Framework National Cyber & Cloud Schemes
IRAP
The Infosec Registered Assessors Program (IRAP) is the Australian Signals Directorate's scheme for endorsing private-sector security assessors who evaluate systems against the Australian Government Information Security Manual (ISM) and related policy such as the Protective Security Policy Framework.
An IRAP assessment is the standard way a cloud service or system used by Australian government agencies has its controls independently examined at a classification level (OFFICIAL, OFFICIAL: Sensitive, PROTECTED, and above).
The assessor produces a report on which controls are implemented, alternative controls, and residual risks; the assessor does not certify or accredit, and the agency's authorizing officer makes the authorization decision using the report.
ASD retired its Certified Cloud Services List in 2020 and replaced it with cloud security guidance that puts the assessment report at the center of each agency's own decision.
In writing, a system owner preparing for an IRAP assessment needs a system security plan that addresses each applicable ISM control, a security risk management plan, an incident response plan, a continuous monitoring plan, an architecture and data flow description, and the operating evidence the assessor will sample.
Assessment reports are typically refreshed every two years or when the system changes materially, and agencies commonly require a report no older than 24 months.
help
Who has to comply
Cloud service providers, software vendors, and outsourced service providers that want Australian government agencies to use their systems, and agencies themselves for systems they operate. Assessment is not legally mandated by name, but agency authorization under the PSPF and ISM depends on independent assessment, and IRAP is the recognized route.
Defence Industry Security Program and state government programs also rely on it.
What the assessor asks to see
System security plan with control-by-control implementation statements against the ISM; security risk management plan; architecture, data flow, and classification boundary; incident response plan; continuous monitoring and vulnerability management plan; configuration and hardening evidence; identity and access records; logging and monitoring; cryptography and key management (ASD-approved algorithms); physical and personnel security for facilities and staff; supply chain and third-party arrangements; prior assessment reports and remediation.
Assessors
Who assesses IRAP
IRAP assessors, individuals endorsed by ASD after meeting experience, qualification, and training requirements and passing the IRAP course; they work independently or within consultancies. Assessors do not accredit or certify; authorization is made by the consuming agency. Accredited by ASD endorses and lists IRAP assessors and sets the assessment methodology.
Public register of assessors: https://www.cyber.gov.au/business-government/protecting-devices-systems/assessment-evaluation-programs/irap/irap-assessors
No firm has claimed a IRAP assessor listing yet. Claim yours →
Consultants
Who helps with IRAP
Australian security consultancies prepare organizations for assessment: ISM gap analysis, system security plan authoring, control implementation, and evidence collection. Readiness commonly takes six to twelve months for a PROTECTED-level cloud service. Firms that prepare a system may not also assess it under the program's independence rules.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a IRAP consultant listing yet. Claim yours →
Software
Tools for IRAP
Tools that name this framework in their own material.
No firm has claimed a IRAP tool listing yet. Claim yours →
Related reading
- IRAP complianceDescribes what an ASD-certified IRAP assessor actually examines and how PROTECTED-level assessment reports are made available.Amazon Web Services
- Australia IRAPUseful on the division of labour: a provider assessment does not remove your own obligation to have your deployment assessed.Microsoft
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for IRAP
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with IRAP
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.