Defence procurement teams should prioritise four things when assessing a critical infrastructure contractor: verified security accreditation, a documented track record on comparable classified or sensitive sites, financial and workforce capacity to sustain the project without gaps, and a compliance framework that holds up to audit, not just a claim of one. Price and technical capability matter, but on defence infrastructure work, a contractor that fails on any of the first three can create delays and security exposure that far outweigh any cost saving.
The reason this list looks different to a standard commercial procurement checklist is that defence infrastructure work carries obligations that commercial contracts don’t: personnel security clearances, controlled access to sites and information, and reporting requirements that continue well after handover.
Security accreditation comes first, not last
The single most disqualifying gap in a contractor assessment is security accreditation that doesn’t hold up. Depending on the contract, this typically means checking for:
- Defence Industry Security Program (DISP) membership, at the level relevant to the work, entry, Level 1, 2 or 3. Membership level determines what a contractor can legally access, store and handle.
- Personnel security clearances held by the actual workforce assigned to the job, not just clearances the company holds in general. A contractor can be DISP accredited as an organisation while still needing to source or sponsor cleared personnel for a specific role.
- Facility and IT security controls, where the work involves handling classified information, drawings or specifications, not just physical site access.
Procurement teams should ask for evidence, not assertions. Current DISP membership status is checkable. Clearance levels for named personnel should be confirmed directly, not assumed from a company’s general security posture.
A track record on comparable work, not just similar-sized work
Contract value and technical scope are the easy things to compare between tenderers. What’s harder to assess, and more important, is whether a contractor has actually delivered work under the same operational constraints defence sites impose: controlled access, restricted communications, staged clearance verification for every worker entering site, and compliance reporting that runs continuously rather than being reviewed once at project close.
A contractor with strong commercial infrastructure experience but no history of working within these constraints will often underestimate how much they slow delivery. This shows up as blown programmes, not necessarily poor workmanship. Procurement teams should ask specifically how a contractor has managed personnel clearance delays, access control changes, or scope handled under NDA on past projects, not just what the past projects were.
Compliance that survives audit
Every contractor bidding for defence infrastructure work will state that they meet relevant standards. The distinction that matters is between a compliance framework that exists on paper and one that’s actively maintained and auditable. Procurement teams should look for:
- Current, not historical, certification. ISO 9001 (quality), ISO 45001 (safety) and ISO 27001 (information security, where relevant) certificates should be checked for current validity, not assumed from a company profile.
- Essential Eight or equivalent cybersecurity maturity, particularly for any contractor with access to networked control systems, SCADA, or site information systems.
- A documented safety record with actual incident data, not just a stated safety policy. Lost time injury frequency rates and incident history are a more reliable indicator than a safety statement in a capability document.
- Evidence of how non-conformances have been handled in the past, which tells you more about a contractor’s actual quality culture than a certificate does. A contractor that can show how they identified and corrected a past issue is generally a safer bet than one that claims a clean record with no supporting detail.
Capacity to sustain delivery, not just win the tender
Defence infrastructure projects often run longer, and with more schedule variability, than commercial equivalents, due to clearance processing times, access windows, and staged approvals. A contractor’s financial and workforce capacity to absorb that variability without compromising delivery is a genuine risk factor, and one that’s often underweighted in favour of technical capability scoring.
Questions worth asking directly:
- What proportion of the contractor’s current workforce holds the clearance level required for this work, and is that number sufficient to cover both the base team and reasonable attrition over the project’s duration?
- Has the contractor delivered projects of comparable duration to completion without requiring contract extensions driven by their own capacity constraints?
- What’s the contractor’s financial standing relative to project value, sufficient to carry extended payment terms or delayed milestones without cash flow risk affecting delivery?
Red flags worth taking seriously
- Security accreditation described in general terms without specific DISP level or expiry dates provided.
- Reluctance to name the personnel who would actually work on site, or vague answers about their clearance status.
- Safety and quality claims with no supporting incident or non-conformance data.
- No prior experience on any access-controlled or clearance-required site, regardless of how strong the general infrastructure experience is.
- Pricing that looks materially lower than comparable tenderers with no clear explanation, often a sign that clearance sponsorship costs, compliance overhead or realistic programme duration haven’t been properly costed in.
Where DCE Electrical fits in
Defence infrastructure work asks more of a contractor than technical delivery alone. It asks for accreditation that’s current and verifiable, a workforce that can actually meet the clearance requirements of the job, and a compliance framework that holds up when it’s checked rather than just when it’s claimed. DCE Electrical works with procurement teams to make those requirements clear and verifiable from the earliest stage of engagement, rather than something clarified after award.
If you’re preparing a tender evaluation for critical infrastructure work and want a clear-eyed view of what to verify versus what to take on trust, that’s a conversation worth having before the request for tender goes out, not after.
Frequently asked questions
What is DISP membership and why does it matter for defence contractors? The Defence Industry Security Program (DISP) is the Australian Government’s framework for accrediting industry to work with Defence on security-sensitive projects. Membership level, entry, Level 1, 2 or 3, determines what information and sites a contractor can legally access. Procurement teams should verify a contractor’s actual membership level, not just that they participate in the program.
Should procurement teams check clearances for the company or for individual workers? Both, but individual worker clearances matter more in practice. A company can hold DISP accreditation while still needing named personnel to hold specific security clearances for a given role. Procurement teams should confirm clearance status for the actual people who will work on site.
What’s the biggest risk in choosing a contractor without defence experience? The most common issue isn’t technical competence, it’s underestimating how much controlled access, staged clearance verification and restricted communications slow delivery compared to commercial projects. This typically shows up as programme delays rather than quality issues.
Are ISO certifications enough to confirm a contractor’s compliance? They’re a starting point, but certification should be checked for current validity, and backed by evidence such as safety incident data and how past non-conformances were handled. A certificate alone doesn’t confirm an active compliance culture.
Why does a lower-priced tender sometimes carry more risk? Materially lower pricing on defence infrastructure work can indicate that clearance sponsorship costs, ongoing compliance overhead, or a realistic project timeline haven’t been fully costed into the bid, which increases the risk of budget or schedule blowouts later.
What financial or capacity questions should procurement teams ask beyond technical scope? Whether the contractor’s cleared workforce is sufficient to cover both the base project team and reasonable attrition, whether they’ve completed comparable-length projects without capacity-driven extensions, and whether their financial position can absorb defence-typical payment terms without affecting delivery.