covered
1%
Canada ITSG-33 - IT Security Risk Management
3 source controls mapped|1 target controls covered
1%
FFIEC Cybersecurity Assessment Tool (CAT)
3 source controls mapped|6 target controls covered
1%
FedRAMP Rev 5
3 source controls mapped|4 target controls covered
1%
Family Educational Rights and Privacy Act (FERPA)
3 source controls mapped|1 target controls covered
1%
FISMA
3 source controls mapped|3 target controls covered
1%
FTC GLBA Safeguards Rule (16 CFR Part 314)
3 source controls mapped|4 target controls covered
1%
Ghana Cybersecurity Act
3 source controls mapped|5 target controls covered
1%
HITECH Act
3 source controls mapped|2 target controls covered
1%
1%
IEEE 1686
3 source controls mapped|4 target controls covered
1%
Indiana Consumer Data Protection Act
3 source controls mapped|1 target controls covered
1%
Indonesia PDP Law
3 source controls mapped|3 target controls covered
1%
Iowa Consumer Data Protection Act
3 source controls mapped|3 target controls covered
1%
Jamaica Data Protection Act 2020
3 source controls mapped|3 target controls covered
1%
Kentucky Consumer Data Protection Act
3 source controls mapped|2 target controls covered
1%
South Korea PIPA
3 source controls mapped|4 target controls covered
1%
Ley Orgánica de Protección de Datos Personales (LOPDP)
3 source controls mapped|1 target controls covered
1%
LGPD
3 source controls mapped|1 target controls covered
1%
Liechtenstein DPA
3 source controls mapped|1 target controls covered
1%
Malaysia PDPA 2010
3 source controls mapped|2 target controls covered
1%
Maryland Online Data Privacy Act of 2024
3 source controls mapped|2 target controls covered
1%
Mauritius DPA
3 source controls mapped|1 target controls covered
1%
Mexico LFPDPPP
3 source controls mapped|1 target controls covered
1%
Minnesota Consumer Data Privacy Act
3 source controls mapped|1 target controls covered
1%
Montana Consumer Data Privacy Act
3 source controls mapped|1 target controls covered
1%
Nebraska Data Privacy Act
3 source controls mapped|4 target controls covered
1%
New Hampshire Data Privacy Act
3 source controls mapped|2 target controls covered
1%
New Jersey Data Privacy Act
3 source controls mapped|2 target controls covered
1%
Nigeria Data Protection Act 2023 (NDPA)
3 source controls mapped|4 target controls covered
1%
Nigeria Data Protection Regulation (NDPR)
3 source controls mapped|1 target controls covered
1%
NIST SP 800-122
3 source controls mapped|2 target controls covered
1%
Oman National Cybersecurity Framework
3 source controls mapped|3 target controls covered
1%
Oregon Consumer Privacy Act
3 source controls mapped|2 target controls covered
1%
PDPA Singapore
3 source controls mapped|2 target controls covered
1%
PDPA Thailand
3 source controls mapped|2 target controls covered
1%
Personal Data Act (personopplysningsloven)
3 source controls mapped|2 target controls covered
1%
Peru DPL
3 source controls mapped|2 target controls covered
1%
POPIA
3 source controls mapped|1 target controls covered
1%
Privacy Act 2020
3 source controls mapped|2 target controls covered
1%
Qatar DPL
3 source controls mapped|2 target controls covered
1%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
3 source controls mapped|4 target controls covered
1%
IEC 62351 - Power Systems Communication Security
3 source controls mapped|4 target controls covered
1%
IATA Operational Safety Audit (IOSA) Standards Manual
3 source controls mapped|2 target controls covered
1%
MITRE ATT&CK
3 source controls mapped|3 target controls covered
1%
NIST SP 800-123
3 source controls mapped|2 target controls covered
1%
NIST SP 800-137
3 source controls mapped|2 target controls covered
1%
NIST SP 800-61 Rev. 3
3 source controls mapped|3 target controls covered
1%
NIST SP 800-63-4
3 source controls mapped|3 target controls covered
1%
1%
NIST SP 800-88
3 source controls mapped|1 target controls covered
1%
NIST SP 800-92
3 source controls mapped|3 target controls covered
1%
O-RAN WG11 Security Specification
3 source controls mapped|4 target controls covered
1%
OpenSSF Scorecard
3 source controls mapped|3 target controls covered
1%
OWASP MASVS
3 source controls mapped|3 target controls covered
1%
OWASP SAMM
3 source controls mapped|2 target controls covered
1%
OWASP Top 10:2025
3 source controls mapped|1 target controls covered
1%
PTES
3 source controls mapped|2 target controls covered
1%
ICAO Annex 17 - Aviation Security (AVSEC)
3 source controls mapped|2 target controls covered
1%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
3 source controls mapped|3 target controls covered
1%
ASD Strategies to Mitigate Cyber Security Incidents
2 source controls mapped|3 target controls covered
1%
APRA CPS 230 Operational Risk Management
2 source controls mapped|6 target controls covered
1%
ASIS SPC.1-2009 - Organizational Resilience Standard
2 source controls mapped|4 target controls covered
1%
APRA CPS 234
2 source controls mapped|6 target controls covered
1%
ISO/IEC 27400:2022
2 source controls mapped|3 target controls covered
1%
GLBA
2 source controls mapped|4 target controls covered
1%
HKMA SPM
2 source controls mapped|3 target controls covered
1%
India CERT-In Cyber Security Directions 2022
2 source controls mapped|2 target controls covered
1%
ISMAP (Japan)
2 source controls mapped|3 target controls covered
1%
Monetary Authority of Singapore Technology Risk Management Guidelines
2 source controls mapped|4 target controls covered
1%
MTCS (Singapore)
2 source controls mapped|4 target controls covered
1%
Nevada Gaming Control Board Cybersecurity Requirements
2 source controls mapped|1 target controls covered
1%
NIST SP 800-144
2 source controls mapped|3 target controls covered
1%
NIST SP 800-145
2 source controls mapped|2 target controls covered
1%
NIST SP 800-146
2 source controls mapped|2 target controls covered
1%
Open Banking Security
2 source controls mapped|4 target controls covered
1%
OSFI B-13
2 source controls mapped|5 target controls covered
1%
PSD2 SCA
2 source controls mapped|4 target controls covered
1%
ISO/IEC 27007:2020
2 source controls mapped|2 target controls covered
1%
ISO/IEC 27031:2011
2 source controls mapped|3 target controls covered
1%
IEC 60601-1 - Medical Electrical Equipment Safety
2 source controls mapped|5 target controls covered
1%
COBIT 2019
2 source controls mapped|2 target controls covered
1%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
2 source controls mapped|3 target controls covered
1%
FDA Quality Management System Regulation (QMSR)
2 source controls mapped|2 target controls covered
1%
French Sapin II Law (Law No. 2016-1691)
2 source controls mapped|2 target controls covered
1%
ICH Q10 - Pharmaceutical Quality System
2 source controls mapped|4 target controls covered
1%
BS 65000:2014 - Guidance on Organizational Resilience
2 source controls mapped|3 target controls covered
1%
AS9100D - Aerospace Quality Management System
2 source controls mapped|2 target controls covered
1%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
2 source controls mapped|2 target controls covered
1%
IEEE 7000
2 source controls mapped|2 target controls covered
1%
IRM Enterprise Risk Management Framework (Institute of Risk Management)
2 source controls mapped|2 target controls covered
1%
Japan AI Guidelines
2 source controls mapped|4 target controls covered
1%
OECD AI Principles
2 source controls mapped|2 target controls covered
1%
Authorised Economic Operator (AEO) Programmes - Global Standards
2 source controls mapped|4 target controls covered
1%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
2 source controls mapped|1 target controls covered
1%
FDA 21 CFR Part 11
2 source controls mapped|2 target controls covered
1%
ITU-T X.805 - Security Architecture for End-to-End Communications
2 source controls mapped|2 target controls covered
1%
MARS-E
2 source controls mapped|4 target controls covered
1%
MDS2 (Medical Device)
2 source controls mapped|4 target controls covered
1%
NIST SP 800-66
2 source controls mapped|3 target controls covered
1%
21 CFR Part 211 - Current Good Manufacturing Practice
2 source controls mapped|4 target controls covered
1%
NAIC Insurance Data Security Model Law (MDL-668)
2 source controls mapped|1 target controls covered
1%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
1 source controls mapped|1 target controls covered
0%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
0%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|1 target controls covered
0%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
1 source controls mapped|3 target controls covered
0%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
0%
SWIFT CSCF
1 source controls mapped|1 target controls covered
0%
Singapore Cybersecurity Act 2018
1 source controls mapped|1 target controls covered
0%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
0%
ISO/IEC 30111:2019
1 source controls mapped|3 target controls covered
0%
Barbados Data Protection Act 2019
1 source controls mapped|2 target controls covered
0%
FIRST CSIRT Services Framework and Standards
1 source controls mapped|1 target controls covered
0%
Japan FSA Cybersecurity Guidelines for Financial Institutions
1 source controls mapped|1 target controls covered
0%
Laos Law on Prevention and Combating Cybercrime (2015)
1 source controls mapped|1 target controls covered
0%
NERC CIP
1 source controls mapped|2 target controls covered
0%
Nigeria Open Banking Regulatory Framework (CBN, 2023)
1 source controls mapped|1 target controls covered
0%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
1 source controls mapped|3 target controls covered
0%
Papua New Guinea National Cybersecurity Policy & Cybercrime Act (2016)
1 source controls mapped|1 target controls covered
0%
Science Based Targets Initiative (SBTi) - Net-Zero Standard
1 source controls mapped|2 target controls covered
0%
US Foreign Corrupt Practices Act (FCPA)
1 source controls mapped|1 target controls covered
0%
Connecticut Data Privacy Act (CTDPA)
1 source controls mapped|1 target controls covered
0%
ISO/IEC 27014:2020
1 source controls mapped|2 target controls covered
0%
ISO/IEC 29147:2018
1 source controls mapped|2 target controls covered
0%
ISO/IEC 29134:2023
1 source controls mapped|1 target controls covered
0%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|1 target controls covered
0%
FedRAMP High
1 source controls mapped|1 target controls covered
0%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
0%
DFARS 252.204-7012 - Safeguarding Covered Defense Information
1 source controls mapped|1 target controls covered
0%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|6 target controls covered
0%
ISO/IEC 23837:2023
1 source controls mapped|1 target controls covered
0%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
0%
0%
ISO/IEC 27004:2016
1 source controls mapped|3 target controls covered
0%
ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
1 source controls mapped|1 target controls covered
0%
PCI DSS 4.0
1 source controls mapped|1 target controls covered
0%
ISO/IEC 27050-1:2019
1 source controls mapped|1 target controls covered
0%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|1 target controls covered
0%
FATF Recommendation 16 - Payment Transparency (Travel Rule)
1 source controls mapped|1 target controls covered
0%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|1 target controls covered
0%
GAMP 5 - Good Automated Manufacturing Practice
1 source controls mapped|2 target controls covered
0%
IATF 16949:2016 - Quality Management System for Automotive Production
1 source controls mapped|2 target controls covered
0%
Israel Protection of Privacy Law (5741-1981)
1 source controls mapped|2 target controls covered
0%
ITAR - International Traffic in Arms Regulations
1 source controls mapped|1 target controls covered
0%
ITU Radio Regulations and Space Security Standards
1 source controls mapped|1 target controls covered
0%
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
1 source controls mapped|1 target controls covered
0%
Notifiable Data Breaches Scheme (Australia)
1 source controls mapped|1 target controls covered
0%
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
1 source controls mapped|2 target controls covered
0%
OCC Heightened Standards (12 CFR Part 30, Appendix D)
1 source controls mapped|3 target controls covered
0%
Philippines Cybercrime Prevention Act (RA 10175)
1 source controls mapped|1 target controls covered
0%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
1 source controls mapped|4 target controls covered
0%
Aged Care Quality Standards 2019 (repealed edition)
1 source controls mapped|1 target controls covered
0%
Singapore AI Governance Framework
1 source controls mapped|1 target controls covered
0%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
1 source controls mapped|1 target controls covered
0%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
0%
German Supply Chain Due Diligence Act (LkSG)
1 source controls mapped|1 target controls covered
0%
GLI-33 - Gaming Laboratories International Event Wagering Systems
1 source controls mapped|1 target controls covered
0%
ICH E6(R3) - Good Clinical Practice
1 source controls mapped|1 target controls covered
0%
ICMM Mining Principles (2024 Update)
1 source controls mapped|1 target controls covered
0%
Lloyd's of London Cyber Insurance Requirements and Underwriting Standards
1 source controls mapped|1 target controls covered
0%
New Zealand Information Security Manual (NZISM)
1 source controls mapped|1 target controls covered
0%
Own Risk and Solvency Assessment (ORSA) - NAIC Model Act
1 source controls mapped|1 target controls covered
0%
OECD Recommendation on Artificial Intelligence (2024 Update)
1 source controls mapped|1 target controls covered
0%
NIST SP 800-39
1 source controls mapped|2 target controls covered
0%
NIST SP 800-37
1 source controls mapped|2 target controls covered
0%
NIST SP 800-30
1 source controls mapped|3 target controls covered
0%
South Korea Cloud Security Assurance Program (CSAP)
1 source controls mapped|1 target controls covered
0%
Aged Care Act 2024 (Australia)
1 source controls mapped|1 target controls covered
0%
ISO 27002:2022
1 source controls mapped|2 target controls covered
0%
ISO 27001:2022
1 source controls mapped|2 target controls covered
0%
21 CFR Part 58 - Good Laboratory Practice (GLP)
1 source controls mapped|1 target controls covered
0%
UK Gambling Commission - Cyber Resilience Requirements
1 source controls mapped|1 target controls covered
0%
UK FCA/PRA Operational Resilience Framework
1 source controls mapped|1 target controls covered
0%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|3 target controls covered
0%
SA8000:2014 - Social Accountability Standard
1 source controls mapped|1 target controls covered
0%
SASB Standards
1 source controls mapped|2 target controls covered
0%
ISO/IEC 27003:2017
1 source controls mapped|2 target controls covered
0%
NIST Cybersecurity Framework 2.0
1 source controls mapped|3 target controls covered
0%
NIST SP 1800-32
1 source controls mapped|3 target controls covered
0%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|3 target controls covered
0%
ISO/IEC 27019:2024
1 source controls mapped|3 target controls covered
0%
BREEAM - Building Research Establishment Environmental Assessment Method
1 source controls mapped|1 target controls covered
0%
IEC 62443
1 source controls mapped|3 target controls covered
0%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
0%
Automotive SPICE (ASPICE) v4.1 - Process Assessment Model
1 source controls mapped|1 target controls covered
0%
NIST SP 800-53 Rev 5
1 source controls mapped|3 target controls covered
0%
0%
ISO 28001:2007 Supply Chain Security Management
1 source controls mapped|2 target controls covered
0%
ISO 50001:2018 - Energy Management Systems
1 source controls mapped|1 target controls covered
0%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
1 source controls mapped|1 target controls covered
0%
ISO/TS 22318:2021
1 source controls mapped|1 target controls covered
0%
ISO/TS 22317:2021
1 source controls mapped|1 target controls covered
0%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|1 target controls covered
0%
ISO 26000:2010
1 source controls mapped|1 target controls covered
0%
ISO 22316
1 source controls mapped|1 target controls covered
0%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|1 target controls covered
0%
South Korea ISMS-P
1 source controls mapped|1 target controls covered
0%
Space ISAC (Information Sharing and Analysis Center) - Threat Framework
1 source controls mapped|1 target controls covered
0%
Solvency II
1 source controls mapped|3 target controls covered
0%
Sigstore - Software Artifact Signing and Verification
1 source controls mapped|1 target controls covered
0%
UK Telecommunications (Security) Act 2021
1 source controls mapped|1 target controls covered
0%
Security of Critical Infrastructure Act 2018 (SOCI)
1 source controls mapped|1 target controls covered
0%
0%
UK Security and Emergency Measures Direction (SEMD) - Water Industry
1 source controls mapped|1 target controls covered
0%

Coverage is not the same as your position

This page shows what Protective Security Policy Framework (PSPF) Release 2026 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is Protective Security Policy Framework (PSPF) Release 2026 and who does it apply to?

Protective Security Policy Framework (PSPF) Release 2026 is a compliance framework from Australia (Commonwealth); administered by the Department of Home Affairs with 6 domains and 220 controls. The Australian Government's Protective Security Policy Framework as issued on 1 July 2026: the 220 mandatory requirements across governance, risk, information, technology, personnel and physical security that non-corporate Commonwealth entities report against each year and that contracts pass to suppliers, from the security plan and incident reporting to foreign ownership checks in procurement, the handling tables, system authorisation, Essential Eight Maturity Level Two, hosting and gateway certification, clearance vetting and waivers, and Security Zone certification. Every leaf read against the Release 2026 text. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Protective Security Policy Framework (PSPF) Release 2026 actually require?

Protective Security Policy Framework (PSPF) Release 2026 has 220 controls organised across 6 domains. The largest domains are Part Five: Personnel (sections 16 to 22) – Protective Security Policy Framework (PSPF) Release 2026 (74 controls), Part Four: Technology (sections 13 to 15) – Protective Security Policy Framework (PSPF) Release 2026 (39 controls), Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026 (36 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Protective Security Policy Framework (PSPF) Release 2026 do I already cover?

Protective Security Policy Framework (PSPF) Release 2026 maps to 225 other compliance frameworks. The top mapping partners are API 1164 (2% coverage), Annex 11 to EU GMP - Computerised Systems (2% coverage), ISO/IEC 27010:2015 (2% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Protective Security Policy Framework (PSPF) Release 2026?

Start your Protective Security Policy Framework (PSPF) Release 2026 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Protective Security Policy Framework (PSPF) Release 2026 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 220 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 703 frameworks.

Get Started Free →

Free forever — no credit card required