The Commonwealth compliance picture
Obligations reach you through the contract, not the statute
No Commonwealth framework regulates a private Canberra business directly. What happens is that an agency is bound, the agency binds its supplier, and the supplier binds its subcontractors — so a security schedule drafted for a department arrives in the inbox of a firm with one part-time bookkeeper and no information technology staff. The obligations are real and enforceable through the contract; the resourcing assumed behind them frequently is not.
PSPF: classification and handling
The Protective Security Policy Framework governs how Commonwealth information is valued, marked and protected across governance, information, personnel and physical domains. For a supplier the operative requirement is usually handling: recognising which material carries a classification, marking it consistently, and stopping it from being forwarded, downloaded or shared beyond its intended audience. Microsoft Purview sensitivity labels, data loss prevention policies and tenant-level external sharing restrictions are the mechanism, and they work only if the label taxonomy matches the markings your contract actually uses.
ISM: the technical control detail
The Information Security Manual, maintained by the Australian Signals Directorate, supplies the detailed controls sitting beneath those policy requirements — identity and authentication, cryptography, system hardening, event logging, media handling and gateway design among them. Suppliers are ordinarily asked to satisfy the specific controls named in their agreement rather than the entire manual, and the useful work is mapping those named controls onto Microsoft 365 and Azure features, implementing them, and recording which capability satisfies which control reference.
Essential Eight maturity as a contractual number
Contracts increasingly name a maturity level rather than a list of controls, which turns the Essential Eight into a commercial term. Application control, patching of applications and operating systems, Microsoft Office macro restrictions, user application hardening, restricted administrative privileges, multi-factor authentication and regular backups each carry level-specific expectations, and the gap between Maturity Level One and Maturity Level Two is far wider than the numbering suggests. We assess against each control, publish the honest position internally to you, and cost the uplift the contract requires.
IRAP, DISP and what we will not claim
IRAP is the Australian Signals Directorate's programme under which endorsed assessors evaluate systems against the Information Security Manual; the Defence Industry Security Program governs businesses working with Defence. Both are frequently invoked loosely in this market. To be explicit: Mycelium 365 does not claim IRAP assessment, DISP membership, security clearances or membership of any Commonwealth procurement panel on this page. We support clients who carry those obligations by building and evidencing the technical controls, and we identify the points at which an accredited or cleared third party is required.
Defence industry supply chain
Suppliers several tiers below a prime often discover their obligations only when an onboarding pack arrives. Our defence contractor guidance sets out how the information and communications technology domain is typically evidenced, and the Essential Eight baseline audit is the usual starting point because it establishes the true position before anyone commits to a date in a response.
Because Canberra buyers are rightly sceptical of unverifiable provider claims, the one certification we do hold is stated plainly with its issuer and number so it can be checked. Our own information security management system is certified to ISO/IEC 27001:2022 (QAS International, certificate AIT1045), covering the managed IT, cloud, cybersecurity and helpdesk services we deliver to clients. See our certifications.