ACSskillsassessment
ACS RPL

ACS Skills Assessment Cyber Security Specialist Guide

Pick the wrong ANZSCO code and your ACS skills assessment cyber security specialist application can return suitable for an occupation you never meant to…

13 min read

Pick the wrong ANZSCO code and your ACS skills assessment cyber security specialist application can return suitable for an occupation you never meant to nominate, or unsuitable because your reference letters describe general IT work instead of security work. The code you choose before you lodge sets the eligibility bar, the evidence ACS weighs, and the visa subclasses you can later target. Most migration pages skip this decision and funnel every applicant toward one generic code. This guide maps the current cyber security ANZSCO codes against what ACS actually assesses, so you pick the right one first.

Why your ANZSCO code decides your skilled migration outcome

The Australian Computer Society (ACS) is the assessing authority for every cyber security ANZSCO code. When you nominate a code, ACS compares your qualifications and employment history against that occupation's ANZSCO description and its underlying ICT requirements. A suitable outcome confirms two things: how your qualification compares to an Australian standard, and the date from which your employment counts as skilled at the nominated level.

That skilled-employment date carries more weight than most applicants expect. Your points claim swings on it.

How ACS sets the eligibility bar from a code

Each code carries its own duty profile and its own expected qualification relatedness. A governance role and an offensive-testing role are assessed against different evidence, even though both sit under the cyber security banner. Nominate a code your documents cannot support, and the assessment strains at exactly the point competitor pages gloss over.

Points-tested visas: subclass 189, 190, and 491

Subclass 189, the Skilled Independent visa, requires a minimum of 65 points before the Department of Home Affairs will invite you. ACS does not award those points directly. It determines which years of your experience count as skilled, and Home Affairs converts that into points for skilled employment. When your evidence cannot support the nominated code, ACS may treat your early years as not-yet-skilled, removing them from your points calculation and dropping you below the invitation threshold. The pathways comparison breaks down how each route feeds a points claim.

Seven cyber security ANZSCO codes and which one fits your role

The heart of any ACS skills assessment cyber security specialist decision is picking the code your duties actually support. This is where most competitor guides go wrong: they treat one code, 262112 ICT Security Specialist, as if it covered the whole field. The ACS cyber security occupations page tells a different story. As of 2026, that page lists seven specialist codes, and 262112 is not among them.

ANZSCO code

Official title

261315

Cyber Security Engineer

261317

Penetration Tester

262114

Cyber Governance Risk and Compliance Specialist

262115

Cyber Security Advice and Assessment Specialist

262116

Cyber Security Analyst

262117

Cyber Security Architect

262118

Cyber Security Operations Coordinator

The 262112 puzzle: on the MLTSSL, off the cyber page

262112 ICT Security Specialist still sits on the Medium and Long-term Strategic Skills List (MLTSSL) with ACS as the assessing authority, so a points-tested applicant can still nominate it for subclass 189, 190, or 491. Yet it no longer appears on the ACS cyber security occupations page, which now routes cyber roles to the seven specialist codes above. Reconcile these two facts before you lodge. Confirm your target specialist code's current list membership at immi.homeaffairs.gov.au, because ACS listing a code does not guarantee its place on the skilled occupation list your visa subclass draws from. This reconciliation step is what nearly every competitor page omits.

What the 2022 ANZSCO update actually changed

The November 2022 ANZSCO update, reported by ACS Information Age, split roles previously bundled under 262112 into new codes: Cyber Security Engineer (261315), DevOps Engineer (261316), Penetration Tester (261317), and three governance and analyst occupations (262114 to 262116). The live ACS cyber security page has evolved since the 2022 announcement: it now lists seven codes, drops 261316 DevOps Engineer (not classed as a cyber security occupation there), and adds two codes the 2022 announcement never named: Cyber Security Architect (262117) and Cyber Security Operations Coordinator (262118). Any code list dated 2022 is already stale, so check the current ACS page directly.

Role-to-code decision matrix

Match your duties, not your job title, to the code. Titles vary by employer; ANZSCO duties do not.

Your role

Core duties

Recommended code

Likely pathway

Security Engineer

Builds and hardens controls, detection engineering, SIEM tuning

261315 Cyber Security Engineer

Formal qualifications with an ICT degree, otherwise RPL

SOC Analyst

Monitoring, alert triage, incident detection

262116 Cyber Security Analyst

Formal qualifications with an ICT degree, otherwise RPL

Cloud Security Architect

Security architecture, design authority, control frameworks

262117 Cyber Security Architect

Formal qualifications; senior RPL if no degree

Penetration Tester

Offensive testing, red teaming, remediation reporting

261317 Penetration Tester

RPL is common; formal qualifications with an ICT degree

GRC Manager

Risk, compliance, audit, policy

262114 Cyber Governance Risk and Compliance Specialist

Formal qualifications or RPL

For advisory work (security assessments, maturity reviews, client-facing recommendations rather than hands-on operations), 262115 Cyber Security Advice and Assessment Specialist often fits better than the analyst or engineer codes.

Formal qualifications pathway: degree rules and the ICT major test

The General Skills pathway expects an AQF Level 7 bachelor's degree or higher with a major in ICT or a closely related field. A dedicated Cyber Security degree usually clears the bar, but ACS reviews the syllabus unit by unit rather than trusting the parchment title. What ACS measures is how much of the program is ICT content and whether that content is closely related to your nominated code. A degree badged Cyber Security but weighted toward law, criminology, or general management can miss the ICT major threshold even when the name sounds like a perfect fit.

The experience ACS then requires is tiered by how well your qualification matches, per the ACS General Skills pathway page:

  • Bachelor's with an ICT major, closely related to the occupation: 2 years in the last 10, or 4 years anytime.

  • Bachelor's with an ICT minor, closely related: 5 years in the last 10, or 6 years anytime.

  • Diploma or advanced diploma with an ICT major, closely related: 5 years in the last 10, or 6 years anytime.

All experience must be professional IT employment at 20 or more hours per week. Read those thresholds carefully, because they decide whether you qualify without touching RPL at all.

When ACS deducts a skills requirement and how to respond

Where your qualification does not fully meet the ICT major or relatedness test, ACS applies an additional experience requirement before your skilled date begins. In practice, more of your early career is treated as pre-skilled, pushing back the date your points-earning experience starts. Arguing the decision rarely helps. Front-loading evidence does: submit a transcript that clearly shows the ICT unit weighting, and provide reference letters that anchor your security duties to the nominated code from your first relevant role. The pathways explained guide covers how the qualification comparison feeds this calculation.

RPL pathway: proving competency without an ICT degree

Lacking an ICT-major degree does not mean no assessment. The Recognition of Prior Learning (RPL) pathway is built for exactly that case, and it is not the three-episode Engineers Australia CDR that some templates recycle. ACS RPL assesses no tertiary qualification at all. The whole case rests on work.

Eligibility starts at six years of relevant IT experience, currently held or completed within the last two years, at a minimum of 20 hours per week.

What ACS expects in an RPL submission

Two project reports, not three career episodes, and no separate summary statement. One report must cover a project completed within the last two years; the other, a project within the last four years, per the ACS RPL pathway page. Each report walks through one real project and demonstrates the ICT competencies you personally applied, mapped to the duties of your nominated code.

Mapping your security work to competency areas

ACS uses the Skills Framework for the Information Age (SFIA) as its competency reference. Neither ACS nor the competitor pages publish a fixed SFIA level for each cyber security code, so do not claim one. Instead, pick the two projects that most directly exercise your nominated code's core duties. For each project, show the decision you made, the technical action you took, and the outcome you owned. A penetration tester nominating 261317 writes about scoping and running an engagement and the vulnerabilities it exposed, not about the organization's overall security posture. That specificity is the difference between a report that reads as competency and one that reads as a project diary.

Documents ACS requires from a cyber security specialist

Employment reference letters in the exact format ACS accepts

Reference letters sink more cyber security applications than any other document. On company letterhead, signed by a direct supervisor or an authorized HR representative, each letter must state your start and end dates, your hours per week, and your duties itemized in security terms. "Managed IT systems" tells the assessor nothing about security work. "Configured and tuned SIEM correlation rules, led incident response for confirmed intrusions, and ran quarterly vulnerability scans" maps cleanly to a cyber security code. Where a former employer refuses to issue a letter, a statutory declaration from a colleague with supporting evidence can stand in, though it carries less weight and invites closer scrutiny. The full document checklist lists every supporting item.

Overseas qualifications: transcripts, translations, and recognition

Submit your degree certificate and complete academic transcripts, not just the final parchment. ACS assesses the transcript to confirm the ICT major and unit weighting. Provide colour-scanned certified copies, and for any document not in English, a translation by a NAATI-accredited translator. A transcript that lists unit names but not the ICT content split is the most common reason ACS requests further information, which stalls a four-to-six-week assessment into something considerably longer.

How a penetration tester built an ACS case under code 261317

Seven years in offensive security, no ICT degree. On paper, the General Skills pathway is closed, so RPL is the route. Nominating 261317 Penetration Tester makes sense here, because scoping engagements, exploiting web and network vulnerabilities, and writing remediation reports map directly to that code rather than to the broader 262112.

One project report covers a web application penetration test completed eight months earlier: the tools used (Burp Suite, Nmap, Metasploit), the classes of vulnerability found, the exploitation path, and the fixes recommended. A second report reaches back three years to an internal network engagement, chosen because it falls inside the four-year window and demonstrates a different competency set. For eligibility, the application evidences six-plus years at 20 or more hours a week, including freelance engagements backed by signed client contracts and invoices. ACS accepts self-employment when it is documented, though the freelance question trips up many testers. To close that gap, the submission includes client statements confirming the scope and dates of each contract, giving ACS a third-party anchor for every period. What emerges is a case that proves competency at the exact code the duties support, rather than defaulting to 262112 and hoping the match holds.

Four mistakes that get cyber security ACS applications rejected

Choosing 262112 when a 2022 specialist code fits better

Defaulting to 262112 because a competitor page featured it is the classic error. Analyst, architect, and offensive-testing roles all have specialist codes that describe the work more accurately, and ACS assesses against the code you nominate. Match the duties first, then confirm the code's list membership for your visa.

References that describe IT rather than security duties

Letters full of "maintained servers" and "supported users" read as general ICT, not cyber security. ACS can find your experience unrelated to the nominated code on that basis alone. Every listed duty should be recognizably a security task.

RPL reports that summarize projects instead of proving competency

A report that narrates what the team delivered, without isolating what you personally decided and executed, fails to demonstrate individual competency. Write in the first person about your own technical actions. The RPL rejection self-audit guide walks through this failure mode in detail.

Payslip gaps and employment dates ACS cannot verify

When reference letter dates, payslips, and tax records disagree, ACS cannot confirm the period, and unverifiable experience is discounted. Reconcile every date across every document before you lodge.

ACS fees, processing times, and outcome validity in 2026

Effective 3 November 2025, the ACS General Skills assessment fee is $1,498 AUD excluding GST, and the RPL pathway fee is $625 AUD excluding GST, according to the ACS Migration Skills Assessment information page. Straightforward applications requiring no further information request are typically processed in four to six weeks.

A suitable ACS skills assessment cyber security specialist outcome is valid for two years from the date of the assessment letter, per the ACS InfoHub assessment process page. Several migration blogs circulate a three-year figure, but the current official source states two years. Planning your visa lodgement around the wrong window is an avoidable risk. Successful applicants also receive a complimentary 12-month ACS membership.

For unsuitable outcomes, an appeal is available. A Level 1 review must be lodged within 60 days of the outcome ($516 ex GST), and a Level 2 review within 30 days of the Level 1 result ($620 ex GST). Confirm current amounts on the 2026 fee guide and expected timelines on the processing time page before you budget.

FAQs: ACS Skills Assessment Cyber Security Specialist Roles

Security Engineer, not Security Specialist: which ANZSCO code?

Nominate the code that matches your duties, not your title. Building and hardening controls, detection engineering, and SIEM tuning point to 261315 Cyber Security Engineer. Monitoring and triage work sits closer to 262116 Cyber Security Analyst. ACS assesses the duties in your reference letters, so the title on your business card does not decide the code.

Does a Cyber Security degree qualify for the formal pathway?

No, not automatically. ACS reviews the syllabus unit by unit to confirm an ICT major and its relatedness to your nominated code before granting the formal qualifications pathway. A Cyber Security degree usually qualifies, but one weighted toward law, criminology, or general business can fall short of the ICT major threshold despite its name. Submit full transcripts so ACS can see the ICT content split.

Can freelance or bug bounty work count as ACS experience?

Yes, when it is documented. ACS accepts self-employment and contract work, including freelance penetration testing, if you evidence it with client contracts, invoices, and signed statements confirming scope, dates, and hours. Undocumented bug bounty activity with no client attestation is hard to verify and rarely counts on its own, so pair it with evidence a third party can confirm.

How does ACS assess experience across sub-specializations?

ACS assesses your experience against the single code you nominate, so mixed cyber security experience is measured by how much of it maps to that code's duties. Choose the code your strongest and most recent duties support, then present references and RPL projects that reinforce that code. Spreading evidence thinly across several sub-specializations weakens the match to any one of them.

What if my ANZSCO code is later removed from the list?

Your ACS outcome stays valid for its two years regardless of list changes, because it assesses your skills, not your visa eligibility. Visa eligibility is a separate test: the code must be on the relevant skilled occupation list at the time Home Affairs invites you. If a code is removed before your invitation, the outcome remains valid, but you may need a different nomination pathway. Check current list membership at immi.homeaffairs.gov.au before you lodge the visa.

Before you submit, confirm your code, pathway, and evidence line up for your ACS skills assessment cyber security specialist application. Check the full ACS document checklist to make sure your cyber security application is ready before you lodge.