Who must comply with Protective Security Policy Framework (PSPF)?
The applicability test for Protective Security Policy Framework (PSPF), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Only if
Applies only if you are a contracted provider handling Commonwealth information. Whether it applies turns on a fact that no industry, structure or size settles on its own.
What the obligation is
Federal entities bound by PSPF — governance, information, personnel + physical security.
The Protective Security Policy Framework sets the Australian Government's minimum protective security standards across six security domains, covering how entities protect their people, information and resources at home and overseas. It is made binding by the Minister's Directive on the Security of Government Business, and the Department of Home Affairs reviews it annually; PSPF Release 2026 was issued on 1 July 2026. The framework mandates named roles (an Accountable Authority, a Chief Security Officer and a Chief Information Security Officer), security planning, incident management and security investigations, third-party risk management in procurement and contracts, classification and handling of information, Essential Eight cyber strategies, personnel vetting and clearances, and physical security zones. Since 1 November 2024 annual reporting has replaced the older maturity self-assessment model.
The applicability test
Applies only if you are a contracted provider handling Commonwealth information. Whether it applies turns on a fact that no industry, structure or size settles on its own.
How the regulator frames it: Non-corporate Commonwealth entities, which must apply the PSPF under s 21 of the Public Governance, Performance and Accountability Act 2013. It is better practice for corporate Commonwealth entities and wholly-owned Commonwealth companies. State and territory agencies holding Australian Government security classified information, and contractors and service providers whose deeds or agreements require it, must apply the relevant parts.
What triggers it: Being a non-corporate Commonwealth entity; for others, accessing Australian Government security classified information or signing a government contract or deed that imports PSPF requirements.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (35 of 35: no).
The answer is the same in every industry: no. Industry does not change who must comply.
Business structure and size
Structure does not change the answer across all industries: for every structure the answer is "no".
Size does not change the answer across all industries: at every size band the answer is "no".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires a trigger outside this questionnaire.
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business supplies government customers: it becomes worth checking, because it applies only if you are a contracted provider handling Commonwealth information.
When you need to check further
The engine shows this obligation as "check whether this applies" when a business has government customers. It then applies only if you are a contracted provider handling Commonwealth information. That fact is not something Rules Mate can infer from industry, structure or size.
What you must do, and when
- When due
- Ongoing, with a protective security report each financial year from the Accountable Authority to its minister and to the Department of Home Affairs, lodged through the PSPF reporting portal.
- Frequency
- Annual
- Evidence to keep
- Annual protective security report and portal submission; security plan and risk tolerance statement; Chief Security Officer and Chief Information Security Officer appointments; security incident register and investigation records; information asset register; contract clauses and third-party risk assessments; security clearance and pre-employment screening records; security zone certification and accreditation records.
- In force from
- 1 July 2025
- Status
- Current
- Priority
- Critical
Penalty for not complying
Maximum penalty: The PSPF is government policy, not a statute, so it carries no pecuniary penalty of its own. Accountable Authorities are accountable to their minister for the security of their entity, Home Affairs quality-assures annual reports, and a contractor's breach of PSPF terms is dealt with under its contract or deed.
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
Where it sits in the corpus
Rules Mate tracks 3 published obligations tagged "cyber security", 2 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated critical priority, and is a annual obligation.
Regulator, legislation and tools
Free tools that help with this obligation:
Questions
- Who must comply with Protective Security Policy Framework (PSPF)?
- Applies only if you are a contracted provider handling Commonwealth information. Whether it applies turns on a fact that no industry, structure or size settles on its own.
- Does Protective Security Policy Framework (PSPF) apply to sole traders?
- No. Across every industry and every size band, the engine's answer for a sole trader is: no.
- Does Protective Security Policy Framework (PSPF) apply to businesses with 1–5 employees?
- No (1–5 employees, turnover $100K–$1M).
- When is "Protective Security Policy Framework (PSPF)" due?
- Ongoing, with a protective security report each financial year from the Accountable Authority to its minister and to the Department of Home Affairs, lodged through the PSPF reporting portal.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.