Skip to content
All insights
RFFR

The RFFR Accreditation Journey: Milestones, Timeframes and the Anniversary Date That Runs Everything

CHAIOS GRC Practitioner·Governance, risk & compliance
Share

RFFR is not a certificate you earn once and file away. It is a lifecycle — an initial accreditation earned across three milestones, followed by annual maintenance, followed by a full re-accreditation every three years. And the entire cadence is governed by a single date most providers underestimate: your accreditation anniversary.

This article maps the journey end to end — the categories that decide your path, the three milestones, the maintenance rhythm, the re-accreditation cycle, and every timeframe the Department holds you to. If you only take one thing away, make it this: know your anniversary date and count backwards from it.

The shape of the journey

The Department accredits providers under its External Systems Assurance Framework (ESAF), using the RFFR approach to gain assurance that data held outside its own ICT environment is properly protected. The path varies with your organisation type, risk profile and Deed, but the overall shape is consistent:

  1. Initial accreditation — complete a set of milestones, checking in with the Department at each, until accreditation is granted.
  2. Accreditation maintenance — prove annually that your ISMS is still operating and compliant.
  3. Re-accreditation — undergo a full renewal by the third anniversary of your initial accreditation.

It is a continuous lifecycle by design, which is exactly why RFFR demands a living ISMS rather than a point-in-time one.

First, your category decides your path

Before any milestone work, the Department classifies you — and your classification determines how much you have to do at every stage thereafter. Classification turns on caseload: the number of individuals receiving services across all your Deeds, counting the provider and any subcontractors together.

Category 1Category 2ACategory 2B
Annual caseload2,000 or moreUnder 2,000Under 2,000
Risk profileGreater riskMedium riskLow risk
Basis of accreditationISO 27001 ISMS, independently certifiedISO 27001 ISMS, self-assessedManagement Assertion Letter
Ongoing maintenanceAnnual surveillance audit + triennial recertificationAnnual self-assessmentAnnual management assertion letter
Milestones required1, 2 and 31, 2 and 31 and 3

A few things worth noting. Third Party Employment and Skills (TPES) system vendors are classified as Category 1. The split between 2A and 2B isn't caseload alone — the Department weighs risk factors including your IT environment, level of outsourcing, subcontracting arrangements, organisational structure, security maturity, and how much sensitive information you hold or how much access you have to departmental systems. And classification isn't permanent: if you enter new Deeds that change your caseload, the Department can reassess your category — and may require your accreditation to be updated if it shifts.

The three milestones

Milestone 1 — Scope and categorisation. Initiated by submitting an RFFR questionnaire to the Department, typically as part of your response to a Request for Proposal or Tender. The Department then conducts an interview, and the completion of that interview and categorisation activity is Milestone 1. You leave it knowing your category and your obligations.

Milestone 2 — Design. Here you demonstrate that your ISMS has been designed to reflect the RFFR requirements applicable to your category, and that appropriate controls are planned for implementation. This is a documentation submission — and it is mandatory to use the Department's own templates: the Scope document, the Statement of Applicability (SoA), and the Self-assessment template. You cannot substitute your own versions; tailored or modified templates won't be accepted. Note that Category 2B providers skip this milestone entirely and proceed straight to Milestone 3.

Milestone 3 — Implementation and accreditation. This milestone is about your progress toward conforming with ISO/IEC 27001 and actually implementing the controls applicable to your organisation, with priority on the controls supporting the RFFR core expectations. If some applicable controls aren't fully implemented at the point of submission, you must tell the Department when each will be in place and when any remaining non-conformances will be resolved — but be aware those gaps feed directly into the Department's assessment of your residual risk and its decision on whether to accredit you. Once the Department is satisfied your risks are being managed, it grants accreditation.

The date that accreditation is granted is the moment that sets everything that follows in motion.

The anniversary date: the spine of the whole lifecycle

When you achieve initial accreditation at Milestone 3, that date becomes your accreditation anniversary — and it governs the timing of every annual and three-yearly obligation from then on. Surveillance audits, self-assessments, attestation letters, re-accreditation: all of them are counted from this single date.

This is why losing track of your anniversary is one of the most avoidable ways to fall out of compliance. (If you don't know yours, the Department's security compliance team can confirm it — securitycompliancesupport@dewr.gov.au.)

Accreditation maintenance: the annual rhythm

Throughout the life of your Deeds, you maintain accreditation through annual reporting and audits, timed off your anniversary. The single most important timing rule:

Maintenance submissions are due six weeks before your anniversary date.

That six-week buffer exists so the Department can request further information if needed and the Accreditation Authority has time to review and approve. What you submit each year depends on your category:

  • Category 1 (and TPES vendors): a surveillance audit (or change-of-scope audit) by your Certification Assessment Body covering your updated SoA.
  • Category 2A: a self-assessment report — including a description of changes since your last report — covering your updated SoA. The Department also judges whether you need to upscale to a certified ISMS.
  • Category 2B: an annual Management Assertion Letter, including a description of changes since your last attestation. The Department judges whether you need to upscale to a self-assessed ISMS.

Two ongoing obligations sit underneath that annual submission. First, because ISM controls are regularly added and changed, your SoA must be kept current — and where a new or changed control is applicable but not yet fully implemented by your annual submission, your SoA needs to show the planned actions and an expected completion date for each. Second, you have a change-notification duty: if your circumstances change in a way that alters your risk profile, you must notify the Department within 5 business days. Triggers include entering a new Deed, changing your subcontracting arrangements, changing the third-party IT vendors supporting your environment, or moving from Category 2 to Category 1. Any of these may prompt the Department to reassess your accreditation.

Running quietly underneath all of it is the ISMS rhythm the Department never names but ISO 27001 requires: your internal audit programme and management reviews. Whichever category you sit in — including the self-assessed and attested ones — these are what produce the evidence that your ISMS is operating rather than merely documented, and they need to have actually happened before anyone comes looking.

What actually happens if you miss the timeframes

Providers ask this constantly and rarely get a straight answer, so here is the one the Workforce Australia Guidelines give — and it is not a warning letter.

If a Provider does not obtain accreditation or reaccreditation within the timeframes specified in the ESAF (including RFFR) or their Deed, the Provider must immediately cease using — and ensure any relevant Subcontractor ceases using — the relevant Provider IT System.

Read that again, because it is the sharpest sentence in the whole framework. The consequence of missing an accreditation deadline is not a penalty applied to you later. It is that you stop using your own systems, now, and so does your supply chain. For an organisation delivering employment services, that is not an administrative inconvenience — it is the business stopping.

There's a second timing rule in the same chapter that catches people at the other end of the lifecycle. Accreditation must be maintained for the duration of your Employment Deed or the period you retain access to personal information collected during delivery of employment services — whichever is later. Your obligation does not end when the Deed does. If you are still holding participant data, you are still accredited, or you should be.

Re-accreditation: the three-year renewal

Re-accreditation is the Department's continuing acceptance of your ISMS, and it must be completed by the third anniversary of your initial accreditation. The process commences once your second annual maintenance submission is approved, and the Department engages with you at the outset to confirm your category is still appropriate.

The submission timing mirrors maintenance — documents are due six weeks before the anniversary date. What you submit depends, again, on category:

  • Category 1 and TPES: ISMS Scope, SoA, your ISO/IEC 27001 stage-2 audit report (or DEWR ISMS Scheme report), your ISO/IEC 27001 certificate (or DEWR ISMS Scheme certificate), and a Corrective Actions Plan if applicable.
  • Category 2A: ISMS Scope, SoA, and an ISMS self-assessment report.
  • Category 2B: a Management Assertion Letter and SoA.

And here is the nuance that catches people: the date your re-accreditation is achieved becomes your new anniversary date. It does not necessarily land on your old one. From that point, your next maintenance is due within 12 months of the new date — and all future obligations re-base to it. Your anniversary can effectively move, and if you keep counting from the old date you'll mistime everything that follows.

A worked example

The Department's own example makes the cadence concrete. Picture a provider accredited on 20 September 2023:

  • Accreditation Maintenance 1 — documents submitted 9 August 2024 (six weeks before the 20 September anniversary); approved 20 September 2024.
  • Accreditation Maintenance 2 — documents submitted 9 August 2025 (six weeks prior); approved 20 September 2025.
  • Re-accreditation — documents submitted 9 August 2026 (six weeks before the third anniversary); re-accreditation achieved 28 August 2026.
  • The anniversary resets. 28 August 2026 is now the anniversary. The next maintenance follows it: documents submitted 17 July 2027 (six weeks before 28 August), approved 28 August 2027.

Notice how the anniversary shifted from 20 September to 28 August once re-accreditation completed. That shift is the whole point of the example — and the thing to watch in your own cycle.

RFFR Accreditation Lifecycle — Example Timeline

Key timeframes at a glance

TimeframeWhat it governs
6 weeks before your anniversaryDeadline to submit annual maintenance and re-accreditation documents
Within 5 business daysNotify the Department of any change in circumstance that alters your risk profile
AnnualMaintenance submission (audit / self-assessment / assertion letter, by category)
By the third anniversaryRe-accreditation must be completed
Within 12 months of the new dateNext maintenance after re-accreditation (anniversary re-bases to the re-accreditation date)

The bottom line

The RFFR accreditation journey is a lifecycle with a clear spine: earn it across three milestones, anchor everything to the anniversary date you're granted, submit six weeks ahead each year, notify within five business days when things change, and renew fully by the third anniversary — remembering that renewal can reset the anniversary itself.

Most providers who run into trouble don't fail on the security; they fail on the calendar — a missed six-week window, an unreported change, or a maintenance counted off a stale anniversary. Map the dates once, count backwards from your anniversary, and the journey becomes a rhythm you can actually keep.

References & sources

External sources are provided for reference and are maintained by their respective bodies. Always confirm current requirements against the official source.

About the author

CHAIOS GRC PractitionerGovernance, risk & compliance

Written by a governance, risk and compliance practitioner on the CHAIOS team who has run RFFR and ISO 27001 programmes end to end — from risk registers and Statements of Applicability to DEWR accreditation. These guides come from hands-on experience, not theory.