Can businesses legally mandate training for contractors?

Yes — businesses can require contractors to complete security awareness training. What Australian law expects, how to write it into the agreement, and how to run it.

Yes. In Australia, businesses can require contractors to complete security awareness training as a written condition of their engagement, and in many cases they should: the Privacy Act 1988 expects organisations to take reasonable steps to protect personal information, and recent reform commentary specifically contemplates training for all staff and contractors with access to that information.

TL;DR

Why the question matters more than it sounds

Contractors sit in an awkward spot in most security programs. They have email addresses, system logins and access to client data, but they sit outside the HR umbrella that covers employees. Many businesses run security awareness training only through their HR system — so every contractor, temp and outsourced bookkeeper quietly skips it.

That gap matters because attackers do not distinguish. Phishing remains the number one initial access vector for attacks against Australian organisations in the ASD's threat reporting — and a phishing email does not check whether the recipient is on your payroll. The contractor with a mailbox is as reachable as the employee (FOIT).

What the law actually requires

Australian law does not name a universal "mandatory security training" statute that covers every business. What it does require, broadly, is reasonable care:

If a contractor handles your customers' personal data, untrained access is a risk you documented but did not manage — the worst position to be in after a breach, and a serious one if penalties apply. Serious or repeated privacy breaches can now attract penalties of up to $50 million under the Privacy Act.

Can you make training a condition of engagement?

Yes, and the mechanism is contractual. A business engaging an independent contractor can include, in the services agreement or the contractor's onboarding pack:

This is standard commercial practice, not legal overreach. You are not compelled to give system access to anyone; conditioning access on training is simply risk management expressed as a contract term. Two caveats: make the requirement proportionate (a short course plus simulations for a contractor with an email account; deeper role-based training for one with production access), and get the requirement into the written agreement before the first day, not after the first incident.

One practical caution: training records about contractors are personal information too. Collect completion data, store it, and share it only for security purposes — the same discipline you apply to employee records.

What contractors actually need trained

Contractors need the same fundamentals as employees, tuned to what they touch:

For contractors whose role is genuinely high-risk — outsourced finance functions, IT administrators, anyone with payment authority — add a role-specific module beyond the baseline.

How to run it without doubling your admin

The mistake most businesses make is running a separate contractor program. Don't. Run one program with two lists:

  1. One platform, one course library. Invite contractors into the same security awareness training program employees use, tagged as contractors so reporting separates them.
  2. Same phishing simulations. Include contractor mailboxes in your phishing simulation schedule — attackers target them anyway, and excluding them blinds you to half the risk.
  3. Completion as an access gate. Tie the onboarding checklist to course completion: no certificate, no system login. Automation makes this a rule, not a chase.
  4. Contractor-specific reporting. When a client or auditor asks for evidence, human risk reporting that splits employees from contractors answers the question directly.
  5. Framework mapping. A gap assessment against Essential 8, SMB1001 or ISO 27001 will surface contractor coverage as a control gap if it is missing — better to find it in a review than in an audit.

If you are evaluating platforms for this, check that they support external user accounts and separate reporting before you sign — compare on that feature, not just price.

The compliance payoff

Contractor training is one of those items that costs little and answers a lot:

Evidence beats intention: completion certificates, simulation participation records and a training policy that names contractors are what a reviewer actually wants to see.

FAQ

Can businesses legally mandate security training for contractors? Yes. Training can be set as a written condition of engagement, with access suspension or termination as the consequence for refusal.

Are contractors required to do security training by law in Australia? No standalone statute mandates it for every business, but the Privacy Act's reasonable-steps expectation and recent reform commentary put contractors with access to personal information inside the training obligation in practice.

Who pays for contractor security training? Whatever the agreement says. Most businesses either include it in the engagement terms at their own cost, or permit the contractor to complete an equivalent course and provide the certificate.

Should contractors be included in phishing simulations? Yes. They receive real phishing at the same rate as employees, and their responses are part of your risk picture.

What happens if a contractor refuses training? The contracted consequence applies — typically suspension of system access until completion, or termination of the engagement if access is essential to the role.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.