Federal Government
Commonwealth agencies do not lack security policy. What they lack, almost universally, is evidence that the policy reaches the devices people actually carry.
Every federal agency we work with has a mature desktop compliance story and a mobile estate that sits somewhere beside it. The workstations are patched, measured and reported. The handsets are enrolled in an MDM, which is a different claim entirely, and the gap between those two sentences is where most of our federal work begins.
It is not negligence. The Essential Eight was written with a Windows workstation in the frame, the devices were procured as telephony, and nobody was ever asked to produce a mobile maturity assessment. The problem surfaces when an assessor asks how application control, patching or MFA apply to the fleet, and the honest answer is that they mostly do not.
CDTS closes that gap as a service rather than a project: the platform is designed, migrated and then operated to a defined standard, with reporting an agency can hand to an assessor without adding a caveat to it.
What we focus on in this sector
Scope is agreed per engagement. These are the areas that consistently carry the most value here.
Mobile in the compliance boundary
Patch currency, application control, MFA and administrative privilege stated for the mobile fleet in the same terms as the desktop, with the evidence produced monthly rather than reconstructed at audit.
Sovereignty stated per service
Where the data sits, where the backups replicate, who holds the keys and where support escalates — recorded per component rather than asserted for the whole environment.
Protective markings that survive mobile
EPMS and PSPF markings enforced on the handset, not just in the desktop client, so mobile mail does not have to be classified down to be permitted.
Security-cleared delivery
Cleared, onshore personnel on the engagements that require them, named in the delivery model rather than promised in the proposal.
Procurement pathways that move
BuyICT listing and Indigenous Procurement Policy eligibility, so an approach to market is not the only route to getting work started.
What changes once it is running properly
- A mobile posture report an assessor can read without a caveat attached
- Zero-touch enrolment that survives each OS release rather than breaking on it
- Sovereignty answers per service, in writing, before a contract is signed
- A single accountable owner for the endpoint platform
What usually applies
A few of the organisations we have delivered for







Common questions
Is CDTS IRAP assessed?
No, and any provider telling you they are as a company is worth a second question. IRAP assessment attaches to systems and solutions, not to organisations. The mobile threat defence solution we deliver is IRAP-assessed at PROTECTED, as is the Oracle Cloud Infrastructure environment it runs in, which we manage. CDTS itself holds no certification.
Can you work on cleared engagements?
Yes. We maintain security-cleared personnel and can staff engagements that require them. We do not publish clearance levels — we confirm what an engagement needs and who will be assigned before work starts.
How does the Indigenous Procurement Policy apply?
CDTS is a 100% Indigenous-owned Australian SMB, which makes eligible purchases available through the IPP exemption arrangements. That is a procurement pathway, not a discount — it removes a procurement cycle, and the value proposition still has to stand on its own.
We already have Intune. Do we have to change platform?
No. We run Intune, Ivanti Neurons, Jamf Pro and SOTI MobiControl in production specifically so the recommendation can follow the requirement. If the incumbent platform is the right one, we say so and operate it.
Relevant to this sector
The Essential Eight leaves your phones out — and everyone knows it
The ACSC mitigation strategies were written for a desktop fleet. Here is what happens to the mobile estate in the gap — and how to close it.
"Hosted in Australia" is not the same as sovereign
Data residency, data sovereignty and operational sovereignty are three different claims. Most vendor answers only address the first one.
Choosing a managed service provider for Australian government work
Sovereignty, personnel vetting, procurement pathways and the certification claims that get blurred. What public sector buyers should check before signing.
The pattern travels
Defence & National Security
Environments where devices go where connectivity does not, and where who touches the system matters as much as what it does.
ExploreParliamentary & Ministerial
High-profile users, high turnover at election cycles, and a very low tolerance for a device that does not just work.
ExploreState & Territory Government
Jurisdictional agencies balancing frontline mobility against budgets and standards that rarely move together.
ExploreTalk to us about Federal Government
Tell us what the environment looks like today. We will tell you honestly whether this is the right place to start.