Right Fit For Risk · DEWR · ISM June 2026 · Employment Services

RFFR, built through the ISMS — not bolted on beside it.

Right Fit For Risk is an ISM Statement of Applicability delivered on an ISO 27001-aligned ISMS with Essential Eight uplift. We build that ISMS once and let it carry all three obligations — the 989 ISM controls, the 7 program-deed requirements, and (for Category 1) ISO 27001 certification — with every register living inside your Microsoft 365 tenant and the technical baseline assessed directly from it.

  • Full ISM June 2026 SoA — 989 controls
  • Built on an ISO 27001 ISMS backbone
  • Essential Eight uplift included (126 mapped controls)
  • 140 controls Microsoft-assessable (48 one-click today)
  • Data sovereignty — nothing leaves your tenant
Illustration of the RFFR Statement of Applicability delivered through an ISO 27001 ISMS

Why is RFFR right for me?

A 20-second self-check. RFFR is almost certainly your programme if any one of these describes you.

1

You deliver a DEWR employment or workforce program

You hold — or are bidding for — a deed to deliver Workforce Australia, Disability Employment Services (DES), ParentsNext, Transition to Work, the Community Development Program, Self-Employment Assistance or a similar DEWR service, and that deed requires cyber-security accreditation.

2

You handle participants' personal & sensitive information

You collect, store or process job-seeker records, health or disability details, income or identity data — OFFICIAL: Sensitive information — under a contract that requires it to stay in Australia. That includes subcontractors who touch that data on a head provider's behalf.

3

"Just get ISO 27001" or "just do the Essential Eight" didn't fit

You've been pointed at a generic framework and it doesn't match what the department is actually asking for. RFFR is assessed against the ISM — ISO 27001 or the Essential Eight on their own don't satisfy it. RFFR includes both and adds the ISM controls and the deed obligations on top.

Not sure whether a subcontract puts you in scope, or which category you fall into? That's the first thing we settle on a call — book 30 minutes and we'll tell you plainly, no pitch.

"We're a subcontractor, not the head provider — do we still need it?"

Usually yes. RFFR flows down the supply chain through the head provider's deed. If you handle Services data, you carry the obligation — and you can't transfer that risk to a third party.

"We already run Microsoft 365 — how much is already done?"

More than you'd expect. 48 ISM controls are assessed straight from your tenant, and with the Essential Eight band about 14% of the SoA is Microsoft-assessable. We start from what you already have.

"What happens if we're not accredited in time?"

RFFR is a contractual condition of the deed — accreditation runs to departmental milestones, then an ongoing maintenance period. Missing it puts the contract at risk, which is exactly why the milestone view prioritises the RFFR Core Expectations first.

"Will our data leave our environment?"

No. Every register lives in your own Microsoft 365 tenant and posture checks run in the browser — nothing is copied to a vendor platform. That directly supports RFFR's onshore-data obligation.

RFFR is one accreditation made of three registers

The department's SoA template stacks three obligations into a single Statement of Applicability. We deliver them as one cross-mapped control set on a shared ISMS, so a control implemented for one is evidenced for all.

7

RFFR Obligations

The program-deed requirements — positive identity confirmation, pre-employment and Working With Vulnerable People checks, right-to-work, IT administrators who are Australian citizens or permanent residents, and Services data that stays onshore. All flagged as RFFR Core Expectations.

989

ISM controls (June 2026)

Every ACSC ISM control applicable to Non-Classified and OFFICIAL: Sensitive information, across 22 guidelines — from cyber security roles through system hardening, cryptography and gateways. 86 are flagged RFFR Core Expectations for milestone prioritisation.

93

ISO 27001 Annex A

For Category 1 providers seeking independent certification — the 2022 Annex A control set, delivered as our existing ISO 27001 module. Category 2A providers skip this worksheet unless they choose to certify voluntarily.

How we build RFFR through the ISMS

RFFR isn't a separate rulebook to satisfy alongside your security programme — it is a security programme, expressed as an ISM SoA. So we build the management system first and let it produce the accreditation.

1. Stand up the ISMS

Scope and boundaries, information security policy, risk methodology and risk register, and the SoA itself — structured to ISO 27001 exactly as the RFFR template expects. This is the system of record every control status and piece of evidence hangs from.

2. Load the SoA as one register

All 989 ISM controls and 7 deed obligations become a single Statement of Applicability in your tenant — applicability decision, implementation status, evidence, plan, date and owner per control, with RFFR Core Expectations and Essential Eight maturity levels flagged for prioritisation.

3. Cross-map, don't duplicate

Every automatable ISM control carries a cross-reference to its ISO 27001 and Essential Eight equivalents. Implement MFA once and it evidences the ISM control, the ISO control and the E8 strategy together — so a Category 1 provider's certification falls out of the same work as the SoA.

4. Assess automatically, maintain continuously

Read-only Microsoft Graph checks assess the technical controls against your live tenant and propose a status a practitioner confirms with one click. An optional drift monitor re-runs them between milestones, so the posture you attest at accreditation is still true at your next review.

How much of the SoA Microsoft 365 assesses for you

We're deliberately honest about this — automation is a layer, not a silver bullet. The identity, hardening, logging, cryptography and backup controls map to live signals in your Microsoft tenant; the governance, personnel and physical controls are work a practitioner has to attest. We never count a manual control as a pass because a scan couldn't reach it.

48

auto-assessed today — controls a live Microsoft Graph check proposes a status for, confirmed with one click. No manual evidence gathering.

140

Microsoft-assessable (~14%) once the 126 Essential Eight-mapped controls in the bundled E8 module are included.

86

RFFR Core Expectations — prioritised first at every milestone, whether automated or manual.

Where the automation lands

ISM guidelineControlsAuto-assessed
system hardening 216 18
system management 56 8
security assurance 35 7
personnel security 49 6
enterprise mobility 45 3
email 25 2

See the full control library & automation matrix →

Who this is for

Category 1 providers

Larger providers who must address the RFFR Obligations, the full ISM control set and ISO 27001 Annex A, and obtain independent ISO 27001:2022 certification. One ISMS produces both the SoA and the certification.

Category 2A providers

Providers who address the RFFR Obligations and the ISM controls without mandatory ISO 27001 certification — the same SoA, the same automation, sized to the two worksheets that apply to you.

Subcontractors in the supply chain

Organisations delivering program services under a head provider whose deed flows RFFR down to them. An evidence-backed SoA — honest about gaps, with a credible plan — is what satisfies the department's review.

Common questions

What is RFFR, exactly?

DEWR's cyber-security accreditation for Employment Services providers. It's delivered as an ISM Statement of Applicability — the ISM controls for Non-Classified and OFFICIAL: Sensitive information plus obligations derived from the program deeds — on an ISO 27001-aligned ISMS.

How does it relate to ISO 27001 and the Essential Eight?

The SoA is structured like an ISO 27001 SoA and Category 1 providers certify to it; many ISM controls are the Essential Eight strategies restated, with ML1–ML3 mappings carried through. We deliver all three cross-mapped so nothing is done three times.

How much can Microsoft 365 assess automatically?

48 ISM controls are auto-assessed today from a live Graph check; with the 126 Essential Eight-mapped controls included, about 14% of the SoA is Microsoft-assessable. Governance, personnel and physical controls stay practitioner-assessed, and a manual result is never counted as a pass.

Where does our data live?

In your own Microsoft 365 tenant, full stop. No backend, no vendor database — the SoA and every register are SharePoint lists in your tenant, and posture checks never leave the browser. That directly supports RFFR's onshore-data obligation.

Category 1 or Category 2A — which am I?

It depends on your contract with the department and the scale of services. Category 1 addresses three worksheets and certifies to ISO 27001; Category 2A addresses two and certifies only if it chooses to. We confirm your category and scope the SoA to match on the first call.

We already have ISO 27001 — what's left?

A strong ISO 27001 ISMS carries much of the governance layer, but RFFR adds the prescriptive ISM technical controls and the deed obligations. We map your existing ISMS across so only the genuinely new ISM and RFFR-specific work gets done.

Does RFFR apply to subcontractors?

Yes — it flows down the supply chain through the head provider's deed. If you handle Services data on a provider's behalf you carry the obligation, and it can't be transferred to a third party. Each party addresses and evidences the applicable controls itself.

What are the milestones and how long does it take?

RFFR runs to departmental milestones building to accreditation, then an ongoing maintenance period. Timelines depend on your current maturity — an existing ISO 27001 or Essential Eight programme moves materially faster. RFFR Core Expectations are prioritised so the highest-risk gaps close first.

Related frameworks

RFFR is built on ISO 27001 and the Essential Eight, and shares its ISM control surface with the DISP / IRAP programme for organisations working across employment and defence government.

365 Free scoping tool

Get a realistic scope in 30 seconds

Three questions. Instant estimate including the third-party platform licence costs you'll avoid. No sign-up.

Pick one from each row to unlock

Keep reading — RFFR

Guides, checklists and case studies

Where do you actually stand against the ISM SoA?

A free 30-minute call gives you an honest read on your RFFR position — which category applies, how much of the 989-control SoA your Microsoft 365 tenant already evidences, and what a realistic path to accreditation looks like whether you're a Category 1 provider, a Category 2A provider, or a subcontractor inheriting the obligation.

Microsoft Teams