Skip to main content
Rules Mate

Who must comply with Protective Security Policy Framework (PSPF)?

The applicability test for Protective Security Policy Framework (PSPF), computed across 35 industries, 9 business structures and 6 size bands.

Short answer: Only if

Applies only if you are a contracted provider handling Commonwealth information. Whether it applies turns on a fact that no industry, structure or size settles on its own.

What the obligation is

Federal entities bound by PSPF — governance, information, personnel + physical security.

The Protective Security Policy Framework sets the Australian Government's minimum protective security standards across six security domains, covering how entities protect their people, information and resources at home and overseas. It is made binding by the Minister's Directive on the Security of Government Business, and the Department of Home Affairs reviews it annually; PSPF Release 2026 was issued on 1 July 2026. The framework mandates named roles (an Accountable Authority, a Chief Security Officer and a Chief Information Security Officer), security planning, incident management and security investigations, third-party risk management in procurement and contracts, classification and handling of information, Essential Eight cyber strategies, personnel vetting and clearances, and physical security zones. Since 1 November 2024 annual reporting has replaced the older maturity self-assessment model.

The applicability test

Applies only if you are a contracted provider handling Commonwealth information. Whether it applies turns on a fact that no industry, structure or size settles on its own.

How the regulator frames it: Non-corporate Commonwealth entities, which must apply the PSPF under s 21 of the Public Governance, Performance and Accountability Act 2013. It is better practice for corporate Commonwealth entities and wholly-owned Commonwealth companies. State and territory agencies holding Australian Government security classified information, and contractors and service providers whose deeds or agreements require it, must apply the relevant parts.

What triggers it: Being a non-corporate Commonwealth entity; for others, accessing Australian Government security classified information or signing a government contract or deed that imports PSPF requirements.

Jurisdiction: Commonwealth law, so the test is the same in every state and territory.

Which industries are in or out

Outcome across the 35 industries Rules Mate maps (35 of 35: no).

The answer is the same in every industry: no. Industry does not change who must comply.

Business structure and size

Structure does not change the answer across all industries: for every structure the answer is "no".

Size does not change the answer across all industries: at every size band the answer is "no".

Worked examples

Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:

  • Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires a trigger outside this questionnaire.

Answers that bring it into scope

Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:

  • The business supplies government customers: it becomes worth checking, because it applies only if you are a contracted provider handling Commonwealth information.

When you need to check further

The engine shows this obligation as "check whether this applies" when a business has government customers. It then applies only if you are a contracted provider handling Commonwealth information. That fact is not something Rules Mate can infer from industry, structure or size.

What you must do, and when

When due
Ongoing, with a protective security report each financial year from the Accountable Authority to its minister and to the Department of Home Affairs, lodged through the PSPF reporting portal.
Frequency
Annual
Evidence to keep
Annual protective security report and portal submission; security plan and risk tolerance statement; Chief Security Officer and Chief Information Security Officer appointments; security incident register and investigation records; information asset register; contract clauses and third-party risk assessments; security clearance and pre-employment screening records; security zone certification and accreditation records.
In force from
1 July 2025
Status
Current
Priority
Critical

Penalty for not complying

Maximum penalty: The PSPF is government policy, not a statute, so it carries no pecuniary penalty of its own. Accountable Authorities are accountable to their minister for the security of their entity, Home Affairs quality-assures annual reports, and a contractor's breach of PSPF terms is dealt with under its contract or deed.

Audit or assurance level

Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.

Where it sits in the corpus

Rules Mate tracks 3 published obligations tagged "cyber security", 2 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated critical priority, and is a annual obligation.

Regulator, legislation and tools

Questions

Who must comply with Protective Security Policy Framework (PSPF)?
Applies only if you are a contracted provider handling Commonwealth information. Whether it applies turns on a fact that no industry, structure or size settles on its own.
Does Protective Security Policy Framework (PSPF) apply to sole traders?
No. Across every industry and every size band, the engine's answer for a sole trader is: no.
Does Protective Security Policy Framework (PSPF) apply to businesses with 1–5 employees?
No (1–5 employees, turnover $100K–$1M).
When is "Protective Security Policy Framework (PSPF)" due?
Ongoing, with a protective security report each financial year from the Accountable Authority to its minister and to the Department of Home Affairs, lodged through the PSPF reporting portal.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.