To obtain RFFR Accreditation, Providers must demonstrate to the department’s satisfaction that reasonable and appropriate security controls have been implemented to support the secure delivery of Services and protect department information.
On this page:
Assurance Lifecycle
The Assurance Lifecycle sets out the stages through which assurance is established and maintained under the RFFR accreditation approach. It provides a structured approach to managing assurance activities throughout the term of the relevant Deed.
| Assurance Lifecycle stages | Requirements |
|---|---|
| Categorisation | The Provider must submit a Categorisation Questionnaire as part of their response to the relevant Request for Proposal or Request for Tender. |
| Initial Assessment | Providers must submit the Initial Assessment deliverables within two months of the Deed Commencement Date of the relevant Deed and complete the Initial Assessment stage within three months of the relevant Deed Commencement Date. |
| Accreditation | Providers must submit their accreditation deliverables at least six weeks before the Provider is required to obtain RFFR Accreditation. Provider must obtain RFFR Accreditation within nine months of the relevant Deed Commencement Date. |
| Accreditation Maintenance | Providers must submit updated deliverables at least six weeks before the Provider is required to complete the Accreditation Maintenance stage. Providers must complete the Accreditation Maintenance stage every 12 months from the date that RFFR Accreditation was obtained, other than every third year, when the Provider must instead complete the Reaccreditation stage. |
| Reaccreditation | Providers must submit updated deliverables at least six weeks before the Provider is required to complete the Reaccreditation stage. The Provider must complete the Reaccreditation stage every 3 years from the date that RFFR Accreditation was obtained. |
Categorisation
Categorisation is the first stage of the Assurance Lifecycle and is used by the department to determine the Provider’s Assurance Category.
| Categorisation Questionnaire | The Provider must submit a Categorisation Questionnaire as part of their response to the relevant Request for Proposal or Request for Tender. |
| Categorisation Meeting | The Provider must attend a Categorisation Meeting with the department for the purposes of:
|
| Outcome and next steps | The Department will assess the information provided by the Provider in the Categorisation Questionnaire and Categorisation Meeting and notify the Provider of their assigned Assurance Category and required deliverables. |
Initial Assessment
The Initial Assessment stage involves an assessment by the department of the Provider’s security posture against the requirements of the assigned Assurance Category.
The Initial Assessment considers:
- The context in which Services are delivered.
- The implementation of applicable security controls.
- Associated risk treatment plans.
The Provider must submit the deliverables required for the assigned Assurance Category.
Category 1 – Provider Security Plan, Provider Security Plan Annex and audit artefacts
A Category 1 Provider must submit:
- A completed Provider Security Plan (PSP) that clearly defines the scope of Services and security controls in place to safeguard department information.
- A Provider Security Plan Annex (PSP-A) addressing all applicable Category 1 controls, their current implementation and treatment plans for controls not yet fully implemented.
- An ISO/IEC 27001 or DEWR ISMS Scheme Stage 1 Audit Report conducted by a JASANZ accredited certification body, validating the Provider’s approach to implementing applicable controls within the PSP-A.
Category 2 – Provider Security Plan and Provider Security Plan Annex
A Category 2 Provider must submit:
- A completed Provider Security Plan (PSP) that clearly defines the scope of Services and security controls in place to safeguard department information.
- A Provider Security Plan Annex (PSP-A) addressing all applicable Category 2 controls, their current implementation and treatment plans for controls not yet fully implemented.
Category 3 – Provider Security Plan and Provider Security Plan Annex
A Category 3 Provider must submit:
- A completed Provider Security Plan (PSP) that clearly defines the scope of Services and security controls in place to safeguard department information.
- A Provider Security Plan Annex (PSP-A) addressing all applicable Category 3 controls, their current implementation and treatment plans for controls not yet fully implemented.
Category 4 – Security Assessment Questionnaire
A Category 4 Provider must complete a Security Assessment Questionnaire (SAQ) outlining the current implementation of applicable security controls, including treatment plans for controls not yet fully implemented.
Accreditation
The department will assess the Provider’s security posture for RFFR Accreditation based on submitted Accreditation Deliverables. The assessment considers the service delivery context, data lifecycle, operating model, implementation of applicable security controls and associated risk treatment plans.
Category 1 – Provider Security Plan, Provider Security Plan Annex and audit artefacts
A Category 1 Provider must submit:
- An updated and completed PSP and PSP-A.
- An ISO/IEC 27001 or DEWR ISMS Scheme Stage 2 Audit Report conducted by a JASANZ accredited certification body.
- An ISO/IEC 27001 or DEWR ISMS Scheme Corrective Actions Plan, if applicable.
- An ISO/IEC 27001 or DEWR ISMS Scheme Certificate.
Category 2 – Updated Provider Security Plan and Provider Security Plan Annex
A Category 2 Provider must submit an updated and completed PSP and PSP-A clearly defining the scope of Services and security controls in place to safeguard department information.
Category 3 – Updated Provider Security Plan and Provider Security Plan Annex
A Category 3 Provider must submit an updated and completed PSP and PSP-A clearly defining the scope of Services and security controls in place to safeguard department information.
Category 4 – Updated Security Assessment Questionnaire
A Category 4 Provider must submit an updated and completed SAQ describing the current implementation of applicable security controls, risk treatment plans and changes to the Provider’s security posture since Initial Assessment.
Accreditation Maintenance
The Accreditation Maintenance stage is an annual assurance activity that ensures the Provider’s security posture remains appropriate for the secure delivery of Services and protection of department information.
Significant changes to service delivery, the operating model, supporting systems or data handling practices must be reflected in the Provider’s updated deliverables.
Further information about maintenance deliverables and timeframes can be found in the ESAF.
Reaccreditation
Reaccreditation involves a full reassessment by the department of the Provider’s security posture to confirm continued compliance with the ESAF requirements for the assigned Assurance Category, taking into account the Provider’s RFFR accreditation history.
The Provider must successfully complete Reaccreditation every third year from the date RFFR Accreditation was obtained. This confirms the Provider’s security posture remains aligned with whole of government requirements and departmental priorities.
Further information about Reaccreditation deliverables and timeframes can be found in the ESAF.
Templates for submission
Standardised RFFR templates have been created to assist Providers in completing accreditation lifecycle stages.
Use of these templates is mandatory. Providers cannot use a modified or tailored version of the PSP-A, as it will not be accepted as part of the RFFR assessment process.
Provider templates
| All categories | Categorisation Questionnaire |
| Categories 1 to 3 | Provider Security Plan (PSP) and Provider Security Plan Annex (PSP-A) |
| Category 4 | Security Assessment Questionnaire (SAQ) |