Government Security

PSPF Reporting Made Practical: Preparing Your Annual Protective Security Self-Assessment

A practical guide to the PSPF annual self-assessment: how maturity is judged, the evidence that matters, and how to turn PSPF reporting into genuine security improvement.

Muhammad Anwar
· 3 min read

For many Commonwealth entities, PSPF reporting arrives every year with the same scramble: chasing evidence, debating maturity ratings and drafting the narrative at the last minute. It doesn’t have to be that way. Handled well, the Protective Security Policy Framework self-assessment becomes the annual health check that drives your security roadmap.

What the PSPF covers

The Protective Security Policy Framework sets out the Australian Government’s protective security policy across four outcomes:

  • Security governance — accountability, planning, risk management and reporting.
  • Information security — classification, access, and the cybersecurity controls that point to the ISM.
  • Personnel security — eligibility, suitability and ongoing assessment of people.
  • Physical security — protecting people, information and assets in facilities.

Entities assess their maturity against the framework’s requirements and report annually. The specific requirements and maturity scale are updated from time to time, so always work from the current release.

Why PSPF reports go wrong

The most common problems aren’t about security at all — they’re about process:

  • Self-ratings without evidence. A “managing” or “embedded” rating that nobody can substantiate won’t survive scrutiny.
  • Security team does everything. Physical and personnel security owners aren’t engaged until the final week.
  • No link to risk. The report describes activity, not whether the most important risks are being managed.
  • Last year’s findings ignored. The same gaps reappear because nobody owned the actions.

A year-round approach

The organisations that find PSPF reporting easy treat it as a cycle, not an event:

  1. Map every requirement to a named owner at the start of the year — across governance, information, personnel and physical security.
  2. Agree what evidence looks like for each maturity level, so owners know what “good” means.
  3. Track actions from last year’s report in your risk or project register, not in a document nobody reopens.
  4. Hold a short quarterly check-in with owners to review progress and collect evidence as you go.
  5. Draft the narrative early, linked to your security plan and top risks.
  6. Brief the accountable executive well before sign-off, so the report reflects a decision, not a surprise.

Accountability is the first thing assessors look for — and it’s the fastest maturity win available to most entities.

Linking PSPF and the ISM

The information security outcome of the PSPF relies heavily on ISM compliance. If your cyber controls, System Security Plans and authorisations are in good shape, much of the information security evidence already exists. The trick is to collect it once and reuse it for both.

Turning the report into a roadmap

The most valuable output of PSPF reporting isn’t the report — it’s the prioritised list of improvements. A good roadmap:

  • Focuses on the few requirements where improvement reduces the most risk.
  • Assigns owners, budgets and dates.
  • Is reviewed by your security governance committee through the year.
  • Becomes the starting point for next year’s assessment.

Frequently asked questions

Who has to report against the PSPF?

PSPF requirements apply to non-corporate Commonwealth entities, and many other government bodies adopt it as better practice. Check the current PSPF policy for which entities must report and when.

How do I decide our maturity level?

Assess each requirement against the current PSPF maturity criteria using evidence, not opinion. Where views differ, an independent review or facilitated workshop helps reach a defensible rating.

Can an external advisor help with PSPF reporting?

Yes. An independent assessor can validate ratings, review evidence, identify quick wins and help draft a report that stands up to scrutiny — while your accountable executive retains ownership of the result.


Preparing for your next PSPF report? See government assurance services or talk to my AI agent.

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader specialising in the ISM, PSPF, NIST SP 800-53, SOCI Act and AI governance (ISO 42001). Views are my own.