Pick the wrong ANZSCO code and your ACS skills assessment cyber security specialist application can return suitable for an occupation you never meant to nominate, or unsuitable because your reference letters describe general IT work instead of security work. The code you choose before you lodge sets the eligibility bar, the evidence ACS weighs, and the visa subclasses you can later target. Most migration pages skip this decision and funnel every applicant toward one generic code. This guide maps the current cyber security ANZSCO codes against what ACS actually assesses, so you pick the right one first.
Why your ANZSCO code decides your skilled migration outcome
The Australian Computer Society (ACS) is the assessing authority for every cyber security ANZSCO code. When you nominate a code, ACS compares your qualifications and employment history against that occupation's ANZSCO description and its underlying ICT requirements. A suitable outcome confirms two things: how your qualification compares to an Australian standard, and the date from which your employment counts as skilled at the nominated level.
That skilled-employment date carries more weight than most applicants expect. Your points claim swings on it.
How ACS sets the eligibility bar from a code
Each code carries its own duty profile and its own expected qualification relatedness. A governance role and an offensive-testing role are assessed against different evidence, even though both sit under the cyber security banner. Nominate a code your documents cannot support, and the assessment strains at exactly the point competitor pages gloss over.
Points-tested visas: subclass 189, 190, and 491
Subclass 189, the Skilled Independent visa, requires a minimum of 65 points before the Department of Home Affairs will invite you. ACS does not award those points directly. It determines which years of your experience count as skilled, and Home Affairs converts that into points for skilled employment. When your evidence cannot support the nominated code, ACS may treat your early years as not-yet-skilled, removing them from your points calculation and dropping you below the invitation threshold. The pathways comparison breaks down how each route feeds a points claim.
Seven cyber security ANZSCO codes and which one fits your role
The heart of any ACS skills assessment cyber security specialist decision is picking the code your duties actually support. This is where most competitor guides go wrong: they treat one code, 262112 ICT Security Specialist, as if it covered the whole field. The ACS cyber security occupations page tells a different story. As of 2026, that page lists seven specialist codes, and 262112 is not among them.
ANZSCO code | Official title |
|---|---|
261315 | Cyber Security Engineer |
261317 | Penetration Tester |
262114 | Cyber Governance Risk and Compliance Specialist |
262115 | Cyber Security Advice and Assessment Specialist |
262116 | Cyber Security Analyst |
262117 | Cyber Security Architect |
262118 | Cyber Security Operations Coordinator |
The 262112 puzzle: on the MLTSSL, off the cyber page
262112 ICT Security Specialist still sits on the Medium and Long-term Strategic Skills List (MLTSSL) with ACS as the assessing authority, so a points-tested applicant can still nominate it for subclass 189, 190, or 491. Yet it no longer appears on the ACS cyber security occupations page, which now routes cyber roles to the seven specialist codes above. Reconcile these two facts before you lodge. Confirm your target specialist code's current list membership at immi.homeaffairs.gov.au, because ACS listing a code does not guarantee its place on the skilled occupation list your visa subclass draws from. This reconciliation step is what nearly every competitor page omits.
What the 2022 ANZSCO update actually changed
The November 2022 ANZSCO update, reported by ACS Information Age, split roles previously bundled under 262112 into new codes: Cyber Security Engineer (261315), DevOps Engineer (261316), Penetration Tester (261317), and three governance and analyst occupations (262114 to 262116). The live ACS cyber security page has evolved since the 2022 announcement: it now lists seven codes, drops 261316 DevOps Engineer (not classed as a cyber security occupation there), and adds two codes the 2022 announcement never named: Cyber Security Architect (262117) and Cyber Security Operations Coordinator (262118). Any code list dated 2022 is already stale, so check the current ACS page directly.
Role-to-code decision matrix
Match your duties, not your job title, to the code. Titles vary by employer; ANZSCO duties do not.
Your role | Core duties | Recommended code | Likely pathway |
|---|---|---|---|
Security Engineer | Builds and hardens controls, detection engineering, SIEM tuning | 261315 Cyber Security Engineer | Formal qualifications with an ICT degree, otherwise RPL |
SOC Analyst | Monitoring, alert triage, incident detection | 262116 Cyber Security Analyst | Formal qualifications with an ICT degree, otherwise RPL |
Cloud Security Architect | Security architecture, design authority, control frameworks | 262117 Cyber Security Architect | Formal qualifications; senior RPL if no degree |
Penetration Tester | Offensive testing, red teaming, remediation reporting | 261317 Penetration Tester | RPL is common; formal qualifications with an ICT degree |
GRC Manager | Risk, compliance, audit, policy | 262114 Cyber Governance Risk and Compliance Specialist | Formal qualifications or RPL |
For advisory work (security assessments, maturity reviews, client-facing recommendations rather than hands-on operations), 262115 Cyber Security Advice and Assessment Specialist often fits better than the analyst or engineer codes.
Formal qualifications pathway: degree rules and the ICT major test
When a Cyber Security degree counts as closely related to ICT
The General Skills pathway expects an AQF Level 7 bachelor's degree or higher with a major in ICT or a closely related field. A dedicated Cyber Security degree usually clears the bar, but ACS reviews the syllabus unit by unit rather than trusting the parchment title. What ACS measures is how much of the program is ICT content and whether that content is closely related to your nominated code. A degree badged Cyber Security but weighted toward law, criminology, or general management can miss the ICT major threshold even when the name sounds like a perfect fit.
The experience ACS then requires is tiered by how well your qualification matches, per the ACS General Skills pathway page:
Bachelor's with an ICT major, closely related to the occupation: 2 years in the last 10, or 4 years anytime.
Bachelor's with an ICT minor, closely related: 5 years in the last 10, or 6 years anytime.
Diploma or advanced diploma with an ICT major, closely related: 5 years in the last 10, or 6 years anytime.
All experience must be professional IT employment at 20 or more hours per week. Read those thresholds carefully, because they decide whether you qualify without touching RPL at all.
When ACS deducts a skills requirement and how to respond
Where your qualification does not fully meet the ICT major or relatedness test, ACS applies an additional experience requirement before your skilled date begins. In practice, more of your early career is treated as pre-skilled, pushing back the date your points-earning experience starts. Arguing the decision rarely helps. Front-loading evidence does: submit a transcript that clearly shows the ICT unit weighting, and provide reference letters that anchor your security duties to the nominated code from your first relevant role. The pathways explained guide covers how the qualification comparison feeds this calculation.
RPL pathway: proving competency without an ICT degree
Lacking an ICT-major degree does not mean no assessment. The Recognition of Prior Learning (RPL) pathway is built for exactly that case, and it is not the three-episode Engineers Australia CDR that some templates recycle. ACS RPL assesses no tertiary qualification at all. The whole case rests on work.
Eligibility starts at six years of relevant IT experience, currently held or completed within the last two years, at a minimum of 20 hours per week.
What ACS expects in an RPL submission
Two project reports, not three career episodes, and no separate summary statement. One report must cover a project completed within the last two years; the other, a project within the last four years, per the ACS RPL pathway page. Each report walks through one real project and demonstrates the ICT competencies you personally applied, mapped to the duties of your nominated code.
Mapping your security work to competency areas
ACS uses the Skills Framework for the Information Age (SFIA) as its competency reference. Neither ACS nor the competitor pages publish a fixed SFIA level for each cyber security code, so do not claim one. Instead, pick the two projects that most directly exercise your nominated code's core duties. For each project, show the decision you made, the technical action you took, and the outcome you owned. A penetration tester nominating 261317 writes about scoping and running an engagement and the vulnerabilities it exposed, not about the organization's overall security posture. That specificity is the difference between a report that reads as competency and one that reads as a project diary.
Documents ACS requires from a cyber security specialist
Employment reference letters in the exact format ACS accepts
Reference letters sink more cyber security applications than any other document. On company letterhead, signed by a direct supervisor or an authorized HR representative, each letter must state your start and end dates, your hours per week, and your duties itemized in security terms. "Managed IT systems" tells the assessor nothing about security work. "Configured and tuned SIEM correlation rules, led incident response for confirmed intrusions, and ran quarterly vulnerability scans" maps cleanly to a cyber security code. Where a former employer refuses to issue a letter, a statutory declaration from a colleague with supporting evidence can stand in, though it carries less weight and invites closer scrutiny. The full document checklist lists every supporting item.
Overseas qualifications: transcripts, translations, and recognition
Submit your degree certificate and complete academic transcripts, not just the final parchment. ACS assesses the transcript to confirm the ICT major and unit weighting. Provide colour-scanned certified copies, and for any document not in English, a translation by a NAATI-accredited translator. A transcript that lists unit names but not the ICT content split is the most common reason ACS requests further information, which stalls a four-to-six-week assessment into something considerably longer.
How a penetration tester built an ACS case under code 261317
Seven years in offensive security, no ICT degree. On paper, the General Skills pathway is closed, so RPL is the route. Nominating 261317 Penetration Tester makes sense here, because scoping engagements, exploiting web and network vulnerabilities, and writing remediation reports map directly to that code rather than to the broader 262112.
One project report covers a web application penetration test completed eight months earlier: the tools used (Burp Suite, Nmap, Metasploit), the classes of vulnerability found, the exploitation path, and the fixes recommended. A second report reaches back three years to an internal network engagement, chosen because it falls inside the four-year window and demonstrates a different competency set. For eligibility, the application evidences six-plus years at 20 or more hours a week, including freelance engagements backed by signed client contracts and invoices. ACS accepts self-employment when it is documented, though the freelance question trips up many testers. To close that gap, the submission includes client statements confirming the scope and dates of each contract, giving ACS a third-party anchor for every period. What emerges is a case that proves competency at the exact code the duties support, rather than defaulting to 262112 and hoping the match holds.
Four mistakes that get cyber security ACS applications rejected
Choosing 262112 when a 2022 specialist code fits better
Defaulting to 262112 because a competitor page featured it is the classic error. Analyst, architect, and offensive-testing roles all have specialist codes that describe the work more accurately, and ACS assesses against the code you nominate. Match the duties first, then confirm the code's list membership for your visa.
References that describe IT rather than security duties
Letters full of "maintained servers" and "supported users" read as general ICT, not cyber security. ACS can find your experience unrelated to the nominated code on that basis alone. Every listed duty should be recognizably a security task.
RPL reports that summarize projects instead of proving competency
A report that narrates what the team delivered, without isolating what you personally decided and executed, fails to demonstrate individual competency. Write in the first person about your own technical actions. The RPL rejection self-audit guide walks through this failure mode in detail.
Payslip gaps and employment dates ACS cannot verify
When reference letter dates, payslips, and tax records disagree, ACS cannot confirm the period, and unverifiable experience is discounted. Reconcile every date across every document before you lodge.
ACS fees, processing times, and outcome validity in 2026
Effective 3 November 2025, the ACS General Skills assessment fee is $1,498 AUD excluding GST, and the RPL pathway fee is $625 AUD excluding GST, according to the ACS Migration Skills Assessment information page. Straightforward applications requiring no further information request are typically processed in four to six weeks.
A suitable ACS skills assessment cyber security specialist outcome is valid for two years from the date of the assessment letter, per the ACS InfoHub assessment process page. Several migration blogs circulate a three-year figure, but the current official source states two years. Planning your visa lodgement around the wrong window is an avoidable risk. Successful applicants also receive a complimentary 12-month ACS membership.
For unsuitable outcomes, an appeal is available. A Level 1 review must be lodged within 60 days of the outcome ($516 ex GST), and a Level 2 review within 30 days of the Level 1 result ($620 ex GST). Confirm current amounts on the 2026 fee guide and expected timelines on the processing time page before you budget.
FAQs: ACS Skills Assessment Cyber Security Specialist Roles
Security Engineer, not Security Specialist: which ANZSCO code?
Nominate the code that matches your duties, not your title. Building and hardening controls, detection engineering, and SIEM tuning point to 261315 Cyber Security Engineer. Monitoring and triage work sits closer to 262116 Cyber Security Analyst. ACS assesses the duties in your reference letters, so the title on your business card does not decide the code.
Does a Cyber Security degree qualify for the formal pathway?
No, not automatically. ACS reviews the syllabus unit by unit to confirm an ICT major and its relatedness to your nominated code before granting the formal qualifications pathway. A Cyber Security degree usually qualifies, but one weighted toward law, criminology, or general business can fall short of the ICT major threshold despite its name. Submit full transcripts so ACS can see the ICT content split.
Can freelance or bug bounty work count as ACS experience?
Yes, when it is documented. ACS accepts self-employment and contract work, including freelance penetration testing, if you evidence it with client contracts, invoices, and signed statements confirming scope, dates, and hours. Undocumented bug bounty activity with no client attestation is hard to verify and rarely counts on its own, so pair it with evidence a third party can confirm.
How does ACS assess experience across sub-specializations?
ACS assesses your experience against the single code you nominate, so mixed cyber security experience is measured by how much of it maps to that code's duties. Choose the code your strongest and most recent duties support, then present references and RPL projects that reinforce that code. Spreading evidence thinly across several sub-specializations weakens the match to any one of them.
What if my ANZSCO code is later removed from the list?
Your ACS outcome stays valid for its two years regardless of list changes, because it assesses your skills, not your visa eligibility. Visa eligibility is a separate test: the code must be on the relevant skilled occupation list at the time Home Affairs invites you. If a code is removed before your invitation, the outcome remains valid, but you may need a different nomination pathway. Check current list membership at immi.homeaffairs.gov.au before you lodge the visa.
Before you submit, confirm your code, pathway, and evidence line up for your ACS skills assessment cyber security specialist application. Check the full ACS document checklist to make sure your cyber security application is ready before you lodge.
