Cyber Authorisation Process Reform solution
Tender Overview
About this tender
Overview The Department of Defence is seeking information on an enabling technology solution to govern the lifecycle management of cyber secure Defence Technology Systems, from identification through to retirement, independent of delivery pathway or organisational structure. The solution would establish traceability between Technology Systems and the evidence associated with lifecycle events. Purpose Defence seeks to understand what commercial solutions are available to address the enterprise cyber assessment and authorisation tools and processes required to enable the Defence Secure Systems Framework (DSSF). The DSSF seeks to ensure all Defence Technology Systems are secure, resilient and fit for their intended use throughout their lifecycle. It establishes the mandatory outcomes, accountabilities and regulatory arrangements for managing cyber risk across the lifecycle of all Defence Technology Systems. The technology solution will not replace Defence delegations, delivery models, systems-of-record or specialist authorities. Rather, it will provide the enabling mechanism through which approved policy, governance, delegations, assurance frameworks and lifecycle requirements are codified, orchestrated and applied consistently across Defence Technology Systems. Scope The key needs and requirements for the technology solution have been identified as follows: Enables lifecycle management of cyber secure Defence Technology Systems from identification through retirement, independent of delivery pathway or organisational structure Enables a canonical Technology System record linking identity, ownership, scope, mission context, architecture, dependencies, composition, security controls, evidence, cyber risk, findings, exceptions, decisions and lifecycle history Combines lifecycle workflows, Governance, Risk and Compliance (GRC), authoritative data and traceable evidence to support proportionate cybersecurity assurance, enterprise cyber risk visibility and accountable decisions A list of key high-level requirements is at Enclosure 1, to support this RFI. Information Requested Management Considerations (Core) Information which evidences the respondent's technical ability, track record and experience, and capacity and resources to fulfil the Statement of Defence Needs An indicative costing (rough order of magnitude) for satisfying the Statement of Defence Needs, with a break-down of this costing where possible Details of available solutions and relevant technologies, or an indication of the time to mature the solution to meet the Statement of Defence Needs Identification of key technical risks relating to the proposed solution, and potential mitigation strategies where possible Identification of proposed teaming arrangements and market constraints to fulfil the Statement of Defence Needs High level schedule information to design, develop, deliver and support the technology solution Identification of the need for Professional Services to design, develop, deliver and support the technology solution The full name of the respondent, any trading or business name, and if a company, the registered office, principal place of business and an outline of the company structure The date and place of incorporation Particulars of any foreign national, foreign bodies or others in a position to exercise or influence control over the respondent For a foreign firm or company, details of its registration, incorporation and place of business in Australia and the name of any Australian representative and its ABN / ARBN (if any) If an Australian company, its ACN / ARBN and ABN as applicable Solution Considerations (Optional) A functional description of any specific products or service offerings believed to satisfy the Statement of Defence Needs, and an explanation of how they will meet those needs Where further development work may be required to fully meet the Statement of Defence Needs, details of scope, cost and risks for that work, an assessment of its feasibility, and an indicative timeframe Where any aspect of the Statement of Defence Needs cannot be met, details of the relevant need(s) and an explanation as to why they cannot be met An initial description of the proposed technical support framework for the offered solution Defence may invite selected respondents to provide a demonstration, briefing, workshop, proof-of-concept, or other showcase to further clarify aspects of their response. Participation in such activities will be at the discretion of Defence and will not constitute a commitment by Defence to any future procurement activity. Eligibility Conditions for Participation: no exclusion clauses Contract Terms and Conditions Timeframe for Delivery: Quarter 3, 2027 Instructions to Tenderers Responses are to be lodged electronically via AusTender at www.tenders.gov.au, in accordance with instructions in the tender documentation. Enquiries Contact: Acting Assistant Director CASPR Project Email: cyberauthorisationprocessreformproject@resources.defence.gov.au
How to respond to this tender
A strong tender response is clear, compliant, and backed by evidence. These steps apply to most Australian and New Zealand public tenders.
Read the requirements in full
Open the official listing and download the full tender pack. Note the response schedules, evaluation criteria, mandatory conditions, and the exact closing time and lodgement method.
Confirm you are eligible and it is worth bidding
Check licences, insurances, certifications, and any conformance requirements before you commit. A quick bid or no-bid decision saves days of wasted effort on a tender you cannot win.
Answer every criterion with evidence
Respond to each evaluation criterion directly and back your claims with concrete examples, referees, and past performance. Address the buyer’s stated need, not a generic capability statement.
Lodge early through the official portal
Submit through the source portal well before the deadline. Late or incorrectly lodged bids are almost always rejected, so leave time for uploads, portal errors, and last-minute questions.
