Australia cyber framework to value skills over papers
Fri, 2nd Oct 2026 (Today)
CyberPath has opened consultation on a national cyber capability framework that would place less weight on qualifications and certifications alone when assessing cyber workers. The proposal is backed by the Department of Home Affairs and led by the Australian Computer Society, with AISA and Aus3C.
The draft model would retain formal credentials as evidence of capability, but not treat them on their own as proof of full proficiency. Instead, workers could demonstrate their ability through workplace performance, simulations, incident records, vulnerability disclosures, code commits, governance and risk policy drafts, exercises, and other independently validated work.
Practical capability
The consultation addresses a long-running question in cyber hiring and workforce development: can a qualification or job title show that someone is ready to respond effectively during a live incident? Under the proposed framework, employers would be encouraged to assess whether people can perform under operational pressure rather than rely mainly on paper credentials.
It also draws a sharper distinction between tasks that artificial intelligence can carry out and areas where human accountability must remain. The issue comes as cyber security teams face faster, more automated attacks, including cases in which AI systems are used for reconnaissance, credential theft, and lateral movement inside networks.
CyberPath is a government-funded pilot program and part of the national cyber strategy. More than 2,000 stakeholders have taken part in its design so far, according to the organisations behind it.
The capability paper follows an occupations framework released earlier, which set out cyber roles and a standardised approach to describing them. The new paper moves from job definitions to a harder question: what a professional should be able to demonstrate in practice before being regarded as capable of doing the work.
Workforce shortage
The debate has become more urgent as Australia faces a shortage of cyber workers. ACS estimates the country's cyber workforce at about 137,500 people and says a further 54,000 will be needed by 2030.
At the same time, the wider technology workforce shrank last year for the first time on record. For employers, that creates a difficult balance between filling vacancies quickly and ensuring staff can handle incidents in real operating environments.
Dr Prins Ralston, Chief Executive Officer, ACS, said the distinction between qualifications and practical performance had become more important as organisations deal with growing cyber risks.
"A certificate or a job title is not proof that someone can protect a hospital, a school or a payments system when an incident is under way. Knowledge and skills matter. Judgement, experience, understanding organisational context, and performance under pressure matter more. Employers and the Australian community are entitled to know the difference," said Dr Ralston.
He said the changing nature of cyber work, including AI's growing role in routine tasks, meant the workforce framework should identify where responsibility still sits with people.
"Work as we know it is transforming while we are still building the workforce. As AI takes on more of the routine load, the capability Australia needs is human: accountability, the ability to see when the technology is wrong, and people who can still act when the playbook runs out. That is what this framework has to get right, or we leave the country exposed," said Ralston.
Dr Ralston said the model was intended to broaden access to cyber careers rather than narrow it, particularly for career changers who may have practical evidence of their work but fewer traditional credentials.
"This is not a licence and it is not a barrier. It gives a career changer a credible way to prove what they can do, and an employer a credible reason to believe them. As a workforce framework, it is also a world first, acknowledging the delineation between the tasks AI can reasonably perform, what human talent performs, and the boundaries that need to be in place. Everyone has responsibilities to ensure the safety of our people, systems, and data. All practitioners and employers have until 27 September to stress-test the model. After that we will continue to evolve the platform on whatever survives that scrutiny to ensure CyberPath remains relevant and has utility across a diverse range of organisations," added Ralston.
Hiring practices
Recruiters say the issue goes beyond cyber security and reflects a wider reassessment of how technical staff are hired. Dean Ellis, Director of Technology Recruitment, Rec4Tech, said formal qualifications remained useful but did not always show how someone would act in the workplace.
"Based on my years of experience recruiting for tech roles, qualifications are valuable, but they do not always demonstrate how someone will perform in a real-world environment. Cyber professionals need to apply their knowledge, respond to evolving threats, communicate risks clearly, and make sound decisions under pressure.
"A consistent, practical way of validating capability will give employers greater confidence that someone can genuinely perform the role, while also giving skilled candidates a fair opportunity to demonstrate what they can do beyond what is written on their CV. I would also recommend using a series of situational-based questions, with follow-up questions to explore responses in greater depth. Interview panels should be diverse in background, gender, role, and seniority to support balanced, less-biased assessments," said Ellis.