Engaging a web development agency as a government or enterprise organisation is more than just a creative decision. It’s a governance one.

We understand that. And we’ve built our practice accordingly.

We fit into your procurement process, not around it.

Government and enterprise organisations have rigorous vendor assessment frameworks for good reason. Third-party suppliers, including web agencies, sit within your supply chain, often with access to your CMS, hosting environments, third-party integrations, and sometimes user data. That access doesn’t always end when the project does.

At Kicking Pixels, we hold ISO 27001 certification, an internationally recognised standard for Information Security Management Systems (ISMS).

It means we’ve been independently audited against a framework that covers risk management, access controls, incident response, business continuity, and supplier relationship management. Not once, but on an ongoing basis.

When you’re completing a vendor assessment, we’re not a gap in your process. We’re a vendor that can meet it.

What we can provide for your assessment

We know procurement teams need more than a conversation, they need documentation. As an ISO 27001 certified agency, we’re able to provide:

  • A copy of our current ISO 27001 certificate
  • Confirmation of our appointment on the Digital Marketplace Panel 2 (DMP2), the Digital Transformation Agency’s whole-of-government panel for digital and ICT services, covering Application, Software Engineering and Development Services, and Architecture Services
  • Participation in your formal vendor security assessment or supplier questionnaire
  • Discussion of our security controls in the context of your organisation’s specific obligations and risk profile
  • Clarity on how we manage access to client environments, including our offboarding process at project completion
  • Information on how we identify and manage vulnerabilities in third-party components such as plugins, themes, and integrations
  • An outline of our incident response process
  • Evidence of WCAG 2.1 AA accessibility testing, covered in more detail in what genuine accessibility compliance requires

We’re used to these conversations. We welcome them.

Benchmarking your current provider

If your current website was built before accessibility and security expectations tightened, the more useful question isn’t which vendor to choose next. It’s whether your existing site meets the bar your procurement or compliance team now expects.

An independent read on the site is often more useful here than a vendor questionnaire alone, since a questionnaire tells you what a vendor says about themselves, not what their output does.

Our website assessments review a site against the same categories an auditor or evaluator would typically look for: security and maintenance practices, WCAG accessibility compliance, legal and regulatory compliance, user experience, and overall site health. You receive a documented report you can use in your own review process, regardless of who built the site originally.

It’s a useful step whether you’re validating an existing vendor ahead of a contract renewal, building a case for a change, or simply establishing a baseline before a formal assessment cycle begins.

How our certification aligns with Australian government frameworks

ISO 27001 is not a direct replacement for the Australian Signals Directorate’s Information Security Manual (ISM) or the Essential Eight, but it is directionally aligned and widely recognised across Australian government and enterprise procurement as a credible baseline for supplier assurance.

Our certification demonstrates an independently verified, systematically maintained approach to information security, which maps meaningfully to the supplier risk expectations embedded in the ISM and in whole-of-government procurement frameworks.

Who you’ll be working with

Kicking Pixels isn’t a generalist agency that occasionally picks up government work. We’ve built our practice specifically around the requirements of organisations operating under scrutiny: an ISO 27001:2022 certified information security management system maintained on an ongoing basis, WCAG 2.1 AA accessibility built in as standard rather than retrofitted, and a development process that can be documented and defended when an auditor or evaluator asks, not just described in a sales conversation.

That distinction matters more in a formal vendor assessment than it does anywhere else. You’re not evaluating a pitch, a portfolio or a list of past clients. You’re evaluating whether the practice behind all of that holds up when someone independent goes looking.

It’s also why we don’t treat security and accessibility as add-on services quoted separately from the build. They’re part of how every project is scoped and delivered by default, government or otherwise.

You can read more about how we work, who we work with, and why we built the practice this way on our About page.

The short version

We’re a web development agency that takes information security seriously enough to have it independently certified and continuously maintained.

If you’re assessing vendors for a government or enterprise web project, we’re ready to support that process with the documentation, the transparency, and the rigour it deserves.

Get in touch with our team or read more about why we pursued ISO 27001 certification and what it means for the organisations we work with.

For a broader look at what ISO 27001 certification means for a web development project generally, see our explainer here.