What is an IRAP assessment?
The Infosec Registered Assessors Program, IRAP, is run by the Australian Signals Directorate. It endorses individual assessors to review systems against the Information Security Manual, the ISM, and against the Protective Security Policy Framework where it applies. An IRAP assessment examines one defined system, at a stated classification such as OFFICIAL: Sensitive or PROTECTED, against the ISM controls applicable to that classification.
The assessment produces a security assessment report. It records the system boundary, the controls assessed, how each is implemented, the assessor's findings, and residual risks. The report does not certify the system. ASD stopped certifying cloud services in 2020, and the decision to use a system sits with the authorising officer of each government entity that wants to use it, informed by the report.
How do government teams choose IRAP-assessed software?
A buying agency's security team reads the vendor's IRAP assessment report against its own use of the system. It checks the classification assessed matches the data it plans to put in, the ISM release the assessment was performed against, and the date. The ISM points entities toward providers assessed against the latest ISM within the previous 24 months, so an older report prompts a question.
It then reads scope. A report that covers the hosting platform and leaves out the vendor's application, its support access path or its development pipeline answers a narrower question than the buyer is asking. Hyperscale cloud providers hold their own IRAP assessments, and a SaaS vendor inherits some controls from them, but the vendor's own layer still needs assessment. Buyers look for the list of inherited controls and the controls the vendor implements itself.
Finally the security team reads the findings and residual risks, decides whether its own controls cover them, and puts a recommendation to the authorising officer. Vendors who supply a clear consumer guide, describing the controls the customer agency is responsible for, shorten that step.
What does an IRAP assessor examine?
The assessor works from the ISM's applicable controls for the classification and the system type. Expect examination of governance and documentation, personnel security for staff with access, physical security of any premises in scope, and the technical controls across the ISM's guidelines: system hardening, system management including patching, system monitoring, communications and network security, cryptography, gateways, data transfers, software development, database systems and email where relevant.
The Essential Eight is embedded in the ISM, and the assessor will look at the vendor's maturity against it for the system's administrative and corporate environment. Personnel security matters more than many vendors expect: at PROTECTED, staff with privileged or unescorted access to the system generally need an appropriate Australian Government security clearance, and offshore support access needs careful treatment.
The assessment is evidence-led. The assessor reviews documentation, interviews staff, and examines configuration and operation directly. Controls described in a policy and not visible in the system are rated against what the system does.
Which documents does the vendor need first?
The ISM sets out the security documentation a system is expected to carry, and an IRAP assessment reads it. Drafting these documents to match the system as it runs is usually the critical path, more than booking the assessor.
- A system security plan, with the ISM control applicability annex, describing the system, its boundary and how each applicable control is implemented.
- A security risk management approach and risk register for the system.
- An incident response plan that covers how the vendor detects, responds to and reports incidents affecting customer agencies.
- A continuous monitoring plan describing vulnerability management, logging and how control effectiveness is checked over time.
- Architecture and data flow diagrams that match the deployed system, including administrative and support access paths.
- A consumer guide that names the controls each customer agency is responsible for.
Where do SaaS vendors usually fall short?
The gaps cluster in a few places. The documented boundary does not match the deployed system, because a logging service, a support tool or a CI/CD runner sits outside the diagram. Administrative access comes from ordinary corporate laptops on unrestricted networks. Logging exists in the platform and nobody reviews it. The development pipeline deploys with long-lived credentials. Offshore staff or subcontractors hold access that the documentation does not mention.
Each of these is engineering and process work that can be done before the assessor is booked. A pre-assessment against the applicable ISM controls finds them, and fixing them before the assessment keeps the report's findings list short. A short findings list is what makes the report easy for a buyer's security team to accept.
How long does preparation take?
The answer turns on the gap between the system and the documents. A vendor running on an IRAP-assessed hyperscale platform, with strong identity controls, infrastructure as code, centralised logging and an Essential Eight programme in place, can often move to assessment once the system security plan and supporting documents describe what is already there. A vendor with administrative access from unmanaged devices and undocumented suppliers needs remediation first.
Assessor availability adds lead time, and the assessment itself scales with system complexity. Vendors aiming at a specific tender should work back from the date the report is needed and leave room for remediation of any findings the assessor raises.
How does IRAP relate to the Essential Eight and ISO 27001?
The three answer different questions. The Essential Eight is a set of mitigation strategies with a maturity model, and the ISM includes its controls. An IRAP assessor reads the vendor's Essential Eight position as part of the wider ISM assessment, so a current, evidence-backed Essential Eight assessment of the administrative environment shortens that part of the work.
ISO/IEC 27001 certifies a management system and is recognised internationally. Many government tenders ask for it alongside or instead of an IRAP assessment, depending on the data involved. An ISO 27001 ISMS gives an IRAP assessment useful structure: a risk register, controlled documents, internal audit and management review records. It does not substitute for the ISM controls, which are more prescriptive on cryptography, gateways and personnel security.
Vendors selling to both enterprise and government buyers often build one control set mapped to all three. The same evidence of patching, privileged access, logging and backup testing serves the Essential Eight assessment, the ISO 27001 audit and the IRAP assessment, provided it is collected with all three in mind from the start.
What does an IRAP assessment cost a vendor?
The direct cost is the assessor's fee, which scales with the system's size, the classification and the number of ISM controls in scope. The larger cost is usually internal: the engineering time to close gaps, the time to write documentation that matches the system, and the staff time during the assessment itself. Vendors also carry the cost of keeping the assessment current, since buyers look for a report against a recent ISM release.
What can be done before the assessor arrives?
The preparation work is security engineering and documentation, and it can be done by the vendor or with outside help. Black Shard runs the preparation around an IRAP assessment: an Essential Eight assessment of the administrative environment, a penetration test of the application and its support paths, remediation of the gaps those find, and documentation that matches the deployed system, delivered as a programme or inside a vCISO engagement. Black Shard runs its own estate at Essential Eight Maturity Level Three and holds SMB1001:2026 Gold.
A vendor that walks into the IRAP assessment with its documents matching its system, its Essential Eight position assessed and its application tested gives the assessor less to find and the buyer less to question. Scope for that work is set on a free 30-minute scoping call.