The CCA strengthens Australia’s sovereignty, resilience and use of technology that is essential to the delivery of government services.
To achieve this principle, the DTA will consider whether the proposed CCA:
- presents risk if the seller, including any parent company, may be subject to laws, regulatory directions or other arrangements which could create risks that override or circumvent Australian contractual protections
- includes assurances on the seller’s ability to demonstrate transparency regarding jurisdictional control, operational control and decision-making authority
- contributes to the development of Australian sovereign capability, including local skills, expertise, intellectual property, supply chains or infrastructure
- strengthens Australia’s resilience by reducing dependency risks and supporting continuity of government operations during disruption
- identifies sovereignty and resilience outcomes that can be measured, monitored and reported throughout the life of the CCA.
What good looks like, in practice:
- Information and infrastructure are located in Australia, subject to our legislation and regulations.
- Information is not shared outside of Australia without our Australian Government’s agreement.
- Australian encryption prevents access from a foreign jurisdiction (for example, if a seller or parent company is compelled by authorities beyond the Australian border).
- Sellers notify our Australian Government immediately if information is accessed overseas, including the circumstances of how the information was accessed, and close gaps after incidents.
- Sellers provide meaningful business continuity and redress if goods and services are not delivered due to foreign activities (the Australian Government in Australia, rather than the seller, decides what is essential to the delivery of government services).
- Capabilities are developed and embedded over the long term within the Australian Government Architecture.
Additional context:
Accountable authorities have a duty to establish and maintain systems relating to risk and control. Furthermore, paragraph 2.6 of the Commonwealth Procurement Rules, released in 2025, states the rules do not apply to the extent that an accountable authority (or an official to whom an accountable authority delegates the power to determine such measures) applies measures necessary for the protection of essential security interests.
Some countries have adopted extraterritorial legislation compelling sellers subject to their jurisdiction, including parent companies, to take actions leaving buyers in other jurisdictions without redress. Australia is not immune from these risks. If a seller, including parent company, is compelled by an extraterritorial jurisdiction:
- access to products and services, which our Australian Government relies on, could be removed
- data stored in Australia could be accessed and decrypted outside the border.
Building our digital and ICT sovereignty, resilience and use of technology is more than a contractual, geographical, jurisdictional, business continuity, or technical (for example, encryption-related) construct. If determined necessary for the protection of essential security interests, it may be necessary to embed such capabilities, over the long term, within the Australian Government Architecture.