Program · IRAP
The Infosec Registered Assessors Program is ASD's roster of endorsed assessors who test a system against the ISM at SECRET and below. An assessment produces a report and a controls matrix for the officer who decides whether the system may operate. It certifies nothing, and ASD says so in writing. This page covers who needs one, the four stages, what you get, and what you are allowed to say afterwards.
Who needs one
The trigger is the Protective Security Policy Framework. Its Table 21 lists the security assessments technology systems need, and for cloud, ICT outsourced service providers and gateway systems up to SECRET the assessor has to be an ASD-endorsed IRAP assessor. A government entity procuring your service inherits that rule and passes it to you.
The Hosting Certification Framework sits beside IRAP, not inside it. Run by Home Affairs, it certifies hosting providers for sensitive government data and PROTECTED systems at two levels, Certified Strategic and Certified Assured. A vendor selling hosted services to government often needs both: an IRAP assessment of the system and a certified host underneath it.
One thing to stop saying: “ASD certified cloud”. The Cloud Services Certification Program that produced that phrase ended on 2 March 2020. What exists now is an IRAP assessment report that a customer's authorising officer reads and decides on.
What IRAP assessors assess
SECRET and below, in ASD's words
Beside it
Hosting Certification Framework (Home Affairs): Certified Strategic, Certified Assured, or Uncertified. Applies to hosting for sensitive government data, whole-of-government systems and PROTECTED systems.
Four stages
ASD's IRAP Common Assessment Framework (April 2025) sets four stages that apply to any environment: a cloud service, a gateway or an on-premise system. Assessor websites often describe a two-stage design-then-implementation model. That is their shorthand, not ASD's process.
01
Plan and prepare
The assessor and system owner settle what will be tested, at which classification, with what access to environments, people and documents, and how evidence will be handled.
Output
Engagement scope and access agreed
02
Define the assessment boundary
What is in and what is out, written down. Shared responsibility with cloud providers and inherited controls are settled here, because they decide which ISM controls are yours to evidence.
Output
Boundary definition
03
Assess the controls
Each in-scope control for the classification is tested. The assessor records whether it is implemented and effective, with evidence, and where it is not, what the gap is.
Output
Findings per ISM control
04
Produce the IRAP assessment report
The two documents ASD requires at minimum. They go to the authorising officer of the organisation that will rely on the system, who decides whether to authorise it, with or without conditions.
Output
Assessment report and security controls matrix
What you get
ASD is unusually direct about this. Its program page says IRAP assessors do not accredit, certify, endorse or register systems on behalf of ASD, that an assessment will generally not cover every ISM control, and that a completed assessment does not by itself mean the system is compliant with the tested controls. The policy goes further: publishing statements that refer to IRAP or ASD accreditation, certification or endorsement is a misrepresentation.
You may say
“<Organisation> has completed an IRAP assessment for <System> against the Information Security Manual's <Classification> level controls.”
The form of words ASD's IRAP policy approves. Fill the brackets and stop there.
You may not say
IRAP policy and procedures v2.0 (June 2026), section 6.2.6: ASD does not accredit, certify, endorse or register any system under IRAP.
The two documents
At minimum, an IRAP assessment report and a security controls matrix. The report describes the boundary, the approach, the findings and the recommended remediation. The matrix is the control-by-control record: which ISM controls were in scope for the classification, and how each fared.
The decision
The report goes to the authorising officer of the organisation that will use the system, the CISO or their delegate. They accept the residual risk and authorise the system to operate, attach conditions, or decline. The assessor does not make that call, and neither does the vendor.
Assessors
IRAP assessors are individuals, not firms. ASD endorses each one against the eligibility rules in the IRAP policy, lists them publicly, and reviews their membership every two years. A consultancy “doing IRAP” is a consultancy that employs endorsed people.
The badge gets you a competent assessor. It does not get you a useful report. Scope does. Choose an assessor who has assessed your kind of system before, and agree the boundary in writing before stage three starts, because the boundary decides which controls are yours and which are your cloud provider's.
ASD's public list of IRAP assessorsEligibility
To be endorsed by ASD
IRAP policy and procedures v2.0 (June 2026), section 2.1.
What the assessor reads
An IRAP assessment tests controls, but the assessor starts from documents. The ISM's risk management framework names the set that goes to the authorising officer. Arriving with these already written, and current, is most of the difference between a short engagement and a long one.
System security plan
The system, its boundary, criticality and objectives.
System security plan annex
Every selected control, its planned and actual implementation.
Cyber security incident response plan
How incidents are detected, reported and handled.
Change and configuration management plan
How changes are approved and baselines kept.
Continuous monitoring plan
What is watched, how, and what triggers reassessment.
Security assessment report
The assessor's findings; for IRAP, the report and controls matrix.
Plan of action and milestones
Each open finding, its owner and its date.
In Alvor
An IRAP assessor tests a system against the ISM. Alvor is where that system's record lives before, during and after the test, so the assessor reads a current picture rather than a folder assembled the month before.
Controls with owners and dated evidence
The assessor's matrix is a list of ISM controls and how each fared. Alvor holds the same list, built in the framework builder in ASD's structure, with an owner and evidence on every control and a status nobody can set by hand. What the assessor tests is what the record already shows.
ComplianceThe SSP generated from the record
The system security plan and its control annex are produced from the assets, controls and risks already on file, so the document the assessor opens first is current on the day they open it rather than the day someone last had time.
System security planResidual risk with a recorded acceptance
Exceptions and open findings live in the risk register with an owner, a treatment and an acceptance recorded by name. The authorising officer sees decisions, which is what they are being asked to make one more of.
Risk ManagementSSP as a Service for the package
Where the documents do not exist yet, Alvor Advisory writes the authorisation package from the record: boundary scoping, gap assessment against the ISM control annex, the SSP and POA&M. Assessor-ready and then it stops; the assessment itself always belongs to an independent assessor.
SSP as a ServiceQuestions
No. ASD's IRAP policy says ASD does not accredit, certify, endorse or register any system under IRAP, and that publishing statements referring to IRAP or ASD certification is a misrepresentation. An IRAP assessment produces a report and a controls matrix; the decision to authorise a system belongs to the authorising officer of the organisation that relies on it.
Get started
Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.