The Cybersecurity Gap Stopping Engineering Firms from Winning Tenders
A structural or civil engineering firm submits a bid through QTenders for a project it is genuinely well suited to deliver. Strong project history, the right licences, a competitive price. Weeks later, the bid comes back marked down, not on the technical submission, but on a section near the back asking for evidence of a cybersecurity framework. Nobody in the business had prepared an answer for that section, because nobody had ever needed to before.
That scenario is becoming common across Queensland, and it did not come from nowhere.
What actually changed
Under the Queensland Procurement Policy 2026 (QPP 2026), agencies are now required to actively consider cyber security risk, including supply chain risk, as part of every procurement decision, and to build appropriate information and cyber security clauses into the resulting contract. That requirement is scaled to the value, risk and complexity of the procurement, not a fixed checklist applied identically to every contract regardless of size. In practice, it still means a supplier bidding on anything beyond the smallest, lowest-risk work can expect cyber security questions or clauses to appear somewhere in the process, and the supplier who can only offer a verbal assurance is the one most likely to be marked down, or asked to accept a contract clause they have no way of actually meeting.
Agencies are also required to weigh supply chain risk as part of that same consideration, which is where this reaches beyond firms bidding directly to government. A subcontractor working under a head contractor, or a specialist consultant engaged on a government project, can find the same cyber security expectations passed down into their subcontract agreement, even if they never submit a bid to a government buyer directly. A mechanical or electrical subcontractor engaged by a head contractor on a council water treatment upgrade, for instance, can find a cyber security clause sitting in their subcontract, passed down from the head contract above it.
It is not only government work
Tier one contractors, mining operators and oil and gas majors have been building the same expectation into their own supplier prequalification for some time. A cybersecurity posture now sits alongside the insurance certificates, ISO manuals and WHS plans that make up a standard prequalification submission for these clients. If your firm is on a mining or utility supplier panel, or hoping to get onto one, this is very likely already part of what you are being assessed against, whether or not it has been called out explicitly. The Essential Eight framework in particular has become a common reference point across both government and private prequalification, to the point where it now shows up as an expected baseline rather than a point of difference.
What "documentation" actually means
This is the part that trips firms up most, because “documentation” sounds vague until a panel is actually asking for it. In practice, it usually means being able to produce: a written cybersecurity policy that staff can point to, not just a verbal assurance that “we take security seriously”; an incident response plan setting out what actually happens if something goes wrong; a current Essential Eight maturity assessment showing where the business sits against the framework’s eight controls; evidence that staff receive some form of security awareness training; and, increasingly, independent certification such as SMB1001 or ISO 27001 sitting behind all of it. None of this needs to be built from scratch under tender pressure. It is groundwork that, done properly once, gets reused on every bid that asks for it.
The frustrating part
Most firms caught out by this do not actually have a security problem. They run sensible IT, have never had an incident, and would probably pass a reasonable security review if anyone sat down and did one. What they lack is the paperwork: a documented framework, an evidenced process, a certificate a panel can point to. A prequalification or tender evaluation has no way to score good practice it cannot see. Undocumented security and no security are treated the same on the page, which is a genuinely frustrating position for a technically excellent firm to find itself in.
Turning it into an advantage
Firms getting ahead of this are not scrambling to build a cybersecurity policy the week before a tender closes. They already have a recognised framework in place, such as Essential Eight or SMB1001, documentation ready to attach without weeks of preparation, and, in a growing number of cases, independent certification behind it. Once that groundwork exists, a cybersecurity question on a QTenders submission or a mining panel prequalification stops being a risk and becomes one more thing your firm can answer confidently while a competitor is still working out what to say.
This is where we spend a lot of our time with engineering and technical firms: building security that is not just genuinely good, but provable on demand, whether that is for a QPP 2026 government tender, a supply chain flow-down requirement, or a private prequalification panel. We hold ourselves to the same bar as an ISO 27001 certified provider and an Essential Eight and SMB1001 specialist, so our clients can meet it without having to become security experts themselves.
If your firm bids on Queensland Government work, sits on a supplier panel, or is hoping to get onto one, it is worth finding out now whether your current documentation would hold up, rather than finding out when a bid comes back marked down over a section you did not expect.
Grassroots IT is a Brisbane-based managed IT services provider and Essential Eight and SMB1001 specialist for engineering and technical firms across South East Queensland. Learn more about our Cybersecurity services or SMB1001 program.