IRAP Compliance

Prepare for IRAP: Your Readiness Assessment Checklist

Tech Blaze Consulting | July 2026 | 7 min read

Failing an IRAP assessment drains your time, budget, and market momentum. To avoid delays, organizations must identify gaps and finalize documentation before the formal engagement starts. The Information Security Registered Assessors Program (IRAP) evaluates systems against the ISM. You need a complete System Security Plan (SSP) and Statement of Applicability (SoA) to begin. Technical evidence must validate your claims. This checklist defines the mandatory prerequisites to survive the audit.

Understanding the IRAP Assessment Process

An IRAP assessment validates your security posture across two distinct phases. Stage 1 focuses strictly on scoping and documentation review to confirm baseline readiness. Stage 2 requires live technical validation and evidence collection. The final output is a Security Assessment Report (SAR) detailing identified risks, which the Authorising Officer uses for accreditation.

Key Domains Covered by IRAP

Assessors probe your infrastructure across multiple domains to verify defense-in-depth architecture. Weaknesses in foundational areas like documentation or governance will trigger a cascade of severe findings. For example, a missing incident response playbook guarantees a finding, even if your technical controls are robust.

Domain Primary Focus
Documentation System Security Plan (SSP), Statement of Applicability (SoA), Security Risk Management Plan (SRMP)
Technical Controls Essential Eight maturity, network segmentation, centralized logging, encryption
Governance Security roles, change management, incident response
Physical Security Access controls, environmental monitoring, secure facilities

Pre-Assessment Steps and Documentation Review

Complete documentation is the fundamental prerequisite for initiating an assessment. Assessors require an accurate SSP, SoA, and SRMP to understand the system architecture and target classification. Missing documentation halts the assessment process immediately.

  • Confirm system boundary and external interconnections.
  • Assign key roles: CISO, System Owner, and Authorising Officer.
  • Identify target security classification (e.g., PROTECTED).
  • Collect existing architectural diagrams and operational procedures.
  • Schedule a configuration freeze prior to the formal assessment.

Technical Controls and Evidence Collection

Written policies must be substantiated by technical evidence. Assessors require configuration exports, log excerpts, and live demonstrations to validate control efficacy. Configuration drift between documentation and the live system is the most frequent source of findings. Review the Information Security Manual (ISM) to ensure technical implementations align with ASD expectations.

  • Implement and tune application control rulesets.
  • Validate patching timeframes against Essential Eight requirements.
  • Enforce multi-factor authentication for all privileged and remote access.
  • Configure centralized logging with 18-month retention and alerting.
  • Deploy ASD Approved Cryptographic Algorithms (AACA) for data at rest and in transit.

Identifying and Addressing Common IRAP Readiness Gaps

Undefined system boundaries and untested incident response plans routinely derail assessments. Organizations often claim compliance without the necessary log retention or multi-factor authentication enforcement. Identifying these gaps through a formal readiness review allows teams to implement remediation strategies before the assessor arrives. Ensure your environment also aligns with the Essential Eight maturity model.

Partnering with an IRAP Assessor for Success

Engaging an experienced consultancy streamlines the accreditation pathway. A preliminary IRAP readiness assessment provides actionable remediation steps tailored to your infrastructure. This proactive approach minimizes formal assessment findings and accelerates time-to-market. For primary guidance on assessor endorsement, consult the ACSC IRAP framework.

Frequently Asked Questions

Do we need to be fully compliant before engaging an assessor?

No, complete compliance is rarely achieved. Assessors expect to find residual risks. Your goal in readiness is to document those known risks accurately and implement compensating controls, preventing surprises during the formal audit.

Can we reuse ISO 27001 or SOC 2 evidence for IRAP?

While existing compliance artifacts are useful baselines, IRAP requires mapping specifically to ISM controls. You must translate and adapt your existing evidence to meet the specific technical rigor demanded by the Australian Cyber Security Centre (ACSC).

Who acts as the Authorising Officer (AO)?

The AO is a senior executive within the government agency consuming your service. They hold the ultimate authority to accept the residual risks outlined in the Security Assessment Report (SAR) and grant Authority to Operate (ATO).

Secure Your Next Accreditation

Validate your security posture before your formal engagement begins. Speak with our endorsed assessors today.

Contact Us