The Protective Security Policy Framework mandates Maturity Level 2 for non-corporate Commonwealth entities, not for their suppliers. Those entities pass the same bar down their supply chain, so suppliers meet Essential Eight requirements through contract clauses and tender conditions. The position that matters is your current maturity level, established and evidenced before a clause asks for it.
The Protective Security Policy Framework (PSPF) mandates that non-corporate Commonwealth entities — federal departments and agencies under the PGPA Act — reach Essential Eight Maturity Level 2. That mandate applies to the entities themselves. No policy instrument binds a supplier directly.
What reaches a supplier is a contract. Entities responsible for their own security posture extend requirements to the suppliers who hold their data, run their systems or operate inside their processes, so the Essential Eight arrives as a tender condition, a schedule in a services agreement, or a renewal clause absent from the previous version. Legally it operates as ordinary contract law, and in substance it is the PSPF’s Maturity Level 2 bar translated into commercial terms.
The Essential Eight itself is published by the Australian Signals Directorate through the Australian Cyber Security Centre at cyber.gov.au: eight mitigation strategies — application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, regular backups — each assessed at Maturity Levels 0 to 3.
Clauses vary more than the framework does. They fall into three forms.
| Clause form | What it says | What a defensible answer contains |
|---|---|---|
| Named maturity level | “The supplier must maintain Essential Eight Maturity Level 2” | An assessment establishing that level, plus operating evidence that it still holds |
| Unnamed compliance | “The supplier must comply with the ACSC Essential Eight” | Your current maturity level, stated per strategy, with the assessment behind it, plus a clarification question to the buyer, since compliance without a level is ambiguous |
| Assurance-specified | “…verified by an independent assessment” or “…by an IRAP assessor” | The named form of assurance, budgeted and scheduled. A self-assessment does not substitute where independence is specified |
Clauses appear at renewal as well as in new tenders. Agreements silent on the Essential Eight one term ago return with a schedule that names it, and a renewal carries less lead time than a tender, because the incumbent relationship makes an eighteen-month uplift a harder position to hold than it would be at bid stage. Where government revenue is material to the plan, the least expensive time to establish a maturity level is between contracts.
Three conditions make these clauses answerable.
A maturity level established in advance. Assessment against ASD’s published Essential Eight assessment process can be a self-assessment, an IRAP assessor, or a private consultancy or MSP. There is no single central provider, and the clause determines which is required. Overall maturity is the lowest level across the eight strategies, so a single weak strategy sets the number that goes into the response.
Evidence maintained continuously. A maturity level is an operating state rather than a certificate. Patch timeframes, MFA coverage, privilege reviews and backup tests decay once nobody runs them, and government clauses survive into the contract, where the buyer can require a demonstration mid-term rather than only at signature. Secure60 is ISO 27001:2022 certified and answers these clauses about its own platform routinely; the ones that resolve quickly are the ones where the evidence already exists.
The named level treated as a standing capability. The requirement reflects the buyer’s PSPF obligation, so it is rarely negotiable. Suppliers who hold Maturity Level 2 continuously answer each new clause from file rather than running a project per tender. Our governance capability maintains that posture between contracts.
Suppliers frequently respond with the material that works on commercial questionnaires — a security policy, an ISO certificate, a completed spreadsheet. None of it addresses a question denominated in maturity levels. The Essential Eight is technical: either unapproved executables are blocked or they are not, and either patches landed inside the timeframe or they did not. An evaluator working from ASD’s assessment process examines the controls beneath the documents.
The suppliers who lose time on this are rarely the insecure ones. They are the ones who establish the difference between holding security controls and holding Maturity Level 2 inside a contract window rather than before it.
Secure60 runs the maturity uplift and operates the controls behind it. For government suppliers that means establishing your current maturity level, running the uplift to the level your contracts name, and keeping the operating evidence current through our governance capability so each new clause is answered from file. Commercials are scoped to the engagement — book a readiness call and bring the contract.
Does the PSPF apply to us as a supplier?
Not directly. The PSPF binds non-corporate Commonwealth entities — federal departments and agencies. What reaches a supplier is contractual: those entities write Essential Eight requirements into their agreements and tenders, and that clause binds you as any contract term does.
Which maturity level do government contracts usually ask for?
Maturity Level 2 is the common reference point, because it is the level the PSPF mandates for the entities themselves. Contracts vary — some name Maturity Level 1, and some say ‘Essential Eight compliance’ without a level. Where the clause is ambiguous, a clarification question to the buyer resolves it.
Do we need an IRAP assessment to supply government?
Only where the contract requires it. IRAP assessors are ASD-endorsed and used where formal independent assurance is required, particularly for OFFICIAL and PROTECTED environments. Many supplier clauses accept a self-assessment against ASD’s assessment process with supporting evidence.
We're ISO 27001 certified. Does that cover the Essential Eight clause?
No. The two overlap, but ISO 27001 certifies a management system while the Essential Eight is a specific set of technical mitigation strategies with maturity levels. A clause naming a maturity level requires an Essential Eight answer — see ISO 27001 or Essential Eight.
What evidence should we keep on file?
An assessment report — independent or self-assessed against ASD’s published process — plus the operating evidence behind it: patch records against timeframes, MFA coverage, privileged-account registers, backup restore tests. The assessment establishes the level; the operating evidence keeps it current.