Government

Choosing a managed service provider for Australian government work

Sovereignty, personnel vetting, procurement pathways and the certification claims that get blurred. What public sector buyers should check before signing.

CDTS Australia 4 min read

Buying managed IT for a Commonwealth or state agency is a different exercise to buying it for a commercial business. The technology questions are similar. The questions around the technology are not.

These are the ones we see decided badly, usually because nobody asked early enough.

1. Sovereignty, stated per service

“Australian owned” and “data stays in Australia” are different claims, and both get used loosely.

Ask for them separately:

  • Ownership. Is the entity Australian owned and controlled, or an Australian subsidiary of a foreign parent? Both can be legitimate. Only one satisfies certain requirements.
  • Data residency, per service. Not “our cloud is in Sydney” — which specific services hold which data, where. Backups and logs are where this usually falls apart: the primary workload is onshore and the log archive is not.
  • Support access. Where do the people who can access your environment physically sit when they access it? A Sydney data centre administered at 2am from another continent is not an onshore arrangement in any meaningful sense.

Get all three in writing before the contract, not during the first incident.

2. Personnel and vetting

If your security plan has personnel requirements, they apply to your provider’s staff too.

  • Are security-cleared personnel genuinely available, or mentioned in a capability statement?
  • Are the people touching your environment employees or subcontractors? Subcontracting is not disqualifying, but it changes who you are actually relying on.
  • Is there a named team, or a rotating pool? For sensitive environments, “named” is often a requirement rather than a preference.

3. The certification claim, precisely stated

This is the one most often blurred, and it is worth being pedantic about.

A vendor product can be IRAP assessed at PROTECTED while the partner delivering it holds no assessment of its own. Both facts can be true simultaneously. What you are watching for is a provider that lets the first fact imply the second.

Ask them to state plainly:

  • What does your organisation hold?
  • What do the solutions you deliver hold?
  • Which assessment applies to the specific thing you are proposing to us?

A provider that answers this crisply is telling you something useful about how they will behave when the answers are less flattering. We publish our own position on exactly this point: CDTS holds no IRAP assessment; specific solutions we deliver do.

4. The procurement pathway

Confirm early that the buying route exists, because the best-fit provider is no use if you cannot contract with them.

  • Are they on the BuyICT Digital Marketplace?
  • Are they on the panels your agency actually uses?
  • Do they meet Indigenous Procurement Policy requirements, if that is part of your target? Buying from an Indigenous-owned SMB contributes to IPP without a separate arrangement.
  • Is the entity a small-to-medium business, if your agency has SME targets?

5. The exit, before the entry

Nobody wants to discuss this at signature. It is the single best predictor of how the relationship will feel in year three.

  • Who owns the documentation, the tooling and the administrative credentials?
  • What does transition assistance cost, and how long is the provider obliged to help?
  • Will your environment be handed over in a state another provider can actually take on?

A provider that has thought this through is confident you will not need it. A provider that has not is planning to rely on inertia.

6. Whether they will say no

The most useful signal in a procurement is a provider declining something.

A provider that recommends everything they sell and nothing they do not is a reseller with a service wrapper. Ask which platforms they recommend against and why. Ask what they would tell you not to spend money on this year. The ones who answer are the ones worth shortlisting.

The short version

Technology capability is table stakes, and every shortlisted provider will have it. What separates them in government work is sovereignty you can evidence, personnel you can name, certification claims stated precisely, a procurement pathway that exists, and an exit you would be comfortable using.

We wrote a broader version of this for any buyer — twelve questions to ask a managed service provider before you sign — and we are happy to be asked all of them.

Next step

Let’s talk about your environment

Tell us what you are running today and where it hurts. We will give you a straight answer on whether we are the right fit, and what we would look at first.