+61 3 9125 0439


    ➤  MELBOURNE | SYDNEY | BRISBANE | PERTH | CANBERRA | AUSTRALIA-WIDE  📞
+61 3 9125 0439

Right Fit For Risk (RFFR) Accreditation Australia

Get end-to-end Right Fit For Risk (RFFR) accreditation support stress-free with Cyber Forte, a leading cyber security company supporting organisations across Australia.

Trusted RFFR Accrediation Consultants in Australia

At Cyber Forte we deliver stress-free, end-to-end Right Fit For Risk (RFFR) accreditation including a powerful compliance tool at an affordable cost. Achieving Right Fit For Risk (RFFR) certification requires more than documentation – it demands structured risk management, board-level oversight, financial accountability, and aligned technical controls. As trusted  Right Fit For Risk (RFFR) accreditation consultants in Australia, Cyber Forte provides practical, regulator-aligned guidance to help organisations prepare with confidence and clarity.

Why choose Cyber Forte for RFFR Accreditation Support?

At Cyber Forte, we provide end-to-end  Right Fit For Risk (RFFR) accreditation and consulting services in Australia tailored to regulatory and government-aligned environments. Our team combines practical security expertise with compliance-driven guidance to help organisations achieve and maintain RFFR accreditation in Australia efficiently. We deliver  Right Fit For Risk (RFFR) accreditation services in Australia across Melbourne, Sydney, Brisbane, Perth, Tasmania, Canberra, Adelaide supporting organisations at every stage of their accreditation journey. 

Award-winning, Australian-owned cyber security company

We know Right Fit for Risk inside-out, making the journey clear, simple, and stress-free.

100% Success Rate

Clients who follow our structured process achieve certification on the first attempt, or we stand by our work with a money-back guarantee.

Expert-Led, AI-Powered Compliance Platform at No Extra Cost

Real-time compliance visibility, evidence collection, and action tracking to reduce ongoing manual effort.

End-to-End Certification

Gap assessment, implementation, documentation, certification, ongoing maintenance, and surveillance audits — full Right Fit for Risk lifecycle managed.

AI-Driven Accreditation with Expert Governance

With our AI powered compliance platform delivered by our team, we typically fast-track accreditation by ~50% with the fastest turnaround.

Fixed end-to-end pricing with no surprises.

With our fixed-price model for Right Fit for Risk certification cost in Australia, you get predictable costs, clear timelines, and no surprises.

End-to-End RFFR Accreditation Program

1. Gap Review & Milestone Roadmap

We begin with a comprehensive gap review to understand your current security posture and determine the required  Right Fit For Risk (RFFR) Milestones (1, 2, and 3) based on your assigned Provider Category (1, 2A, or 2B). Using the results, we create a clear roadmap outlining the specific controls you need to adopt, drawing from ISO/IEC 27001, the Australian Government Information Security Manual (ISM), and any additional RFFR-specific requirements.

2. Risk Assessment & Risk Treatment Planning

We conduct a detailed risk assessment and develop a risk treatment plan aligned with both ISO 27001 and ISM control frameworks. This is tailored to your operating model, the sensitivity of the data you handle, and the DEWR contract scope applicable to your organisation. The process includes defining scope and boundaries, selecting controls, and documenting supporting evidence in an audit-ready format.

3. Statement of Applicability (SoA) & Control Justification

We prepare your Statement of Applicability (SoA) using the official RFFR-approved template. This covers all relevant ISO 27001 Annex A controls, ISM requirements, and other contractual security obligations. We assist in determining control applicability, providing clear justifications for inclusion or exclusion, and ensuring the documentation meets assessment and audit expectations.

4. Compliance Automation

All controls and documentation are implemented and managed directly within our Compliance Manager platform. Policies, registers, evidence and repositories are centrally maintained, providing a streamlined experience without the need for additional tools or complex onboarding.

5. Category-Aligned Requirements & Milestones

The accreditation approach is aligned to the organisation’s RFFR provider category. Category 1 providers, typically associated with higher risk environments or larger caseloads, are required to implement a fully established Information Security Management System (ISMS), obtain independent ISO 27001 certification, and maintain a comprehensive Statement of Applicability (SoA) aligned with both ISO 27001 and Information Security Manual (ISM) controls. Category 2A and 2B providers, which generally operate in lower risk environments or have a more limited scope, may be permitted to complete certain milestones through self-assessment. However, they are still required to conduct formal risk assessments, maintain SoA alignment, and ensure compliance with applicable ISM and ISO security requirements.

6. Milestone Delivery Support

We support organisations through each stage of the required RFFR milestones. Milestone 1 focuses on establishing organisational context, conducting maturity assessments, completing required questionnaires, reviewing the IT environment, and defining the accreditation scope. Milestone 2 involves developing the Statement of Applicability (SoA), designing security controls aligned with ISO 27001 and ISM requirements, and preparing the necessary documentation for certification or self-assessment. Milestone 3 includes full implementation of the required controls, demonstrating operational effectiveness through supporting evidence, submitting the required reports, and ensuring the organisation is prepared for audit and accreditation verification.

7. Ongoing Accreditation & Continuous Support

Achieving  Right Fit For Risk (RFFR) accreditation is not the end. Ongoing obligations include periodic surveillance or self-assessments (annually or every three years, depending on category), updates to the SoA following ISM revisions, and changes driven by business growth or new services. We continue to work alongside you to ensure your accreditation remains current, effective, and aligned with DEWR’s evolving security expectations.

Benefits of Being Right Fit for Risk-Ready in Australia

Protect Registration & Funding

Demonstrate accreditation before regulators identify gaps.

Reduce Audit Findings

Structured preparation minimises compliance weaknesses.

ionicons-v5-d

Strengthen Governance

Enhance Board oversight, reporting, and accountability structures.

Improve Security Posture

Align systems with government cyber security expectations.

Increase Trust

Build credibility with regulators, participants, and stakeholders.

Access Government Opportunities

Position your organisation for contracts requiring security assurance.

Understanding Right Fit for Risk (RFFR) Provider Categorise

An organisation’s provider category determines the level of scrutiny applied during the assessment process. Low-risk providers are generally required to demonstrate basic governance structures, workforce background checks, and financial stability. Medium-risk providers must implement structured risk management frameworks and provide evidence of service quality and operational controls. High-risk providers are subject to more rigorous requirements, including comprehensive governance frameworks, well-maintained risk registers, strong financial sustainability, advanced security controls, and evidence of workforce capability. Cyber Forte assists organisations in identifying their appropriate category and preparing the necessary documentation to meet the applicable requirements.

The Principles and Key Structure of RFFR Accreditation

Governance

Controls establish clear Board oversight, structured reporting, strong policy frameworks, and defined accountability across the organisation.

Risk management

Controls focus on maintaining risk registers, implementing treatment plans, continuous monitoring, and formal incident management processes.

Workforce and organisational

Controls ensure appropriate screening, ongoing training, clearly defined responsibilities, and a strong culture of compliance.

Cyber security and technical

Controls include multi-factor authentication, encryption, access management, logging and monitoring, and structured incident response planning.

Client Engagement Process

01

Define Scope

We identify applicable RFFR requirements based on your services, funding arrangements, and risk category.

02

Gap Assessment

Cyber Forte conducts a comprehensive assessment against Right Fit for Risk (RFFR) governance, financial, workforce, and security expectations.

03

Framework Design & Documentation

We develop or uplift: • Risk management frameworks • Governance policies • Security documentation • Statement of Applicability (where applicable)

04

Implementation Support

We guide implementation across people, processes, and technology.

05

Internal Review & Audit Preparation

We perform structured readiness reviews and address non-conformities before external scrutiny.

06

Regulator & Audit Support

We support your organisation through RFFR audits and regulator engagement.

Frequently Asked Questions

Right Fit for Risk (RFFR) is the Australian Government's cyber security accreditation framework for organisations delivering services funded by the Department of Employment and Workplace Relations (DEWR). RFFR is based on ISO 27001 and the Australian Government Information Security Manual (ISM) and ensures an organisation's security controls are appropriate for the government data it handles.
Unlike ISO 27001, RFFR is a contractual requirement under a DEWR Services Deed rather than a voluntary certification. Organisations must obtain and maintain RFFR accreditation to deliver eligible DEWR-funded employment services.
Any organisation contracted to deliver DEWR-funded employment services must comply with Right Fit for Risk (RFFR). This also includes Third-Party Employment and Skills (TPES) system vendors whose systems connect to DEWR environments, as well as subcontractors providing services under a prime provider.
Even where subcontractors do not have a direct contract with DEWR, the prime provider remains responsible for ensuring they meet applicable RFFR requirements.
Yes. Right Fit for Risk (RFFR) is mandatory for organisations delivering services under a DEWR Services Deed.
Failure to achieve or maintain accreditation may result in contract breaches, funding restrictions, suspension of services, or the inability to continue delivering DEWR-funded employment programs.
Most organisations become RFFR assessment-ready within 6 to 10 weeks, depending on their existing cyber security maturity, provider category, and documentation.
Organisations with an existing ISO 27001 Information Security Management System (ISMS) or mature Essential Eight controls generally complete the process more quickly. Category 1 providers usually require additional time because they must complete an independent ISO 27001 certification audit.
The cost of Right Fit for Risk accreditation depends on your provider category, existing cyber security maturity, and whether independent ISO 27001 certification is required.
Category 2A and 2B organisations generally incur lower costs because they follow a self-assessment pathway, while Category 1 providers must complete independent certification. Organisations should also budget for annual maintenance activities to maintain accreditation.

DEWR assigns organisations to one of three provider categories.

CategoryAccreditation Requirement
Category 1ISO 27001 Certification and Independent Audit
Category 2ASelf-Assessment Report
Category 2BManagement Assertion Letter
The provider category is determined by DEWR through the Categorisation Questionnaire and is based on the organisation's risk profile and participant numbers.
Typical documentation includes:
  • Categorisation Questionnaire
  • Statement of Applicability (SoA)
  • Security Risk Management Plan (SRMP)
  • Risk Register
  • Risk Treatment Plan
  • Information Security Policies
  • Incident Response Plan
  • Access Control Policy
  • Evidence supporting implemented controls
  • ISO 27001 Certificate (Category 1 only)
The exact documentation requirements vary depending on the provider category.
The RFFR accreditation process consists of three milestones:
Milestone 1
  • Organisation profile
  • Categorisation Questionnaire
  • IT environment review
Milestone 2
  • Information Security Management System (ISMS)
  • Statement of Applicability
  • Risk Assessment
  • Security documentation
Milestone 3
  • Control implementation
  • Evidence collection
  • Independent audit (Category 1)
  • Self-assessment (Category 2A/2B)
DEWR reviews the submission before granting accreditation.
Right Fit for Risk accreditation requires ongoing annual maintenance.
  • Category 1: Annual surveillance audit
  • Category 2A: Annual ISMS Self-Assessment Report
  • Category 2B: Annual Management Assertion Letter
Your Statement of Applicability and supporting documentation should also be reviewed whenever the Australian Government Information Security Manual (ISM) or your business environment changes.
The most common reasons include:
  • Incomplete Statement of Applicability
  • Poor evidence collection
  • Outdated security documentation
  • Incomplete risk register
  • Weak governance
  • Missing management reviews
  • Treating RFFR as a one-time project instead of an ongoing Information Security Management System
A formal gap assessment before submission significantly reduces these risks.
It depends on your provider category.
Category 1 organisations must hold an independently certified ISO 27001 Information Security Management System (ISMS) as part of their RFFR accreditation.
Category 2A and Category 2B organisations generally follow a self-assessment pathway and are not required to obtain independent ISO 27001 certification, although they must still align with ISO 27001 controls.
Right Fit for Risk (RFFR)ISO 27001
Australian Government accreditationInternational information security standard
Mandatory for DEWR providersVoluntary unless contractually required
Based on ISO 27001 and the Australian Government ISMBased on ISO 27001 Annex A controls
Includes DEWR contractual obligationsGeneric information security framework
Annual maintenance requirementsAnnual surveillance audits by certification bodies
Organisations with ISO 27001 certification already have a strong foundation for Right Fit for Risk but must still address DEWR-specific and ISM requirements.
A Right Fit for Risk gap assessment compares your current information security controls against DEWR's RFFR requirements, ISO 27001 and the Australian Government ISM.
The assessment identifies compliance gaps, prioritises remediation activities and provides a roadmap to achieve RFFR accreditation efficiently.
Cyber Forte provides an end-to-end Right Fit for Risk consulting service, including:
  • RFFR Gap Assessments
  • ISO 27001 implementation
  • Information Security Manual (ISM) alignment
  • Statement of Applicability development
  • Security Risk Management Plans
  • Risk Assessments
  • Control implementation support
  • Internal audits
  • Audit readiness assessments
  • Ongoing annual compliance support
Our consultants combine practical cyber security expertise with an AI-powered compliance platform, helping organisations achieve and maintain Right Fit for Risk accreditation with confidence.
Ready To Safeguard Your Business?

Secure you business against evolving cyber threats with leading cyber security company in Australia.

EXPLORE MORE SERVICES

ISO 42001 Certification

Elevate your business’s credibility and client trust with ISO 42001 certification from Cyberforte, a leading ISO 42001 certification company in Melbourne, Australia.

SOC 2 Compliance

Fast Track SOC2 compliance end to end from Cyber Forte to scale your business and client trust.

Security Monitoring

In today’s rapidly evolving digital landscape, businesses face increasing cybersecurity threats, from data breaches to ransomware attacks.