How Supplier Cyber Security Assurance Works

Your Journey

A structured pathway to independent certification

Australian Cyber Essentials (ACE) is not a self-assessment checklist. It is a guided, evidence-based pathway that supports organisations through preparation, evidence gathering, and independent certification by Bureau Veritas.

The outcome is practical supplier cyber security assurance that enterprises can rely on.

The programme is structured across three tiers: ACE Ready, ACE Robust, ACE Resilient

This allows organisations to start at the level that reflects their current maturity and build capability over time.

ACE is designed to be practical, proportionate, and manageable, including for organisations without large internal security teams. The process gives suppliers a clear pathway to improve their cyber security posture and demonstrate independent certification.

Once certified, organisations can use ACE to demonstrate cyber security assurance to current and prospective customers, partners, and enterprise procurement teams.

Transparency
Watch Now

The ACE Process

1. Register Interest

Organisations provide basic details about their business, operating context, supplier assurance needs, and certification objectives.

2. Readiness and Preparation Support

The ACE programme team helps the organisation identify its likely starting point, understand evidence requirements, and prepare for certification.


This includes up to twelve guided workshops with Cyber Audit Team, covering the key control areas relevant to the organisation’s tier and operating context.

3: Evidence Review and Assessment

The organisation compiles practical evidence, including documentation, artefacts, screenshots, configuration exports, policies, and other supporting materials.

Evidence is uploaded to the ACE evidence portal in a structured and manageable way. Cyber Audit Team conducts a readiness review to help confirm the evidence pack is complete before independent certification review.

4: Independent Certification Decision

Bureau Veritas conducts the independent certification review and, where requirements are met, issues ACE certification at the appropriate tier.

5: Ongoing Assurance and Renewal

ACE supports ongoing supplier assurance, not only point-in-time certification.

Certified organisations may be required to complete defined ongoing activities, including periodic confirmation that key controls remain in operation, refresh of selected evidence, notification of material changes, and renewal at defined intervals.

This helps maintain credible, evidence-based supplier cyber security assurance over time.

Common Questions

Is ACE a self-assessment or is it independently verified?

Australian Cyber Essentials (ACE) is not a self-assessment or traditional questionnaire-based exercise. ACE is an evidence-based certification pathway supported by an Information Security Management System (ISMS), guided workshops, structured evidence submission, and independent certification by Bureau Veritas.

Organisations submit practical evidence through the ACE evidence portal. Bureau Veritas independently reviews that evidence and, where requirements are met, issues certification at the appropriate tier. This gives enterprises factual, evidence-based supplier cyber security assurance, rather than relying on unsupported self-attested claims.

What happens if our evidence submission doesn't meet requirements?

ACE is a maturity journey, not a one-off pass/fail exercise. If evidence gaps are identified during preparation, Cyber Audit Team (CAT) provides clear guidance through the guided workshops to help the organisation understand what needs to be addressed.

The organisation can then implement the necessary controls, improve its evidence, and progress toward independent certification. The goal of the process is to help organisations succeed while maintaining the credibility of an evidence-based certification pathway

What counts as evidence?

Evidence consists of practical artefacts that demonstrate a control is in place and operating as intended. Depending on the requirement, this may include policies, procedures, screenshots, configuration exports, system reports, registers, records, and other supporting materials. This evidence gives the organisation factual information about its current cyber security posture and helps identify areas for uplift.

How is evidence submitted?

Evidence is submitted through the ACE evidence portal, which is structured to make the process manageable. The guided workshops help organisations understand what is needed for their tier, operating context, and certification objectives. This gives suppliers a practical way to prepare evidence, address gaps, and demonstrate cyber security assurance to current and prospective customers.

Does certification mean we are protected against cyber security incidents?

No. ACE certification reflects an independent review of evidence at the time of certification. It demonstrates that required controls have been evidenced, but it does not guarantee that an organisation will not experience a cyber security incident.

Ongoing assurance activities, including periodic confirmation that key controls remain in operation, evidence refresh, notification of material changes, and renewal at defined intervals, help maintain certification over time.

Combined diagonal image to represent the types of businesses in a supply chain Australian Cyber Essentials (ACE) can help protect. Customer service / call centres, warehouse & logistics and technical and IT third parties