HomeFrameworksNational Cyber & Cloud SchemesIRAP

Framework  National Cyber & Cloud Schemes

IRAP

The Infosec Registered Assessors Program (IRAP) is the Australian Signals Directorate's scheme for endorsing private-sector security assessors who evaluate systems against the Australian Government Information Security Manual (ISM) and related policy such as the Protective Security Policy Framework.

An IRAP assessment is the standard way a cloud service or system used by Australian government agencies has its controls independently examined at a classification level (OFFICIAL, OFFICIAL: Sensitive, PROTECTED, and above).

The assessor produces a report on which controls are implemented, alternative controls, and residual risks; the assessor does not certify or accredit, and the agency's authorizing officer makes the authorization decision using the report.

ASD retired its Certified Cloud Services List in 2020 and replaced it with cloud security guidance that puts the assessment report at the center of each agency's own decision.

In writing, a system owner preparing for an IRAP assessment needs a system security plan that addresses each applicable ISM control, a security risk management plan, an incident response plan, a continuous monitoring plan, an architecture and data flow description, and the operating evidence the assessor will sample.

Assessment reports are typically refreshed every two years or when the system changes materially, and agencies commonly require a report no older than 24 months.

AI-compiled
Share
Sponsored
IRAP
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with IRAP
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Cloud service providers, software vendors, and outsourced service providers that want Australian government agencies to use their systems, and agencies themselves for systems they operate. Assessment is not legally mandated by name, but agency authorization under the PSPF and ISM depends on independent assessment, and IRAP is the recognized route.

Defence Industry Security Program and state government programs also rely on it.

What the assessor asks to see

System security plan with control-by-control implementation statements against the ISM; security risk management plan; architecture, data flow, and classification boundary; incident response plan; continuous monitoring and vulnerability management plan; configuration and hardening evidence; identity and access records; logging and monitoring; cryptography and key management (ASD-approved algorithms); physical and personnel security for facilities and staff; supply chain and third-party arrangements; prior assessment reports and remediation.

Assessors

Who assesses IRAP

IRAP assessors, individuals endorsed by ASD after meeting experience, qualification, and training requirements and passing the IRAP course; they work independently or within consultancies. Assessors do not accredit or certify; authorization is made by the consuming agency. Accredited by ASD endorses and lists IRAP assessors and sets the assessment methodology.

Public register of assessors: https://www.cyber.gov.au/business-government/protecting-devices-systems/assessment-evaluation-programs/irap/irap-assessors

No firm has claimed a IRAP assessor listing yet. Claim yours →

Consultants

Who helps with IRAP

Australian security consultancies prepare organizations for assessment: ISM gap analysis, system security plan authoring, control implementation, and evidence collection. Readiness commonly takes six to twelve months for a PROTECTED-level cloud service. Firms that prepare a system may not also assess it under the program's independence rules.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a IRAP consultant listing yet. Claim yours →

Software

Tools for IRAP

Tools that name this framework in their own material.

No firm has claimed a IRAP tool listing yet. Claim yours →

Related reading

  1. IRAP complianceDescribes what an ASD-certified IRAP assessor actually examines and how PROTECTED-level assessment reports are made available.Amazon Web Services
  2. Australia IRAPUseful on the division of labour: a provider assessment does not remove your own obligation to have your deployment assessed.Microsoft

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for IRAP

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with IRAP

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.