Micheal Travis

RFFR and ESAF Changes: What Australian Government Service Providers Need to Know

Australian Government service providers must protect data and systems. They must also meet Right Fit For Risk (RFFR) and External Systems Assurance Framework (ESAF) rules. These rules help protect government systems, client details, and other private data.

What are RFFR and ESAF?

DEWR uses ESAF to set security rules for outside IT systems. These systems are used by service providers and their subcontractors. RFFR checks how well each provider manages cyber risk. It also checks whether key security controls are in place.

The updated ESAF starts on 1 October 2026. It uses a risk-based model. Each provider will receive an assurance category. The category will reflect its size, services, data, systems, and supply chain. Each provider must meet the core RFFR controls. Some providers will also need extra controls.

Key changes for service providers

  • Clear core controls: DEWR has updated the controls that apply to all providers.
  • Controls based on risk: Your assurance category will set any extra controls.
  • New documents: The Provider Security Plan replaces the old scope document. The PSP Annex replaces the RFFR Statement of Applicability.
  • Better detail: You must clearly list your systems, services, suppliers, and data use.
  • A wider model: The new category model aims to match the level of review to the level of risk.
  • Less focus on ISO 27001 for some providers: Some smaller providers may use more PSPF and ISM controls.

How ISO 27001 can help

ISO/IEC 27001:2022 gives you a strong base for security. It helps with risk, policies, controls, reviews, and audits. But an ISO 27001 certificate may not meet every RFFR rule. You must also meet DEWR needs. This may include ISM and PSPF controls. Your evidence must be clear and up to date.

How to get ready

  • Check your RFFR assurance category.
  • List the controls that apply to you.
  • Compare those controls with your current ISO 27001 and ISM work.
  • Find gaps in controls and proof.
  • List your systems, data flows, cloud services, suppliers, and IT partners.
  • Update your policies, risks, plans, and records.
  • Plan for reviews, incident reports, and major business changes.

How Forde Consulting can help

Forde Consulting turns RFFR and ESAF rules into clear tasks. We can review your current setup and find gaps. We can write your Provider Security Plan and PSP Annex. We can update old ISO 27001 documents. We can map ISM controls, plan fixes, and prepare your audit proof. We can also work with your own IT team or MSP.

Need help with RFFR or ESAF? Contact Forde Consulting. We can help you improve security, collect proof, and get ready for review.

 

Scroll to Top