How Supplier Cyber Security Assurance Works
Your Journey
A structured pathway to independent certification
Australian Cyber Essentials (ACE) is not a self-assessment checklist. It is a guided, evidence-based pathway that supports organisations through preparation, evidence gathering, and independent certification by Bureau Veritas.
The outcome is practical supplier cyber security assurance that enterprises can rely on.
The programme is structured across three tiers: ACE Ready, ACE Robust, ACE Resilient
This allows organisations to start at the level that reflects their current maturity and build capability over time.
ACE is designed to be practical, proportionate, and manageable, including for organisations without large internal security teams. The process gives suppliers a clear pathway to improve their cyber security posture and demonstrate independent certification.
Once certified, organisations can use ACE to demonstrate cyber security assurance to current and prospective customers, partners, and enterprise procurement teams.
Watch Now
The ACE Process
Common Questions
Is ACE a self-assessment or is it independently verified?
Australian Cyber Essentials (ACE) is not a self-assessment or traditional questionnaire-based exercise. ACE is an evidence-based certification pathway supported by an Information Security Management System (ISMS), guided workshops, structured evidence submission, and independent certification by Bureau Veritas.
Organisations submit practical evidence through the ACE evidence portal. Bureau Veritas independently reviews that evidence and, where requirements are met, issues certification at the appropriate tier. This gives enterprises factual, evidence-based supplier cyber security assurance, rather than relying on unsupported self-attested claims.
What happens if our evidence submission doesn't meet requirements?
ACE is a maturity journey, not a one-off pass/fail exercise. If evidence gaps are identified during preparation, Cyber Audit Team (CAT) provides clear guidance through the guided workshops to help the organisation understand what needs to be addressed.
The organisation can then implement the necessary controls, improve its evidence, and progress toward independent certification. The goal of the process is to help organisations succeed while maintaining the credibility of an evidence-based certification pathway
What counts as evidence?
Evidence consists of practical artefacts that demonstrate a control is in place and operating as intended. Depending on the requirement, this may include policies, procedures, screenshots, configuration exports, system reports, registers, records, and other supporting materials. This evidence gives the organisation factual information about its current cyber security posture and helps identify areas for uplift.
How is evidence submitted?
Evidence is submitted through the ACE evidence portal, which is structured to make the process manageable. The guided workshops help organisations understand what is needed for their tier, operating context, and certification objectives. This gives suppliers a practical way to prepare evidence, address gaps, and demonstrate cyber security assurance to current and prospective customers.
Does certification mean we are protected against cyber security incidents?
No. ACE certification reflects an independent review of evidence at the time of certification. It demonstrates that required controls have been evidenced, but it does not guarantee that an organisation will not experience a cyber security incident.
Ongoing assurance activities, including periodic confirmation that key controls remain in operation, evidence refresh, notification of material changes, and renewal at defined intervals, help maintain certification over time.