At a glance
- The Digital Transformation Agency published six tests on 31 August 2026 for companies that want one of the pre-negotiated contracts every government department buys under.
- One of the tests is sovereignty, and the agency warns that data stored in Australia could still be decrypted overseas if a foreign government compels the seller's parent company.
- Good practice, in the agency's own words, is that "Information and infrastructure are located in Australia", the encryption is Australian, and the government hears immediately if data is reached from overseas.
- Six companies hold one of these contracts: Amazon Web Services, Microsoft, IBM, Oracle, SAP and Rimini Street. Google Cloud does not.
- Data centre space is bought a different way, through a panel, and the agency has not said whether the same sovereignty test will apply there.
The agency published six tests on 31 August
The Australian Government buys most of its big technology through a handful of pre-negotiated contracts. One deal is struck centrally with each supplier, and every department buys under it. On 31 August 2026 the Digital Transformation Agency published six tests a company has to pass to get one. The release says the principles "will require prospective CCA sellers to demonstrate they can" do six things. The fourth is to strengthen Australia's sovereignty.
The supporting document asks for three things at once. The information and the infrastructure in Australia. No foreign law able to override the Australian contract. Australian encryption on top. Data held here by a company with a foreign parent can still sit inside that parent's legal reach. That is an old argument in the hosting market, and the buyer has now written its side of it down.
An independent review the agency commissioned from SolsticeIT in 2025 made five recommendations. One was to publish a framework for judging sellers, which is what arrived on 31 August. Another was to strengthen the model by "specifying stronger cyber and sovereignty requirements". The review also asked the agency to define data and digital sovereignty, "with consideration of localisation requirements and existing policy (e.g. the Hosting Certification Framework)".
Foreign law is the risk the document names
The agency says it will ask whether a deal "presents risk if the seller, including any parent company, may be subject to laws, regulatory directions or other arrangements which could create risks that override or circumvent Australian contractual protections". It also wants "transparency regarding jurisdictional control, operational control and decision-making authority", which in plain terms means knowing whose law applies, who runs the service day to day, and who decides.
Then it sets out what good looks like. Information and infrastructure sit in Australia, under Australian law. Nothing goes offshore without the government's agreement. Australian encryption blocks access from another country, "for example, if a seller or parent company is compelled by authorities beyond the Australian border". If data is reached from overseas, the seller says so immediately and fixes the hole. If foreign action stops delivery, the seller owes "meaningful business continuity and redress". And the government, not the seller, decides what counts as essential.
Some countries, the document notes, have passed laws that reach across borders and compel companies, parent companies included, in ways that leave buyers elsewhere with no recourse. "Australia is not immune from these risks," it says. The government could then lose access to something it depends on, or data stored in Australia could be "accessed and decrypted outside the border".
| Test | What the agency looks at |
|---|---|
| Deliver capability at scale | Whether a central deal beats the alternatives, and whether it leaves room for competitors |
| Accept the government's terms | Which government terms beat the seller's own, including for resellers and subcontractors |
| Deliver benefits to Australians | Local skills, innovation and industry participation, measured and reported |
| Strengthen Australia's sovereignty | Foreign legal reach, who controls the service, Australian encryption, notice and redress |
| Preserve technology choice | Whether data and workloads can be moved out, and whether exit is practical |
| Work for small and large buyers | Workable pricing and commercial terms across departments of very different sizes |
Source: Certified Strategic summary of the Digital Transformation Agency's published principles.
Six companies hold one of these contracts
These deals used to be called single seller arrangements and were renamed coordinated contracting arrangements in June 2026. Six companies hold one, on the Department of Finance's register, read on 2 September 2026: Amazon Web Services, Microsoft, IBM, Oracle, SAP and Rimini Street. Departments and agencies must buy under them. Who else can opt in varies by deal, from other Commonwealth bodies through to state, territory and local government. Google Cloud is not on the register.
The government leases its space in Australian data centres through Data Centre Panel 3. A panel is a list of approved suppliers, not one of the central deals the six tests are written for. The agency has not said whether it will ask the same sovereignty questions when that panel is next refreshed.
A company cannot put its hand up. The document says "it is not intended for sellers to request a CCA without the DTA's request". And these deals are not where most of the money goes. The review found about 76 per cent of the spending it looked at between 2019 and 2024 ran through other panels, and valued the central deals at "over $1.6 billion in discounts between 2019 to 2024" rather than in spend. It also asked the agency to publish what is actually spent under these arrangements.
What counts as a benefit to Australians
The benefits test names local skills, innovation and industry participation first. Building things here comes lower down, on a second list opening with "and potentially also". On that same second list sits "research and development activities conducted in Australia, with ownership (such as intellectual property) remaining in Australia".
The agency reports that respondents in its consultation said the benefits can come in many ways, "not just through infrastructure investment", and names local jobs, Australian delivery capability, sovereign capability and innovation. The 2025 review had counted "investment in local infrastructure, such as data centres throughout the country" among what these suppliers already give back. Building here still counts, and it is no longer the only thing that counts.
What to watch
The agency says the principles will be built into how these contracts are run from here, and that it is still working through the review's other recommendations. The first renegotiation is where it shows: whether the sovereignty questions reach an actual contract's published terms, and which of the six suppliers is asked first.
The Australian Government data centre strategy already covers part of this. Its cloud-first policy, in force since 1 July 2026, asks whether a department can get its data back out again, which is the fifth test in another form. And the requirement that every GovAI model be hosted in Australia shows the limit of a location condition: the government can only offer what its suppliers have already switched on here. The harder question, whether the model itself runs in Australia or only the storage does, the six tests do not reach.