Gatekeeper Public Key Infrastructure Framework

This framework is currently under review. Annual audits of existing accredited providers and the accreditation of new providers is temporarily paused while the framework is being reviewed. More information will be provided in coming months.

This framework explains the requirements for issuing digital keys and certificates.

What this framework does#

The Gatekeeper Public Key Infrastructure (PKI) Framework governs the way the Australian Government uses digital keys and certificates to assure the identity of subscribers to authentication services.

Subscribers can include individual users, organisations and devices, such as applications and computers.

The framework sets out the requirements for organisations to become accredited to issue digital keys and certificates for use in government for PKI-based authentication.

Policy requirement: the Gatekeeper PKI Framework states that Australian Government agencies must only use digital keys and certificates issued by a gatekeeper-accredited organisation for PKI authentication.

Gatekeeper accreditation covers the issuing of digital keys and certificates to subscribers that need to work in:

  • open environments, such as the internet
  • closed environments, such as communities of interest
  • hybrid communities

Assessors from the Information Security Registered Assessor Program (IRAP) assess providers. They also audit them annually to make sure they comply with the Gatekeeper PKI Framework.

If a service provider contracts you to carry out an IRAP assessment you can get in touch with us  to ask for a list of their approved documents.

Accredited service providers#

The Gatekeeper Competent Authority has granted accreditation to the following services:

ProviderService typeAccreditation date
DigiCert (formally Symantec) Certification and Registration AuthoritySeptember 2015
Cogito Group Registration Authority, Certification Authority and Validation Authority11 October 2021
Department of Defence Certification and Registration Authority17 May 2007
Department of Industry and Science Validation Authority6 January 2011
Medicare Australia Certification Authority29 June 2011
Verizon Australia Certification Authority16 February 2012
Australian Taxation Office Certification Authority30 April 2013
Registration AuthorityJune 2019
Property Exchange Australia Limited Certification Authority1 October 2014
Registration AuthorityJune 2019

Policy background#

The framework replaces the following policies, which no longer apply:

  • National e-Authentication Framework
  • Third Party Identity Services Assurance Framework

More information about the framework#

Download the following documents to find out more about the Gatekeeper PKI Framework:

If you have any questions you can get in touch with us at gatekeeper.pki@finance.gov.au.


Did you find this content useful?