Released 2 September 2026 · Voluntary frameworkSix chapters · sourced

Australia's new Industry Data Classification Framework explained for business

On 2 September 2026 the Department of Home Affairs, with CSIRO's Data61, released the Industry Data Classification Framework (IDCF). It gives Australian organisations of every size a common way to assess, classify and communicate the value of their data through Data Security Levels. This guide covers what the framework is, its four modules, how the levels work, and how it fits with the Essential Eight, SMB1001, ISO 27001 and Privacy Act work you may already have underway.

Summarised from the Home Affairs IDCF publication under CC BY 4.0. Not legal advice.

Four modules

Introduction, Risk Assessment, DSLs, Markers

DSL-0 to DSL-5+

One label any recipient understands

Voluntary, Strategy Shield 2

Adoption support through Horizon 2

Editorially reviewed
Last reviewed7 Sep 2026
Sources verified7 Sep 2026
Industry Data Classification Framework official mark

The official IDCF mark. Diagrams on this page are reproduced from the Home Affairs publication under CC BY 4.0. Read the source document: Industry Data Classification Framework (PDF, Department of Home Affairs).

IDCF diagram: a risk assessment block asking what needs protection and how severe and likely an adverse event would be, feeding an assessed inherent risk level into a data classification block that assigns a Data Security Level from a DSL-0 to DSL-5+ pyramid

The IDCF in three steps

Understand the asset. Assess the risk. Assign a level.

Every module in the framework serves one of these three steps. If you remember nothing else, remember the order.

  1. 01

    Understand the data asset

    What it is, who it is about, how much of it there is, and whether time makes it more or less sensitive.

  2. 02

    Assess consequence, impact and likelihood

    What happens to individuals, assets, operations and the organisation if the data is lost, altered, exposed or unavailable.

  3. 03

    Assign a Data Security Level

    One label that tells every recipient how to store, handle and share the data. Optional markers add context on top.

01

Released 2 September 2026

Australia now has a common language for classifying business data.

Voluntary, modular, and written for organisations of every size.

The Industry Data Classification Framework (IDCF) was released by the Department of Home Affairs on 2 September 2026, developed with CSIRO's Data61. It gives Australian organisations a consistent way to understand the value of the data they hold, assess the risk attached to it, classify it, and communicate that classification to anyone who receives it. It is voluntary. It does not replace the Privacy Act, Essential Eight, SMB1001 or ISO 27001. It sits underneath them and gives you the vocabulary they all assume you already have.

01

What it is

Comprehensive industry guidance for identifying, assessing, classifying and communicating the value of data holdings. It covers electronic data, the systems and devices that carry it, and can be applied to physical copies as well.

Source · IDCF overview, Home Affairs
02

Who built it

The Department of Home Affairs (Technology Security Policy Branch) in partnership with CSIRO's Data61, drawing on research and consultation with industry across Australia.

Source · CSIRO partner release
03

Who it is for

Any Australian organisation, from a small business to a large enterprise. Home Affairs describes it as designed to work whether you are just starting your data security journey or already have mature handling practices.

04

What it is not

It is not legislation, not a certification, and not legal advice. Home Affairs is explicit that publication does not constitute endorsement for specific circumstances and that users must make their own determination about appropriate use.

02

Why the government built it

A Cyber Security Strategy deliverable, now moving into the adoption phase.

Shield 2 of the 2023-2030 Strategy. Horizon 2 is about getting industry to use it.

The IDCF is a named measure under Shield 2 of the 2023-2030 Australian Cyber Security Strategy. The framework itself is Horizon 1 work. Under Horizon 2 (2026 to 2028), Home Affairs has committed to working with industry to support adoption and to keep the framework current against the threat landscape. Expect it to start appearing in procurement questionnaires, supplier standards and insurer conversations before it appears in law.

01

The stated aims

Provide guidance on how to identify, assess, classify and communicate the value of data. Give industry a common classification language. Enable organisations to assess data risk and apply controls. Support confidentiality, integrity and availability requirements together, not confidentiality alone.

Source · 2023-2030 Australian Cyber Security Strategy
02

Where it draws from

Existing classification systems, including the Protective Security Policy Framework (PSPF) that applies to Australian Government entities. The intent is to promote common approaches between government and industry rather than invent a parallel system.

03

What Horizon 2 means for you

Home Affairs will work with industry on adoption through 2026 to 2028. In practice that is where a voluntary framework becomes an expectation in supply chains, tenders and cyber insurance proposal forms.

Source · Horizon 2: Expanding our reach (2026-2028)
04

Data as an economic asset

The release frames data as a source of growth for the Australian economy. The framework is pitched as much at enabling confident data sharing between organisations as it is at protection.

03

The four modules

Introduction, Risk Assessment, Data Security Levels and Markers.

Adopt what you need. DSL classification is the one non-negotiable.

The framework is deliberately modular so that an organisation with an existing risk process can skip straight to classification, and an organisation starting from nothing can work through it in order. Adopting all four modules is not required to gain the benefit. However, the framework is clear that applying Data Security Level classification is the prerequisite to being identified as using the IDCF.

01

Module 1: Introduction

Purpose, key terms, expectations of use, labelling and marking (both visual and metadata), and a code of conduct for organisations that adopt the framework.

02

Module 2: Risk Assessment

For organisations that need guidance on how to conduct a risk assessment across their data holdings. Understanding the data, the consequences of an adverse event, impact rating, and the kinds of adverse events to plan for.

03

Module 3: Data Security Levels (DSL)

The core of the IDCF. A system to classify data holdings from DSL-0 to DSL-5+ and communicate the required protection in a universal way to every user and recipient.

04

Module 4: Markers

An optional secondary system to communicate extra information or risks attached to a data holding, over and above its DSL. Integrated, adopted and user-defined markers with a consistent prefix format.

05

The appendices do the heavy lifting

Glossary, consequences questionnaire, impact rating worksheet, adverse event identification questionnaire, and a Statement of System Security template. These are the pieces most SMBs will actually fill in.

IDCF diagram of the four modules — Introduction, Risk Assessment, Data Security Levels highlighted as the core, and Markers — with arrows to the risk assessment steps and to a DSL pyramid running from DSL-0 up to DSL-5+ under a stronger protection arrow

Pick the modules you need

Four modules. One is the core, three are there when you need them.

The framework is modular by design. An organisation with a mature risk process can go straight to Data Security Levels; one starting from nothing can work through in order.

  1. M1

    Introduction

    Purpose, key terms, labelling and marking, code of conduct.

  2. M2

    Risk Assessment

    Data types, scale and currency; consequences; impact rating; adverse events.

  3. M3

    Data Security Levels

    The core. DSL classification is the prerequisite for being identified as using the IDCF.

  4. M4

    Markers

    Optional secondary system for extra information or risk attached to a holding.

IDCF module stack showing Introduction, Risk Assessment, Data Security Levels highlighted as the core, Markers, and online resources shown as a dashed optional block
FigureThe module stack, with Data Security Levels highlighted as the core of the framework. Figure 3, Industry Data Classification Framework, Department of Home Affairs.
04

Assessing the risk on your data

Understand the asset, assess the consequence, rate the impact.

The Risk Assessment module turns 'we have a lot of data' into something you can classify.

The IDCF process is three steps: understand the data asset, assess the consequence, impact and likelihood of adverse events, then assign a DSL label. The Risk Assessment module walks through the first two. It is written for people who are not risk professionals, with questionnaires and worksheets in the appendices rather than abstract theory.

01

Understand your data

Three lenses: data type (what it is and who it is about), data scale (how much of it and how many people it concerns), and data currency or timeliness (whether it loses or gains sensitivity over time).

02

Consequences of an adverse event

The framework groups consequences into harm to individuals, harm to organisational assets, harm to organisational operations, and harm to the organisation in general. Appendix B is a consequences questionnaire built around those four.

03

Impact assessment

Consequences are rated on an impact scale using an impact rating table. Appendix C is the worksheet: understand your data, work through consequences and impacts, then summarise a single impact rating.

04

Understanding adverse events

The module defines what an adverse event is, catalogues the different kinds, and shows them in practice. Appendix D is a questionnaire for identifying the adverse events that are realistic for your holdings.

05

Where this meets your existing work

If you have already done a Privacy Act personal information inventory or an SMB1001 asset register, most of the 'understand your data' step is done. The IDCF adds the consequence and impact discipline on top.

IDCF diagram showing how threats act on assets through a vulnerability to cause adverse events, which in turn create consequences and impact
FigureHow the IDCF models risk: a threat exploits a vulnerability in an asset, causing an adverse event, which produces consequences and impact. Industry Data Classification Framework, Department of Home Affairs.
IDCF five-step risk assessment process diagram: understand your data asset, identify consequences and assess impacts, identify potential events and their likelihood, evaluate inherent risks, then review and monitor
FigureThe five-step risk assessment cycle, mapped back to the threat, asset, adverse event and consequence model above. Industry Data Classification Framework, Department of Home Affairs.
05

Data Security Levels

DSL-0 to DSL-5+: one label that tells any recipient how to treat the data.

The core of the framework, and the part that makes it interoperable.

A Data Security Level is a classification attached to a data holding that communicates the level of protection it needs. Levels run from DSL-0 through DSL-4, with DSL-5+ covering data whose protection requirements exceed the framework's scope. The module also describes the three event types the levels are built to withstand, how to select a level, what constitutes an appropriate system or environment for each, and what to do when no label is present.

01

Three event types

The DSL module models a physical event, cyber events, and an authorised person event (misuse by someone who legitimately has access). Each level is defined by what it is expected to withstand across those three.

02

Selecting a DSL

The impact rating from the Risk Assessment module drives the level. The framework also warns about the risks of streamlined classification, where an organisation shortcuts the assessment and labels everything the same.

03

Appropriate systems and environments

Each level carries expectations about the systems allowed to store and process the data. The module maps these to related cyber security frameworks and standards so that existing Essential Eight, SMB1001 or ISO 27001 work counts toward the evidence.

04

Absence of a DSL label

The framework addresses unlabelled data explicitly. Not labelling something is a decision with consequences, and recipients need a rule for how to treat data that arrives without a level.

05

Rules versus guidance

The module separates rules (what you must do to claim IDCF alignment at a level) from guidance (communication and movement of data, classifying containers, data for publication, assessing systems).

06

Statement of System Security

Appendix E is a template for documenting what a system is approved to hold and why. It is the artefact you hand to a client, auditor or insurer to show the level a system supports.

Protection level requirements

What each Data Security Level is expected to withstand.

Every level sets a protection requirement across physical security, three tiers of cyber attack capability, and misuse by an authorised person. This is the table that turns a label into a control conversation.

Data Security LevelPhysicalCyberAuthorised person
CommonModerateComplex
DSL-0Very lowVery lowVery lowVery lowVery low
DSL-1MediumVery lowVery lowVery lowLow
DSL-2MediumHighMediumLowMedium
DSL-3HighVery highHighMediumHigh
DSL-4Very highVery highVery highHighVery high
DSL-5+As agreed between parties.

Source: Industry Data Classification Framework, Department of Home Affairs, 2 September 2026. Reproduced under CC BY 4.0.

06

Markers and labelling

Markers add context. Labels make the level visible and machine-readable.

Optional, but this is where Microsoft Purview and the IDCF meet.

The Markers module is optional. A marker communicates something a DSL cannot on its own, such as a legal restriction, a contractual condition or a handling caveat. The Introduction module separately covers labelling and marking: how a classification is shown visually on a document, and how it is carried as metadata so systems can act on it. For most Australian SMBs on Microsoft 365, that metadata is a sensitivity label.

01

Three marker categories

Integrated markers (defined within the framework), adopted markers (taken from another recognised scheme), and user-defined markers (created by your organisation for your own needs). All follow a consistent format and prefix convention.

02

Visual labelling

How the DSL and any markers appear on the document, email or system so a human reader knows how to handle it.

03

Metadata labelling

How the same classification is carried in a machine-readable form so DLP, encryption and access controls can enforce it automatically. This is where the framework becomes operational rather than a policy on a shelf.

04

Code of conduct

Organisations that adopt the IDCF agree to general conduct expectations around honest classification and respecting the labels applied by others. The framework only works if a DSL means the same thing when it leaves your building.

05

How Real Bytes maps it

Our practical four-tier scheme for SMBs maps cleanly onto DSL levels and deploys as Purview sensitivity labels, auto-labelling and DLP. The IDCF gives that work a nationally recognised vocabulary.

Adopted markers

The IDCF adopts Traffic Light Protocol for sharing restrictions.

A Data Security Level says how well data must be protected. A TLP marker says how far it may travel. The framework adopts the TLP v2.0 set referenced by ASD and authored by FIRST, colour coded with a TLP prefix. TLP v2.0 formatting is preferred, though the framework allows changes to the black background where that is impractical.

  • TLP:RED

    For the eyes and ears of individual recipients only, no further disclosure.

  • TLP:AMBER+STRICT

    Limited disclosure. Recipients can only spread this on a need-to-know basis within their organisation.

  • TLP:AMBER

    Limited disclosure. Recipients can only spread this on a need-to-know basis within their organisation and its clients.

  • TLP:GREEN

    Limited disclosure. Recipients can spread this within their community.

  • TLP:CLEAR

    Recipients can spread this to the world, there is no limit on disclosure.

Source: Industry Data Classification Framework section 5.2.3, Department of Home Affairs. Authoritative TLP v2.0 definitions are authored by FIRST.

Self-assessment

Work one data holding through the framework and see where it lands.

This follows the IDCF risk assessment process: understand the data asset, assess the consequences and impacts, then read an indicative Data Security Level. Questions and rating scales are the framework's own. Nothing you enter leaves your browser.

  1. 01Understand your data
  2. 02Consequences and impacts
  3. 03Your rating and next steps
Select the types of data you want to assess and classify from the list below.
Does the data include personal information, such as names and addresses?
Is the data current or is the data historical and/or archived?
Is the data subject to any laws or regulations, for example nationally important data, which might require data to be physically stored at a location within Australia or controlled by an Australian organisation?
How significant is the size of this data in the context of your organisational operations? Consider the scale and value of the data with respect to your organisation.

Questions and options taken from Appendix C, Section 1 of the framework.

Common questions

Questions Australian leadership teams are asking about the IDCF.

No. The IDCF is a voluntary framework released by the Department of Home Affairs on 2 September 2026. There is no legal obligation to adopt it. Home Affairs has committed to supporting industry adoption under Horizon 2 of the 2023-2030 Australian Cyber Security Strategy, so expect it to appear in supplier and procurement expectations over time.

From framework to labels your systems enforce

The IDCF gives you the vocabulary. Sensitivity labels, DLP and access control make it real.

Real Bytes helps Australian organisations map the IDCF Data Security Levels onto a practical classification scheme, deploy it as Microsoft Purview sensitivity labels with auto-labelling and DLP, and document the Statement of System Security that clients, auditors and insurers ask for. If you already hold SMB1001 or Essential Eight evidence, most of it carries straight across.

This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.