Right Fit for Risk is what this test paragraph is about.

Home / Services / Right Fit for Risk (RFFR)

Right Fit for Risk (RFFR) Accreditation

Win and keep DEWR contracts
with RFFR accreditation.

Right Fit for Risk decides this bluntly: no accreditation, no contract.

The Department of Employment and Workplace Relations expects every provider handling job seeker and employer data to prove its security holds up through the Right Fit for Risk scheme. Specifically, that means milestone submissions, an ISM-mapped Statement of Applicability, and for larger providers, a certified ISO 27001 ISMS behind it all. In short, Cyber Compliance Pro handles the heavy lifting: we work out your category, close the gaps, build the evidence, and stay with you through every milestone until DEWR signs off.

Quick answer: Right Fit for Risk (RFFR) is an assessment framework used by Australian government suppliers (particularly DEWR providers) to apply security controls proportionate to actual risk. It requires milestone submissions, an ISM-mapped Statement of Applicability, and often a certified ISO 27001 ISMS for larger providers.
Aligned frameworks
DEWR RFFR ISM Controls Essential Eight ISO/IEC 27001:2022 Privacy Act NDB Scheme
DEWR RFFR
Engagement outcome
From category decision
to accredited provider —
milestone by milestone.
Statement of Applicability
MAPPED TO THE ISM
Category 1 & 2 Pathways
SCOPED TO YOUR CASELOAD
Three Milestones
TRACKED & SUBMITTED
M1 M3 RFFR MILESTONE PROGRESS
What accreditation proves
Security controls that
match the sensitivity of
the data you hold.
What RFFR actually asks of you

Right Fit for Risk: security scaled to your risk, not a fixed checklist.

Right Fit for Risk is DEWR's accreditation scheme for organisations delivering employment and skills services under its contracts. The name describes the logic: rather than holding a five-person community provider and a national network to identical requirements, the scheme sizes your obligations to your caseload and the sensitivity of the personal information moving through your systems. As a result, larger providers sit in Category One and must run a certified ISO 27001 management system with a Statement of Applicability built around the Australian Government Information Security Manual. Meanwhile, smaller providers follow a lighter Category Two pathway with self-assessment and management attestation.

Accreditation is earned across three milestone submissions, then kept alive through annual reporting to the department. Ultimately, missing a milestone or letting maintenance slide puts your deed on the line. Overall, Cyber Compliance Pro manages the whole arc — categorisation, gap closure, documentation, milestone submissions, and the yearly upkeep that follows.

3
Accreditation Milestones
2
Provider Categories
12mo
Reporting Cadence
3yr
Recertification Cycle
What's included

Six stages from deed signing to accreditation

Typically, some clients come to us before their deed starts and want a clean run at the milestones. Instead, others arrive mid-scheme with a deadline looming and a gap list nobody has looked at in months. The engagement flexes either way.

01 · CATEGORISE

Category & Scope Determination

Naturally, everything downstream depends on getting your category right. Then, we confirm where your caseload and data holdings place you, and what that means in dollars and effort.

  • Caseload and data-sensitivity review
  • Category One vs Two determination
  • Accreditation scope agreed with your board
02 · ASSESS

Gap Analysis Against the ISM

Specifically, we measure your current controls against the ISM requirements DEWR expects you to address, plus the ISO 27001 clauses if you're on the Category One pathway.

  • ISM control gap register, prioritised
  • Essential Eight maturity check
  • Risk assessment across job seeker data flows
03 · BUILD

Documentation & Control Uplift

Then, we write the policy suite, the Statement of Applicability, and the risk treatment records DEWR wants to see — shaped around how your sites and staff actually operate.

  • ISM-mapped Statement of Applicability
  • Security policy and procedure suite
  • Control implementation and hardening
04 · EMBED

Frontline Training & Rollout

Typically, employment services run on caseworkers, site managers, and shared systems. Ultimately, controls stick when those people know what changed and why it protects their clients.

  • Awareness training tuned to frontline roles
  • Site and process-owner briefings
  • Evidence-capture habits built into daily work
05 · SUBMIT

Milestone Submissions & DEWR Liaison

Next, we prepare each milestone pack, sanity-check it against what assessors have pushed back on before, and handle the department's questions as they land.

  • Milestone 1, 2 and 3 pack preparation
  • Responses to assessor queries
  • Certification audit support for Category One
06 · MAINTAIN

Annual Maintenance & Re-accreditation

Right Fit for Risk isn't a one-off submission. In fact, annual reporting, surveillance audits, and the three-year recertification all need to happen on time, every time.

  • Annual reporting pack and attestations
  • Surveillance audit preparation
  • Recertification planning well ahead of expiry
Why it matters

What accreditation does for your organisation

Job seekers hand your organisation some of the most sensitive information a person can share — health details, financial hardship, employment history. Essentially, RFFR is the department's way of making sure that trust is earned. Done well, it strengthens far more than a compliance file.

Contracts

Deed Eligibility, Protected

A Condition Of Doing Business

Accreditation is written into DEWR deeds. As a result, holding it keeps your current contracts safe and keeps you in the room when new panels and tenders open up.

Protection

Job Seeker Data, Properly Guarded

Sensitive Personal Information

Specifically, the controls RFFR demands close real attack paths — compromised caseworker accounts, unpatched site machines, third-party leaks — before they become notifiable breaches.

Alignment

Built On Recognised Standards

ISM · ISO 27001 · Essential Eight

Notably, RFFR borrows its backbone from the ISM and ISO 27001, so the work you do here carries over to other certifications and government requirements rather than duplicating them.

Risk

Risk Decisions You Can Defend

Proportionate By Design

The scheme forces you to weigh what you hold, what could go wrong, and what treatment fits — and to record that reasoning where an assessor or regulator can follow it.

Supply Chain

Subcontractor Assurance

Your Risk, Their Systems

In practice, if subcontractors touch deed data, their weaknesses become yours. Right Fit for Risk pushes assurance down the chain, so partner failures don't take your accreditation with them.

Confidence

Credibility Beyond DEWR

Boards, Funders & Partners

Ultimately, an accreditation backed by independent assessment reassures boards, insurers, and other government funders that security at your organisation is managed, not assumed.

What the scheme covers

Three milestones, one evidence trail — built once, used everywhere.

RFFR accreditation moves through staged submissions: first your business context and security posture, then proof the management system is taking shape, and finally the full accreditation package. Every artefact below feeds at least one milestone — and most keep working for you at annual reporting time.

Request an RFFR Gap Snapshot

Milestone One

Business Context & Posture

Milestone Two

Management System Progress

Milestone Three

Full Accreditation Package

Statement of Applicability

Mapped To The ISM

Policy & Procedure Suite

Written For Your Sites

Risk Register

Treatment Plans Tracked

Essential Eight Uplift

Maturity Where It Counts

Annual Reporting Pack

Maintenance Without Panic
Our methodology

Five stages from
deed to accreditation

Providers rarely fail RFFR because the controls are too hard. They fail because sequencing goes wrong — documentation written before scope is settled, or milestones prepared in a rush the week they're due. Here's the order that works.

01
Orient

Scheme Familiarisation

First, your leadership team learns what RFFR demands of your specific organisation — the category logic, the milestone deadlines in your deed, and who inside the business owns what.

02
Assess

Gap Analysis & Risk Assessment

Next, we benchmark your controls against the ISM and, for Category One, the ISO 27001 clauses — producing a prioritised gap register and a risk picture your board can act on.

03
Build

Remediation & Documentation

Meanwhile, gaps get closed in priority order while the Statement of Applicability, policy suite, and evidence records take shape alongside them — never as an afterthought.

04
Submit

Milestones & Certification

Then, each milestone pack goes to DEWR reviewed and complete. Category One providers also clear their ISO 27001 Stage 1 and Stage 2 audits with our support on both sides.

05
Sustain

Accreditation & Maintenance

Once accredited, the calendar takes over — annual reporting, surveillance audits, and recertification all scheduled and prepared long before their due dates.

Why work with us

Built for the way employment services actually run

Generic security consultants treat RFFR like any other framework and burn months learning the scheme on your invoice. We've done that learning already — the milestone quirks, the assessor expectations, the questions DEWR asks back.

Fluent In The Scheme Itself

Milestone structure, category thresholds, ISM mapping, DEWR's review habits — we work inside this scheme routinely, so you're not paying a consultant to read the guidance for the first time.

Sized To Your Category

A Category Two community provider shouldn't be sold a Category One program. Instead, we scope the engagement to your actual obligations, which usually costs less than clients expect.

One Build, Two Outcomes

For Category One providers, we design the ISMS so your ISO 27001 certificate and your RFFR accreditation come out of the same body of work — no parallel projects, no duplicated evidence.

Still Here After Milestone Three

The scheme's real test is year two, when the launch energy has faded and annual reporting comes due. Overall, we stay engaged so maintenance is routine, not a scramble.

Who we help

Right Fit for Risk support across the provider network

From national providers managing Category One obligations to small community organisations working through self-assessment, the approach adjusts to your size and deed.

Employment
Services Providers
Disability
Employment Services
Skills, Training
& RTOs
Community &
Not-For-Profits
Subcontractors
& Consortia
Frequently asked

Common questions,
clear answers

What providers usually want to know before committing to a Right Fit for Risk program.

The Department of Employment and Workplace Relations (DEWR) expects every provider handling job seeker and employer data to meet the Right Fit for Risk scheme. Requirements depend on your category and include milestone submissions, an ISM-mapped Statement of Applicability and, for larger providers, a certified ISO 27001 ISMS.

Typically, your deed sets the milestone deadlines, and they arrive faster than most providers expect. A Category Two self-assessment pathway can be completed in a few months with focused effort. Category One takes longer because a certified ISO 27001 management system has to be built and audited along the way — plan for six to twelve months depending on where your controls sit today and how many sites are in scope.

In short, Category One providers do — accreditation rests on a certified ISMS with a Statement of Applicability that addresses the ISM controls relevant to your services. Category Two providers don't need the certificate; they demonstrate their security posture through self-assessment and management attestation instead. If you're near the category boundary, we'll model both pathways before you commit budget to either.

Broadly, scale and sensitivity. Specifically, providers managing large caseloads sit in Category One and carry the fullest obligations, including independent certification. Smaller providers fall into Category Two, where the requirements are lighter and largely attestation-based. DEWR makes the final determination, but your caseload numbers and the nature of the data you handle tell you where you're likely to land — and we confirm this at the start of every engagement.

The Information Security Manual is the Australian Government's control framework, published by the Australian Signals Directorate. Specifically, RFFR uses it as the reference point for what "good" looks like: your Statement of Applicability maps your controls to the ISM requirements relevant to the services you deliver. Instead, you don't implement every control in the manual — you justify which apply, which don't, and why, in a way an assessor can verify.

Very likely, yes. Typically, lead providers are responsible for the security of deed data wherever it flows, so they pass RFFR obligations down through their subcontracting arrangements. What that means for you depends on your role and the data you touch — it might be a lighter attestation, or something closer to the full scheme. Overall, we help subcontractors meet their head contractor's requirements without over-building, and help lead providers set sensible requirements for their chains.

Annual upkeep. Specifically, each year you confirm to DEWR that your security posture still holds — updated attestations, a current Statement of Applicability, and evidence that the system is genuinely running. Additionally, Category One providers carry their ISO 27001 surveillance audits and the three-year recertification. As a result, we build this into a maintenance calendar at handover, so nothing surfaces as a surprise the week it's due.

"

Initially, milestone one was due in eight weeks and our IT manager was carrying the whole thing alone. Within a month we had a gap register we understood, a realistic plan, and someone who'd clearly dealt with the department before. Ultimately, all three milestones went through without a single rework request.

KM
General Manager Employment Services · Regional NSW

Milestone deadline
on the horizon?

In short, book a readiness call and we'll confirm your likely category, flag the gaps that would slow a submission down, and map a timeline that gets each milestone in on schedule.