Cyber Security Advisory and Governance, Risk and Compliance Assessment Services

Closes in 13 daysClose date: 21 August 2026

About this tender

Overview The Department of Climate Change, Energy, the Environment and Water is seeking a trusted, scalable and security-cleared cyber security capability to support governance, risk management, compliance, assurance and accreditation activities across its ICT environment. Purpose The services will assist the Department to prepare and maintain security artefacts, assess cyber security risks, support system accreditation and Authority to Operate (ATO) decisions, and provide defensible assurance advice aligned with applicable Australian Government cyber security requirements. Scope The scope includes: Governance, Risk and Compliance advisory services, including cyber security governance, compliance reporting, risk minutes, security risk assessments, risk treatment planning, audit response, remediation planning and ongoing maintenance of GRC risk tooling and supporting documentation Security documentation and accreditation support, including development and review of System Security Plans (SSPs), Security Risk Management Plans (SRMPs), Security Risk Assessments (SRAs), ATO documentation, accreditation evidence packages, risk registers and executive briefing material Security architecture, cloud security and solution assurance services, including security architecture reviews, solution design reviews, cloud security assessments, security maturity and capability assessments, independent cyber security assurance reviews and strategic cyber security advice Compliance assessment services, including assessment against the Protective Security Policy Framework (PSPF), Information Security Manual (ISM), Essential Eight and related Australian Government cyber security requirements, together with audit and compliance reports and remediation assurance activities Contractor Requirements Each successful Seller must be able to provide access to a nominated pool of suitably qualified and security-cleared cyber security personnel, collectively providing expertise across GRC, security architecture, cyber security assessment and assurance, cloud security, risk management, PSPF, ISM, Essential Eight assessments, system accreditation, ATO support and strategic cyber security advisory services All nominated personnel must hold and maintain a current Australian Government NV1 security clearance as a minimum throughout the contract term All nominated personnel must comply with all Departmental security, privacy, confidentiality and information handling requirements Contract Terms and Conditions Nomination of personnel by a Seller does not guarantee the allocation of work, minimum work volumes or ongoing engagements Assessment and advisory activities will be commissioned on an as-needed basis, depending on Departmental priorities, project demand, funding availability and operational requirements The Department may engage one or more successful Sellers depending on the skills, availability, pricing and suitability of resources for each requirement Where possible, the Department will provide advance notice of upcoming assessment activities, generally a minimum of two (2) weeks' notice for planned engagements, to enable Seller(s) to plan resource availability and mobilise appropriate personnel The Department reserves the right to request specific personnel where specialised expertise is required and to scale resource usage up or down in response to operational demand

How to respond to this tender

A strong tender response is clear, compliant, and backed by evidence. These steps apply to most Australian and New Zealand public tenders.

Read the requirements in full

Open the official listing and download the full tender pack. Note the response schedules, evaluation criteria, mandatory conditions, and the exact closing time and lodgement method.

Confirm you are eligible and it is worth bidding

Check licences, insurances, certifications, and any conformance requirements before you commit. A quick bid or no-bid decision saves days of wasted effort on a tender you cannot win.

Answer every criterion with evidence

Respond to each evaluation criterion directly and back your claims with concrete examples, referees, and past performance. Address the buyer’s stated need, not a generic capability statement.

Lodge early through the official portal

Submit through the source portal well before the deadline. Late or incorrectly lodged bids are almost always rejected, so leave time for uploads, portal errors, and last-minute questions.

Ready to write winning tenders?

Sign up today, what a relief.

Sign up