About the PSR

Self-assessment and reporting

Information and tools to help your organisation assess and report on your protective security capability maturity

The annual Protective Security Requirements (PSR) capability self-assessment round for 2024/25 is closed.

Minor updates have been made to the PSR self-assessment report template, including in response to agency feedback. These updates are summarised in the template itself, and in the accompanying information sheet.

PSR Assurance Framework resources

The following resources have been created to support organisations in undertaking the annual PSR assurance process.

Document name Description Use in step
PSR Assurance Framework Guide [PDF, 864 KB] An updated PSR Capability Maturity Model (PS-CMM) with checklists to help organisations select capability maturity targets demonstrating specific capability and measures expected for each security domain at each capability maturity level. All steps
PSR Self-Assessment Tool An updated guide to support organisations when gathering evidence and undertaking moderation of the PSR self-assessment. All steps
Enterprise Security Risk CMM Calculator [XLSX, 65 KB] A tool to help an organisation assess and decide their target capability maturity level. The calculator provides a set of general organisational characteristics and qualities that may influence security risks in their environment. Step 1
PSR Capability Maturity Model [PDF, 532 KB] An updated PSR Capability Maturity Model (PS-CMM) with checklists to help organisations select capability maturity targets demonstrating specific capability and measures expected for each security domain at each capability maturity level. Steps 1 – 4
PSR Moderation Framework [PDF, 376 KB] An updated guide to support organisations when gathering evidence and undertaking moderation of the PSR self-assessment. Step 2 (evidence guide)
Step 4 (moderation)
PSR Self-Assessment CMM and Moderator Tool A tool for use by moderators or auditors when verifying an organisation’s PSR self-assessment. The tool outlines the questions in the PSR Self-Assessment Tool, showing the relevant requirement in the PSR Capability Maturity Model (PS-CMM) and provides a moderation area to track the original answer provided and a moderated answer (if different) and provide any moderation commentary as appropriate. Step 4
PSR Assurance Report template – Original

A mandatory reporting template used to summarise the results for the Chief Executive from the PSR assurance round for the year.

Two templates provided – original and portrait.

Steps 5 – 6 
PSR Assurance Report template – Portrait
PSR Security Measures Roadmap [XLSX, 77 KB]

An optional PSR roadmap template to track the security measures in place, are putting in place, and are planning to put in place to protect its people, information, and assets.

Step 7
PSR Policy Framework

Refer to the PSR Policy Framework documents for more information and guidance on appropriate mandatory and recommended security measures.

All steps