Protective Security Policy Framework
AGD protective security policy for NCEs. Four domains, PSPF Release 2025 Policy 14 cyber floor, Essential Eight to Maturity Level 2 since July 2022.
The Protective Security Policy Framework (PSPF) is issued by the Attorney-General's Department. It is how non-corporate Commonwealth entities (NCEs) are expected to manage protective security across four domains: governance, information security, personnel security, and physical security. It is government policy, not an ISO certificate and not a substitute for the ISM on the technical controls.
Cyber sits inside that policy as a hard floor, not a slogan. Since 1 July 2022, the PSPF has required NCEs to implement all eight Essential Eight strategies to at least Maturity Level 2, and to consider whether their threat environment warrants Level 3. ASD's Commonwealth cyber security posture reports (2024 and 2025) restate that duty. Under PSPF Release 2025 the cyber strategies requirement is expressed as Policy 14: Cyber Security Strategies (it previously sat under the Policy 10 information-security line). A network's overall maturity equals its least mature strategy — you do not average eight scores into a vanity number.
NCEs must respond to ASD's annual Commonwealth cyber security posture survey under the PSPF; corporate Commonwealth entities and companies are encouraged to participate. That survey is how government gets an aggregated view of Essential Eight maturity and related controls. It is not a licence to claim maturity you cannot evidence. If you are not an NCE, PSPF is still a useful dialect when you sell into government. It does not, by itself, make you an NCE.
AGD publishes the mandatory requirement list for each PSPF release (Release 2025 list of requirements, updated into 2026). Use that spreadsheet to name owners, map reporting questions, record exceptions, and accept residual risk in writing. Use the ISM and Essential Eight for the work list. If a board paper says 'we align to PSPF' and the patching queue is a quarter long, the paper is the vulnerability.
Evidence for the cyber floor is the same evidence as Essential Eight: scope, artefact, date, owner, and overall maturity equal to the weakest strategy. PSPF tells you the policy duty; Essential Eight evidence is how you show you met it. Keep the PSPF self-assessment, the ASD survey extract, and the Essential Eight evidence pack next to each other — not in separate SharePoint graveyards. Cross-link ISM controls where the assessor will ask.
Primary sources: protectivesecurity.gov.au (PSPF policies and Release 2025 requirements list); ASD Commonwealth cyber security posture reports on cyber.gov.au for the Essential Eight Maturity Level 2 mandate and survey expectations. Pair this page with Essential Eight evidence, ISM, and IRAP when the buyer is Commonwealth.
Fact source: ASD, Commonwealth cyber security posture 2025 (PSPF Policy 14 / Essential Eight ML2).
