IRAP & ISM: Meeting Australian Government Cyber Security Standards

This guide explains who needs IRAP, how the assessment process works, and best practices for government & defence suppliers to ensure compliance. Includes the latest requirements, step-by-step process, and expert tips for IRAP readiness.

Consultants discussing IRAP and ISM requirements to meet Australian Government cyber security standards.

Executive Summary

For any company aiming to work with the Australian Government or defence sector, cyber security compliance is a non-negotiable requirement. Two key acronyms dominate this landscape: IRAP (Infosec Registered Assessors Program) and ISM (Information Security Manual). Together, IRAP and the ISM set the standard for protecting government systems and data, and they provide a framework to assess whether an organisation’s security measures are up to scratch2. 

In this knowledge guide, we break down what IRAP and the ISM are, how they interrelate, and what government and defence suppliers need to do to meet these standards. We target two main audiences: business leaders (who need to understand why IRAP compliance matters for contracts and risk management) and IT/security managers (who must implement controls and navigate the IRAP assessment). Below, we highlight the key takeaways for each group: 

For Business Leaders & Compliance Officers at Government Suppliers 

Competitive & Risk Imperative: Achieving IRAP compliance demonstrates your organisation meets Australian government cyber standards, which is often mandatory for contracts. It strengthens credibility and trust, showing you handle sensitive data responsibly. By investing in IRAP, you reduce risk of breaches and gain a competitive advantage when bidding on government projects. 

For IT & Security Teams at Government Suppliers 

Framework & Implementation Guide: Use the ASD Information Security Manual (ISM) as your blueprint for security controls. IRAP assessors will evaluate your system against the latest ISM controls. Focus on closing gaps in these controls (e.g., patch management, access controls, monitoring) and prepare strong documentation. Proactively addressing ISM requirements will streamline the IRAP assessment and help you achieve compliance efficiently. 

Cyber risk on the leadership agenda?

This Executive Cyber Brief is designed as a practical pre-read for MDs, GMs and Ops leaders before the next leadership meeting.

Executive Cyber Risk Brief

What is IRAP?

IRAP stands for Infosec Registered Assessors Program. It is an Australian Government initiative, governed by the Australian Cyber Security Centre (ACSC, part of ASD), that endorses qualified cyber security professionals (IRAP assessors) to conduct independent security assessments of ICT systems. In simpler terms, IRAP provides a structured process for having an external expert review your organisation’s security and ensure it meets the government’s standards. 

IRAP’s primary goal is to protect government data by assessing whether appropriate security controls are in place in systems that handle such dataEndorsed IRAP assessors come from the private or public sector and are certified by ASD to evaluate systems, suggest mitigations, and highlight residual risks. They check your security against official Australian Government policies and guidelines, especially the Information Security Manual (ISM). 

Key points about IRAP: 

  • Not a “certification” in itself: Importantly, an IRAP assessor does not directly certify or accredit your system. Instead, the assessor produces a report on your security controls, which is then used by a government authority (the “authorising officer”) to decide if your system can be approved (authorised) to handle government information. Think of IRAP as an independent audit – it provides assurance and identifies gaps, but the final sign-off lies with the government agency consuming your service. 
  • Scope of IRAP: IRAP assessments are typically required for systems that will store or process Australian Government data, such as cloud services offered to agencies, outsourced IT solutions, or vendor platforms that manage sensitive information. The IRAP program originally emerged to support cloud security (replacing older certification schemes in 2020), but it now applies to a broad range of technology including on-premises systems (especially at higher classifications). 
  • Outcome of IRAP: After an IRAP assessment, you receive a Security Assessment Report (SAR) and a Controls Matrix. The SAR summarises the system’s security posture, listing strengths and weaknesses found, while the controls matrix details the implementation status of each applicable ISM control (with justifications). These documents are intended for both executive decision-makers and technical teams to understand exactly where the system stands against the requirements16. 

What is the ASD Information Security Manual (ISM)?

The Information Security Manual (ISM) is the Australian Government’s official cyber security framework – essentially a comprehensive set of guidelines and controls to protect information systems from threats. Published (and regularly updated) by the Australian Signals Directorate (ASD), the ISM covers all aspects of securing government systems, from governance and personnel security to technical controls like encryption, access management, and network security. 

Key features of the ISM include: 

  • Scope & Purpose: The ISM is designed for Government agencies (and any organisations handling government data) to apply a risk-based approach to cyber security. It complements the Protective Security Policy Framework (PSPF), which sets out overarching security obligations for Australian Government entities (covering areas like physical and personnel security). Essentially, the ISM provides the detailed technical cyber controls guidance that agencies (and their contractors) should implement to meet the PSPF’s requirements. 
  • Structure: The ISM is structured around cyber security principles and detailed control guidelines. It outlines roles (e.g., what a CISO should do), broad principles (like defence-in-depth, least privilege), and then a large number of specific security controls and mitigation strategies. Controls are organised by categories such as governance, physical, personnel, system hardening, network management, incident response, etc. Each control is typically worded as a recommendation or requirement (e.g., “Ensure multi-factor authentication is implemented for all remote access”). 
  • Continuous Updates: The ISM is not static – it is updated regularly (often multiple times per year) to reflect emerging threats and new best practices. For example, encryption standards or patching guidelines are revised as technology evolves. IRAP assessments always use the latest version of the ISM at the start of the engagement, meaning organisations targeting IRAP compliance need to keep up with these updates to ensure their controls remain current. 

In short, if IRAP is the test, the ISM is the syllabus. The ISM tells you what security measures you should have; IRAP then validates whether you have them in place effectively.

Who Needs IRAP Compliance (and Why)?

Do all organisations need IRAP? No – IRAP is specifically relevant to Australian Government agencies and any businesses that handle government or classified data. If your organisation is a government agency or department building a new system, you’ll likely follow ISM controls and may opt for an IRAP assessment (especially at higher classifications). If you are a private or commercial provider offering services to government (such as a cloud service, SaaS platform, MSP, or defence contractor), you will often need a current IRAP assessment to win or maintain contracts. 

Government Policy Requirements: The Protective Security Policy Framework (PSPF) explicitly requires that certain systems and services be IRAP assessed before use: 

  • Outsourced IT & Cloud Services: All cloud or externally provided services that will store or process government information classified as OFFICIAL, OFFICIAL: Sensitive, or PROTECTED must undergo an IRAP assessment. This ensures government data is not hosted on a third-party system without an independent security check. 
  • Higher Classifications: For systems handling SECRET data, on-premise government systems can be assessed either by an internal (entity) assessor or an IRAP assessor, but if it’s a SECRET cloud or outsourced system, an IRAP assessor is mandatory. At the TOP SECRET level, assessments are handled by ASD itself rather than IRAP. Simply put, the more sensitive the data, the more formal the assessment required. 

Benefits of IRAP for Suppliers: Even beyond compliance mandates, undergoing IRAP assessment has advantages for companies: 

  • It validates your security posture against a respected government standard, which can reassure clients in other industries too (not just government). 
  • It often leads to improved internal security by identifying gaps to fix – essentially serving as a high-quality audit of your cyber defences. 
  • It’s frequently seen as a badge of credibility in the Australian market, signalling your organisation meets rigorous security benchmarks (which can set you apart from competitors). 
  • For cloud providers, a valid IRAP assessment (updated ideally within the last 24 months per government guidance) is usually necessary to onboard government customers. 

In summary, if you intend to handle Australian Government data (especially sensitive or classified information), IRAP compliance will almost certainly be required. Ensuring your system meets the ISM’s controls and passing an IRAP assessment is both a contractual necessity and a valuable investment in security quality.

The IRAP Assessment Process (Step-by-Step)

Under IRAP, an independent assessor methodically evaluates your system’s security controls. Although every assessment is tailored to the system’s complexity and context, the process follows four standard stages: 

  • Stage 1: Plan & Prepare

    The organisation and the IRAP assessor start with thorough planning. This includes defining objectives, assembling the assessment team, gathering preliminary information, and agreeing on logistics. The assessor formally notifies ASD’s IRAP administrators about the engagement (including signing a conflict-of-interest declaration). The organisation should ensure key security documentation is ready (e.g. system security plan, risk assessment, architecture diagrams, incident response plan) to support the upcoming review.

  • Stage 2: Define the Scope & Boundary

    The assessor works with the organisation to clearly define the assessment boundary – i.e., which system components, networks, and data are in-scope. This step ensures everyone agrees on what will be evaluated and that no critical parts are overlooked. If the system involves multiple layers (e.g., cloud infrastructure plus an application layer), the assessor may organise the assessment in layers but with a well-defined overall boundary. Any parts not being assessed are documented and justified here.

  • Stage 3: Assess the Controls (against the ISM)

    This is the core of IRAP. The assessor evaluates the implementation and effectiveness of ISM controls in the system. They typically review documentation, interview personnel (e.g. admins, developers), inspect configurations, and may perform technical testing or sampling to verify controls. Both design (are policies/controls in place on paper?) and operational effectiveness (are they working in practice?) are checked. The assessor gathers evidence for each relevant ISM control to determine if it’s Implemented Effectively, Partially, or Not Implemented, etc. Any security weaknesses or deviations from ISM requirements are identified and discussed with the organisation.

  • Stage 4: Report & Recommendations

    After assessment, the IRAP assessor compiles findings into an IRAP Security Assessment Report (SAR) and an accompanying Controls Matrix. The SAR summarises the system’s security posture, listing strengths, weaknesses, and any gaps or residual risks, without issuing a pass/fail judgement. The Controls Matrix provides a detailed, control-by-control breakdown of compliance with the ISM. With these deliverables, the organisation gets a clear roadmap of where to improve. The final step is for the Government agency’s authorising officer to review the IRAP report and decide whether to grant the system an Authority to Operate (ATO) based on the remaining risks. Each agency makes its own determination using the IRAP results, so sometimes further mitigation might be required before full approval.

How long does an IRAP assessment take? It varies widely with system size and complexity. A small, well-documented system might be assessed in a few weeks, whereas a large, complex cloud service can take several months from planning to final report. Engaging early and preparing thoroughly (Stage 1) helps the process go smoothly. 

After the IRAP: If any controls were found lacking, your team should address those findings (e.g., apply missing patches, tighten configurations) and update the documentation. You might then share the IRAP report with multiple government clients (the report is typically valid for any agencies who want to rely on it, usually up to 24 months old is accepted). Regular re-assessment every 1–2 years is wise, since the ISM updates and threat landscape shift over time. 

Preparing for IRAP: Practical Guidance for Suppliers

  • Undergoing an IRAP assessment can seem daunting, but with the right preparation you can set yourself up for success. Here are some practical tips for government and defence suppliers aiming to meet IRAP requirements: 
    • Align Early with the ISM: Use the ISM controls as a checklist from day one of system design or project planning. Ensure your system’s architecture and policies are built around ISM expectations for your target data classification (e.g., if aiming to handle PROTECTED data, implement all controls tagged as PROTECTED in the ISM). 
    • Conduct a Pre-Assessment (Gap Analysis): Before bringing in an IRAP assessor, perform an internal audit or hire a consultant to assess your system against the ISM. Identify which controls are not yet fully implemented or effective. This early gap analysis will highlight areas to fix (e.g., missing encryption on certain data, incomplete logging, inadequate network monitoring) so you can remediate the easy issues ahead of time. 
    • Develop Comprehensive Documentation: Up-to-date documentation is crucial! Government standards expect extensive security documentation, and the IRAP assessor will need to review it. This includes a System Security Plan (describing the system and its controls), Risk Management Plan, network diagrams, standard operating procedures, incident response plans, user access policies, etc. Having these approved and ready speeds up the assessment and demonstrates a mature security posture. 
    • Engage the Right IRAP Assessor: ASD provides a list of certified IRAP assessors. When selecting one, ensure they have experience relevant to your industry or technology (e.g., someone with cloud expertise for a cloud service). Clarify timelines, costs, and what support they will need from your team. Also, be mindful of conflict of interest rules – an assessor cannot have helped design or build your system, and they must remain independent. 
    • Involve Your Team & Allocate Resources: An IRAP assessment is a collaborative effort. Assign a project manager or coordinator on your side to liaise with the assessor, schedule meetings with subject matter experts, and track evidence requests. Ensure technical staff are available to demonstrate systems and answer questions. Prepare for some productivity impact during the assessment period (answering assessor queries, gathering logs, etc.), and factor that into planning. 
    • Be Ready to Demonstrate Controls: The assessor may not just take documents at face value; they could ask to observe configurations or run tests (within agreed scope). Be prepared with test environments or safe ways to show configurations if needed. For example, if you claim all admin access requires multi-factor authentication, have a way to prove it (screenshots or a live demo). 
    • Focus on Remediation & Continuous Improvement: If the assessor finds issues, treat these findings constructively. It’s common to have some “partial” or “not implemented” controls identified. Work on a plan of action for each gap. You can often fix minor gaps even before the final report is issued if discovered early. Ultimately, use IRAP as a learning process to elevate your security maturity long-term. 

    By taking these steps, you transform IRAP from a box-ticking exercise to a strategic security upgrade for your organisation. Not only will you meet the compliance bar, but you’ll also be tangibly harder to hack – a win-win outcome. 

Additional Cyber Security Resources

Protecting Australian Businesses from Evolving Digital Threats

At KMTech, we understand the unique cybersecurity challenges facing Australian organisations. Our expert team delivers proactive, scalable solutions to safeguard your data, infrastructure, and reputation so you can focus on growth with confidence.

Conclusion & Next Steps

The IRAP and ISM together provide a robust framework to ensure that any system entrusted with government data has strong cyber security controls in place. For government suppliers and defence contractors, understanding this framework isn’t just about meeting a mandate – it’s about building trust with your most important clients and protecting sensitive information against cyber threats. 

By implementing the ASD’s Information Security Manual controls, and validating them through an IRAP assessment, your organisation demonstrates it can meet the high security standards expected in the Australian public sector. This positions you favorably for contracts and reduces the risk of security incidents. 

Remember that IRAP is an ongoing journey rather than a one-off checkbox. As threats evolve and the ISM updates, continuous vigilance is needed to maintain compliance. It pays to integrate ISM-aligned security practices into your organisation’s DNA, so that preparing for re-assessments or new projects becomes business-as-usual. 

If you’re navigating IRAP compliance or preparing for an upcoming assessment, consider reaching out for expert guidance. Contact us for a compliance readiness assessment or support – with the right preparation and partner, meeting Australian Government cyber security standards can be a smooth and rewarding process. 

Frequently Asked Questions

What is IRAP in Australian cyber security?

IRAP stands for Infosec Registered Assessors Program. It’s an Australian Government initiative where certified independent assessors review an organisation’s security controls to ensure they meet government standards, especially the ASD Information Security Manual. An IRAP assessment results in a detailed report on your system’s security, used by government authorities to decide if your system can handle sensitive government data.

What is the ASD Information Security Manual (ISM)?

The Information Security Manual (ISM) is a comprehensive set of cyber security guidelines and controls issued by the Australian Signals Directorate. It outlines what organisations, especially government agencies and contractors, should do to protect IT systems and data from cyber threats, covering everything from governance and personnel security to technical controls. The ISM is updated regularly to stay current with evolving threats.

Who needs an IRAP assessment?

IRAP assessments are typically required for any organisation handling Australian Government data on external or cloud systems. Government policy mandates IRAP for outsourced IT and cloud services at OFFICIAL, Sensitive, PROTECTED and higher classifications. So if you’re a vendor to government or defence, such as a cloud provider or software or service supplier dealing with sensitive data, you will likely need IRAP compliance. Some government agencies also use IRAP for their own high-risk systems.

What are the steps in an IRAP assessment?

RAP assessments follow four main stages: (1) Planning & Preparation – the assessor and organisation agree on scope and gather information; (2) Definition of Scope and Boundary – deciding exactly which system components and data to assess; (3) Control Assessment – the assessor evaluates the system against ISM security controls through document reviews, interviews and technical testing; and (4) Reporting – the assessor provides a Security Assessment Report and Controls Matrix detailing findings. Then a government authorising officer reviews these results to determine if the system is approved for use.

Is IRAP a certification or accreditation?

Not exactly – IRAP by itself is an assessment, not a formal certification. The IRAP assessor does not “pass” or “fail” your system. Instead, they report on how well you meet the ISM controls and highlight any risks. The actual decision to authorise a system to handle government data is made by the relevant government agency, based on the IRAP report’s findings. In other words, IRAP is an important step towards approval, but the final accreditation comes from the government client.

Related Stories

IT professional working in a security operations environment, representing the transition and ongoing evolution of the ACSC Essential Eight framework.

The Essential Eight Is Evolving, Not Disappearing

Around mid-2028: full retirement. The Essential Eight is expected to be retired as a whole at roughly the 24-month mark, with the cloud and operational technology chapters landing before then.

Person seated at a desk facing a large screen during a video conference, with text overlay reading “AI Compliance Frameworks.”

AI Compliance Frameworks

AI adoption is accelerating across Australian businesses, but so is regulatory scrutiny. From ethical use and data integrity to accountability and transparency, organisations can no longer afford a “move fast and hope for the best” approach to artificial intelligence.

The Evolution of Web Filtering | Modern Cyber Security Solutions

The Evolution of Web Filtering & Shadow AI Governance

This article explores how web filtering has changed, why older DNS‑based models are no longer sufficient, and what modern organisations need to control web, cloud, and AI‑driven risk effectively.

Want to be part of the crowd?

html