Australian Government Architecture
Search

Hosting certification framework

Direct link: hostingcertification.gov.au
Responsible agency: Department of Home Affairs 
Last updated: March 2021

The Hosting certification framework provides guidance to Australian Government customers enabling them to identify and source hosting services that meet enhanced privacy, sovereignty and security requirements. 

The framework will continue to be iterated to ensure the Government’s commitment to data security can be met, and so Australians can have trust in government systems and the information they hold. 

Certification under the framework ensures service providers are offering secure services to their Australian Government customers. 

The Hosting certification framework is for: 

  • Australian Government customers procuring hosting arrangements for sensitive government data, whole-of-government systems and systems rated at the classification level of PROTECTED
  • service providers that deliver hosting services to Australian Government customers, including the facilities that host government data, their systems and supply chains.

There are three levels of certification: 

  • Strategic – represents the highest level of assurance and is only available to service providers that allow the government to specify ownership and control conditions.
  • Assured – provides safeguards against the change of ownership or control through financial penalties aimed at minimising the transition costs borne by the Commonwealth should a service alter their profile.
  • Uncertified – offers minimal protections to government. 

The framework supports the Protective security policy framework and the Information security manual

Applicability

Hosting certification framework requirements apply to new contracts and extensions to existing contracts from 30 June 2022.

Extensions to contracts with service providers awaiting certification are restricted to a maximum of 1 year, with the option of a 1-year extension.

Where certification of a service provider is pending, entities may apply for an exemption by emailing hostingcertifications@homeaffairs.gov.au

Access the framework

The hostingcertification.gov.au website hosts the Hosting certification framework (full text). 

Capabilities

This standard supports digital solutions in the following capability.
CAP28

Hosting

Strategies

This standard assists in supporting the following strategies.
STR11

Secure Cloud Strategy

Policies

This standard assists in meeting the requirements of the following policies.
POL25

Hosting policy

Was this information helpful?

Do not include any personal information. We are unable to respond to comments or feedback. If you would like a response, please email, or phone us. Our details are on the AGA contact page www.architecture.digital.gov.au/contact-us.