Black Shard

Insights23 July 2026

What a government tender means when it asks for the Essential Eight

A map from Australian government buyer to the security artefact they actually want, what each one evidences and fails to evidence, and how to answer a schedule asking for something you do not yet have.

A brass padlock resting on a stack of unmarked bound folders, lit cold cyan on dark slate

Where the Essential Eight requirement in a government tender comes from

The requirement rarely originates in the tender document. The Protective Security Policy Framework, administered by the Department of Home Affairs, directs the accountable authorities of non-corporate Commonwealth entities to comply with it and represents better practice for corporate Commonwealth entities and wholly owned Commonwealth companies. In PSPF Release 2026 the eight mitigation strategies appear as requirements 0099 to 0106, each requiring implementation to Maturity Level Two under the Australian Signals Directorate's Essential Eight Maturity Model, and each last updated on 31 October 2024. That obligation attaches to the entity rather than to the businesses it buys from, so what lands in a supplier schedule is the entity managing its own exposure once its data or part of its environment sits with someone else.

The framework also sets out how the obligation reaches you. Requirement 0040 tells entities to put proportionate security terms and conditions into procurements, contracts and third party outsourced arrangements. Requirement 0041 tells the entity to ensure service providers, contractors and subcontractors comply with relevant PSPF requirements as detailed by the entity, which is why two agencies buying the same thing can send you very different schedules. Requirement 0042 turns incident reporting into a contract term, 0044 makes the entity monitor those terms across the life of the contract including subcontractors, and 0045 covers what happens at completion or termination. The word carrying the most weight for a supplier is proportionate, because it is the one that supports a conversation about scope.

This is also why the questions look strange from the supplier side. Maturity level language was built for an entity assessing its own environment against eight named strategies and producing a rating for each one. Compressed into a supplier questionnaire it usually becomes a single field asking for your Essential Eight maturity level, and that field has no correct answer. Give a rating for each of the eight, name the environment assessed, give the date, and name whoever performed the assessment, because the first follow-up question is almost always about scope.

Two details tell you how current the document in front of you is. The framework now sets out mandatory requirements under six domains, each requirement carrying a number retained indefinitely, so a schedule citing PSPF Policy 10 was drafted against a structure the current release does not use and its other clauses deserve the same scepticism. Separately, the Commonwealth Procurement Rules that took effect on 17 November 2025 set the procurement threshold for non-corporate Commonwealth entities at $125,000 for everything other than construction services. Below that threshold the additional rules in Division 2 do not apply, and the security questions usually arrive as an informal questionnaire rather than a schedule with mandatory criteria attached.

Which buyer is asking, and what each one wants

Establish which kind of buyer is in front of you before you draft anything, because the artefact set differs sharply and so does the lead time. A non-corporate Commonwealth entity carries the maturity obligation directly and pushes terms down under requirement 0041. Defence runs a separate programme with its own membership regime. Local government and small statutory bodies often have no framework at all and send a questionnaire assembled from their insurer's requirements, which is a different drafting problem again.

The lead times below are planning ranges rather than measurements, and the driver named in each row is the thing to manage, because that is what decides whether the range collapses or stretches. Two of these buyers can appear in the same procurement, since a prime contractor bidding to a Commonwealth entity will pass its own obligations to you while the entity remains the one that has to be satisfied. Work out which row you are actually in before you decide what to build.

BuyerWhat binds themArtefact usually named in the schedulePlanning lead time and its driver
Non-corporate Commonwealth entityThe Protective Security Policy Framework by ministerial direction, including the Essential Eight at Maturity Level TwoA rating against each of the eight strategies plus a signed attestation, and Information Security Manual alignment for anything holding their dataTwo to four months to Maturity Level One, six to twelve to Level Two, driven by application control and privileged access
Corporate Commonwealth entityIts own enabling legislation and board policy, with the framework treated as better practice rather than a directionEssential Eight self-assessment, or ISO 27001 or SOC 2 where the buyer has an enterprise procurement habitFollows whichever artefact is named, and the certification path is the long one
Defence and the defence supply chainThe Defence Security Principles Framework, reaching industry through the Defence Industry Security ProgramDISP membership at a level matching the information handled, with the full Essential Eight at Maturity Level Two across the systems used to correspond with Defence, evidenced through the cyber security questionnaireSix to twelve months, longer where personnel clearances or facility certification are involved
An entity buying a system it will have to authorisePSPF technology system authorisation, plus the Hosting Certification Framework for security classified hostingAn IRAP assessment of the system, hosting on a certified provider, and an authorisation decision signed inside the entityThree to nine months for a first assessment, driven by writing the system documentation rather than by assessor availability
State or territory agencyThe jurisdiction's own cyber security policy, which is not the Protective Security Policy FrameworkEssential Eight maturity, commonly Level One as a floor, self-assessed and datedTwo to four months to Level One, driven by patching cadence and administrative privilege cleanup
Local government and small statutory bodiesContract terms and insurance conditions rather than a frameworkA tiered small business certification such as SMB1001, evidence of cyber insurance, or a completed security questionnaireWeeks to a few months, driven by how much evidence already exists
A prime contractor passing terms downThe head contract, which carries whatever the entity detailed under requirement 0041Whatever the head contract names, frequently copied across without rescopingSet by the head contract, so negotiate scope in the teaming phase rather than after award

Australian government buyer types, the security artefact usually named, and realistic lead time

What each artefact actually evidences

No Commonwealth body certifies anyone against the Essential Eight. There is no register to appear on, and anything sold as Essential Eight certification is a private assertion by whoever issued it. What exists is an assessment, performed by you or by an assessor you engage, and an attestation you sign. The Australian Signals Directorate also no longer certifies cloud services, and requirement 0109 instead tells entities to use providers that have completed an IRAP assessment against the latest version of the Information Security Manual within the previous 24 months.

For a system the entity runs itself, the framework accepts an entity assessor or an IRAP assessor. For outsourced systems, cloud services and gateways it names an IRAP assessor at every classification from OFFICIAL up to SECRET, with the Australian Signals Directorate taking that role at TOP SECRET, and in every case below TOP SECRET the authorising officer is the accountable authority or chief information security officer of the entity that owns the system. A supplier delivering a system into a Commonwealth entity therefore cannot self-assess its way to an authorisation, and cannot sign one either. The rest of the artefact set is a mix of independent attestations, certifications issued by accredited bodies, and government programmes that certify somebody other than you, and each of them answers a narrow question. The third and fourth columns below are where tender responses fail.

ArtefactWho can issue itHow current it staysWhat it does not tell the buyer
Essential Eight assessment and attestationYou, or an assessor you engage, since no government body certifies itPoint in time, and most buyers treat anything older than about twelve months as staleNothing about the application you are building, the data you hold, or your suppliers
IRAP assessment against the Information Security ManualAn assessor endorsed under the Infosec Registered Assessors Program, with the authorisation decision left to the government entityThe framework asks entities to use cloud providers assessed against the latest manual within the previous 24 monthsIt documents implemented controls and residual risk for an assessor and an authorising officer, and it is not a pass mark
Hosting Certification Framework statusThe Department of Home Affairs, to the hosting or data centre provider rather than to youHeld by the provider, and the framework is being replaced, with certification under Hosting Certification Framework 2 expected to open from late 2026 or early 2027Anything about how you configured, segmented or operated what you run on that provider
ISO 27001 certificateA certification body, so check the accreditation mark as well as the certificateThree-year cycle with surveillance audits in betweenThe scope statement can lawfully exclude the exact systems the buyer cares about
SOC 2 reportA public accounting firm under United States attestation standardsA Type II report covers a defined period that ends and does not renew itselfRead the exceptions, the subservice carve-outs, and the controls the report assumes the customer performs
DISP membershipDefence, on application with an eligibility and suitability assessmentOngoing obligations including annual security reporting, the cyber security questionnaire, and selection for audit on a risk basisThe level maps to the information the member may handle, and it says nothing about product quality
SMB1001 or another tiered small business certificationA certification scheme operating against a published tiered standardRenewal at the tier heldIt is scaled to a small business, so a large agency may accept it only as a floor

Security artefacts named in Australian government tenders: issuer, currency and blind spots

Can you offer ISO 27001 instead of the Essential Eight?

The framework answers this one directly. Its section on alternate cyber security standards treats other Australian and international standards, naming ISO/IEC 27001, as useful resources that are not targeted at the Australian Government and are not suitable as an alternative authorisation to operate pathway. An entity that elects to rely on such a standard has to detail why it was necessary to deviate from the Information Security Manual and the Strategies to Mitigate Cyber Security Incidents in its annual report on security to its minister and to the Department of Home Affairs. An evaluator therefore has a reporting reason to decline the substitution, whatever the schedule's wording appears to allow.

The certificate still does useful work if you stop offering it as a replacement and start using it as evidence. Take the eight strategies as the spine of your answer, show which of your certified controls satisfy each one, name the artefact behind each claim, and state plainly where the certified scope stops. A buyer can accept a mapped answer and record on the evaluation file why it accepted it, which is the outcome you are actually after.

The same discipline applies to an attestation report. A Type II report tests whether controls operated over a defined period, which is closer to what the buyer wants than a management system certificate, but it is bounded by the criteria selected, the systems in scope, the exceptions the auditor recorded, and the controls the report assumes you perform at the customer end. Map it onto the eight strategies and name the gaps, and the report becomes a supporting document instead of an argument.

How does an evaluator read what you send?

An evaluation panel is usually working through a scoring matrix with a security schedule attached, and the security schedule is often a pass or fail gate rather than a scored criterion. The panel is not assessing your security programme in any deep sense. It is checking whether the claims you made are specific enough to rely on and whether the artefacts you attached cover the work being bought. Almost every discount applied at that table comes from a mismatch between the artefact and the scope rather than from a control being genuinely weak, and the claims below are the ones that reliably lose value in front of an experienced evaluator.

  • An undated maturity claim. Every rating needs the assessment date, the environment assessed, and the name of whoever performed the assessment.
  • A licence inventory offered as evidence of coverage. Owning a product capable of enforcing application control is a different claim from enforcing it on every workstation.
  • An ISO 27001 certificate whose scope statement covers one office, one product line or one management system, when the tendered work sits somewhere else.
  • A SOC 2 report attached without its exceptions, its subservice carve-outs, or the complementary controls the report assumes the customer performs.
  • A hosting provider's IRAP report presented as though it covered your system. It covers the provider's platform, and the controls you inherit from it have to be named individually.
  • A maturity level asserted for the corporate environment when the tendered work will run in a build or delivery environment nobody has assessed.
  • A subcontractor answer that stops at the first tier, when the entity has to satisfy itself about subcontractors as well as contractors.
  • A remediation plan with no owner and no dates, offered in the place a control was supposed to go.

State and territory buyers ask a different set of questions

Every state and territory runs its own policy and none of them is the Protective Security Policy Framework. The common pattern is Maturity Level One as the baseline for the agency's own environment, an annual self-assessment, and an attestation signed by an accountable officer. What reaches a supplier is usually an evidence request shaped by that reporting cycle, which is why a state tender often asks you for the same thing the agency has to report about itself. Read the policy the schedule names, because assuming the Commonwealth position applies will put your answer a maturity level out.

Victoria is the jurisdiction to know about, because there the obligation reaches the supplier through the standards themselves rather than only through the contract. The Victorian Protective Data Security Standards were issued by the Information Commissioner under sections 86 and 87 of the Privacy and Data Protection Act 2014 (Vic), they set outcomes across governance, information, personnel, ICT and physical security, and they require contracted service providers with direct or indirect access to public sector information to adhere to them. There is no certification scheme for a contracted service provider to point at, so the evidence has to be assembled directly against the standards.

JurisdictionPolicy binding the agencyEssential Eight positionHow it reaches a supplier
New South WalesThe NSW Cyber Security Policy, issued by Cyber Security NSWThe eight sit inside mandatory requirements 3.3 to 3.10 at a minimum of Maturity Level One, mapped to the December 2024 release of the Information Security Manual, with Level Two and Three considered on a threat basisAgencies report their assurance assessment, high and extreme residual risks, an attestation and a crown jewel inventory by 31 October each year, and the same questions are passed to suppliers
VictoriaThe Victorian Protective Data Security Standards, administered by the Office of the Victorian Information CommissionerThe standards set security outcomes across five areas rather than a separate Essential Eight maturity targetThe standards apply directly to contracted service providers with direct or indirect access to public sector information
QueenslandThe information security policy known as IS18, under the Queensland Government Enterprise ArchitectureAgencies run an information security management system and set their own control baseline, so any maturity target in a schedule is the agency's choice rather than the policy'sAnnual attestation by the agency's accountable officer, pushed down as evidence requests
Other states and territoriesEach publishes its own cyber security policy or frameworkMaturity Level One is the common floor, mandated in some jurisdictions and recommended in others, with uplift above it set by the agency's own risk assessmentContractual flow-down shaped by what the agency has to report about itself, so read the named policy rather than assuming

How three state positions on the Essential Eight reach a supplier

What the Essential Eight does not tell a buyer about software you build

The Essential Eight assesses eight mitigation strategies across endpoints, servers and the identity plane of a corporate environment. It says nothing about the software you are proposing to build and run for the buyer. Authorisation logic, tenant separation, the audit trail, whether a record can be edited after the fact, the third parties your application calls: none of that is in the model, and none of it improves because you moved from Maturity Level One to Level Two. A supplier whose entire security narrative rests on maturity has answered a question about its office and left the question about its product open.

The gap that costs suppliers work is usually the same one. The corporate fleet gets assessed because that is what the questionnaire asked about, and the build and deployment environment does not, even though that is the environment holding credentials to production. Assess it as its own environment, rate it separately, and put both ratings in the response with their dates. Where the buyer is procuring a system it will have to authorise rather than a service it will consume informally, the assessment that decides the outcome is the assessment of that system against the Information Security Manual, and your corporate maturity rating is a supporting document in that conversation.

What can you achieve when the tender closes in six weeks?

Certification is not available in six weeks, and pretending otherwise is how suppliers get disqualified for a misleading response. What is achievable is a scoped, dated assessment with evidence behind it, plus real movement on the controls that need no procurement. Multi-factor authentication extended across every account that matters, administrative privileges cut back to a justified list, a patch cadence written down with an owner and dated exceptions, and a restore actually tested and evidenced. Those four moves shift genuine maturity, need nothing bought, and produce artefacts an evaluator can read.

The work that cannot compress is anything needing an operating period or a third party's calendar. A Type II attestation needs its observation window to elapse. An ISO 27001 certificate needs a management system that has run long enough to have internal audit and management review records behind it, then a two-stage audit. A first IRAP assessment needs a system security plan, a risk management plan and an incident response plan that describe the system as it actually is, and drafting those documents rather than booking the assessor is usually the critical path. DISP membership runs on Defence's timetable through an eligibility and suitability process.

Sequence the six weeks backwards from the response deadline. Week one settles which environment the tendered work will run in, what classification of data it will hold, and which of the eight strategies you can evidence today. Weeks two to four are the identity and privilege work plus evidence collection, which takes longer than teams expect because every artefact needs a date and an owner attached. Leave the final fortnight for drafting, and start that fortnight with the assessment already finished.

How to answer a schedule asking for something you do not have

Claiming a maturity level you cannot evidence creates a problem that outlasts the tender. A compliance statement in a tender response is a representation the buyer relies on, it survives into the contract, and it is discoverable the first time an incident or an audit looks backwards. The alternative is a precise statement of position, a dated plan and a commitment structured so the buyer can price the risk. Buyers accept gaps regularly, and what they rarely accept is a gap they find out about after award.

A strong answer has four parts. State what you assess today, per strategy, with the environment and the date. State what is not yet in place and describe it in terms of the control rather than the excuse. State what will be in place by contract commencement, with dates and a named owner. Then offer the compensating arrangement for the gap in between, whether that is a restricted data flow, a segregated environment for the buyer's work, or an agreement that the buyer's data never enters your general fleet.

Use the clarification mechanism before you resort to any of that. For a procurement at or above the threshold, paragraph 10.8 of the Commonwealth Procurement Rules requires the entity to deal with potential suppliers fairly and without discrimination and to reply promptly to reasonable requests for information while avoiding any supplier gaining an unfair advantage, which is why a well-framed scope question asked before close reaches the whole field. Paragraph 10.14 limits conditions for participation to those that ensure a supplier has the legal, commercial, technical and financial abilities to fulfil the requirements of the procurement. An artefact aimed at a system the entity will authorise, demanded for an engagement where you deliver advice and never hold their data, is a fair thing to put to that test. The worst outcome is that the requirement stands and you learn it six weeks early rather than on the day the evaluation report is written.

How we work on this at Black Shard

We run Essential Eight assessments and uplift as an evidence exercise rather than a scoring exercise, because the evidence trail is what a buyer's evaluator, and later a buyer's auditor, actually reads. The deliverable is a rating per strategy against a named environment, the artefact behind each rating, and a plan for the gaps with owners and dates attached. Where a client needs the posture held together across a tender programme rather than assessed once, that is vCISO work, and it usually includes writing the response schedules and handling the clarification questions.

The second half of this problem is engineering, because most of what a serious government buyer asks about lives in how the system was built. The operations and compliance portal we built and run for GRM LAW, a Brisbane law firm, carries intake, conflicts checks, a matter register and AML/CTF readiness over an append-only audit ledger. The staff portal we built for Stone Leaf Capital, an Australian capital-markets firm, carries critical-event tracking and policy modules over a compliance audit log recording actor, action, and before and after state. Aurii, our own clinical software venture, runs tenant health data on Azure in Australia with tamper-evident audit trails.

We hold ourselves to the standard we ask buyers to apply. Our trust page states what we hold, what we self-assess and what we have not done, with each labelled for what it is, and our approach page sets out how the engineering side works. On a tender response the output is the assessment, the evidence index sitting behind it and the schedule text itself, so the next buyer's questions get answered from material that already exists rather than rebuilt against another deadline.

Walk into the audit with the evidence in hand.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au