How to Meet ACSC PROTECTED Compliance for Government Contractors in Australia
Alexander Sverdlov
Security Analyst

If you want to handle Australian Government information classified at PROTECTED, the bar is set by two documents: the Protective Security Policy Framework (PSPF) and the Information Security Manual (ISM), which the Australian Signals Directorate publishes through the Australian Cyber Security Centre. I have spent the last decade running security assessments for organisations that sell into regulated and government markets, and the pattern is always the same. Contractors treat PROTECTED as a paperwork exercise, discover during the assessment that half their controls do not actually exist, and lose months. This guide walks through what PROTECTED really requires and how to get there without wasting a tender cycle.
What PROTECTED Actually Means
The Australian Government classifies information by the damage its compromise would cause. The security classifications, from lowest to highest, are OFFICIAL, OFFICIAL: Sensitive, PROTECTED, SECRET and TOP SECRET. PROTECTED sits at the point where compromise could cause damage to the national interest, organisations or individuals. If you build software, host data, provide managed services or handle documents at this level for a Commonwealth entity, your systems and your people come into scope.
Two things follow from that. First, PROTECTED is not a badge you buy. It is a state your environment has to be in and stay in, evidenced against specific controls. Second, the controls are not invented by the buying agency. They come from the ISM and the PSPF, and increasingly they are assessed by an IRAP (Infosec Registered Assessors Program) assessor endorsed by the ASD. Understanding that chain of authority is the difference between a clean assessment and an expensive surprise.
The Frameworks You Are Actually Being Measured Against
Contractors routinely conflate three separate things. Keep them distinct and the rest of the work gets simpler.
- PSPF - the policy layer. It covers governance, information security, personnel security and physical security. It tells you what outcomes you must achieve and who is accountable.
- ISM - the technical control catalogue. It is where the specific system hardening, cryptography, access control, logging and network segmentation requirements live. It is updated regularly, so you always assess against the current release.
- Essential Eight - the ASD baseline mitigation strategies: application control, patching applications, patching operating systems, restricting Microsoft Office macros, hardening user applications, restricting administrative privileges, multi-factor authentication and regular backups. For PROTECTED work you are generally expected to be operating at a mature level across all eight, not cherry-picking.
If you already run an Essential Eight programme, you have a head start, but do not mistake it for the finish line. The ISM is broader. I have written more about where teams stall in challenges in ACSC Essential Eight and how to turn that baseline into commercial advantage in leveraging Essential Eight for business growth.
How the Real Requirements Break Down
Here is a truthful map of the domains a PROTECTED assessment touches, and what each one asks of you.
| Domain | What it covers | Where it comes from |
|---|---|---|
| Governance | Named accountable authority, risk management framework, security plan, system authorisation | PSPF |
| Information security | System hardening, cryptography with ASD-approved algorithms, access control, logging and monitoring, data at rest and in transit | ISM |
| Personnel security | Security clearances for staff who access PROTECTED (Baseline, NV1, NV2 as required), onboarding and offboarding, need-to-know | PSPF |
| Physical security | Secure zones, handling and storage of classified material, data centre certification for hosting | PSPF and Hosting Certification Framework |
| Assurance | IRAP assessment of the system, authorisation to operate by the Commonwealth entity | ISM and IRAP |
Notice that none of this is about marketing. An agency does not award work because you say you are secure. It awards work because an independent assessor has documented that your controls exist, function and are managed over time, and because their own authorising officer accepts the residual risk.
Step 1: Establish Governance Before You Touch Technology
The single most common reason contractors fail is that no one owns the outcome. The PSPF expects a named accountable authority and a security governance structure that actually meets and makes decisions. In practice you need:
- A designated person accountable for protective security, with real authority and board or executive visibility.
- A documented risk management framework that ties identified risks to specific controls and to a treatment plan.
- A system security plan that describes the system boundary, what data it handles, and how each applicable ISM control is met.
- A cadence of review, because PROTECTED is a continuing obligation, not a point-in-time pass.
Get this wrong and every later step floats free with nothing to anchor it to. Get it right and the assessor has a clear narrative to test against.
Step 2: Define the System Boundary and Data Flows
Scope creep is where budgets die. Before you harden anything, draw the boundary of the system that will hold or process PROTECTED information. Map exactly where the data enters, where it rests, where it moves and where it leaves. Everything inside that boundary is in scope for the ISM; everything you can defensibly place outside it is not. A tightly drawn, well justified boundary is the cheapest control you will ever implement, because it removes systems from assessment entirely. This is the same discipline that underpins a good IT security audit: you cannot secure what you have not first inventoried and bounded.
Step 3: Implement ISM Controls and Harden the System
This is the technical core. At PROTECTED you should expect to demonstrate, at minimum:
- Multi-factor authentication for all access, especially privileged and remote access.
- Encryption of data at rest and in transit using ASD-approved cryptographic algorithms and protocols.
- Application control and a disciplined patching regime for both operating systems and applications, aligned to Essential Eight maturity.
- Least-privilege administration, with privileged accounts separated, logged and time-limited.
- Centralised logging and monitoring capable of detecting and supporting investigation of security events.
- Network segmentation that isolates the PROTECTED environment from lower-classification and internet-facing systems.
A gap assessment against the current ISM before you invite an assessor saves real money. It is far cheaper to find a missing control yourself than to have an IRAP assessor find it and send you back to remediate. A penetration test and a vulnerability assessment against the in-scope environment give you evidence that the controls hold up under pressure rather than just on paper.
Step 4: Handle Personnel and Physical Security
Technology is only part of PROTECTED. People who access the information generally need an appropriate Australian Government security clearance, and clearances take time to sponsor and process, so start early. You also need enforced need-to-know, clean onboarding and offboarding, and defensible physical handling of classified material. If you are hosting the data, the facility itself matters: the Hosting Certification Framework and certified data centre zones exist precisely because physical compromise defeats every logical control you built in Step 3.
Step 5: Get Assessed and Authorised
For PROTECTED systems the assurance step is typically an IRAP assessment. An ASD-endorsed IRAP assessor evaluates your system against the ISM, documents the effectiveness of your controls and identifies residual risk. That assessment then supports the Commonwealth entity's own authorising officer in granting authorisation to operate. Two points I stress with every client:
- The IRAP assessor assesses; they do not authorise. The buying agency owns the risk decision. Your job is to give them a clean, well-evidenced package that makes saying yes easy.
- Do a readiness or internal assessment first. Walking into a formal IRAP assessment cold, hoping it goes well, is how contractors burn a tender window.
Step 6: Prepare for Incidents and Breach Notification
PROTECTED environments must be able to detect, respond to and report security incidents. Beyond the reporting expectations tied to government systems, the Notifiable Data Breaches scheme under the Privacy Act 1988 can also apply where eligible personal information is involved. You need an incident response plan that is written down, assigned to named people and, crucially, tested. An untested plan is a document, not a capability. Run tabletop exercises against realistic scenarios so that when something does happen, your team executes rather than improvises.
A Realistic Sequence and Timeline
| Phase | Focus | Typical duration |
|---|---|---|
| Governance and scoping | Accountable authority, risk framework, system boundary | 2 to 6 weeks |
| Gap assessment | Current state against the ISM and Essential Eight | 3 to 6 weeks |
| Remediation | Implement and document missing controls | 2 to 6 months |
| Personnel and physical | Clearances, facility, handling procedures | Runs in parallel, clearances longest |
| IRAP assessment | Independent assessment and reporting | 4 to 8 weeks |
| Authorisation | Agency risk decision and authorisation to operate | Agency dependent |
These are indicative ranges, not promises. The variables that move them most are how mature your Essential Eight posture already is and how disciplined your documentation is.
The Mistakes That Cost Contractors the Tender
- Starting clearances too late. They gate access and they are slow. Sponsor them the moment you know the roles.
- Assessing against an old ISM. The manual updates. Always work against the current release.
- A boundary that is too wide. Every extra system in scope is extra cost and extra risk of a finding.
- Controls that exist on paper only. Assessors test operation, not intention. If it is not logged and evidenced, it does not count.
- Treating PROTECTED as one-and-done. Authorisation has to be maintained. Drift is the enemy.
Where an External Partner Actually Helps
The honest answer is that most contractors do not need to become PROTECTED experts internally; they need to reach and sustain the state once, cleanly. That is where structured security leadership pays for itself. A virtual CISO can own the governance layer, drive the gap assessment, sequence remediation sensibly and prepare you for the IRAP assessment so it is a formality rather than a gamble. If your environment is cloud-based, cloud security consulting keeps the ISM controls aligned to how AWS or Azure actually implement them. I would rather a client spend on getting ready properly than spend twice fixing findings after a failed assessment.
Frequently Asked Questions
Is ACSC PROTECTED compliance mandatory for government contractors?
If you handle Australian Government information classified at PROTECTED, then yes, you must meet the applicable PSPF and ISM controls, and your system will generally need to be assessed and authorised before it goes live. The exact obligations flow from your contract and the agency's requirements.
What is the difference between the Essential Eight and PROTECTED?
The Essential Eight is a baseline set of eight mitigation strategies. PROTECTED is a classification level whose controls are drawn from the broader ISM, of which the Essential Eight forms a part. Being mature across the Essential Eight is necessary but not sufficient for PROTECTED work.
Do I need an IRAP assessment?
For systems handling PROTECTED information, an IRAP assessment by an ASD-endorsed assessor is the usual path to assurance. The assessor documents your control effectiveness; the Commonwealth entity's authorising officer makes the final risk decision.
Do my staff need security clearances?
Staff who access PROTECTED information generally need an appropriate Australian Government security clearance. Clearances take time to sponsor and process, so identify the roles and start early rather than treating it as a formality at the end.
How long does it take to become PROTECTED-ready?
It depends heavily on your starting posture. Organisations with a mature Essential Eight programme and disciplined documentation can move faster; those starting from a low base should plan for several months of remediation before an assessment, with personnel clearances often the longest single item.
Is PROTECTED a one-time certification?
No. Authorisation to operate must be maintained. Controls have to keep working, the environment has to stay within its assessed boundary, and material changes can require reassessment. Treat it as an ongoing obligation.
Getting Started
PROTECTED compliance rewards discipline and punishes wishful thinking. Establish governance, draw a tight boundary, implement and evidence the ISM controls, sort your people and facilities, then get assessed and authorised. Do it in that order and the assessment becomes confirmation rather than discovery. If you want an experienced partner to run the gap assessment and get you assessment-ready, get in touch.

Alexander Sverdlov
Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.