Australia's new Industry Data Classification Framework explained for business
On 2 September 2026 the Department of Home Affairs, with CSIRO's Data61, released the Industry Data Classification Framework (IDCF). It gives Australian organisations of every size a common way to assess, classify and communicate the value of their data through Data Security Levels. This guide covers what the framework is, its four modules, how the levels work, and how it fits with the Essential Eight, SMB1001, ISO 27001 and Privacy Act work you may already have underway.
Summarised from the Home Affairs IDCF publication under CC BY 4.0. Not legal advice.
Four modules
Introduction, Risk Assessment, DSLs, Markers
DSL-0 to DSL-5+
One label any recipient understands
Voluntary, Strategy Shield 2
Adoption support through Horizon 2

The official IDCF mark. Diagrams on this page are reproduced from the Home Affairs publication under CC BY 4.0. Read the source document: Industry Data Classification Framework (PDF, Department of Home Affairs).

The IDCF in three steps
Understand the asset. Assess the risk. Assign a level.
Every module in the framework serves one of these three steps. If you remember nothing else, remember the order.
- 01
Understand the data asset
What it is, who it is about, how much of it there is, and whether time makes it more or less sensitive.
- 02
Assess consequence, impact and likelihood
What happens to individuals, assets, operations and the organisation if the data is lost, altered, exposed or unavailable.
- 03
Assign a Data Security Level
One label that tells every recipient how to store, handle and share the data. Optional markers add context on top.
Released 2 September 2026
Australia now has a common language for classifying business data.
Voluntary, modular, and written for organisations of every size.
The Industry Data Classification Framework (IDCF) was released by the Department of Home Affairs on 2 September 2026, developed with CSIRO's Data61. It gives Australian organisations a consistent way to understand the value of the data they hold, assess the risk attached to it, classify it, and communicate that classification to anyone who receives it. It is voluntary. It does not replace the Privacy Act, Essential Eight, SMB1001 or ISO 27001. It sits underneath them and gives you the vocabulary they all assume you already have.
What it is
Comprehensive industry guidance for identifying, assessing, classifying and communicating the value of data holdings. It covers electronic data, the systems and devices that carry it, and can be applied to physical copies as well.
Source · IDCF overview, Home AffairsWho built it
The Department of Home Affairs (Technology Security Policy Branch) in partnership with CSIRO's Data61, drawing on research and consultation with industry across Australia.
Source · CSIRO partner releaseWho it is for
Any Australian organisation, from a small business to a large enterprise. Home Affairs describes it as designed to work whether you are just starting your data security journey or already have mature handling practices.
What it is not
It is not legislation, not a certification, and not legal advice. Home Affairs is explicit that publication does not constitute endorsement for specific circumstances and that users must make their own determination about appropriate use.
Why the government built it
A Cyber Security Strategy deliverable, now moving into the adoption phase.
Shield 2 of the 2023-2030 Strategy. Horizon 2 is about getting industry to use it.
The IDCF is a named measure under Shield 2 of the 2023-2030 Australian Cyber Security Strategy. The framework itself is Horizon 1 work. Under Horizon 2 (2026 to 2028), Home Affairs has committed to working with industry to support adoption and to keep the framework current against the threat landscape. Expect it to start appearing in procurement questionnaires, supplier standards and insurer conversations before it appears in law.
The stated aims
Provide guidance on how to identify, assess, classify and communicate the value of data. Give industry a common classification language. Enable organisations to assess data risk and apply controls. Support confidentiality, integrity and availability requirements together, not confidentiality alone.
Source · 2023-2030 Australian Cyber Security StrategyWhere it draws from
Existing classification systems, including the Protective Security Policy Framework (PSPF) that applies to Australian Government entities. The intent is to promote common approaches between government and industry rather than invent a parallel system.
What Horizon 2 means for you
Home Affairs will work with industry on adoption through 2026 to 2028. In practice that is where a voluntary framework becomes an expectation in supply chains, tenders and cyber insurance proposal forms.
Source · Horizon 2: Expanding our reach (2026-2028)Data as an economic asset
The release frames data as a source of growth for the Australian economy. The framework is pitched as much at enabling confident data sharing between organisations as it is at protection.
The four modules
Introduction, Risk Assessment, Data Security Levels and Markers.
Adopt what you need. DSL classification is the one non-negotiable.
The framework is deliberately modular so that an organisation with an existing risk process can skip straight to classification, and an organisation starting from nothing can work through it in order. Adopting all four modules is not required to gain the benefit. However, the framework is clear that applying Data Security Level classification is the prerequisite to being identified as using the IDCF.
Module 1: Introduction
Purpose, key terms, expectations of use, labelling and marking (both visual and metadata), and a code of conduct for organisations that adopt the framework.
Module 2: Risk Assessment
For organisations that need guidance on how to conduct a risk assessment across their data holdings. Understanding the data, the consequences of an adverse event, impact rating, and the kinds of adverse events to plan for.
Module 3: Data Security Levels (DSL)
The core of the IDCF. A system to classify data holdings from DSL-0 to DSL-5+ and communicate the required protection in a universal way to every user and recipient.
Module 4: Markers
An optional secondary system to communicate extra information or risks attached to a data holding, over and above its DSL. Integrated, adopted and user-defined markers with a consistent prefix format.
The appendices do the heavy lifting
Glossary, consequences questionnaire, impact rating worksheet, adverse event identification questionnaire, and a Statement of System Security template. These are the pieces most SMBs will actually fill in.

Pick the modules you need
Four modules. One is the core, three are there when you need them.
The framework is modular by design. An organisation with a mature risk process can go straight to Data Security Levels; one starting from nothing can work through in order.
- M1
Introduction
Purpose, key terms, labelling and marking, code of conduct.
- M2
Risk Assessment
Data types, scale and currency; consequences; impact rating; adverse events.
- M3
Data Security Levels
The core. DSL classification is the prerequisite for being identified as using the IDCF.
- M4
Markers
Optional secondary system for extra information or risk attached to a holding.

Assessing the risk on your data
Understand the asset, assess the consequence, rate the impact.
The Risk Assessment module turns 'we have a lot of data' into something you can classify.
The IDCF process is three steps: understand the data asset, assess the consequence, impact and likelihood of adverse events, then assign a DSL label. The Risk Assessment module walks through the first two. It is written for people who are not risk professionals, with questionnaires and worksheets in the appendices rather than abstract theory.
Understand your data
Three lenses: data type (what it is and who it is about), data scale (how much of it and how many people it concerns), and data currency or timeliness (whether it loses or gains sensitivity over time).
Consequences of an adverse event
The framework groups consequences into harm to individuals, harm to organisational assets, harm to organisational operations, and harm to the organisation in general. Appendix B is a consequences questionnaire built around those four.
Impact assessment
Consequences are rated on an impact scale using an impact rating table. Appendix C is the worksheet: understand your data, work through consequences and impacts, then summarise a single impact rating.
Understanding adverse events
The module defines what an adverse event is, catalogues the different kinds, and shows them in practice. Appendix D is a questionnaire for identifying the adverse events that are realistic for your holdings.
Where this meets your existing work
If you have already done a Privacy Act personal information inventory or an SMB1001 asset register, most of the 'understand your data' step is done. The IDCF adds the consequence and impact discipline on top.


Data Security Levels
DSL-0 to DSL-5+: one label that tells any recipient how to treat the data.
The core of the framework, and the part that makes it interoperable.
A Data Security Level is a classification attached to a data holding that communicates the level of protection it needs. Levels run from DSL-0 through DSL-4, with DSL-5+ covering data whose protection requirements exceed the framework's scope. The module also describes the three event types the levels are built to withstand, how to select a level, what constitutes an appropriate system or environment for each, and what to do when no label is present.
Three event types
The DSL module models a physical event, cyber events, and an authorised person event (misuse by someone who legitimately has access). Each level is defined by what it is expected to withstand across those three.
Selecting a DSL
The impact rating from the Risk Assessment module drives the level. The framework also warns about the risks of streamlined classification, where an organisation shortcuts the assessment and labels everything the same.
Appropriate systems and environments
Each level carries expectations about the systems allowed to store and process the data. The module maps these to related cyber security frameworks and standards so that existing Essential Eight, SMB1001 or ISO 27001 work counts toward the evidence.
Absence of a DSL label
The framework addresses unlabelled data explicitly. Not labelling something is a decision with consequences, and recipients need a rule for how to treat data that arrives without a level.
Rules versus guidance
The module separates rules (what you must do to claim IDCF alignment at a level) from guidance (communication and movement of data, classifying containers, data for publication, assessing systems).
Statement of System Security
Appendix E is a template for documenting what a system is approved to hold and why. It is the artefact you hand to a client, auditor or insurer to show the level a system supports.
Protection level requirements
What each Data Security Level is expected to withstand.
Every level sets a protection requirement across physical security, three tiers of cyber attack capability, and misuse by an authorised person. This is the table that turns a label into a control conversation.
| Data Security Level | Physical | Cyber | Authorised person | ||
|---|---|---|---|---|---|
| Common | Moderate | Complex | |||
| DSL-0 | Very low | Very low | Very low | Very low | Very low |
| DSL-1 | Medium | Very low | Very low | Very low | Low |
| DSL-2 | Medium | High | Medium | Low | Medium |
| DSL-3 | High | Very high | High | Medium | High |
| DSL-4 | Very high | Very high | Very high | High | Very high |
| DSL-5+ | As agreed between parties. | ||||
Source: Industry Data Classification Framework, Department of Home Affairs, 2 September 2026. Reproduced under CC BY 4.0.
Markers and labelling
Markers add context. Labels make the level visible and machine-readable.
Optional, but this is where Microsoft Purview and the IDCF meet.
The Markers module is optional. A marker communicates something a DSL cannot on its own, such as a legal restriction, a contractual condition or a handling caveat. The Introduction module separately covers labelling and marking: how a classification is shown visually on a document, and how it is carried as metadata so systems can act on it. For most Australian SMBs on Microsoft 365, that metadata is a sensitivity label.
Three marker categories
Integrated markers (defined within the framework), adopted markers (taken from another recognised scheme), and user-defined markers (created by your organisation for your own needs). All follow a consistent format and prefix convention.
Visual labelling
How the DSL and any markers appear on the document, email or system so a human reader knows how to handle it.
Metadata labelling
How the same classification is carried in a machine-readable form so DLP, encryption and access controls can enforce it automatically. This is where the framework becomes operational rather than a policy on a shelf.
Code of conduct
Organisations that adopt the IDCF agree to general conduct expectations around honest classification and respecting the labels applied by others. The framework only works if a DSL means the same thing when it leaves your building.
How Real Bytes maps it
Our practical four-tier scheme for SMBs maps cleanly onto DSL levels and deploys as Purview sensitivity labels, auto-labelling and DLP. The IDCF gives that work a nationally recognised vocabulary.
Adopted markers
The IDCF adopts Traffic Light Protocol for sharing restrictions.
A Data Security Level says how well data must be protected. A TLP marker says how far it may travel. The framework adopts the TLP v2.0 set referenced by ASD and authored by FIRST, colour coded with a TLP prefix. TLP v2.0 formatting is preferred, though the framework allows changes to the black background where that is impractical.
- TLP:RED
For the eyes and ears of individual recipients only, no further disclosure.
- TLP:AMBER+STRICT
Limited disclosure. Recipients can only spread this on a need-to-know basis within their organisation.
- TLP:AMBER
Limited disclosure. Recipients can only spread this on a need-to-know basis within their organisation and its clients.
- TLP:GREEN
Limited disclosure. Recipients can spread this within their community.
- TLP:CLEAR
Recipients can spread this to the world, there is no limit on disclosure.
Source: Industry Data Classification Framework section 5.2.3, Department of Home Affairs. Authoritative TLP v2.0 definitions are authored by FIRST.
Sources referenced
- 01
Industry Data Classification Framework (5MB PDF)
Department of Home Affairs2 Sep 2026www.homeaffairs.gov.au - 02
Industry Data Classification Framework website
Department of Home Affairs2 Sep 2026www.homeaffairs.gov.au - 03
Media release: Australian Government releases the IDCF
Department of Home Affairs2 Sep 2026www.homeaffairs.gov.au - 04
Introducing the Industry Data Classification Framework
CSIRO partner release2 Sep 2026www.csiro.au - 05
2023-2030 Australian Cyber Security Strategy
Department of Home Affairswww.homeaffairs.gov.au - 06
Horizon 2: Expanding our reach (2026-2028)
Department of Home Affairswww.homeaffairs.gov.au
This page summarises publicly available Australian government, regulator and legal sources. It is general information, not legal advice.
Self-assessment
Work one data holding through the framework and see where it lands.
This follows the IDCF risk assessment process: understand the data asset, assess the consequences and impacts, then read an indicative Data Security Level. Questions and rating scales are the framework's own. Nothing you enter leaves your browser.
- 01Understand your data
- 02Consequences and impacts
- 03Your rating and next steps
Questions and options taken from Appendix C, Section 1 of the framework.
Common questions
Questions Australian leadership teams are asking about the IDCF.
No. The IDCF is a voluntary framework released by the Department of Home Affairs on 2 September 2026. There is no legal obligation to adopt it. Home Affairs has committed to supporting industry adoption under Horizon 2 of the 2023-2030 Australian Cyber Security Strategy, so expect it to appear in supplier and procurement expectations over time.
Related in this cluster
Other operational and regulatory pages for Australian businesses.
From framework to labels your systems enforce
The IDCF gives you the vocabulary. Sensitivity labels, DLP and access control make it real.
Real Bytes helps Australian organisations map the IDCF Data Security Levels onto a practical classification scheme, deploy it as Microsoft Purview sensitivity labels with auto-labelling and DLP, and document the Statement of System Security that clients, auditors and insurers ask for. If you already hold SMB1001 or Essential Eight evidence, most of it carries straight across.
This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.

Remote Support