The Protective Security Policy Framework: What Government Contractors Need to Know

disp government security pspf security security compliance Jul 20, 2026

The Protective Security Policy Framework: What Government Contractors Need to Know

The Protective Security Policy Framework (PSPF) is the Australian Government's policy framework for protective security. It applies directly to all non-corporate Commonwealth entities β€” government departments and agencies β€” and flows through to private sector organisations that contract to, or are entrusted with, Australian Government assets, information, or interests.

For businesses working with government, the PSPF is not background context. It is a set of obligations that can affect contract eligibility, create legal exposure, and determine whether an organisation is trusted with sensitive government work.


What the PSPF Is

The PSPF is administered by the Attorney-General's Department (AGD). It establishes the government's requirements for protective security β€” the management of security risk to government people, information, and assets β€” across five outcome areas:

  • Governance β€” security governance and accountability
  • Information security β€” protection of government information and ICT systems
  • Personnel security β€” management of people with access to government assets
  • Physical security β€” protection of government facilities and assets
  • Security risk management β€” the framework for assessing and managing security risk

The PSPF is not a checklist. It is a risk-based framework β€” entities are expected to assess their own security risk environment and implement controls proportionate to that risk, against the standards the PSPF establishes.


How the PSPF Applies to the Private Sector

Government entities that contract with the private sector have obligations under the PSPF to ensure that contracted service providers handle government information and assets appropriately. This obligation flows down through contracts.

In practice, this means:

Contract clauses. Government contracts for services involving access to sensitive information, government ICT systems, or government facilities typically include clauses that require the contractor to comply with PSPF requirements β€” or specific elements of them β€” for the duration of the contract.

Personnel security. If contract personnel require access to government systems or facilities, they may need to hold appropriate security clearances and undergo vetting. This is a personnel security requirement flowing from the PSPF.

Information handling. Contractors entrusted with government information at any classification level must handle it in accordance with the Government Security Classification System β€” not simply in accordance with whatever their own internal information security policy happens to be.

Physical security. Contractors operating within government facilities must comply with the physical security requirements of those facilities. Contractors who bring government assets or information into their own facilities must implement the physical security standards appropriate to the classification level of that material.


The Core Requirements Most Relevant to Contractors

Security governance. An organisation working with government should have a defined security accountability structure β€” someone responsible for security governance, policy, and incident response. For larger contractors and those with DISP obligations, this is typically a formal Security Officer role.

Security planning. A Security Management Plan (SMP) or equivalent security governance document that describes how the organisation manages its security obligations.

Personnel security β€” pre-employment screening. PSPF-aligned pre-employment screening for personnel who will have access to government information or assets. The depth of screening is proportionate to the sensitivity of access.

Information classification and handling. Understanding the Australian Government Security Classification System (OFFICIAL, OFFICIAL: Sensitive, PROTECTED, SECRET, TOP SECRET) and ensuring that information at each level is handled appropriately.

Incident reporting. Security incidents affecting government information or assets must be reported in accordance with the contractual and PSPF requirements β€” not managed internally and quietly resolved.


PSPF Self-Assessment and Reporting

For entities directly subject to the PSPF (government agencies), annual self-assessment against the PSPF core requirements and reporting to AGD is mandatory. For contracted private sector organisations, formal reporting to AGD is not typically required β€” but demonstrating compliance to the contracting agency is.

Organisations that cannot demonstrate security governance appropriate to the information and assets they are entrusted with risk contract termination, exclusion from future procurement, and in serious cases, legal consequences.


PSPF vs DISP

The PSPF and DISP are related but distinct frameworks. DISP is the specific accreditation program for defence industry access to classified Defence information. The PSPF is the broader Australian Government protective security framework that applies across all agencies and flows to all contractors.

Many defence industry organisations must comply with both β€” DISP for their Defence-specific obligations and PSPF requirements embedded in other government contracts. The frameworks are complementary, but they are not interchangeable.


Empire Protection β€” PSPF Advisory

Empire Protection provides PSPF compliance advisory services for private sector organisations with Australian Government contracts. We assess current security posture against PSPF requirements, identify gaps, and provide practical recommendations for alignment.

Contact Empire Protection


Empire Protection β€” Demand Excellence in everything we do. Sydney, Australia | empireprotection.global

The Right People, The Right Methods, The Right Results.
In everything we do,Β Empire ProtectionΒ Demands Excellence.