NSW Government

Advanced Supplier to the NSW Government

Code Brewery is an Advanced supplier on the NSW Government ICT Services Scheme (SCM0020). Advanced is the higher of the scheme’s two tiers, and it prequalifies us for government ICT engagements valued above $150,000 and for high-risk engagements of any value.

Prequalification is a government procurement team’s judgement about delivery risk. This page sets out what sits behind ours: how we treat security, how we meet compliance requirements, and how we make sure the thing we deliver actually works.

What does Advanced prequalification assess?

The ICT Services Scheme, known as SCM0020, is the NSW Government’s prequalification scheme for suppliers of ICT and digital goods and services. It is managed by the NSW Department of Customer Service, and it is mandatory: under NSW Procurement Board Direction PBD 2021-04, agencies and other eligible buyers must use scheme suppliers when they buy ICT.

The scheme has two lists. Registered suppliers can take low-risk engagements up to $150,000 excluding GST, and the entry requirements are lighter to keep government work open to smaller businesses. Advanced suppliers can take engagements above that figure, and high-risk engagements whatever their value.

The assessment is heavier to match. An Advanced application is supported by referee reports from previous clients, it can involve credit checks, and it carries higher insurance requirements. The questions are about capacity, track record and whether previous clients would have us back.

How do we approach security?

Code Brewery is rated Very Strong on the ProcessUnity Risk Index, the highest of its five ratings. ProcessUnity is a third-party risk platform that procurement teams use to assess the suppliers they depend on, and the rating combines the controls we have attested to with what its scanning can observe from outside.

The rating covers the areas a security team would expect to see, including application security, data protection and privacy, identity and access management, network security, vulnerability management, and incident response and business continuity. Our security rating page explains what the rating measures and how to request the report.

Underneath the rating, the practices are deliberately unglamorous. Dependencies get patched on a schedule rather than when something breaks. Access is granted narrowly and removed when people leave. Backups are restored and timed, not merely configured. None of it is interesting, and that is rather the point.

For systems that handle money or personal information, we scope independent penetration testing before launch and price it as part of the project, so the system itself is tested and not only the studio that built it.

What about compliance requirements?

Government and enterprise buyers usually arrive with a list: where data is held, who can reach it, what happens in an incident, how accessibility is handled, what the audit trail looks like. Those requirements shape the build, so we would rather see them at scoping than discover them at testing.

In practice that means agreeing early where data lives and who holds the keys, keeping production access separate from development access, and building accessibility in from the start rather than auditing it three weeks before launch. Retrofitting accessibility is expensive; specifying it at the outset mostly costs a conversation.

If you have a compliance requirement we have not met before, tell us during scoping. The answer is sometimes that a requirement changes the architecture, and that is a much cheaper thing to learn in week one than in month six.

How do we make sure the quality holds?

Delivery risk is what a prequalification is really asking about, so it is fair to say how we manage it.

We scope before we build. A short scoping phase turns assumptions into a defined, costed set of requirements, and it lowers the total cost of a project rather than adding to it.

We plan for the end of the project, not just the start. The last stretch of work, where a system becomes something you can put in front of real users, takes longer than anyone expects. Compressing it does not remove that work, it relocates it into your launch week and your support inbox.

We build so that someone else could maintain it. Conventional, widely used technology, documented decisions, and as little dependence on any one person or platform as the job allows.

Which services are we prequalified for?

The scheme is organised into 18 categories of supply, and a supplier is approved category by category rather than across the board. Code Brewery is approved across a number of them.

In practice that covers the work we do every day: custom software, business systems, customer and staff portals, websites, integrations between systems that were never designed to talk to each other, and the support that keeps all of it running after launch.

How do government buyers engage us?

NSW Government agencies and other eligible buyers can find Code Brewery on the buy.nsw supplier list and engage us through the ICT Services Scheme. Buyers who are logged in to buy.nsw can see our scheme membership and tier on our supplier profile.

If you are scoping a project and want to know whether it suits the scheme, we are happy to talk it through before anything formal begins.

Buying for a NSW Government agency?

Contact our team to talk through your project and how to engage us under SCM0020.