Gatekeeper Public Key Infrastructure Framework
This framework explains the requirements for issuing digital keys and certificates.
What this framework does
The Gatekeeper Public Key Infrastructure (PKI) Framework governs the way the Australian Government uses digital keys and certificates to assure the identity of subscribers to authentication services.
Subscribers can include individual users, organisations and devices, such as applications and computers.
The framework sets out the requirements for organisations to become accredited to issue digital keys and certificates for use in government for PKI-based authentication.
Policy requirement: the Gatekeeper PKI Framework states that Australian Government agencies must only use digital keys and certificates issued by a gatekeeper-accredited organisation for PKI authentication.
Gatekeeper accreditation covers the issuing of digital keys and certificates to subscribers that need to work in:
- open environments, such as the internet
- closed environments, such as communities of interest
- hybrid communities
Assessors from the Information Security Registered Assessor Program (IRAP) assess providers. They also audit them annually to make sure they comply with the Gatekeeper PKI Framework.
If a service provider contracts you to carry out an IRAP assessment you can get in touch with us to ask for a list of their approved documents.
Checking legal documents
The Gatekeeper Legal Evaluation Panel checks legal documents for organisations applying for gatekeeper accreditation.
It also does this for service providers who want to amend legal documentation they’ve previously had approved.
Accredited service providers
The Gatekeeper Competent Authority has granted accreditation to the following services:
Provider |
Service type |
Accreditation date |
Certification and Registration Authority |
September 2015 |
|
Registration Authority |
December 2001 |
|
Cogito Group | Registration Authority, Certification Authority and Validation Authority | 11 October 2021 |
Certification and Registration Authority |
17 May 2007 |
|
Validation Authority |
6 January 2011 |
|
Certification Authority |
29 June 2011 |
|
Certification Authority |
16 February 2012 |
|
Certification Authority |
30 April 2013 |
|
Registration Authority |
June 2019 |
|
Certification Authority |
1 October 2014 |
|
Registration Authority |
June 2019 |
Policy background
The framework replaces the following policies, which no longer apply:
- National e-Authentication Framework
- Third Party Identity Services Assurance Framework
More information about the framework
Download the following documents to find out more about the Gatekeeper PKI Framework:
- Gatekeeper PKI Framework (V3.1 — December 2015) PDF (1.9 MB)
- Gatekeeper PKI Framework (V3.1 — December 2015) DOCX (601 KB)
- Information Security Registered Assessors Program (IRAP) Guide (V2.1 — December 2015) PDF (2.1 MB)
- Information Security Registered Assessors Program (IRAP) Guide (V2.1 — December 2015) DOCX (179 KB)
- Compliance Audit Program (V2.1 — December 2015) PDF (1.3 MB)
- Compliance Audit Program (V2.1 — December 2015) DOCX (175 KB)
Get in touch
If you have any questions you can get in touch with us at identity@dta.gov.au