ALVOR
Platform
Advisory
PricingBlog
Get Demo
ALVOR
Platform
Advisory
PricingBlog
Get Demo

Program · IRAP

IRAP assessments, explained.

The Infosec Registered Assessors Program is ASD's roster of endorsed assessors who test a system against the ISM at SECRET and below. An assessment produces a report and a controls matrix for the officer who decides whether the system may operate. It certifies nothing, and ASD says so in writing. This page covers who needs one, the four stages, what you get, and what you are allowed to say afterwards.

The four stagesThe ISM, explained

Who needs one

Cloud, outsourced ICT and gateway systems that hold government data.

The trigger is the Protective Security Policy Framework. Its Table 21 lists the security assessments technology systems need, and for cloud, ICT outsourced service providers and gateway systems up to SECRET the assessor has to be an ASD-endorsed IRAP assessor. A government entity procuring your service inherits that rule and passes it to you.

The Hosting Certification Framework sits beside IRAP, not inside it. Run by Home Affairs, it certifies hosting providers for sensitive government data and PROTECTED systems at two levels, Certified Strategic and Certified Assured. A vendor selling hosted services to government often needs both: an IRAP assessment of the system and a certified host underneath it.

One thing to stop saying: “ASD certified cloud”. The Cloud Services Certification Program that produced that phrase ended on 2 March 2020. What exists now is an IRAP assessment report that a customer's authorising officer reads and decides on.

What IRAP assessors assess

SECRET and below, in ASD's words

  • ICT systems
  • Cloud services
  • Gateways
  • GovLink

Beside it

Hosting Certification Framework (Home Affairs): Certified Strategic, Certified Assured, or Uncertified. Applies to hosting for sensitive government data, whole-of-government systems and PROTECTED systems.

Four stages

Plan, define the boundary, assess, report.

ASD's IRAP Common Assessment Framework (April 2025) sets four stages that apply to any environment: a cloud service, a gateway or an on-premise system. Assessor websites often describe a two-stage design-then-implementation model. That is their shorthand, not ASD's process.

01

Plan and prepare

The assessor and system owner settle what will be tested, at which classification, with what access to environments, people and documents, and how evidence will be handled.

Output

Engagement scope and access agreed

02

Define the assessment boundary

What is in and what is out, written down. Shared responsibility with cloud providers and inherited controls are settled here, because they decide which ISM controls are yours to evidence.

Output

Boundary definition

03

Assess the controls

Each in-scope control for the classification is tested. The assessor records whether it is implemented and effective, with evidence, and where it is not, what the gap is.

Output

Findings per ISM control

04

Produce the IRAP assessment report

The two documents ASD requires at minimum. They go to the authorising officer of the organisation that will rely on the system, who decides whether to authorise it, with or without conditions.

Output

Assessment report and security controls matrix

What you get

A report, a controls matrix, and a decision that is not yours to announce.

ASD is unusually direct about this. Its program page says IRAP assessors do not accredit, certify, endorse or register systems on behalf of ASD, that an assessment will generally not cover every ISM control, and that a completed assessment does not by itself mean the system is compliant with the tested controls. The policy goes further: publishing statements that refer to IRAP or ASD accreditation, certification or endorsement is a misrepresentation.

You may say

“<Organisation> has completed an IRAP assessment for <System> against the Information Security Manual's <Classification> level controls.”

The form of words ASD's IRAP policy approves. Fill the brackets and stop there.

You may not say

  • IRAP certified
  • ASD accredited
  • ASD endorsed system
  • IRAP compliant
  • ASD certified cloud

IRAP policy and procedures v2.0 (June 2026), section 6.2.6: ASD does not accredit, certify, endorse or register any system under IRAP.

The two documents

At minimum, an IRAP assessment report and a security controls matrix. The report describes the boundary, the approach, the findings and the recommended remediation. The matrix is the control-by-control record: which ISM controls were in scope for the classification, and how each fared.

The decision

The report goes to the authorising officer of the organisation that will use the system, the CISO or their delegate. They accept the residual risk and authorise the system to operate, attach conditions, or decline. The assessor does not make that call, and neither does the vendor.

Assessors

Who can run one.

IRAP assessors are individuals, not firms. ASD endorses each one against the eligibility rules in the IRAP policy, lists them publicly, and reviews their membership every two years. A consultancy “doing IRAP” is a consultancy that employs endorsed people.

The badge gets you a competent assessor. It does not get you a useful report. Scope does. Choose an assessor who has assessed your kind of system before, and agree the boundary in writing before stage three starts, because the boundary decides which controls are yours and which are your cloud provider's.

ASD's public list of IRAP assessors

Eligibility

To be endorsed by ASD

  • 01Australian citizen
  • 02One Category A qualification: CISSP, CISM or GSLC
  • 03One Category B qualification: CISA, PCI QSA or CRISC
  • 04At least five years in information security roles using the ISM and the PSPF
  • 05Passed the IRAP training course and assessment
  • 06An active NV1 or higher security clearance
  • 07Membership renewed on a rolling 24-month cycle

IRAP policy and procedures v2.0 (June 2026), section 2.1.

What the assessor reads

The authorisation package the ISM expects.

An IRAP assessment tests controls, but the assessor starts from documents. The ISM's risk management framework names the set that goes to the authorising officer. Arriving with these already written, and current, is most of the difference between a short engagement and a long one.

System security plan

The system, its boundary, criticality and objectives.

System security plan annex

Every selected control, its planned and actual implementation.

Cyber security incident response plan

How incidents are detected, reported and handled.

Change and configuration management plan

How changes are approved and baselines kept.

Continuous monitoring plan

What is watched, how, and what triggers reassessment.

Security assessment report

The assessor's findings; for IRAP, the report and controls matrix.

Plan of action and milestones

Each open finding, its owner and its date.

The SSP and its annex, generated from the record

In Alvor

Arrive with the record the assessor wants to read.

An IRAP assessor tests a system against the ISM. Alvor is where that system's record lives before, during and after the test, so the assessor reads a current picture rather than a folder assembled the month before.

Controls with owners and dated evidence

The assessor's matrix is a list of ISM controls and how each fared. Alvor holds the same list, built in the framework builder in ASD's structure, with an owner and evidence on every control and a status nobody can set by hand. What the assessor tests is what the record already shows.

Compliance

The SSP generated from the record

The system security plan and its control annex are produced from the assets, controls and risks already on file, so the document the assessor opens first is current on the day they open it rather than the day someone last had time.

System security plan

Residual risk with a recorded acceptance

Exceptions and open findings live in the risk register with an owner, a treatment and an acceptance recorded by name. The authorising officer sees decisions, which is what they are being asked to make one more of.

Risk Management

SSP as a Service for the package

Where the documents do not exist yet, Alvor Advisory writes the authorisation package from the record: boundary scoping, gap assessment against the ISM control annex, the SSP and POA&M. Assessor-ready and then it stops; the assessment itself always belongs to an independent assessor.

SSP as a Service
SOCI readinessThe Essential EightAlvor for Australian organisations

Questions

Common questions about IRAP

No. ASD's IRAP policy says ASD does not accredit, certify, endorse or register any system under IRAP, and that publishing statements referring to IRAP or ASD certification is a misrepresentation. An IRAP assessment produces a report and a controls matrix; the decision to authorise a system belongs to the authorising officer of the organisation that relies on it.

Get started

See how Alvor works for your role

Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.

Request DemoView Pricing
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • Secure by Design
  • Asset Management
  • Risk Management
  • Compliance
  • Policy
  • Security Management
  • Third-Party Risk Management
  • Business Continuity

Capabilities

  • Security Architecture
  • Security Design Review
  • Threat Modeling
  • Dependency Mapping
  • Data Governance
  • Components & SBOM
  • System Security Plan
  • Deployment models

Solutions

  • All solutions
  • CISO
  • Security architect
  • GRC lead
  • Engineering leader
  • Startups
  • Mid-Market
  • Enterprise
  • Regulated & Sovereign
  • Australia

Frameworks

  • ISO 27001
  • SOC 2
  • NIST CSF
  • HIPAA
  • GDPR
  • ISM
  • IRAP
  • Essential Eight
  • ASD Essentials
  • SABSA
  • PCI DSS
  • CMMC
  • FedRAMP
  • Control alignment

Advisory

  • Advisory overview
  • Assess
  • Architect
  • Build
  • Operate
  • All engagements

Company

  • About
  • Blog
  • Security
  • Pricing
  • Compare Alvor

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

PrivacyTermsCookie PolicyDisclosure