Protective Security Policy Framework (PSPF)
Federal entities bound by PSPF — governance, information, personnel + physical security.
Who must comply
Non-corporate Commonwealth entities, which must apply the PSPF under s 21 of the Public Governance, Performance and Accountability Act 2013. It is better practice for corporate Commonwealth entities and wholly-owned Commonwealth companies. State and territory agencies holding Australian Government security classified information, and contractors and service providers whose deeds or agreements require it, must apply the relevant parts.
What triggers it
Being a non-corporate Commonwealth entity; for others, accessing Australian Government security classified information or signing a government contract or deed that imports PSPF requirements.
When due
Ongoing, with a protective security report each financial year from the Accountable Authority to its minister and to the Department of Home Affairs, lodged through the PSPF reporting portal.
Evidence required
Annual protective security report and portal submission; security plan and risk tolerance statement; Chief Security Officer and Chief Information Security Officer appointments; security incident register and investigation records; information asset register; contract clauses and third-party risk assessments; security clearance and pre-employment screening records; security zone certification and accreditation records.
Max penalty
The PSPF is government policy, not a statute, so it carries no pecuniary penalty of its own. Accountable Authorities are accountable to their minister for the security of their entity, Home Affairs quality-assures annual reports, and a contractor's breach of PSPF terms is dealt with under its contract or deed.
Effective from
1 July 2025
Who must comply with this? The applicability test by industry, business structure and size.
Summary
The Protective Security Policy Framework sets the Australian Government's minimum protective security standards across six security domains, covering how entities protect their people, information and resources at home and overseas. It is made binding by the Minister's Directive on the Security of Government Business, and the Department of Home Affairs reviews it annually; PSPF Release 2026 was issued on 1 July 2026. The framework mandates named roles (an Accountable Authority, a Chief Security Officer and a Chief Information Security Officer), security planning, incident management and security investigations, third-party risk management in procurement and contracts, classification and handling of information, Essential Eight cyber strategies, personnel vetting and clearances, and physical security zones. Since 1 November 2024 annual reporting has replaced the older maturity self-assessment model.
Topics
Related
- CWLTHSoNS — Systems of National Significance (SOCI)Declared SoNS face enhanced cyber security obligations.
- CWLTHPublic Interest Disclosure Act 2013 (federal whistleblower)Federal public sector whistleblower regime + protections.
- CWLTHDefence Industry Security Program (DISP)Defence contractors handling classified info must be DISP-accredited at appropriate level.
- CWLTHData Availability and Transparency Act 2022Commonwealth data sharing regime — accredited users + entities.
Reading
Frequently asked questions
- Who must comply with Protective Security Policy Framework (PSPF)?
- Non-corporate Commonwealth entities, which must apply the PSPF under s 21 of the Public Governance, Performance and Accountability Act 2013. It is better practice for corporate Commonwealth entities and wholly-owned Commonwealth companies. State and territory agencies holding Australian Government security classified information, and contractors and service providers whose deeds or agreements require it, must apply the relevant parts.
- What triggers Protective Security Policy Framework (PSPF)?
- Being a non-corporate Commonwealth entity; for others, accessing Australian Government security classified information or signing a government contract or deed that imports PSPF requirements.
- When is Protective Security Policy Framework (PSPF) due?
- Ongoing, with a protective security report each financial year from the Accountable Authority to its minister and to the Department of Home Affairs, lodged through the PSPF reporting portal.
- What is the maximum penalty for Protective Security Policy Framework (PSPF)?
- The PSPF is government policy, not a statute, so it carries no pecuniary penalty of its own. Accountable Authorities are accountable to their minister for the security of their entity, Home Affairs quality-assures annual reports, and a contractor's breach of PSPF terms is dealt with under its contract or deed.
- What evidence is required for Protective Security Policy Framework (PSPF)?
- Annual protective security report and portal submission; security plan and risk tolerance statement; Chief Security Officer and Chief Information Security Officer appointments; security incident register and investigation records; information asset register; contract clauses and third-party risk assessments; security clearance and pre-employment screening records; security zone certification and accreditation records.
Source: https://www.protectivesecurity.gov.au/pspf-annual-release. Rules Mate is not a law firm. Always verify against the live regulator source before acting.