A Department of Home Affairs-backed cyber workforce initiative is seeking feedback on a draft national framework that would shift how cyber professionals are assessed, placing more emphasis on demonstrated performance rather than qualifications and certifications alone.
The CyberPath pilot program, led by the Australian Computer Society in partnership with the Australian Information Security Association and the Australian Cyber Collaboration Centre, has released a draft Capability Framework Discussion Paper for public consultation.
Under the proposed model, qualifications and certifications would remain “important evidence of capability” but would not be treated as proof of proficiency on their own. The framework proposes that capability could also be demonstrated through workplace performance, simulations, incident records, vulnerability disclosures, code commits, governance and risk documentation, exercises, and independently validated work.
The framework also seeks to set clearer expectations around which cyber tasks can reasonably be performed by AI and where human accountability should remain, as AI-enabled attacks increase pressure on cyber teams.
CyberPath said the Capability Framework builds on its Occupations Framework released in May, which defined cyber occupations and roles and introduced a standardised approach to describing roles. The new work is intended to address “what must someone actually demonstrate, under different contexts and pressures, and to a professional standard before they are treated as capable of performing that work.”
The consultation is being held against a backdrop of workforce constraints. ACS Australia’s Digital Pulse 2026 report estimates the cyber workforce at around 137,500 people, with a further 54,000 needed by 2030. The release also states that Australia’s technology workforce shrank for the first time on record last year.
ACS chief executive Dr Prins Ralston said the community and employers should be able to distinguish between credentials and real-world ability during incidents. “A certificate or a job title is not proof that someone can protect a hospital, a school or a payments system when an incident is on. Knowledge and skills matter. Judgement, experience, understanding the organisation context, and performance under pressure matter more,” he said.
The release argues that the need for clearer capability measures is being sharpened by the emergence of “agentic AI” being used in intrusions to automate reconnaissance, credential theft and lateral movement, compressing timelines that would traditionally take human teams days or weeks.
Dean Ellis, director of technology recruitment at Rec4Tech, said qualifications “do not always demonstrate how someone will perform in a real-world environment” and argued for consistent validation, alongside structured interview practices such as situational questions and diverse panels.
CyberPath said feedback is intended to test whether proposed capabilities reflect operational realities and employer needs, whether evidence requirements are practical and fair, and whether the framework can operate across government, industry and education and support diverse career pathways.
Consultation closes at 11.59pm AEST on 27 September 2026.

