Who we work with

Federal Government

Commonwealth agencies do not lack security policy. What they lack, almost universally, is evidence that the policy reaches the devices people actually carry.

Every federal agency we work with has a mature desktop compliance story and a mobile estate that sits somewhere beside it. The workstations are patched, measured and reported. The handsets are enrolled in an MDM, which is a different claim entirely, and the gap between those two sentences is where most of our federal work begins.

It is not negligence. The Essential Eight was written with a Windows workstation in the frame, the devices were procured as telephony, and nobody was ever asked to produce a mobile maturity assessment. The problem surfaces when an assessor asks how application control, patching or MFA apply to the fleet, and the honest answer is that they mostly do not.

CDTS closes that gap as a service rather than a project: the platform is designed, migrated and then operated to a defined standard, with reporting an agency can hand to an assessor without adding a caveat to it.

Where the work goes

What we focus on in this sector

Scope is agreed per engagement. These are the areas that consistently carry the most value here.

01

Mobile in the compliance boundary

Patch currency, application control, MFA and administrative privilege stated for the mobile fleet in the same terms as the desktop, with the evidence produced monthly rather than reconstructed at audit.

02

Sovereignty stated per service

Where the data sits, where the backups replicate, who holds the keys and where support escalates — recorded per component rather than asserted for the whole environment.

03

Protective markings that survive mobile

EPMS and PSPF markings enforced on the handset, not just in the desktop client, so mobile mail does not have to be classified down to be permitted.

04

Security-cleared delivery

Cleared, onshore personnel on the engagements that require them, named in the delivery model rather than promised in the proposal.

05

Procurement pathways that move

BuyICT listing and Indigenous Procurement Policy eligibility, so an approach to market is not the only route to getting work started.

Outcomes

What changes once it is running properly

  • A mobile posture report an assessor can read without a caveat attached
  • Zero-touch enrolment that survives each OS release rather than breaking on it
  • Sovereignty answers per service, in writing, before a contract is signed
  • A single accountable owner for the endpoint platform
Services

What usually applies

A few of the organisations we have delivered for

Department of Defence
Department of Defence
Royal Australian Air Force
Royal Australian Air Force
Department of the Prime Minister and Cabinet
Department of the Prime Minister and Cabinet
Department of Foreign Affairs and Trade
Department of Foreign Affairs and Trade
Department of Home Affairs
Department of Home Affairs
Attorney-General’s Department
Attorney-General’s Department
Parliament of Australia
Parliament of Australia
Parliament of New South Wales
Parliament of New South Wales

Common questions

Is CDTS IRAP assessed?

No, and any provider telling you they are as a company is worth a second question. IRAP assessment attaches to systems and solutions, not to organisations. The mobile threat defence solution we deliver is IRAP-assessed at PROTECTED, as is the Oracle Cloud Infrastructure environment it runs in, which we manage. CDTS itself holds no certification.

Can you work on cleared engagements?

Yes. We maintain security-cleared personnel and can staff engagements that require them. We do not publish clearance levels — we confirm what an engagement needs and who will be assigned before work starts.

How does the Indigenous Procurement Policy apply?

CDTS is a 100% Indigenous-owned Australian SMB, which makes eligible purchases available through the IPP exemption arrangements. That is a procurement pathway, not a discount — it removes a procurement cycle, and the value proposition still has to stand on its own.

We already have Intune. Do we have to change platform?

No. We run Intune, Ivanti Neurons, Jamf Pro and SOTI MobiControl in production specifically so the recommendation can follow the requirement. If the incumbent platform is the right one, we say so and operate it.

Next step

Talk to us about Federal Government

Tell us what the environment looks like today. We will tell you honestly whether this is the right place to start.