Penetration Testing Services

Closes in 8 daysClose date: 29 July 2026

Tender Overview

PCS-04296
Issued by Australian Competition & Consumer Commission (ACCC)
Western Australia : Gascoyne : Goldfields/Esperance : Great Southern : Kimberley : Mid West : Peel : Perth Metropolitan : Pilbara : South West : Wheatbelt New South Wales : Central West : Far North Coast : Far West : Hunter : Illawarra : Mid North Coast : Murray : New England : Orana : Riverina : Southern Highlands : Sydney Queensland : Cairns & Far North Queensland : Gladstone : Mackay Whitsunday Region : Mount Isa & North West Region : Rockhampton : South East Queensland : South West & Darling Downs : The Central West : Townsville : Wide Bay Burnett Victoria : Barwon South West : Gippsland : Grampians : Hume : Loddon Mallee : Melbourne South Australia : Adelaide : Eyre & Western : Far North : Fleurieu & Kangaroo Island : Limestone Coast : Murray & Mallee : York & Mid North Northern Territory : Barkly : Big Rivers : Central Australia : East Arnhem : Greater Darwin : Top End Australian Capital Territory Tasmania
Information & Communication Technology : IT Security Services

About this tender

This Tender is invited by the Issuer. Overview The Australian Competition & Consumer Commission (ACCC) Digital ID Program requires a one-time engagement of an external penetration testing provider to conduct an independent and comprehensive security assessment of the Digital ID Regulator System (DIRS) prior to its production release. Purpose This engagement is intended to provide independent validation of the platform's security posture by simulating real-world attack scenarios across both external and internal threat vectors. While a range of internal security controls and automated tools are already in place, penetration testing introduces adversarial techniques that allow for the identification of vulnerabilities that may not be detected through standard testing approaches. The outcome of this engagement is to identify vulnerabilities, assess the effectiveness of implemented security controls, and provide clear and actionable remediation guidance to support risk reduction prior to public release. Scope The scope includes: Conducting an independent and comprehensive security assessment of the Digital ID Regulator System (DIRS) Simulating real-world attack scenarios across both external and internal threat vectors Identifying vulnerabilities in the platform Assessing the effectiveness of implemented security controls Providing clear and actionable remediation guidance to support risk reduction prior to public release Instructions to Tenderers The engagement is time-sensitive, with external penetration testing required in August. Please see the document for further details about requirements.

How to respond to this tender

A strong tender response is clear, compliant, and backed by evidence. These steps apply to most Australian and New Zealand public tenders.

Read the requirements in full

Open the official listing and download the full tender pack. Note the response schedules, evaluation criteria, mandatory conditions, and the exact closing time and lodgement method.

Confirm you are eligible and it is worth bidding

Check licences, insurances, certifications, and any conformance requirements before you commit. A quick bid or no-bid decision saves days of wasted effort on a tender you cannot win.

Answer every criterion with evidence

Respond to each evaluation criterion directly and back your claims with concrete examples, referees, and past performance. Address the buyer’s stated need, not a generic capability statement.

Lodge early through the official portal

Submit through the source portal well before the deadline. Late or incorrectly lodged bids are almost always rejected, so leave time for uploads, portal errors, and last-minute questions.

Ready to write winning tenders?

Sign up today, what a relief.

Sign up