RFFR Assurance Lifecycle

To obtain RFFR Accreditation, Providers must demonstrate to the department’s satisfaction that reasonable and appropriate security controls have been implemented to support the secure delivery of Services and protect department information.

On this page:

Assurance Lifecycle

The Assurance Lifecycle sets out the stages through which assurance is established and maintained under the RFFR accreditation approach. It provides a structured approach to managing assurance activities throughout the term of the relevant Deed.

Assurance Lifecycle stagesRequirements
CategorisationThe Provider must submit a Categorisation Questionnaire as part of their response to the relevant Request for Proposal or Request for Tender.
Initial Assessment Providers must submit the Initial Assessment deliverables within two months of the Deed Commencement Date of the relevant Deed and complete the Initial Assessment stage within three months of the relevant Deed Commencement Date. 
Accreditation

Providers must submit their accreditation deliverables at least six weeks before the Provider is required to obtain RFFR Accreditation. 

Provider must obtain RFFR Accreditation within nine months of the relevant Deed Commencement Date.

Accreditation Maintenance 

Providers must submit updated deliverables at least six weeks before the Provider is required to complete the Accreditation Maintenance stage. 

Providers must complete the Accreditation Maintenance stage every 12 months from the date that RFFR Accreditation was obtained, other than every third year, when the Provider must instead complete the Reaccreditation stage.  

Reaccreditation

Providers must submit updated deliverables at least six weeks before the Provider is required to complete the Reaccreditation stage. 

The Provider must complete the Reaccreditation stage every 3 years from the date that RFFR Accreditation was obtained. 

Categorisation

Categorisation is the first stage of the Assurance Lifecycle and is used by the department to determine the Provider’s Assurance Category.

 

Categorisation QuestionnaireThe Provider must submit a Categorisation Questionnaire as part of their response to the relevant Request for Proposal or Request for Tender.
Categorisation Meeting

The Provider must attend a Categorisation Meeting with the department for the purposes of:

  • validating the information provided by the Provider in the Categorisation Questionnaire,
  • enabling the Department to understand the Provider’s operating model and External IT Systems,
  • discussing the RFFR accreditation approach, including key stages and timeframes, to assist in identifying the systems and processes that are within the scope of accreditation. 
Outcome and next stepsThe Department will assess the information provided by the Provider in the Categorisation Questionnaire and Categorisation Meeting and notify the Provider of their assigned Assurance Category and required deliverables.

Initial Assessment

The Initial Assessment stage involves an assessment by the department of the Provider’s security posture against the requirements of the assigned Assurance Category.

The Initial Assessment considers:

  • The context in which Services are delivered.
  • The implementation of applicable security controls.
  • Associated risk treatment plans.

The Provider must submit the deliverables required for the assigned Assurance Category.

Accreditation

The department will assess the Provider’s security posture for RFFR Accreditation based on submitted Accreditation Deliverables. The assessment considers the service delivery context, data lifecycle, operating model, implementation of applicable security controls and associated risk treatment plans.

Accreditation Maintenance

The Accreditation Maintenance stage is an annual assurance activity that ensures the Provider’s security posture remains appropriate for the secure delivery of Services and protection of department information.

Significant changes to service delivery, the operating model, supporting systems or data handling practices must be reflected in the Provider’s updated deliverables.

Further information about maintenance deliverables and timeframes can be found in the ESAF.

Reaccreditation

Reaccreditation involves a full reassessment by the department of the Provider’s security posture to confirm continued compliance with the ESAF requirements for the assigned Assurance Category, taking into account the Provider’s RFFR accreditation history.

The Provider must successfully complete Reaccreditation every third year from the date RFFR Accreditation was obtained. This confirms the Provider’s security posture remains aligned with whole of government requirements and departmental priorities.

Further information about Reaccreditation deliverables and timeframes can be found in the ESAF.

Templates for submission

Standardised RFFR templates have been created to assist Providers in completing accreditation lifecycle stages.

Use of these templates is mandatory. Providers cannot use a modified or tailored version of the PSP-A, as it will not be accepted as part of the RFFR assessment process.

Provider templates

All categoriesCategorisation Questionnaire
Categories 1 to 3Provider Security Plan (PSP) and Provider Security Plan Annex (PSP-A)
Category 4Security Assessment Questionnaire (SAQ)

View RFFR templates