SaaS Go-To-Market Playbook: Selling Software in ANZ
Market sizing, GST on digital services, data residency, government procurement and channel strategy for foreign SaaS companies entering Australia and New Zealand
The ANZ SaaS Opportunity
How large is the Australian SaaS market, and why should a foreign software company care about ANZ?
Australia and New Zealand represent one of the most commercially attractive English-speaking technology markets outside North America and the United Kingdom. High rates of cloud adoption, a concentration of globally competitive enterprises in financial services, mining, energy and healthcare, and a federal government that runs dedicated digital procurement portals all combine to create a genuine runway for foreign SaaS companies.
According to Grand View Research — a commercial market research firm — the Australian SaaS market generated approximately USD 10,662 million (roughly A$16 billion) in revenue in 2024 and is forecast to reach USD 19,870 million by 2030 at a compound annual growth rate of 10.1% between 2025 and 2030. These are industry estimates, not government-verified statistics, but they reflect a pattern of strong structural demand that is broadly consistent with broader cloud-adoption trends across APAC. Software accounts for approximately 97.6% of the market segment within that forecast.
What the numbers do not capture is the qualitative advantage: Australian and New Zealand buyers transact in English, operate under common-law legal frameworks, and benchmark their vendor selections against the same global software categories that drive deals in the United States and Europe. A SaaS product that works in London or Toronto typically requires minimal localisation to resonate in Sydney or Auckland — the primary work is regulatory and go-to-market adaptation, not product re-engineering.
What does a successful ANZ SaaS entry actually look like?
Two Irish-founded companies illustrate what a well-executed ANZ SaaS GTM motion can produce. LearnUpon, a learning management system built in Dublin, entered the Australian market by targeting mid-market enterprises in highly regulated industries — sectors where structured, auditable learning programmes are not optional. The company landed Telstra, Origin Energy, and more than 200 Australian mid-market customers by pairing a product that solved a genuine compliance-learning pain point with a local customer success function that could sit across the table from procurement teams in Sydney and Melbourne.
FINEOS, a Dublin-based insurance and claims-management platform, followed a longer enterprise sales cycle into Australia's life and group insurance sector, ultimately becoming the core claims platform for TAL, MLC Life and AIA Australia. Both cases share a common pattern: the companies chose a well-defined vertical, invested in Australian-based account management before they needed it, and understood the compliance context their buyers operated in — rather than treating ANZ as a simple geographic extension of a European deal.
New Zealand is frequently underweighted in ANZ entry plans. With a population of roughly five million, it does not offer the same volume as Australia, but it shares the same language, similar procurement culture, and a government that is itself a meaningful buyer of SaaS through All-of-Government contracts. Companies that treat NZ as a secondary market from day one typically find that the incremental cost of coverage is low and the deal quality can be high, particularly in the public sector and primary industries.
GST on Imported Digital Services
When does a foreign SaaS company have to register for Australian GST?
From 1 July 2017, Australia extended its Goods and Services Tax (GST) to cover the sale of imported services and digital products by non-resident businesses to Australian consumers. The regime is commonly referred to as the "Netflix tax" but it captures far more than streaming — it applies to virtually every SaaS product sold to Australian end-users.
The registration trigger is an annual Australian GST turnover of A$75,000 (A$150,000 for non-profit organisations). Once a foreign business meets or expects to meet that threshold in a 12-month period, it must register for GST with the Australian Taxation Office (ATO), charge 10% GST on covered supplies, lodge Business Activity Statements (BAS), and remit the tax collected. The A$75,000 threshold is low by global standards — a foreign SaaS company with only a handful of Australian enterprise customers may exceed it quickly.
Covered supplies include software and software maintenance, apps, game codes, online subscriptions (e-books, newspapers, music, video), webinars, distance learning programmes, and accounting, legal or consulting services delivered digitally. The full scope is set out in detail on the ATO's imported digital services page. B2B sales where the Australian purchaser is itself GST-registered are generally outside the regime (the recipient accounts for GST), but the practical burden of verifying customer GST status should not be underestimated.
What are the Electronic Distribution Platform rules, and do they affect SaaS vendors?
Where a foreign SaaS company sells entirely through an Electronic Distribution Platform (EDP) — an online marketplace or app store that controls the supply — the EDP operator, not the underlying merchant, is generally responsible for collecting and remitting GST. This mirrors the approach taken by the major app stores. A pure-marketplace vendor selling solely through a qualifying EDP may not need to register for GST independently.
However, most B2B SaaS companies sell directly — through their own website, via a reseller arrangement, or through a channel partner. In those cases the EDP exemption does not apply and the foreign vendor retains the registration and lodgement obligation. The practical advice is to audit your Australian revenue channels early, confirm whether any EDP operator has already assumed the GST obligation, and register directly if you are selling via your own platform or through a non-EDP reseller. Non-compliance attracts ATO scrutiny and can create unexpected liabilities when an Australian enterprise customer's finance team asks for a valid tax invoice showing 10% GST.
New Zealand operates a similar regime: the Inland Revenue Department (IRD) requires non-resident businesses supplying remote services and distantly taxable goods to register for NZ GST once NZ-sourced sales reach NZ$60,000 per year, at a rate of 15%. The NZ regime predates the Australian one and follows broadly comparable logic, though the rate and threshold differ. Foreign SaaS companies should model both thresholds when projecting ANZ revenue.
Selling to the Australian Government
How does the Australian federal government buy SaaS, and how do foreign vendors access those contracts?
The Australian federal government channels most of its digital and ICT procurement through Whole-of-Government (WoG) panel arrangements, administered by the Digital Transformation Agency (DTA). The DTA's BuyICT platform (buyict.gov.au) is the single point of access for government buyers seeking digital goods and services — covering hardware, software, cloud, and professional digital services. Foreign and domestic ICT suppliers must list on the relevant panel or arrangement before they are eligible for federal government contracts under a WoG arrangement; an unlisted vendor typically cannot be engaged without an agency running a separate open tender, which is a slower and more expensive path.
In October 2024, the DTA launched Digital Marketplace Panel 2, opening new opportunities for ICT and digital services suppliers to participate in federal government contracts. The DTA's media release confirmed the panel is open to both large and small suppliers, making it a realistic pathway for foreign SaaS companies that can meet the security and compliance requirements. Getting listed on Digital Marketplace Panel 2 is therefore one of the first structural actions a foreign SaaS company targeting government revenue should take.
How does state government procurement differ from federal, and what should vendors know?
State and territory governments operate their own procurement frameworks and panel arrangements, and they are not automatically bound by DTA WoG arrangements. Victoria, New South Wales, Queensland and Western Australia each have their own ICT procurement policies, digital marketplace equivalents, and vendor pre-qualification programmes. A foreign SaaS company that has successfully listed on BuyICT and Digital Marketplace Panel 2 at the federal level will still need to pursue separate accreditation or panel listings for material state government revenue.
The practical implication is that "government" is not a single sales motion in Australia — it is at least nine separate buyer segments (Commonwealth plus eight states and territories), each with its own procurement rules, preferred vendors, and commercial thresholds. Companies that treat government as a single channel and invest all their compliance effort at the federal level often discover later that state agencies — which collectively represent a very large share of public ICT spend — require a fresh process. Engaging an experienced local channel partner or government relations adviser who has navigated these frameworks previously is typically the most efficient path to multi-jurisdiction government revenue.
Hosting Certification and Data Residency
What is the Hosting Certification Framework and how does it affect SaaS companies?
Any cloud or data centre provider wishing to host Australian Government data must navigate the Hosting Certification Framework (HCF), administered by the Department of Home Affairs. The HCF creates three certification levels:
- Strategic — the highest assurance level, with sovereign ownership and control conditions. Required for sensitive and PROTECTED government data. Most government entities are expected to seek services at the Certified Strategic level.
- Assured — financial penalties apply for significant changes in ownership or control; an intermediate tier for lower-sensitivity workloads.
- Uncertified — minimal protections; appropriate only for non-sensitive, public-domain data.
According to the Hosting Certification Framework service-providers page, the HCF has applied to new government hosting contracts and extensions since 30 June 2022. Assessment typically takes 3–6 months on average. For a foreign SaaS company whose infrastructure is hosted in hyperscaler regions outside Australia, this creates a significant planning challenge: either host government workloads in a HCF-certified data centre region in Australia, or partner with an Australian managed service provider that already holds certification.
Important 2025 update: From 3 November 2025, new registrations and supplementary assessments under the HCF were paused pending completion of a review and reform of the framework. Existing certified providers are not affected. Foreign SaaS companies planning to enter the Australian government market should verify the current status of this pause before initiating an HCF application, and consider building relationships with already-certified hosting partners in the interim.
What are the government's data residency expectations for SaaS products?
The Australian Government's default preference under the Protective Security Policy Framework (PSPF) and the Hosting Certification Framework is that government data be hosted in Australia, in HCF-certified facilities. For data classified at PROTECTED and above, sovereign control conditions may apply — meaning not only must the data be physically located in Australia, but the provider must meet the Strategic certification's ownership and control requirements. Non-sensitive government data may in principle be hosted on uncertified services, but agencies are increasingly risk-averse and contractually conservative.
For a foreign SaaS company this typically means one of three things: (1) deploy a dedicated Australian cloud region through AWS, Azure or Google Cloud (all of which have Australian regions), but confirm that the specific region meets HCF requirements; (2) partner with a HCF-certified Australian managed service provider who hosts the government workload on your behalf; or (3) restrict your government sales motion to non-sensitive data workloads until a compliant hosting arrangement is in place. The third option is viable in early stages but limits TAM significantly — the most valuable government contracts almost always involve at least some OFFICIAL: Sensitive data.
Data residency expectations also apply to certain regulated private sector workloads. The Prudential Regulation Authority (APRA) expects regulated financial institutions to maintain control over data and operational resilience, which in practice creates strong pull toward Australian-hosted SaaS for banking, superannuation, and insurance customers. A SaaS company targeting both government and financial services in Australia should architect its Australian infrastructure with both sets of requirements in mind from day one.
Security Standards: IRAP and Essential Eight
What is IRAP assessment and when does a foreign SaaS vendor need one?
The Information Security Registered Assessors Program (IRAP) is administered by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre (ACSC). IRAP-accredited assessors conduct independent assessments of a system's cybersecurity posture against the Information Security Manual (ISM) — the Australian Government's primary cybersecurity framework. According to the ACSC's IRAP common assessment framework, the resulting IRAP risk report can also serve as evidence in Hosting Certification Framework applications.
Any foreign SaaS or ICT company seeking to supply services to Australian government agencies should treat an IRAP assessment as an essential prerequisite, not a nice-to-have. Agencies routinely ask for IRAP reports or equivalent evidence during procurement evaluation. Without one, a vendor is relying on the agency's own risk acceptance process, which is slower and less predictable than presenting a completed third-party assessment. The assessment covers your cloud infrastructure, application architecture, access controls, logging, and incident response capabilities — broadly the same domains that international frameworks like ISO 27001 and SOC 2 address, which makes cross-certification sensible where you hold one of those already.
What is the Essential Eight, and what maturity level do government buyers expect from SaaS vendors?
The Essential Eight is a set of eight baseline cybersecurity mitigation strategies published by the ACSC: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups. There are four maturity levels (ML0 to ML3). Under PSPF Policy 14, all non-corporate Commonwealth entities must implement the Essential Eight to at least Maturity Level 2.
As at 2025, 22% of federal entities had achieved overall Essential Eight Maturity Level 2 — up from 15% in 2024 — according to the ACSC's Commonwealth Cyber Security Posture in 2025 report. This means both that the bar is rising (government agencies are themselves investing in compliance) and that vendors are increasingly expected to match or exceed ML2 in their own operational security posture. A foreign SaaS vendor that cannot demonstrate ML2-equivalent controls — or has not engaged an IRAP assessor to validate this — will find government sales cycles materially longer.
The Essential Eight is also influencing private-sector procurement in Australia. Large regulated enterprises in banking, insurance and critical infrastructure are embedding Essential Eight alignment into their supplier security questionnaires, treating it as the de facto national baseline. A foreign SaaS company that has already invested in SOC 2 Type II will find partial overlap, but should perform a gap analysis against the ISM and Essential Eight specifically, as there are material differences — particularly around application control and macro restriction.
Privacy, Data Obligations and Channel Strategy
What Privacy Act obligations apply to a foreign SaaS company processing Australian personal data?
Any foreign SaaS company that collects, uses, or discloses personal information of Australians — which in practice means any SaaS product where end-users log in, submit data, or are identified — is subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). The Privacy Act's extraterritorial reach covers foreign businesses that carry on business in Australia, even if they have no physical Australian presence.
The APPs govern the collection, storage, use, disclosure, and correction of personal information. Key obligations for SaaS vendors include: collecting only what is reasonably necessary; providing a compliant privacy policy; not using or disclosing personal information for purposes beyond the original collection; taking reasonable steps to protect information from misuse, interference, loss, or unauthorised access; and responding to access and correction requests. The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024, delivering the first substantive amendments to the Privacy Act since 2012. A new right to explanation for automated decisions is scheduled to take effect in December 2026 — SaaS companies using algorithmic decision-making features in their products should begin preparation now.
New Zealand has its own Privacy Act 2020, which already incorporates many modernised obligations including a mandatory breach notification regime. Foreign SaaS companies operating in both markets should review both Acts as part of a single privacy compliance project — the frameworks are compatible enough that a combined effort is efficient, but they are not identical and NZ-specific requirements should not be assumed to be covered by APP compliance alone.
What channel and go-to-market strategies work best for foreign SaaS companies entering ANZ?
ANZ is a relationship-driven market. Foreign SaaS companies that attempt a pure inbound or product-led growth motion without any local human presence typically find that their pipeline development stalls at the mid-enterprise and government segments, where buyers expect a local account manager, a local support contact, and a vendor they can reference-check through their own professional networks. The most successful entrants — including both LearnUpon and FINEOS — invested in a Sydney (and in some cases Melbourne) presence before their revenue justified it on a pure cost-of-sales basis.
The most common channel structures in ANZ for foreign SaaS are: (1) a direct sales hire — a senior enterprise account executive based in Sydney, typically recruited from a competitor or adjacent SaaS company; (2) a value-added reseller (VAR) or systems integrator — firms like Datacom, Empired, Telstra Purple, or smaller specialist integrators in verticals like financial services or healthcare, who bring existing agency relationships; and (3) a distributor-led motion common in mid-market, where a local distributor manages a reseller network across Australia and NZ. These models can be combined: a direct hire manages named enterprise accounts while a VAR covers the broader mid-market.
For the government channel specifically, specialist government channel partners with existing panel memberships and agency relationships provide the fastest path to revenue — building those relationships from scratch as a new entrant takes 12–24 months. Consider also that the ANZ government procurement cycle runs on the Australian financial year (July–June), meaning budget decisions are made in Q4 (April–June) for the following year. Vendors who are not in active evaluation by February typically miss the budget cycle entirely.
Are there any other compliance obligations a SaaS company should be aware of?
Beyond GST, privacy, and government-specific requirements, foreign SaaS companies should be aware of several cross-cutting obligations. Foreign company registration with ASIC under Part 5B.2 of the Corporations Act 2001 is required before conducting business in Australia — this is a prerequisite for opening a bank account, signing leases, and engaging employees. The ASIC registration process is straightforward and typically completed within two weeks, but it must precede commercial activity.
If your SaaS product processes personal data for Australian financial institutions, superannuation funds or insurers, your customers will likely require you to comply with APRA Prudential Standard CPS 230 (Operational Risk Management) and potentially CPS 234 (Information Security). These standards impose obligations on the regulated entity's service providers — your customer will flow down contractual requirements covering your security controls, incident notification timelines (as short as 24 hours for material incidents), and audit rights. SaaS companies targeting the financial services vertical should review CPS 230 and CPS 234 as part of their pre-sales due diligence process.
The Security of Critical Infrastructure (SOCI) Act 2018 is a further consideration if your SaaS product stores or processes data for operators of critical infrastructure — energy, water, transport, healthcare, telecommunications, financial markets, and several other sectors. Cloud and data processing services for critical infrastructure operators can themselves be caught as a "critical data storage or processing asset," triggering registration and risk management obligations. If your SaaS is positioned at enterprise customers in these sectors, engage specialist Australian legal advice on SOCI implications before contracting.
Your First Steps: ANZ SaaS Launch Checklist
What should a foreign SaaS company do in its first 90 days of ANZ market entry?
Use this checklist as a practical sequence. Items are roughly ordered by dependency — some can run in parallel, others must precede what follows.
Legal and tax foundations
- ☐ Register as a foreign company with ASIC under Part 5B.2 of the Corporations Act 2001 — required before conducting business in Australia.
- ☐ Determine whether your projected Australian digital-service revenue will reach the A$75,000 GST threshold within 12 months; if yes (or likely), register for GST with the ATO and configure your billing system to collect and remit 10% GST.
- ☐ Audit your NZ revenue trajectory against the NZ IRD's NZ$60,000 remote-services registration threshold; register for NZ GST if applicable.
- ☐ Review your existing privacy policy for compliance with the Australian Privacy Principles (APPs) under the Privacy Act 1988; update for the December 2024 amendments and plan for the December 2026 automated-decision-right changes.
- ☐ If serving NZ customers, review NZ Privacy Act 2020 obligations — particularly the mandatory breach notification regime.
Government and security readiness
- ☐ Assess your product against the Essential Eight Maturity Model — target at least ML2 alignment before initiating government sales discussions.
- ☐ Engage an IRAP-accredited assessor to independently validate your security posture against the ISM; budget 3–6 months for the assessment process.
- ☐ Decide whether your government target workloads require HCF-certified hosting — if yes, check the current status of the HCF registration pause (paused from 3 November 2025) and engage a HCF-certified hosting partner in the interim.
- ☐ Apply to list on the DTA Digital Marketplace Panel 2 (launched October 2024) and relevant BuyICT arrangements to become eligible for federal government contracts.
- ☐ Research state government panel listings in your priority states (NSW, Victoria, Queensland) — federal listing does not automatically qualify you for state contracts.
Market and channel setup
- ☐ Define your primary ICP (ideal customer profile) for the ANZ market — vertical, company size, buyer role — and identify 20–30 named accounts as your initial target list.
- ☐ Decide on your channel structure: direct hire, VAR/systems integrator, distributor, or hybrid — and initiate conversations with at least two potential local channel partners before committing.
- ☐ If targeting financial services customers, review APRA CPS 230 and CPS 234 requirements that your customers will flow down to you contractually.
- ☐ If your product will process data for critical infrastructure operators, obtain specialist legal advice on SOCI Act implications.
- ☐ Identify three to five Australian reference customers as priority targets in your first 12 months — local references accelerate every subsequent deal in this relationship-driven market.
Frequently Asked Questions
Do I need to have Australian-hosted infrastructure before I can sell SaaS in Australia?
For commercial (non-government) customers, no — there is no general legal requirement to host data in Australia. However, buyers in regulated industries (banking, insurance, healthcare, government agencies) will increasingly ask where your data is hosted, and many will contractually require Australian data residency. For federal government contracts involving non-public data, the Hosting Certification Framework effectively mandates HCF-certified Australian hosting. The pragmatic answer is: you do not need Australian hosting on day one to begin commercial conversations, but you will need a clear data residency roadmap before you can close government or regulated-industry deals at scale.
How long does it take to get IRAP assessed, and how much does it cost?
An IRAP assessment timeline varies depending on the scope and complexity of your system, but the planning assumption is 3–6 months from engaging an assessor to receiving a completed risk report — the same indicative range cited by the Hosting Certification Framework for related assessments. Costs are not published by the ACSC in primary sources, as assessors set their own commercial rates — market rates vary significantly by scope and assessor, so obtain at least three quotes. Begin the IRAP process well before your first substantive government sales engagement, not after a request for proposal arrives.
Our SaaS product is sold through an app store — do we still need to register for Australian GST?
If all of your Australian sales flow through an Electronic Distribution Platform (EDP) that has assumed the GST collection and remittance obligation, you may not need to register independently. However, you must confirm this with the specific EDP operator and obtain evidence of their GST-registered status. If any of your Australian revenue is earned outside the EDP — for example, through direct invoicing, enterprise agreements, or a self-hosted checkout — that revenue remains your GST obligation once the A$75,000 threshold is met. Review the ATO's guidance on imported digital services and obtain Australian tax advice if your revenue mix spans multiple channels.
Is the HCF registration still open to new applicants?
As of 3 November 2025, the Department of Home Affairs paused new registrations and supplementary assessments under the Hosting Certification Framework pending completion of HCF reforms. Existing certified providers continue to operate under their current certification. Foreign SaaS companies that had planned to pursue HCF certification should monitor the Hosting Certification Framework service-providers page for updates on when the pause is lifted, and in the interim should consider whether partnering with an already-certified hosting provider can meet their government customers' requirements.
What is the fastest path to a first Australian government contract?
The fastest structural path is to (1) list on BuyICT and the Digital Marketplace Panel 2, which makes you contractually eligible; (2) partner with a government-specialist channel partner who has existing agency relationships and can introduce you into active procurement processes; and (3) target smaller agencies or sub-agencies first — large Commonwealth departments have longer procurement timelines and more intensive security vetting than smaller statutory bodies or state agencies. Agencies in the ACT (Canberra) are accessible for direct relationship-building given the concentration of federal government buyers in a single city. Budget a minimum of 12–18 months from market entry to first government contract signature.
Do the ANZ data residency rules apply in New Zealand as well?
New Zealand does not have an equivalent to Australia's Hosting Certification Framework. However, the NZ government's Privacy Act 2020 requires agencies to take reasonable steps to prevent information from being disclosed or accessed outside New Zealand in ways that would contravene the Act, and the NZ Government ICT Strategy encourages agencies to consider data sovereignty. In practice, NZ government buyers will ask questions about data residency and may contractually require NZ or Australian hosting for sensitive workloads. The NZ All-of-Government cloud framework, managed by the Department of Internal Affairs, sets guidance on cloud procurement but does not impose a formal certification equivalent to the HCF. Research the current NZ government cloud policy as part of any NZ public-sector sales strategy.
Related Guides
Localising your product, pricing and marketing for Australian buyers
Price in AUD inclusive of GST, switch to Australian English and local proof points, and rebuild your channel mix around LinkedIn, Google and industry associations rather than the channels that work at home.
How to choose the right market entry strategy for Australia
Exporting, licensing, a local subsidiary, a joint venture or an acquisition each carry different capital, control and speed trade-offs when entering Australia. This guide walks through when each makes sense.
How to decide whether Australia or New Zealand is your first ANZ market
Australia is roughly five times the GDP of New Zealand, but NZ is often faster, cheaper and more forgiving as a proving ground before an east-coast Australian launch.
