Keycloak-based CIAM solution Time and Materials

Closes in 13 daysClose date: 4 August 2026

Tender Overview

PCS-04334
Issued by Department of Agriculture, Fisheries and Forestry
Western Australia : Gascoyne : Goldfields/Esperance : Great Southern : Kimberley : Mid West : Peel : Perth Metropolitan : Pilbara : South West : Wheatbelt New South Wales : Central West : Far North Coast : Far West : Hunter : Illawarra : Mid North Coast : Murray : New England : Orana : Riverina : Southern Highlands : Sydney Queensland : Cairns & Far North Queensland : Gladstone : Mackay Whitsunday Region : Mount Isa & North West Region : Rockhampton : South East Queensland : South West & Darling Downs : The Central West : Townsville : Wide Bay Burnett Victoria : Barwon South West : Gippsland : Grampians : Hume : Loddon Mallee : Melbourne South Australia : Adelaide : Eyre & Western : Far North : Fleurieu & Kangaroo Island : Limestone Coast : Murray & Mallee : York & Mid North Northern Territory : Barkly : Big Rivers : Central Australia : East Arnhem : Greater Darwin : Top End Australian Capital Territory Tasmania
Information & Communication Technology : Consultancy & Project Management : IT Security Services : IT Services : Software & Application Development Services : Software Support & Maintenance Services

About this tender

Overview The Department of Agriculture, Fisheries and Forestry (DAFF) is seeking a time and materials arrangement with a vendor for the supply of suitably qualified consultation support for the implementation of Keycloak in the department. Scope Provision of consultation support, on a time and materials basis, for the implementation of a Keycloak-based CIAM solution in the department Contractor Requirements The supplier must demonstrate extensive experience in the design, installation, configuration, and operation of Keycloak-based CIAM solutions. This includes expertise in identity protocols (OIDC, OAuth2, SAML), secure authentication mechanisms (including MFA), integration with enterprise systems and external identity providers, and deployment in cloud-native environments using containerisation and automation tools. The supplier must also have capability in customisation (SPI development, authentication flows), high availability design, performance tuning, and migration from legacy identity platforms. Strong DevOps, security, and documentation practices are essential, along with the ability to provide knowledge transfer and ongoing support. 1. Core Keycloak Platform Expertise Keycloak architecture, including realms, clients, roles, groups, users, identity providers (IdPs), and service providers (SPs) Multi-realm and multi-tenant designs Installation and deployment in cloud (Azure) and containerised (Kubernetes) environments Configuration and administration, including realm setup, authentication flows, and client configuration Custom themes for login, registration, and account management 2. Identity & Access Management (IAM / CIAM) Expertise Authentication protocols: OAuth 2.0, OpenID Connect (OIDC), SAML 2.0 Authorization models: RBAC, ABAC, and fine-grained authorization services in Keycloak User lifecycle management, including registration, verification, password resets, and account linking Customer identity use cases, including external users and federated identity Identity federation, including integration with external IdPs (AGDIS) 3. Security & Compliance Expertise Secure authentication mechanisms, including MFA, OTP, and WebAuthn/FIDO2 (Passkeys) Threat mitigation, including brute-force protection, session management, and token security Secure token handling, including JWT, access tokens, refresh tokens, and token exchange Compliance understanding, including privacy considerations for customer identity, and data protection and consent management Secure configuration practices, including TLS, secrets management, and vault integration 4. Integration & API Expertise Integration with enterprise systems, APIs, gateways, and microservices architectures Experience integrating with API gateways such as Azure APIM, and with backend services and web/mobile applications User federation, including LDAP and Active Directory integration Custom extensions, including SPI (Service Provider Interfaces) development in Keycloak Event listeners and hooks for auditing, logging, and external system integration 5. DevOps & Automation Capability Container orchestration, including Kubernetes with Helm charts and operators Configuration automation, including realm import/export and scripted configuration Monitoring and observability 6. Performance, Scalability & HA Design Keycloak clustering and scaling, including horizontal scaling strategies High availability and resilience, including load balancing and failover design Caching and session management, including load testing and benchmarking 7. Cloud Platform Expertise Experience implementing Keycloak CIAM solutions in Azure environments Managed Kubernetes services, including AKS Understanding of native identity services, including Azure AD B2C Networking and security, including VPCs, firewalls, and private endpoints 8. Customisation & Development Development skills in Java (for Keycloak extensions) and JavaScript, including React, for themes and UI customisation Custom authentication flows, including conditional authentication Custom providers, including REST, user storage, and identity brokering Branding and UX customisation, including login pages and user journeys 9. Data Migration & Transition Migration from legacy IAM systems, including user migration strategies such as bulk import and password migration Data transformation and validation Coexistence strategies during transition phases 10. Documentation & Knowledge Transfer Production of quality documentation, including architecture designs (HLD/LLD) and configuration and operational runbooks Provision of knowledge transfer, including workshops for internal teams and training for administrators and developers 11. Governance & Delivery Capability Proven delivery experience in CIAM or IAM transformations, using agile delivery methodologies Strong stakeholder engagement across business, security, and technical teams Risk management and mitigation

How to respond to this tender

A strong tender response is clear, compliant, and backed by evidence. These steps apply to most Australian and New Zealand public tenders.

Read the requirements in full

Open the official listing and download the full tender pack. Note the response schedules, evaluation criteria, mandatory conditions, and the exact closing time and lodgement method.

Confirm you are eligible and it is worth bidding

Check licences, insurances, certifications, and any conformance requirements before you commit. A quick bid or no-bid decision saves days of wasted effort on a tender you cannot win.

Answer every criterion with evidence

Respond to each evaluation criterion directly and back your claims with concrete examples, referees, and past performance. Address the buyer’s stated need, not a generic capability statement.

Lodge early through the official portal

Submit through the source portal well before the deadline. Late or incorrectly lodged bids are almost always rejected, so leave time for uploads, portal errors, and last-minute questions.

Ready to write winning tenders?

Sign up today, what a relief.

Sign up