Right Fit For Risk · DEWR · ISM June 2026 · Employment Services
Right Fit For Risk is an ISM Statement of Applicability delivered on an ISO 27001-aligned ISMS with Essential Eight uplift. We build that ISMS once and let it carry all three obligations — the 989 ISM controls, the 7 program-deed requirements, and (for Category 1) ISO 27001 certification — with every register living inside your Microsoft 365 tenant and the technical baseline assessed directly from it.
A 20-second self-check. RFFR is almost certainly your programme if any one of these describes you.
You hold — or are bidding for — a deed to deliver Workforce Australia, Disability Employment Services (DES), ParentsNext, Transition to Work, the Community Development Program, Self-Employment Assistance or a similar DEWR service, and that deed requires cyber-security accreditation.
You collect, store or process job-seeker records, health or disability details, income or identity data — OFFICIAL: Sensitive information — under a contract that requires it to stay in Australia. That includes subcontractors who touch that data on a head provider's behalf.
You've been pointed at a generic framework and it doesn't match what the department is actually asking for. RFFR is assessed against the ISM — ISO 27001 or the Essential Eight on their own don't satisfy it. RFFR includes both and adds the ISM controls and the deed obligations on top.
Not sure whether a subcontract puts you in scope, or which category you fall into? That's the first thing we settle on a call — book 30 minutes and we'll tell you plainly, no pitch.
Usually yes. RFFR flows down the supply chain through the head provider's deed. If you handle Services data, you carry the obligation — and you can't transfer that risk to a third party.
More than you'd expect. 48 ISM controls are assessed straight from your tenant, and with the Essential Eight band about 14% of the SoA is Microsoft-assessable. We start from what you already have.
RFFR is a contractual condition of the deed — accreditation runs to departmental milestones, then an ongoing maintenance period. Missing it puts the contract at risk, which is exactly why the milestone view prioritises the RFFR Core Expectations first.
No. Every register lives in your own Microsoft 365 tenant and posture checks run in the browser — nothing is copied to a vendor platform. That directly supports RFFR's onshore-data obligation.
The department's SoA template stacks three obligations into a single Statement of Applicability. We deliver them as one cross-mapped control set on a shared ISMS, so a control implemented for one is evidenced for all.
7
The program-deed requirements — positive identity confirmation, pre-employment and Working With Vulnerable People checks, right-to-work, IT administrators who are Australian citizens or permanent residents, and Services data that stays onshore. All flagged as RFFR Core Expectations.
989
Every ACSC ISM control applicable to Non-Classified and OFFICIAL: Sensitive information, across 22 guidelines — from cyber security roles through system hardening, cryptography and gateways. 86 are flagged RFFR Core Expectations for milestone prioritisation.
93
For Category 1 providers seeking independent certification — the 2022 Annex A control set, delivered as our existing ISO 27001 module. Category 2A providers skip this worksheet unless they choose to certify voluntarily.
RFFR isn't a separate rulebook to satisfy alongside your security programme — it is a security programme, expressed as an ISM SoA. So we build the management system first and let it produce the accreditation.
Scope and boundaries, information security policy, risk methodology and risk register, and the SoA itself — structured to ISO 27001 exactly as the RFFR template expects. This is the system of record every control status and piece of evidence hangs from.
All 989 ISM controls and 7 deed obligations become a single Statement of Applicability in your tenant — applicability decision, implementation status, evidence, plan, date and owner per control, with RFFR Core Expectations and Essential Eight maturity levels flagged for prioritisation.
Every automatable ISM control carries a cross-reference to its ISO 27001 and Essential Eight equivalents. Implement MFA once and it evidences the ISM control, the ISO control and the E8 strategy together — so a Category 1 provider's certification falls out of the same work as the SoA.
Read-only Microsoft Graph checks assess the technical controls against your live tenant and propose a status a practitioner confirms with one click. An optional drift monitor re-runs them between milestones, so the posture you attest at accreditation is still true at your next review.
We're deliberately honest about this — automation is a layer, not a silver bullet. The identity, hardening, logging, cryptography and backup controls map to live signals in your Microsoft tenant; the governance, personnel and physical controls are work a practitioner has to attest. We never count a manual control as a pass because a scan couldn't reach it.
48
auto-assessed today — controls a live Microsoft Graph check proposes a status for, confirmed with one click. No manual evidence gathering.
140
Microsoft-assessable (~14%) once the 126 Essential Eight-mapped controls in the bundled E8 module are included.
86
RFFR Core Expectations — prioritised first at every milestone, whether automated or manual.
| ISM guideline | Controls | Auto-assessed |
|---|---|---|
| system hardening | 216 | 18 |
| system management | 56 | 8 |
| security assurance | 35 | 7 |
| personnel security | 49 | 6 |
| enterprise mobility | 45 | 3 |
| 25 | 2 |
Larger providers who must address the RFFR Obligations, the full ISM control set and ISO 27001 Annex A, and obtain independent ISO 27001:2022 certification. One ISMS produces both the SoA and the certification.
Providers who address the RFFR Obligations and the ISM controls without mandatory ISO 27001 certification — the same SoA, the same automation, sized to the two worksheets that apply to you.
Organisations delivering program services under a head provider whose deed flows RFFR down to them. An evidence-backed SoA — honest about gaps, with a credible plan — is what satisfies the department's review.
DEWR's cyber-security accreditation for Employment Services providers. It's delivered as an ISM Statement of Applicability — the ISM controls for Non-Classified and OFFICIAL: Sensitive information plus obligations derived from the program deeds — on an ISO 27001-aligned ISMS.
The SoA is structured like an ISO 27001 SoA and Category 1 providers certify to it; many ISM controls are the Essential Eight strategies restated, with ML1–ML3 mappings carried through. We deliver all three cross-mapped so nothing is done three times.
48 ISM controls are auto-assessed today from a live Graph check; with the 126 Essential Eight-mapped controls included, about 14% of the SoA is Microsoft-assessable. Governance, personnel and physical controls stay practitioner-assessed, and a manual result is never counted as a pass.
In your own Microsoft 365 tenant, full stop. No backend, no vendor database — the SoA and every register are SharePoint lists in your tenant, and posture checks never leave the browser. That directly supports RFFR's onshore-data obligation.
It depends on your contract with the department and the scale of services. Category 1 addresses three worksheets and certifies to ISO 27001; Category 2A addresses two and certifies only if it chooses to. We confirm your category and scope the SoA to match on the first call.
A strong ISO 27001 ISMS carries much of the governance layer, but RFFR adds the prescriptive ISM technical controls and the deed obligations. We map your existing ISMS across so only the genuinely new ISM and RFFR-specific work gets done.
Yes — it flows down the supply chain through the head provider's deed. If you handle Services data on a provider's behalf you carry the obligation, and it can't be transferred to a third party. Each party addresses and evidences the applicable controls itself.
RFFR runs to departmental milestones building to accreditation, then an ongoing maintenance period. Timelines depend on your current maturity — an existing ISO 27001 or Essential Eight programme moves materially faster. RFFR Core Expectations are prioritised so the highest-risk gaps close first.
RFFR is built on ISO 27001 and the Essential Eight, and shares its ISM control surface with the DISP / IRAP programme for organisations working across employment and defence government.
Three questions. Instant estimate including the third-party platform licence costs you'll avoid. No sign-up.
Estimate based on typical engagement patterns. Precise scope confirmed on call after reviewing your environment.
Keep reading — RFFR
A free 30-minute call gives you an honest read on your RFFR position — which category applies, how much of the 989-control SoA your Microsoft 365 tenant already evidences, and what a realistic path to accreditation looks like whether you're a Category 1 provider, a Category 2A provider, or a subcontractor inheriting the obligation.
Hi! I’m the Compliance365 AI. I can help you work out which security or privacy framework you need, explain what’s involved, and answer questions about ISO 27001, SOC 2, Essential Eight, and more.
What can I help you with today?
Messages are sent to our AI assistant (Claude, by Anthropic) to generate a reply — not stored as part of your account and not used to train AI models.