IRAP: Australian Government Security Assessment Guide
The Information Security Registered Assessors Program (IRAP) is the Australian Signals Directorate's framework for independently assessing ICT systems against Australian government security requirements. IRAP assessors evaluate whether systems meet the controls specified in the Australian Government Information Security Manual (ISM).
What IRAP Covers
IRAP assessments evaluate systems against the ISM, which contains hundreds of controls organized across governance, physical, personnel, and ICT security domains. The assessment determines whether a system is suitable for handling Australian government data at a specific classification level: OFFICIAL, OFFICIAL: Sensitive, PROTECTED, or above.
Key assessment areas include security governance and risk management, personnel security, physical security, communications security, ICT security (operating systems, databases, applications, networks), and gateway security for systems connecting to government networks.
Who Needs IRAP
IRAP assessment is required for any ICT system that processes, stores, or communicates Australian government data. This primarily affects cloud service providers, managed service providers, and technology companies seeking to serve Australian government agencies.
Major cloud providers (AWS, Azure, Google Cloud) have obtained IRAP assessments for their Australian regions. SaaS companies selling to Australian government agencies are increasingly expected to demonstrate IRAP assessment at the appropriate classification level.
The IRAP Assessment Process
- Scope definition — Determine the system boundary and target classification level
- Engage an IRAP assessor — Select an ASD-endorsed assessor from the published register
- Stage 1 assessment — Review of security documentation, policies, and architecture
- Remediation — Address gaps identified in Stage 1
- Stage 2 assessment — Technical testing and validation of control implementation
- Assessment report — Assessor produces a Security Assessment Report (SAR)
- ASD review — For cloud services, ASD reviews the report and may list the service on the Certified Cloud Services List (CCSL)
Cost Factors
Assessment costs depend heavily on the target classification level and system complexity. OFFICIAL-level assessments for straightforward systems may cost $50,000 to $100,000, while PROTECTED-level assessments for complex cloud platforms can exceed $300,000. The largest cost components are assessor fees, remediation of identified gaps, and the documentation effort required to produce compliant security documentation.
Relationship to Essential Eight
The Essential Eight maturity model is a subset of ISM controls that IRAP assessments frequently reference. Organizations targeting IRAP assessment should aim for Essential Eight Maturity Level 2 or 3 as a foundation before engaging an assessor.
The ISM Control Framework in Detail
The Australian Government Information Security Manual (ISM) is a living document updated monthly by the ASD. It contains hundreds of controls organized across a structured hierarchy of topics.
Security governance — Organizational security policies, roles and responsibilities, security risk management, and security documentation requirements. The ISM requires formal system security documentation including a System Security Plan and Risk Assessment Report.
Personnel security — Background checking, security clearances, privileged user management, and security training and awareness requirements. For PROTECTED-level systems, personnel accessing data typically require minimum NV1 security clearances.
Physical security — Physical access controls, secure rooms, data centre requirements, and equipment management. The physical security requirements for PROTECTED-level systems are substantial and often drive significant infrastructure investment.
ICT security — This is the largest section, covering operating systems, databases, applications, network security, cryptography, email security, web browser security, mobile device management, and virtualisation. ISM control compliance in this area is where most technical remediation effort concentrates.
Cyber security — Incident management, vulnerability management, and application security. The ISM aligns cyber security requirements with the Essential Eight, requiring documented maturity levels for each of the eight strategies.
Gateway security — Controls for systems that connect to government networks (GovLink, PROTECTED networks). Gateway requirements include specific approved products and configurations and are among the most technically demanding in the ISM.
Classification Levels and What They Mean
IRAP assessments target specific classification levels, and the control burden increases significantly at higher levels.
OFFICIAL — The baseline classification for most government information that is not sensitive. Most SaaS providers serving non-sensitive government functions aim for OFFICIAL level.
OFFICIAL: Sensitive — Information requiring careful management but not formal classification. This level covers most information that would benefit from protection, including financial, commercial-in-confidence, and personal information. Many government agency requirements fall at this level.
PROTECTED — The highest non-SECRET classification level available for commercial cloud providers. PROTECTED systems require significantly more controls, stricter physical security, personnel security clearance requirements, and ASD-approved gateways and products.
Classification levels are determined by the Protective Security Policy Framework (PSPF) administered by the Attorney-General's Department.
The IRAP Assessment Process in Detail
Stage 1 — Scope and engagement. Define the exact system boundary, target classification level, and assessment scope. Engage an ASD-endorsed IRAP assessor from the official list. IRAP assessors must be individually endorsed by ASD and maintain their endorsement through ongoing professional development.
Stage 2 — Documentation review. The assessor reviews your system security documentation: System Security Plan (SSP), Risk Assessment Report (RAR), Standard Operating Procedures, incident management plans, and evidence of control implementation. Documentation gaps at this stage add time and cost.
Stage 3 — Technical assessment. The assessor conducts technical testing proportionate to the target classification level. For PROTECTED, this includes network architecture review, vulnerability scanning, penetration testing, and review of cryptographic implementations.
Stage 4 — Assessment report. The assessor produces a Security Assessment Report (SAR) documenting findings and residual risks. The SAR does not grant authorization — it is an independent assessment that the authorizing organization uses to make a risk acceptance decision.
Stage 5 — ASD Cloud Services List (for cloud providers). Cloud service providers seeking government customers must be listed on the ASD Certified Cloud Services List (CCSL). ASD reviews the SAR and independently decides whether to list the service and at what classification level.
Stage 6 — Authority to Operate. The agency authorizing official reviews the SAR and decides whether to grant an Authority to Operate (ATO) for the specific system and purpose. ATOs are not transferable between agencies.
Costs and Timeline
| Component | Low Estimate | High Estimate |
|---|---|---|
| System security documentation (SSP, RAR) | $20,000 | $80,000 |
| Technical remediation | $20,000 | $150,000 |
| IRAP assessor fees | $30,000 | $100,000 |
| ASD review (cloud providers) | $0 | $50,000 |
| Ongoing maintenance | $15,000 | $50,000 |
| Total (OFFICIAL: Sensitive) | $85,000 | $430,000 |
Timeline: 3 to 12 months. PROTECTED-level assessments for complex cloud platforms often run 12 to 24 months including remediation.
How IRAP Compares to Related Frameworks
IRAP vs. Essential Eight — Essential Eight maturity requirements are embedded in ISM controls. Achieving Essential Eight Maturity Level 2 satisfies many ISM cyber security controls, making it a natural prerequisite for IRAP assessment. IRAP covers a much broader range of controls than the Essential Eight alone.
IRAP vs. ISO 27001 — About 70% overlap. ISO 27001-certified organizations have a strong documentation and management system foundation that IRAP assessors value. The ISM's specific technical controls and Australian government context require additional work beyond ISO 27001. Many government-focused cloud providers pursue both certifications.
IRAP vs. FedRAMP — Both are government cloud security authorization frameworks with overlapping technical requirements (both reference NIST-based controls). FedRAMP is the U.S. equivalent; IRAP is Australian. Organizations serving both markets maintain both authorizations, leveraging shared technical controls.
How Automation Helps
IRAP assessment documentation requirements — SSPs, RARs, evidence records for hundreds of ISM controls — are among the most documentation-intensive of any framework in this category. Continuous evidence collection and structured documentation tools materially reduce the assessment preparation effort.
LowerPlane supports Australian government frameworks including IRAP/ISM controls alongside its 50-plus framework library. At $4,000/year entry pricing with a free tier, it provides a structured way to manage ISM control evidence across the assessment cycle. AuditXYZ rates it 9.4/10. See Best Compliance Automation Platforms.
Frequently Asked Questions
What is an IRAP assessor and how do I find one? IRAP assessors are security professionals individually endorsed by the ASD to conduct ISM assessments. The ASD maintains a public list of endorsed IRAP assessors at their website. Assessors have varying specialisations (cloud, network, application) — select one with experience at your target classification level and system type.
Does an IRAP assessment automatically grant access to government networks? No. An IRAP assessment report is an independent evaluation of your security posture. Authorization to operate or connect to specific government networks requires separate decisions by the relevant agency's authorizing official or the Australian Cyber Security Centre (ACSC). The SAR is evidence used to support that decision.
How long is an IRAP assessment valid? Assessments are typically valid for two years, or until significant changes to the assessed system occur. Significant changes — new functionality, architectural changes, new cloud services — trigger reassessment requirements. ASD CCSL listings are updated when assessments expire or are withdrawn.
What is the difference between OFFICIAL and PROTECTED assessment requirements? OFFICIAL assessments focus primarily on baseline ISM controls, confidentiality of relatively insensitive information, and standard technical security measures. PROTECTED assessments require substantially more: stricter personnel security, approved products and configurations from ASD's Evaluated Products List, physical security measures, and ASD-approved gateway solutions. The cost and complexity gap between OFFICIAL and PROTECTED assessments is significant.