top of page
Abstract Digital Mesh

Queensland’s New Supplier Code: Cyber Security Has Moved From “Trust Us” to “Show Us”

Aug 7
7 min read

There is a relatively important change happening for businesses that supply the Queensland Government, and I suspect quite a few small and medium-sized suppliers haven't quite realised what it means yet.


The Queensland Government Supplier Code of Conduct 2026 came into effect on 1 January 2026, alongside the Queensland Procurement Policy 2026 and the new Procurement Assurance Model (PAM). The basic idea is fairly straightforward: suppliers aren't just expected to deliver what is in the contract. They are expected to be able to demonstrate that they are meeting the standards and commitments that come with supplying government.


And cyber security is explicitly part of that.


Under the Code's "Handling information" requirement, suppliers are expected to take a practical approach to implementing appropriate cyber security and privacy practices so information is protected and services continue to operate. More importantly, PAM allows the Queensland Government Procurement Assurance Branch to ask suppliers for evidence demonstrating that this is actually happening!


The examples given by government include information management and data governance policies, internal security audit records and cyber security risk assessments. The list is explicitly not exhaustive.


That last part is worth paying attention to!


The Good News: This Isn't Another Mandatory ISO 27001

There is a lot to like about the direction Queensland has taken here.


The Code doesn't simply say, "You must have ISO 27001."


Nor does it prescribe that every supplier must achieve Essential Eight maturity level 2, deploy a particular EDR product, have a SOC, or spend six figures building an enterprise security program.


Instead, the language is deliberately broad: suppliers need to have an appropriate and practical approach to cyber security and privacy.


From a security practitioner's perspective, I actually like that.


A 25-person professional services firm supplying a department does not have the same risk profile as a technology provider hosting sensitive government information.


They shouldn't have the same security program!


The problem is that this flexibility comes with a fairly significant downside.


So... What Exactly Is "Appropriate"?

This is where I think things could get interesting.


The Code tells suppliers to implement "appropriate cybersecurity and privacy practices".

Appropriate to what?

The size of the business?

The type of information being handled?

The services being delivered?

The sensitivity of the government information?

The supplier's technology environment?

The potential consequences of a compromise?

Presumably, the answer is all of the above.


But that's a very different proposition for a small business trying to answer a tender question. Imagine you're a 40-person Queensland business bidding for a government contract. The tender asks about your cyber security arrangements.


You don't have ISO 27001.

You don't have a dedicated CISO.

You don't have a security operations centre.

But you do have MFA, endpoint protection, good backup arrangements, patch management, access controls.


Are you secure enough?


Probably, maybe.


Can you demonstrate that objectively?

That's a different question.

And this is where I think smaller suppliers could get caught.

 

The Problem With Saying "Yes"

For years, cyber security questionnaires have contained some variation of:

"Do you have appropriate cyber security controls in place?"

The supplier ticks Yes.

Everyone moves on.


That model is becoming increasingly difficult to defend.


PAM is explicitly built around assurance. Suppliers working under the new arrangements must provide documents and information reasonably requested by the Procurement Assurance Branch as part of an assurance assessment. Suppliers with contracts executed after 1 January 2026 are also expected to retain records supporting their adherence to the Code and their contractual commitments.


That's a meaningful change.

The conversation is moving from:

"Tell us you're secure."

to:

"Show us."


Frankly, that's where procurement assurance should have been heading anyway.

The awkward bit is working out what "show us" means when the baseline itself isn't particularly prescriptive.

 

And That's Where I Have Some Concerns

For a large organisation with an established security team, this ambiguity is manageable.

For a small business, it can be incredibly difficult.


If there isn't a defined minimum security baseline, a supplier has to make a judgement about what "appropriate" means. And if you're preparing a tender, you don't necessarily know how that judgement will be viewed by the government agency evaluating your response.


Should you implement Essential Eight?

Should you pursue ISO 27001?

Should you get SMB1001 certified?

Do you need a formal cyber risk assessment?

Do you need penetration testing?

Do you need a documented incident response plan?

Do you need all of those things?


And, naturally, the answer is: it depends. Wow, such a consultant answer…


Which is a perfectly reasonable answer from a risk management perspective and a rather frustrating answer when you're trying to price a tender. The danger is that suppliers start over-engineering their security programs simply because they're worried about being perceived as insufficient.


That's not particularly good for small or medium sized business. Nor is it good procurement.


There's Another Issue: Contractual Risk

There is another aspect of the new model that I think deserves more attention.

The Code's requirements aren't simply theoretical guidance sitting on a government website. Suppliers are required to adhere to the behavioural standards outlined in the Code as specified in their contract.


That creates an interesting legal and commercial question when the security requirement is expressed in broad terms. If a contract says the supplier must maintain "appropriate cybersecurity and privacy practices", what happens when someone later decides those practices weren't appropriate?


That doesn't necessarily mean every security shortcoming becomes a contractual breach. The actual contract wording and circumstances will matter enormously. But the potential for disagreement is obvious.


The supplier believes it implemented reasonable security measures based on its size, services and risk profile. The government agency believes the supplier should have done more. And suddenly everyone is sitting around a table debating what "appropriate" meant when the contract was signed.


That's exactly the sort of ambiguity that becomes expensive once something has gone wrong. And unfortunately these days, it likely will…


The Better Approach: Prove What Is Appropriate

This is why I think suppliers should approach the new requirements from a risk and assurance perspective rather than simply buying another certification.


Start with the actual government engagement.

What information will you hold?

What systems will you operate?

What access will you have?

What services are you providing?

What would happen if your business was compromised?

What does the government agency actually need to be protected from?


Then assess the supplier against those risks and establish a security baseline that makes sense for that particular business.


That might result in an Essential Eight-based program. It might involve strengthening Microsoft 365 and Entra ID, formalising backup and recovery, improving privileged access management, conducting a penetration test, implementing better security policies or introducing a formal incident response process.


It might be relatively modest...


Or it might be considerably more involved.


The important thing is that there is a defensible rationale behind it. And, crucially, evidence.


A supplier should be able to put together a body of evidence that demonstrates:

"Here is what we do. Here is why we do it. Here is how it addresses the risks associated with the government services we provide. And here is the evidence that it actually operates."

That's a much stronger position than simply ticking "Yes" on a questionnaire.


Certification Can Help - But Don't Automatically Reach for ISO 27001

There is also a role for certification.


A small supplier may benefit enormously from being able to put an independently recognised certification in front of a government procurement team rather than handing over 40 pages explaining why their security is adequate.


But I don't think the answer should automatically be ISO 27001. ISO 27001 is an excellent standard. We implement it for clients and understand the value it provides.


It is also a significant undertaking.


For some smaller suppliers, it can be disproportionately expensive and administratively heavy relative to the risk they're actually managing. That's where frameworks such as SMB1001 become interesting.


SMB1001 is a multi-tiered cybersecurity certification standard specifically designed for small and medium-sized businesses, with progressive levels rather than an all-or-nothing enterprise certification model. The current SMB1001:2026 standard is positioned by its publisher as a scalable and cost-effective pathway for SMBs to demonstrate cybersecurity maturity.


I'm not suggesting SMB1001 should automatically become the new Queensland Government requirement. It isn't.


What I am suggesting is that there is a growing need for proportionate, independently defensible evidence of cyber security, particularly for smaller businesses entering government supply chains. If a 30-person supplier can demonstrate that it has assessed its risks, implemented appropriate controls and independently attested or certified against a suitable baseline, that's considerably more useful than asking the business to pretend it is a 5,000-person enterprise.


PAM Is Probably Going to Change How Suppliers Think About Cyber

The broader PAM model reinforces this direction. The Queensland Government has explicitly built PAM around recognition, capability building and accountability. For suppliers with unmet commitments, outcomes can range from mandatory capability building through to improvement notices and, for major matters, sanctions. A major sanction can make a supplier ineligible for new contracts and extensions and can result in suspension from relevant prequalification or panels.


That's not something suppliers should panic about.


But they should take it seriously.


The point isn't that every small supplier suddenly needs an enterprise-grade security department. The point is that "we've got antivirus and our IT guy looks after it" probably isn't going to be a particularly compelling assurance position anymore. And, frankly, it shouldn't be.

 

What Should Queensland Government Suppliers Do Now?

If you're an existing or prospective Queensland Government supplier, I wouldn't start by buying a certification. I'd start by asking a much simpler question:


"Can we demonstrate that our cyber security is appropriate for the government services we provide?"


If the answer is no, that's the gap to address.


At Arotech, we are developing a Queensland Government Supplier Code of Conduct 2026 Readiness Assessment specifically for this purpose.


The assessment would look at the supplier's size, technology environment, services to government, information handled and relevant risks, then assess the organisation's current security posture against those requirements.


From there, we can help establish a proportionate remediation plan rather than automatically pushing an SMB into an expensive enterprise framework.


And importantly, we can build a Supplier Code Evidence Pack that provides a structured body of evidence for future Queensland Government tender and assurance activity.


Because I suspect this is where procurement is heading. Not:

"Are you cyber secure?"

But:

"Show me."


And if you're a small or medium-sized supplier, having a credible answer to that question before the tender lands on your desk could be the difference between confidently demonstrating your security posture and scrambling to work out what "appropriate" was supposed to mean.


Frederick Prinsloo

 
 
bottom of page