Here is a procurement fact that surprises a remarkable number of Commonwealth security teams: for procurements up to $500,000, the Commonwealth Procurement Rules allow you to engage a small or medium enterprise directly. No open tender. No panel gymnastics. Exemption 17 of the CPRs exists so agencies can buy from Australian SMEs without the overhead that makes small procurements slower and more expensive than the work itself, and a penetration test is close to the ideal use case for it.
Think about what a typical agency pentest procurement looks like through a panel or open approach: weeks of documentation to buy two weeks of testing, evaluation criteria that reward bid-writing over testing ability, and, too often, a winning bid from a large firm whose senior people wrote the proposal and whose graduates do the work. The SME pathway inverts that. You can identify a specialist firm, verify their credentials and value for money, document the decision, and have testers on target in a fraction of the time. For time-sensitive work, such as an IRAP-readiness test before an assessment window or a pre-launch application test, that speed decides whether you test before go-live or after.
Using the pathway well still requires discipline. Value for money remains the core CPR obligation; direct engagement is not an excuse to skip checking the market, it is a proportionate way of doing it. Your file should show why the supplier was selected, how price was validated, and that the SME status is genuine. This post walks through that: the mechanics of the exemption, what your procurement file needs, how to scope a pentest so a fixed quote is possible, and the questions that separate a specialist firm from a rebadged scan. Ironbark Cyber is, in the interest of full disclosure, an Australian SME that sells penetration testing, which is also why we know this pathway from both sides.
What do the CPRs say about SMEs?
The Commonwealth Procurement Rules are the framework that governs how non-corporate Commonwealth entities buy. Most of the time, procurements at or above the relevant threshold require an open approach to market. The SME provisions, commonly referenced as Exemption 17, carve out an exception: for procurements valued up to $500,000, an entity may procure directly from a small or medium enterprise without running an open tender.
The intent is deliberate policy rather than a loophole. Government wants more of its spend flowing to Australian SMEs, and it recognises that the transaction cost of a full tender is disproportionate for smaller, well-defined pieces of work. A penetration test that is clearly scoped, time-boxed and delivered by a named specialist fits that description almost perfectly. Two things remain true and non-negotiable: the procurement must still represent value for money, and the entity's own accountable-authority instructions and procurement policies sit on top of the CPRs. Check your internal delegations; some agencies set lower internal thresholds than the CPR figure.
When is direct engagement appropriate, and when isn't it?
The pathway is a good fit when the work is specialist, well-scoped and below the threshold, and when you can articulate why a particular supplier is the right choice. It is a poor fit when the requirement is genuinely commoditised and you have no basis to prefer one supplier, when the value exceeds $500,000, or when an existing panel already offers better value and less risk for that category.
Penetration testing sits firmly in the good-fit column for most agencies. It is specialist work where the identity and seniority of the tester matters a great deal, it is naturally sized below the threshold, and value for money turns on capability that is hard to assess through a paper tender anyway. That said, direct engagement is a tool rather than a default. Use it when you can defend the choice, not to avoid the market.
How do you build the procurement file?
Value for money without a tender is demonstrated by a clear, contemporaneous record. Your file should be able to answer, on its face, the questions an auditor would ask. At a minimum:
- The requirement. What is being tested, why now, and the scope in enough detail to justify the price.
- Supplier selection rationale. Why this SME: relevant expertise, track record, and the specific capability that makes them suitable.
- Value-for-money assessment. How you validated price: a comparison against known market rates or published ranges, or quotes from more than one supplier where practical. You do not need a full tender, but you should show you did not accept the first number blindly.
- SME confirmation. Evidence the supplier genuinely qualifies as an SME.
- Approvals. The delegate's approval consistent with your entity's procurement policies.
Published, transparent pricing makes the value-for-money step much easier. Ironbark Cyber, for example, publishes indicative ranges (a focused web application or external network test typically lands between AU$6,000 and AU$18,000 depending on scope) so a delegate can sense-check a quote against the market without chasing three proposals.
How do you scope a pentest so you can get a fixed quote?
A fixed quote is only possible when the scope is concrete, so give the supplier what they need on the first call:
- What is in scope: the specific applications, URLs, IP ranges, cloud accounts or API surface.
- The environment: production or a staging mirror, and any rules of engagement or maintenance windows.
- Access and roles: whether testing is authenticated, how many user roles, and how credentials will be provided.
- The driver: IRAP-readiness, pre-launch assurance, ISM alignment, or a specific deadline.
- Reporting expectations: the format your assessors or executives need.
A specialist firm should turn that into a fixed price within a business day. If a supplier can only quote a day rate and a vague range, the scope is not tight enough yet, or they are hedging because they do not know how long the work will take, which tells you something in itself.
How do you verify a supplier?
Direct engagement puts more weight on your due diligence, so make it deliberate. A short verification checklist:
| Check | What good looks like |
|---|---|
| Who does the testing | The senior people who scope the work do it, rather than a graduate bench behind a named principal. |
| Method | Manual, hands-on testing aligned to a recognised methodology, rather than a scanner run lightly reviewed. |
| Insurance | Professional indemnity and public liability cover; ask for a certificate of currency. |
| Clearances | Confirm the clearance level your engagement requires can be staffed. |
| References | Comparable work, ideally in government or regulated environments. |
| Deliverables | Executive summary, technical report with reproduction steps, attestation letter, and a retest of fixed issues. |
The single most useful question is "who, specifically, will be testing, and can I see their background?" It cuts straight through bid-writing to the thing that determines the quality of your test.
What about the state equivalents?
The states run their own SME-friendly direct-engagement provisions. Queensland and New South Wales both have procurement frameworks that allow agencies to engage SMEs directly for lower-value work, with their own thresholds and documentation expectations rather than the Commonwealth's. The principle is the same everywhere: below a threshold, for well-scoped specialist work, you can go direct to a capable local supplier if you can show value for money and follow your jurisdiction's rules. Check your own procurement framework for the exact figure and process, and do not assume the Commonwealth's $500,000 applies to a state agency.
What does the timeline look like?
Speed is the point. A realistic path from decision to testers-on-target under the SME pathway:
- Day 0. Scoping call; agree scope, environment and rules of engagement.
- Day 1. Fixed quote received.
- Days 2–4. Value-for-money check, supplier verification, delegate approval, contract or work order.
- Week 2. Testing begins; critical findings escalated live.
- Week 3–4. Report delivered; free retest of fixed issues within 90 days.
Compare that to the multi-week open-tender path and the case for the SME pathway on time-sensitive testing writes itself.
The SME direct-engagement provisions were built for this: specialist Australian firms doing well-defined work, bought without the overhead that helps no one. Ironbark Cyber is an Australian-owned SME (ABN 18 692 781 561) that delivers penetration testing and AI security to government, with published pricing that makes the value-for-money step straightforward and delivery by senior, named testers. If you are an agency with a time-sensitive test and a threshold you can work within, the how-to-engage-us conversation takes about half an hour.
FAQ
Frequently asked questions
Can a Commonwealth agency buy a penetration test without going to tender?
Often, yes. The Commonwealth Procurement Rules allow direct engagement of a small or medium enterprise for procurements up to $500,000 (the SME provisions, Exemption 17). A well-scoped penetration test typically sits well under that threshold. Value for money still applies, and your entity's own procurement policies sit on top of the CPRs.
What does the procurement file need to show?
The requirement, why this SME was selected, how price was validated against the market (published ranges or comparative quotes), evidence the supplier genuinely qualifies as an SME, and the delegate's approval consistent with your procurement policies.
How do I verify a penetration testing supplier?
Confirm the senior people who scope the work do the testing (not a graduate bench), that testing is manual and methodology-aligned, that they hold professional indemnity and public liability cover, that the required clearance level can be staffed, and that deliverables include an attestation letter and a retest of fixed issues.
Do the states have the same pathway?
The states run their own SME-friendly direct-engagement provisions with their own thresholds and documentation rules. Queensland and NSW both allow direct engagement of SMEs for lower-value work. Check your jurisdiction's procurement framework for the exact figure; do not assume the Commonwealth's $500,000 applies to a state agency.
How fast can testing start under the SME pathway?
Realistically a couple of weeks: scoping call and fixed quote in a day or two, then value-for-money check, verification, approval and contracting, with testing beginning around week two. That speed is the main reason to use the pathway for time-sensitive work.
Put this into practice
A senior Ironbark Cyber consultant will scope your engagement on a free 30-minute call and give you a fixed quote within one business day.