IRAP Assessment in Australia 2026: A Guide for Businesses Seeking Government Contracts
IRAP is the gateway to Australian government contracts. Learn the five-stage assessment process, costs, timelines, and how to choose the right cyber consultant.
For Australian businesses seeking to win government contracts, supply services to defence agencies, or operate within critical infrastructure sectors, the Infosec Registered Assessors Program (IRAP) has become a defining compliance milestone. Administered by the Australian Signals Directorate (ASD), IRAP provides an independent, evidence-based assessment of an organisation's ICT security posture against the Australian Government Information Security Manual (ISM). Understanding what IRAP involves — and how to prepare for it — is essential for any business operating in or entering the government supply chain in 2026.
What Is IRAP and Who Needs It?
IRAP stands for the Infosec Registered Assessors Program. It is the Australian Government's framework for independently evaluating the security of ICT systems that handle government information. An IRAP assessment is conducted by an ASD-endorsed assessor who reviews your systems, documentation, and controls against the requirements of the ISM.
IRAP is not a general compliance requirement for all Australian businesses. It becomes mandatory — or effectively mandatory — when your organisation seeks to provide ICT services to Commonwealth, state, or territory government agencies, or when you operate within sensitive supply chains such as defence, critical infrastructure, or intelligence-adjacent sectors.
A current IRAP assessment report is typically a prerequisite for obtaining an Authority to Operate (ATO) from a government agency — the formal approval that allows your system to process, store, or transmit government data. Without it, many government contracts are simply inaccessible, regardless of your technical capability or commercial track record.
The Five Stages of an IRAP Assessment
An IRAP assessment follows a structured lifecycle that typically spans 12 to 16 weeks for a well-prepared organisation. Businesses with lower security maturity may require six to nine months of preparation before the formal assessment can begin.
- Scoping — The assessor works with your team to define the system boundary, identify the classification level (OFFICIAL, PROTECTED, or SECRET), and determine which security controls are inherited from cloud providers or other platforms versus those your organisation must implement directly.
- Documentation Review — The assessor evaluates your System Security Plan (SSP), risk management framework, standard operating procedures, and incident response documentation. Poor or outdated documentation is the most common cause of assessment delays and failures.
- Technical Assessment — Hands-on validation of your security controls, including configuration reviews, vulnerability scanning, identity and access management verification, and network architecture analysis.
- Reporting — The assessor delivers a formal report detailing findings, your current risk posture, and specific remediation recommendations. This report is provided to both your organisation and the relevant government agency.
- Remediation — Your organisation addresses identified gaps and implements the recommended controls to reach the required security maturity level before the agency issues an Authority to Operate.
Key Considerations When Preparing for IRAP
Preparing for an IRAP assessment is a significant undertaking that requires coordination across your IT, security, legal, and operations teams. The following considerations are critical to a successful outcome.
- Essential Eight maturity as a foundation — Achieving ASD Essential Eight Maturity Level 2 or 3 is widely considered a practical prerequisite for a successful IRAP assessment. Organisations that have not implemented the Essential Eight will face significant remediation requirements before assessment can proceed.
- Assessor independence — IRAP assessors are prohibited from providing remediation consulting to the organisations they assess. This independence requirement means you cannot use the same firm for both gap remediation and formal assessment. Plan your engagement accordingly.
- Assessor selection from the ASD register — You must select your assessor from the official ASD public register of IRAP assessors. Verify that your chosen assessor has specific experience with your technology stack — cloud-native environments, on-premises infrastructure, and hybrid architectures each require different expertise.
- Documentation currency — Your System Security Plan and supporting documentation must accurately reflect your live environment at the time of assessment. Outdated or aspirational documentation that describes planned rather than implemented controls is a leading cause of assessment failure.
- Classification level clarity — The classification level of the data your system will handle (OFFICIAL, OFFICIAL: Sensitive, or PROTECTED) determines the depth and rigour of the assessment. Confirm the required classification with the government agency before scoping begins.
Common Mistakes Organisations Make
Many organisations underestimate the complexity of IRAP and approach it as a documentation exercise rather than a genuine security uplift program. This misunderstanding leads to predictable and costly mistakes.
- Starting too late — Organisations that begin IRAP preparation only after winning a government contract often find themselves unable to meet the agency's timeline. IRAP preparation should begin during the tender or proposal phase, not after contract execution.
- Conflating IRAP with ISO 27001 — While ISO 27001 certification demonstrates good security governance, it does not satisfy IRAP requirements. The ISM has specific technical controls that go beyond ISO 27001's scope, particularly around patching, application control, and multi-factor authentication.
- Underestimating remediation costs — Total program costs, including internal remediation, can range from AUD 100,000 to AUD 300,000 or more for complex systems. Assessor fees alone typically range from AUD 25,000 to AUD 80,000. Budgeting only for the assessment fee without accounting for remediation is a common and expensive oversight.
- Neglecting inherited controls — Many organisations assume that using a cloud provider (such as AWS, Azure, or Google Cloud) automatically satisfies security controls. In reality, the shared responsibility model means your organisation retains responsibility for a significant portion of controls, even in cloud environments.
- Failing to maintain the assessment — An IRAP assessment is not a one-time event. Government agencies typically require reassessment when significant changes are made to the system, and annual reviews of the security posture are expected. Treating IRAP as a checkbox rather than an ongoing program creates compliance gaps over time.
Australian Regulatory Context
IRAP operates within a broader Australian government cybersecurity framework anchored by the Australian Signals Directorate (ASD) and the Australian Cyber Security Centre (ACSC). The Australian Government Information Security Manual (ISM) is the primary technical standard against which IRAP assessments are conducted, and it is updated regularly to reflect the evolving threat landscape.
The Security of Critical Infrastructure Act 2018 (SOCI Act), as amended by the Security Legislation Amendment (Critical Infrastructure Protection) Act 2022, imposes additional cybersecurity obligations on operators of critical infrastructure assets across 11 sectors, including energy, water, communications, financial services, and data storage. Businesses in these sectors may face IRAP requirements as part of their Critical Infrastructure Risk Management Program (CIRMP) obligations.
The Cyber Security Act 2024 introduced mandatory ransomware payment reporting obligations for businesses with annual turnover exceeding AUD 3 million, further expanding the regulatory environment in which Australian businesses must operate. A qualified cyber consultant can help organisations navigate the intersection of IRAP, SOCI Act, and Cyber Security Act obligations.
The Digital Transformation Agency (DTA) oversees the Whole-of-Government ICT procurement framework, within which IRAP assessments play a central role for cloud and ICT service providers seeking to be listed on the Digital Marketplace or supply to government agencies.
Questions to Ask a Cyber Consultant About IRAP
Engaging the right cyber consultant is critical to a successful IRAP outcome. Before committing to an engagement, ask prospective consultants the following questions.
- Are you an ASD-endorsed IRAP assessor, or do you provide IRAP preparation and remediation services? (These are distinct roles — the same firm cannot do both for your organisation.)
- What is your experience with systems at the classification level we require (OFFICIAL, OFFICIAL: Sensitive, or PROTECTED)?
- Have you worked with our technology stack (cloud provider, on-premises, hybrid)?
- What is your typical timeline from initial engagement to a completed assessment report?
- How do you approach the System Security Plan — do you provide a template, or do you develop it from scratch based on our environment?
- What is your approach to maintaining compliance after the initial assessment?
- Can you provide references from organisations that have successfully obtained an Authority to Operate following your engagement?
How MyMoney® Can Help
Navigating IRAP — from initial gap analysis through to a successful Authority to Operate — requires a cyber consultant with deep expertise in the Australian Government Information Security Manual, the ASD Essential Eight, and the specific requirements of the government agency you are working with. Finding the right consultant is one of the most important decisions your organisation will make in this process.
MyMoney® connects Australian businesses with qualified cyber consultants who specialise in IRAP preparation, Essential Eight uplift, and government security compliance. Whether you are beginning your IRAP journey or seeking to maintain an existing assessment, our marketplace makes it straightforward to find and compare experienced professionals.
Post a Brief to outline your IRAP requirements and receive proposals from qualified cyber consultants, or Browse Cyber Consultants on the MyMoney® Marketplace to find the right expert for your government security compliance needs.
This article provides general information only and does not constitute personal financial advice. Consider whether the information is appropriate for individual circumstances before acting on it. MyMoney® Marketplace is operated by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640).