Cloud services help Australian public sector organisations by replacing up-front hardware spending with on-demand software (SaaS), development platforms (PaaS) and infrastructure (IaaS). For government data, agencies look for services assessed under the Australian Signals Directorate’s IRAP program and providers certified under the Hosting Certification Framework, then complete their own risk assessment before going live.
Key Takeaways
- The three main service models are Software as a Service (SaaS), Platform as a Service (PaaS) and Infrastructure as a Service (IaaS).
- IRAP (Information Security Registered Assessors Program) assessments check cloud services against the Australian Government Information Security Manual (ISM); AWS, Microsoft and Google Cloud have services reported as assessed at the PROTECTED level.
- The Hosting Certification Framework, moved from the Digital Transformation Agency to the Department of Home Affairs on 1 May 2023, has two levels: Certified Assured and Certified Strategic.
- AWS, Microsoft and Google Cloud are each reported as Certified Strategic, the highest level.
- A provider’s assessment does not replace the agency’s own: each agency remains responsible for how it configures and authorizes the services it uses.
Many Australian government agencies already use products and services from leading cloud providers such as Amazon Web Services (AWS), Microsoft and Google Cloud, and rely on them for everyday applications, data storage and new digital services.
If your public sector organisation has yet to make the move to the Cloud, you may be wondering what services are available and why they may be of interest to you.

To answer these questions, we are going to take a brief look at the most useful Cloud services offered by the major service providers in Australia, from the perspective of the public sector.
Public sector Cloud services in Australia
As you would expect, the Cloud service providers that provide the most services and support for government agencies are the biggest and most well-established in the industry.
AWS Australia, Microsoft Azure and Google Cloud have all made efforts to tailor their services for the public sector, both in Australia and in other countries across the globe. Other cloud service providers that market solutions to government entities include IBM, Salesforce and Huddle. Huddle, a secure document collaboration service founded in London in 2006, was acquired by Ideagen in December 2020, so it is now sold as part of Ideagen’s portfolio.
Many of the Cloud services that are of interest to the public sector are the same as those that private sector organisations have enthusiastically adopted in recent years.
Software as a Service (SaaS)
With SaaS, the applications that your organisation uses on a daily basis are hosted in the Cloud and maintained by your Cloud service provider. This allows your in-house IT team to focus on new developments and enhancements.
Platform as a Service (PaaS)
With a highly capable platform that provides numerous tools and resources, your software team can develop and deploy new applications and IT services more rapidly.
Infrastructure as a Service (IaaS)
Highly scalable storage and compute resources, along with a global network, can be accessed on demand by public sector entities, allowing them to budget for future IT requirements more accurately.
In addition to these services, providers such as AWS have had their infrastructure independently assessed for government use: according to AWS, in-scope services in its Sydney and Melbourne Regions have been assessed under IRAP for Australian government workloads at the PROTECTED level.
Security is, of course, a major concern for the public sector and has given some government IT administrators pause for thought when considering a move to the Cloud.
The biggest cloud platforms have strong data protection and security measures in place, and their IRAP assessments give agencies evidence to use in their own risk assessments. Security in the cloud is still shared, however: the provider secures the underlying platform, while each agency remains responsible for how it configures, monitors and authorizes the services it uses.
Benefits for the public sector
Similar to commercial organisations, those in the public sector can look forward to potential cost savings, a more agile development environment and a more flexible IT infrastructure when moving to a Cloud platform in Australia.
For Australian Government agencies, the policy direction is already set: the Digital Transformation Agency’s Secure Cloud Strategy says agencies must use cloud services for new or modernized services whenever those services are fit for purpose, provide value for money and demonstrate appropriate risk management. On-demand services and resources, independently assessed security and little up-front capital expense make cloud platforms an attractive option for many public sector organisations, although agencies still need to budget for ongoing usage, migration, staff training and security assessment costs.
What Are SaaS, PaaS and IaaS in Government?
The three cloud service models differ in how much of the technology stack the provider manages and how much the agency manages. The table below summarizes the usual split.
| Model | Provider manages | Agency manages | Typical public sector use |
|---|---|---|---|
| Software as a Service (SaaS) | The application, platform and infrastructure | Users, data, access settings | Email, document collaboration, Microsoft 365, case management |
| Platform as a Service (PaaS) | Runtime, operating system, infrastructure | Its own application code and data | Citizen-facing web services and internal apps built by agency teams |
| Infrastructure as a Service (IaaS) | Physical data centers, servers, storage, network | Operating systems, applications, data, security settings | Moving existing workloads, data storage, backup and disaster recovery |
The more the provider manages, the less configuration work falls to the agency, but the agency is always responsible for its own data and user access. For a provider-specific starting point, see this introduction to Amazon Web Services.
What Is IRAP and Why Does It Matter?
The Information Security Registered Assessors Program (IRAP) is the Australian Government’s program for independent security assessment of ICT systems, including cloud services. The Australian Cyber Security Centre (ACSC), an agency within the Australian Signals Directorate (ASD), governs and administers IRAP and endorses individual assessors from the private and public sectors.
IRAP assessors check whether a system meets the controls in the Australian Government Information Security Manual (ISM). Before the ASD’s Certified Cloud Services List (CCSL) ended, the ASD itself certified cloud services; Microsoft notes that its December 2020 reports followed the new guidance issued after the CCSL ceased. Agencies now use a provider’s IRAP report as an input to their own assessment and authorization.
Which major providers have IRAP assessments?
- Microsoft: according to Microsoft, Azure was launched in 2014 as the first IRAP-assessed cloud service in Australia, Azure and Office 365 were certified at the PROTECTED classification in April 2018, and the September 2019 assessment scope covered 113 services at PROTECTED.
- AWS: according to AWS, in-scope services in its Sydney and Melbourne Regions are covered by an IRAP assessment at the PROTECTED level.
- Google Cloud: iTnews reported that Google Cloud services were assessed to carry PROTECTED Australian government data under IRAP in February 2021. Google Cloud runs two Australian regions, Sydney (opened in 2017) and Melbourne (announced in July 2021).
Assessments cover specific services, not a whole provider, so agencies should check that each service they plan to use is in scope of the current report.
What Is the Hosting Certification Framework?
The Hosting Certification Framework (HCF) helps Australian Government agencies identify hosting providers that meet ownership, control, supply chain and security requirements. The Digital Transformation Agency released it, and responsibility transferred to the Department of Home Affairs on 1 May 2023 as part of a machinery-of-government change.
The HCF has two certification levels:
- Certified Assured: protects against the risk of a change of ownership or control through financial penalties or incentives.
- Certified Strategic: the highest level of assurance, available only to providers that allow the government to specify ownership and control conditions.
The first four Certified Strategic cloud providers, reported by iTnews in October 2021, were AWS, Vault Cloud, Sliced Tech and AUCloud. Microsoft became Certified Strategic in November 2021 with more than 180 core online services, including Dynamics 365, Microsoft 365 and Azure, according to iTnews. Google Cloud states that it is Certified Strategic under the HCF and lists its Sydney and Melbourne regions as in scope. The Department of Home Affairs publishes the current list of certified providers.
How Should a Public Sector Agency Move to the Cloud?
- Classify the data. Decide whether the workload holds OFFICIAL, OFFICIAL: Sensitive or PROTECTED information, because that sets the level of assurance required.
- Shortlist assessed services. Check the provider’s current IRAP report and its Hosting Certification Framework status, and confirm the exact services are in scope.
- Choose the service model. Use SaaS where an off-the-shelf application fits; use PaaS or IaaS where the agency needs to build or migrate its own systems.
- Assess and authorize. Microsoft’s own guidance says customers are responsible for engaging an assessor to evaluate their implementation as deployed, and for the controls and processes within their own organization.
- Plan the migration. Move lower-risk workloads first, test backups and recovery, and train staff. Common pitfalls are covered in this guide to cloud implementation challenges and strategies.
- Monitor continuously. Review access, logs and configuration after go-live, not only at launch.
What Are the Risks of Cloud for Government?
Cloud adoption brings real benefits, but public sector organisations should plan for the following risks:
- Misconfiguration: a well-secured platform can still be set up insecurely by its customer. See the risk of data breaches in the cloud.
- Data breach obligations: under the Privacy Act 1988, the Notifiable Data Breaches scheme run by the Office of the Australian Information Commissioner (OAIC) requires covered organizations and agencies, including Australian Government agencies, to notify affected individuals and the OAIC when a breach is likely to cause serious harm.
- Supplier lock-in and ownership change: the Hosting Certification Framework exists partly to manage the risk of a provider changing ownership or control.
- Cost overruns: pay-as-you-go pricing can grow quickly without usage monitoring and budgeting.
- Data loss: agencies still need their own backup and recovery plans; see why backup and recovery matter in the cloud.
Which Cloud Providers Serve the Australian Public Sector?
| Provider | Australian regions or presence | IRAP (as reported by the provider or press) | HCF status (as reported) |
|---|---|---|---|
| Amazon Web Services | Sydney and Melbourne Regions | PROTECTED (in-scope services) | Certified Strategic (October 2021) |
| Microsoft (Azure, Microsoft 365, Dynamics 365) | Melbourne and Sydney data centers since 2014 | PROTECTED since April 2018 | Certified Strategic (November 2021) |
| Google Cloud | Sydney (2017) and Melbourne (2021) | PROTECTED (reported February 2021) | Certified Strategic |
| AUCloud, Vault Cloud, Sliced Tech | Australian providers | Check each provider’s current report | Certified Strategic (October 2021) |
Status changes over time, so confirm the current position with the provider and the Department of Home Affairs before procurement. For a wider view of the market, see this list of top cloud computing companies.
Frequently Asked Questions
Do Australian government agencies have to use the cloud?
Australian Government agencies are expected to use cloud services for new or modernized services when those services are fit for purpose, provide value for money and demonstrate appropriate risk management, according to the Digital Transformation Agency’s Secure Cloud Strategy. Where no suitable commercial cloud exists, agencies are asked to design applications to be cloud ready.
What does IRAP PROTECTED mean?
IRAP PROTECTED means an ASD-endorsed IRAP assessor has checked a cloud service against the Information Security Manual controls required for data classified up to PROTECTED. It is evidence for an agency’s risk assessment, not an automatic approval to use the service.
Who runs the Hosting Certification Framework?
The Department of Home Affairs runs the Hosting Certification Framework. Responsibility moved from the Digital Transformation Agency to Home Affairs on 1 May 2023.
Is the cloud safe for government data?
The cloud can be safe for government data when agencies choose assessed services and configure them correctly. Security is shared: the provider secures the platform, and the agency is responsible for its data, user access and configuration.
Is Huddle still available for government use?
Huddle is no longer an independent company: Ideagen acquired Huddle in December 2020, when Huddle had around 380 customers, including government agencies such as the UK National Audit Office and the US Department of Defense.