All insights
Government Compliance May 27, 2026 7 min read

IRAP Assessments: What They Are and How to Prepare

For any organisation seeking to handle Australian Government information or sell technology services into government, the term IRAP comes up quickly. An IRAP assessment is the recognised way to gain independent assurance that a system meets the requirements of the Information Security Manual. Understanding what the program is, what the assessor actually does, and how to prepare can be the difference between a smooth engagement and an expensive, drawn-out one.

What IRAP actually is

IRAP stands for the Infosec Registered Assessors Program. It is administered by the Australian Signals Directorate through the Australian Cyber Security Centre. The program endorses suitably qualified and experienced cyber security professionals to provide independent assessment services to government and to organisations that supply government. These endorsed individuals are IRAP assessors.

The purpose of the program is to grow a pool of trusted assessors who can evaluate whether a system and its security controls are implemented and operating in line with the Information Security Manual. Because the ISM is the Commonwealth’s central cyber security framework, an IRAP assessment is effectively the standard mechanism for demonstrating, with independent evidence, that a system is fit to handle government data.

The assessor’s role, and its limits

The single most important thing to understand about IRAP is what the assessor does and does not do. An IRAP assessor independently assesses the security of a system against ISM controls, identifies the effectiveness of those controls, and documents residual risks in a security assessment report. The assessor provides findings and, where appropriate, recommendations.

What the assessor does not do is authorise the system. The decision to accept residual risk and authorise a system to operate sits with the responsible authorising officer inside the entity that owns or relies on the system. This separation is deliberate. The assessor brings independent, evidence-based judgement; the authorising officer owns the risk decision. Vendors sometimes assume that passing an IRAP assessment means their product is now approved for all government use. It does not. It means an independent assessor has documented how the system measures up, which each prospective government customer then weighs in their own authorisation decision.

When you need an assessment

An IRAP assessment is generally warranted in several situations:

  • A system stores, processes or communicates sensitive or classified government information.
  • A cloud service provider or software vendor wants to demonstrate suitability for government buyers.
  • The Protective Security Policy Framework, a contract or a funding agreement mandates independent assurance.
  • An entity is standing up a new system and needs evidence to support an authorisation to operate.

Many service providers pursue assessment proactively. In a competitive market, being able to hand a government buyer a current IRAP security assessment report removes a major procurement obstacle and signals genuine investment in security. For organisations weighing whether to invest, the broader question of supplier and system risk is exactly what a structured cyber due diligence process is designed to answer.

How to prepare: the work happens before the assessor arrives

The most expensive mistake in IRAP is treating the assessment itself as the place to discover and fix gaps. The assessor evaluates what exists; they are not there to build your controls for you. Genuine readiness is what keeps an assessment short and the report clean. A sensible preparation programme looks like this.

  1. Define the system boundary precisely. Scope creep is the most common cause of blown timelines. Document exactly what is in and out of scope, including data flows, integrations and underlying infrastructure.
  2. Classify the data. Be clear about the sensitivity and classification of the information the system handles, because this drives which ISM controls apply and at what rigour.
  3. Conduct an internal gap assessment. Measure your current implementation against the relevant ISM controls before the assessor does. Fix what you can and document risk decisions for what you cannot.
  4. Assemble evidence. Assessors work from evidence, not assertions. Gather policies, configuration baselines, system architecture documents, access control records, logging and monitoring evidence, and your system security plan.
  5. Implement and bed in your Essential Eight controls. The Essential Eight mitigation strategies underpin many ISM controls; having them genuinely operating, not just planned, removes a large block of findings.
  6. Prepare your people. Make sure the staff who will speak to the assessor understand the system and can produce evidence on request without scrambling.

The cloud dimension

A large share of IRAP activity today concerns cloud services. When the ACSC stepped back from maintaining a centralised certified cloud list, responsibility shifted firmly onto entities to assess the cloud services they consume, using IRAP-assessed evidence as a key input. The practical effect is twofold. Cloud and software providers increasingly commission IRAP assessments of their platforms so they can hand prospective government customers a current security assessment report. Government entities, in turn, must read those reports critically and make their own authorisation decisions rather than assuming a vendor’s assessment equals approval.

This shared-responsibility reality is easy to get wrong. A provider’s IRAP report typically covers the controls the provider is responsible for, not the controls that remain the customer’s job, such as identity management, data classification and configuration of the service. An entity that treats a vendor’s clean report as covering the whole system is accepting risk it has not actually assessed. Reading the report’s scope and the responsibility matrix carefully is essential, and is exactly the kind of nuance a virtual CISO can help an agency navigate.

What the assessor examines

It helps to know what an assessor will actually look at, because it shapes the evidence you need to assemble. An IRAP assessor will typically work through the relevant guidelines and controls of the Information Security Manual, examining areas such as governance and security documentation, personnel and physical security, system hardening and configuration baselines, access control and privileged access management, network architecture and segmentation, gateways and data transfers, cryptography, logging and monitoring, and incident response. For each, the assessor seeks evidence that the control is both implemented and effective, not merely planned.

The distinction between implemented and effective is where unprepared organisations are caught out. A policy that says administrative privileges are restricted is not evidence; the assessor wants to see the actual privileged account inventory, the approval records and the technical enforcement. The lesson is straightforward: collect the artefacts that prove a control operates, and be ready to demonstrate it live rather than describe it.

What the assessment produces

The principal output is a security assessment report. It describes the system, the controls assessed, how effectively each is implemented, and the residual risks that remain. A strong report is not one with zero findings; that almost never happens and can even signal a superficial assessment. A strong report is one that accurately reflects reality, clearly articulates residual risk, and gives the authorising officer a sound basis for their decision. That honesty is what makes the report useful to the government customers who will read it.

Getting it right the first time

IRAP assessments reward preparation and punish improvisation. The organisations that move through smoothly are those that have done the unglamorous groundwork: a tightly defined scope, real implemented controls, documented risk decisions and a tidy evidence pack. Those that treat the assessor as a consultant who will help them figure out their security posture during the engagement end up with longer timelines, larger bills and reports full of avoidable findings.

This is where independent preparation support pays for itself. CISO Advisory helps government departments, agencies and vendors get assessment-ready, run pre-assessment gap reviews, and stand up the governance and evidence that an IRAP engagement demands. Whether you are a private sector provider chasing government work or an agency standing up a new system, our virtual CISO service can get you to the starting line in good shape. To talk through an upcoming assessment, call 07 2112 8502 or get in touch via our contact page.

An IRAP assessment is not a hoop to jump through. Done well, it is a genuine, independent health check that builds trust with the government decision-makers you need on side. Prepare for it as the serious exercise it is, and it becomes an asset rather than an ordeal.

Frequently asked questions

What does IRAP stand for?

IRAP is the Infosec Registered Assessors Program, administered by the Australian Signals Directorate through the Australian Cyber Security Centre. It endorses suitably qualified cyber security professionals to provide independent assessments of how well systems and their controls meet the requirements of the Information Security Manual.

Does an IRAP assessor certify or accredit my system?

No. This is a common and important misunderstanding. An IRAP assessor independently assesses a system against the ISM and documents the findings, including residual risks. The decision to authorise a system to operate, sometimes called accreditation, rests with the responsible authorising officer within the entity, not the assessor.

When do I need an IRAP assessment?

IRAP assessments are typically required when a system handles sensitive or classified government information, when a cloud or service provider seeks to demonstrate suitability for government use, or when a contract or the PSPF mandates independent assurance. Many vendors pursue assessment proactively to make their offering credible to government buyers.

How long does an IRAP assessment take?

It varies considerably with system scope and complexity, but most assessments run over several weeks to a few months once preparation is complete. The single biggest determinant of timeline is readiness: organisations with mature documentation, evidence and implemented controls move quickly, while those treating preparation as part of the assessment do not.

Who can perform an IRAP assessment?

Only an individual endorsed under the Infosec Registered Assessors Program may perform one. Assessors meet defined competency and experience requirements and are listed by the ACSC. Engaging a genuinely endorsed assessor matters, because an assessment by an unendorsed party will not carry the recognition government decision-makers require.

Talk to a Virtual CISO

Need this handled for your organisation?

Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.

Confidential. We typically respond same business day — or call us 24/7.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act