Right Fit for Risk is what this test paragraph is about.
Right Fit for Risk (RFFR) Accreditation
Win and keep DEWR contracts
with RFFR accreditation.
Right Fit for Risk decides this bluntly: no accreditation, no contract.
The Department of Employment and Workplace Relations expects every provider handling job seeker and employer data to prove its security holds up through the Right Fit for Risk scheme. Specifically, that means milestone submissions, an ISM-mapped Statement of Applicability, and for larger providers, a certified ISO 27001 ISMS behind it all. In short, Cyber Compliance Pro handles the heavy lifting: we work out your category, close the gaps, build the evidence, and stay with you through every milestone until DEWR signs off.
to accredited provider —
milestone by milestone.
match the sensitivity of
the data you hold.
Right Fit for Risk: security scaled to your risk, not a fixed checklist.
Right Fit for Risk is DEWR's accreditation scheme for organisations delivering employment and skills services under its contracts. The name describes the logic: rather than holding a five-person community provider and a national network to identical requirements, the scheme sizes your obligations to your caseload and the sensitivity of the personal information moving through your systems. As a result, larger providers sit in Category One and must run a certified ISO 27001 management system with a Statement of Applicability built around the Australian Government Information Security Manual. Meanwhile, smaller providers follow a lighter Category Two pathway with self-assessment and management attestation.
Accreditation is earned across three milestone submissions, then kept alive through annual reporting to the department. Ultimately, missing a milestone or letting maintenance slide puts your deed on the line. Overall, Cyber Compliance Pro manages the whole arc — categorisation, gap closure, documentation, milestone submissions, and the yearly upkeep that follows.
Six stages from deed signing to accreditation
Typically, some clients come to us before their deed starts and want a clean run at the milestones. Instead, others arrive mid-scheme with a deadline looming and a gap list nobody has looked at in months. The engagement flexes either way.
Category & Scope Determination
Naturally, everything downstream depends on getting your category right. Then, we confirm where your caseload and data holdings place you, and what that means in dollars and effort.
- Caseload and data-sensitivity review
- Category One vs Two determination
- Accreditation scope agreed with your board
Gap Analysis Against the ISM
Specifically, we measure your current controls against the ISM requirements DEWR expects you to address, plus the ISO 27001 clauses if you're on the Category One pathway.
- ISM control gap register, prioritised
- Essential Eight maturity check
- Risk assessment across job seeker data flows
Documentation & Control Uplift
Then, we write the policy suite, the Statement of Applicability, and the risk treatment records DEWR wants to see — shaped around how your sites and staff actually operate.
- ISM-mapped Statement of Applicability
- Security policy and procedure suite
- Control implementation and hardening
Frontline Training & Rollout
Typically, employment services run on caseworkers, site managers, and shared systems. Ultimately, controls stick when those people know what changed and why it protects their clients.
- Awareness training tuned to frontline roles
- Site and process-owner briefings
- Evidence-capture habits built into daily work
Milestone Submissions & DEWR Liaison
Next, we prepare each milestone pack, sanity-check it against what assessors have pushed back on before, and handle the department's questions as they land.
- Milestone 1, 2 and 3 pack preparation
- Responses to assessor queries
- Certification audit support for Category One
Annual Maintenance & Re-accreditation
Right Fit for Risk isn't a one-off submission. In fact, annual reporting, surveillance audits, and the three-year recertification all need to happen on time, every time.
- Annual reporting pack and attestations
- Surveillance audit preparation
- Recertification planning well ahead of expiry
What accreditation does for your organisation
Job seekers hand your organisation some of the most sensitive information a person can share — health details, financial hardship, employment history. Essentially, RFFR is the department's way of making sure that trust is earned. Done well, it strengthens far more than a compliance file.
Deed Eligibility, Protected
Accreditation is written into DEWR deeds. As a result, holding it keeps your current contracts safe and keeps you in the room when new panels and tenders open up.
Job Seeker Data, Properly Guarded
Specifically, the controls RFFR demands close real attack paths — compromised caseworker accounts, unpatched site machines, third-party leaks — before they become notifiable breaches.
Built On Recognised Standards
Notably, RFFR borrows its backbone from the ISM and ISO 27001, so the work you do here carries over to other certifications and government requirements rather than duplicating them.
Risk Decisions You Can Defend
The scheme forces you to weigh what you hold, what could go wrong, and what treatment fits — and to record that reasoning where an assessor or regulator can follow it.
Subcontractor Assurance
In practice, if subcontractors touch deed data, their weaknesses become yours. Right Fit for Risk pushes assurance down the chain, so partner failures don't take your accreditation with them.
Credibility Beyond DEWR
Ultimately, an accreditation backed by independent assessment reassures boards, insurers, and other government funders that security at your organisation is managed, not assumed.
Three milestones, one evidence trail — built once, used everywhere.
RFFR accreditation moves through staged submissions: first your business context and security posture, then proof the management system is taking shape, and finally the full accreditation package. Every artefact below feeds at least one milestone — and most keep working for you at annual reporting time.
Request an RFFR Gap SnapshotMilestone One
Business Context & PostureMilestone Two
Management System ProgressMilestone Three
Full Accreditation PackageStatement of Applicability
Mapped To The ISMPolicy & Procedure Suite
Written For Your SitesRisk Register
Treatment Plans TrackedEssential Eight Uplift
Maturity Where It CountsAnnual Reporting Pack
Maintenance Without PanicFive stages from
deed to accreditation
Providers rarely fail RFFR because the controls are too hard. They fail because sequencing goes wrong — documentation written before scope is settled, or milestones prepared in a rush the week they're due. Here's the order that works.
Scheme Familiarisation
First, your leadership team learns what RFFR demands of your specific organisation — the category logic, the milestone deadlines in your deed, and who inside the business owns what.
Gap Analysis & Risk Assessment
Next, we benchmark your controls against the ISM and, for Category One, the ISO 27001 clauses — producing a prioritised gap register and a risk picture your board can act on.
Remediation & Documentation
Meanwhile, gaps get closed in priority order while the Statement of Applicability, policy suite, and evidence records take shape alongside them — never as an afterthought.
Milestones & Certification
Then, each milestone pack goes to DEWR reviewed and complete. Category One providers also clear their ISO 27001 Stage 1 and Stage 2 audits with our support on both sides.
Accreditation & Maintenance
Once accredited, the calendar takes over — annual reporting, surveillance audits, and recertification all scheduled and prepared long before their due dates.
Built for the way employment services actually run
Generic security consultants treat RFFR like any other framework and burn months learning the scheme on your invoice. We've done that learning already — the milestone quirks, the assessor expectations, the questions DEWR asks back.
Fluent In The Scheme Itself
Milestone structure, category thresholds, ISM mapping, DEWR's review habits — we work inside this scheme routinely, so you're not paying a consultant to read the guidance for the first time.
Sized To Your Category
A Category Two community provider shouldn't be sold a Category One program. Instead, we scope the engagement to your actual obligations, which usually costs less than clients expect.
One Build, Two Outcomes
For Category One providers, we design the ISMS so your ISO 27001 certificate and your RFFR accreditation come out of the same body of work — no parallel projects, no duplicated evidence.
Still Here After Milestone Three
The scheme's real test is year two, when the launch energy has faded and annual reporting comes due. Overall, we stay engaged so maintenance is routine, not a scramble.
Right Fit for Risk support across the provider network
From national providers managing Category One obligations to small community organisations working through self-assessment, the approach adjusts to your size and deed.
Services Providers
Employment Services
& RTOs
Not-For-Profits
& Consortia
Common questions,
clear answers
What providers usually want to know before committing to a Right Fit for Risk program.
The Department of Employment and Workplace Relations (DEWR) expects every provider handling job seeker and employer data to meet the Right Fit for Risk scheme. Requirements depend on your category and include milestone submissions, an ISM-mapped Statement of Applicability and, for larger providers, a certified ISO 27001 ISMS.
Typically, your deed sets the milestone deadlines, and they arrive faster than most providers expect. A Category Two self-assessment pathway can be completed in a few months with focused effort. Category One takes longer because a certified ISO 27001 management system has to be built and audited along the way — plan for six to twelve months depending on where your controls sit today and how many sites are in scope.
In short, Category One providers do — accreditation rests on a certified ISMS with a Statement of Applicability that addresses the ISM controls relevant to your services. Category Two providers don't need the certificate; they demonstrate their security posture through self-assessment and management attestation instead. If you're near the category boundary, we'll model both pathways before you commit budget to either.
Broadly, scale and sensitivity. Specifically, providers managing large caseloads sit in Category One and carry the fullest obligations, including independent certification. Smaller providers fall into Category Two, where the requirements are lighter and largely attestation-based. DEWR makes the final determination, but your caseload numbers and the nature of the data you handle tell you where you're likely to land — and we confirm this at the start of every engagement.
The Information Security Manual is the Australian Government's control framework, published by the Australian Signals Directorate. Specifically, RFFR uses it as the reference point for what "good" looks like: your Statement of Applicability maps your controls to the ISM requirements relevant to the services you deliver. Instead, you don't implement every control in the manual — you justify which apply, which don't, and why, in a way an assessor can verify.
Very likely, yes. Typically, lead providers are responsible for the security of deed data wherever it flows, so they pass RFFR obligations down through their subcontracting arrangements. What that means for you depends on your role and the data you touch — it might be a lighter attestation, or something closer to the full scheme. Overall, we help subcontractors meet their head contractor's requirements without over-building, and help lead providers set sensible requirements for their chains.
Annual upkeep. Specifically, each year you confirm to DEWR that your security posture still holds — updated attestations, a current Statement of Applicability, and evidence that the system is genuinely running. Additionally, Category One providers carry their ISO 27001 surveillance audits and the three-year recertification. As a result, we build this into a maintenance calendar at handover, so nothing surfaces as a surprise the week it's due.
Initially, milestone one was due in eight weeks and our IT manager was carrying the whole thing alone. Within a month we had a gap register we understood, a realistic plan, and someone who'd clearly dealt with the department before. Ultimately, all three milestones went through without a single rework request.
Milestone deadline
on the horizon?
In short, book a readiness call and we'll confirm your likely category, flag the gaps that would slow a submission down, and map a timeline that gets each milestone in on schedule.