Independent IRAP Assessment Services

The Australian Signals Directorate (ASD) IRAP program serves two distinct purposes in the Australian Government security landscape:

For government agencies, independent IRAP assessments provide the cyber assurance evidence base needed to make informed risk decisions about the systems and services they own and operate.

For technology and service suppliers, an IRAP Security Assessment Report has become a practical prerequisite for government procurement – the document that demonstrates their cyber security posture to agencies seeking to consume those services.

In both cases, the quality of the assessment and the rigour of the resulting report determine its usefulness. An IRAP Security Assessment Report, conducted by an ASD-endorsed assessor against the Australian Government Information Security Manual (ISM), gives agencies and authorising officers the independent, structured evidence they need to make a well-informed risk decision, and gives suppliers documented proof of the security standards their systems and services have achieved.

Artefakt maintains a permanent team of ASD endorsed IRAP assessors conducting independent IRAP assessments across non-classified and OFFICIAL: Sensitive, PROTECTED and SECRET classified systems. Our assessors are career cyber security professionals, on average bringing more than 20 years of hands-on security expertise across:

  • cloud and hybrid environments

  • multi-tenant SaaS platforms

  • enterprise and shared services

  • systems supporting Commonwealth, State and regulated industry use cases

IRAP readiness and uplift*

Expert Guidance

Identify control gaps and build your evidence base before the assessment begins, with guidance from ASD-endorsed assessors.

Authorisation Package preparation

Decision Ready

Clear, structured authorisation packages that provide everything needed to support a confident ATO decision.

Independent IRAP Assessments

Depth and Experience

Senior ASD-endorsed assessors applying a proven methodology across systems of all complexity, from non-classified through to SECRET classification.

Ongoing IRAP maintenance

Preserve Value

Track ASD's quarterly ISM updates and keep your IRAP Security Assessment Report current as your system and its controls evolve.

* To preserve independence, some activities cannot be performed by the same assessor or organisation conducting an IRAP assessment.

Artefakt IRAP services streamline the assessment engagement and reporting process, delivering high quality artefacts that demonstrate your commitment to security, enhance your reputation, and establish confidence that Australian Government information is appropriately protected.

Artefakt is a registered supplier to Commonwealth and State Governments under various arrangements including the DTA DMP2 Professional and Consulting Services panel, and the ICT Services prequalification scheme SCM0020

Why organisations choose Artefakt for their IRAP assessments

Choosing an IRAP assessor is not simply a matter of choosing someone from the ASD assessors list. The depth of the assessor’s experience, the quality of their reporting, and their understanding of how systems authorisation and procurement in government actually works all have a direct bearing on the usefulness of the report you receive.

Here is what Artefakt brings to that decision:

Permanent team of senior assessors

Artefakt’s IRAP assessors are a permanent team of hand selected career cyber security professionals. That continuity matters: it means consistent methodology, consistent reporting quality, and assessors who are invested in the outcome of every engagement.

Structured methodology, aligned to objectives

Artefakt’s assessment engagements follow a defined, repeatable methodology: agreed scope, documented controls selection, and consistent findings criteria throughout. Within that framework, delivery is shaped around each client’s operating context, timeline, and internal constraints. Whether your priority is achieving an optimised report outcome, meeting a procurement deadline, or minimising disruption to your team during the engagement, the methodology accommodates it.

Quality Assured

Every IRAP deliverable produced by Artefakt is subject to a formal quality review by a second senior assessor before it reaches the client. That second pair of eyes is not a sign-off formality, rather it is a substantive review of findings, risk ratings, and recommendations by someone with equivalent seniority and experience. The result is a report you can present to an authorising officer with confidence in its accuracy and defensibility.

Reporting that works for every stakeholder

Artefakt’s assessors bring an average of more than 20 years of security experience to the reporting process. Findings are clearly evidenced, risk ratings are graded consistently and supported by specific control observations, and  recommendations are practical and prioritised. Reports are structured so that technical teams can act on them and executives can make informed risk decisions from them, giving the document genuine utility across the organisation from the day it is delivered.

Accelerate Your IRAP Readiness

Preparation is always the key to an optimal IRAP assessment and report. As part of our commitment to achieving the best possible outcome for every client, we have developed a simple, easy-to-use (and importantly, free) tool to help gauge your readiness.

Our IRAP Accelerator™ brings structure to the preparation phase – giving your team a clear, informed position from which to commence, and a basis for directing effort where it matters most.

Supplying to Australian Government?

Australian Government at all levels is responding to the global cyber threat climate with increased scrutiny of cyber in the supply chain. IRAP assessments have been a mandated prerequisite for consumption of Cloud, Gateway and Managed Services, and agencies are increasingly requesting IRAP reports to fulfil their supply chain cyber assurance obligations.

IRAP assessments are a formal requirement under the Australian Government’s Protective Security Policy Framework (PSPF) and are referenced in the Information Security Manual (ISM) as the mechanism for independent evaluation of system security controls. Cloud services, gateway services, and managed service providers seeking to supply to Commonwealth agencies are required to maintain an IRAP Security Assessment Report. Under the SOCI Act, operators of critical infrastructure assets also face increased scrutiny of supplier cyber security posture, making IRAP assessments a practical tool for demonstrating due diligence across supply chain relationships.

Showcase your cyber credibility, open new procurement opportunities, and give government agencies the independent assurance evidence they need to make confident risk decisions with an Artefakt IRAP Security Assessment Report.

Frequently Asked Questions

  • What is an IRAP Assessment?

    An IRAP (Infosec Registered Assessors Program) Assessment is an independent review conducted by an Australian Signals Directorate (ASD) endorsed assessor. It evaluates a system or service's security posture against the controls defined in the Australian Government Information Security Manual (ISM).

    The resulting IRAP Security Assessment Report provides a point-in-time view of security strengths and weaknesses, helping government agencies and regulated organisations make informed decisions about whether a product or service meets their cyber security requirements.

  • Who are IRAP Assessors?

    IRAP Assessors are individuals endorsed by the Australian Signals Directorate (ASD) to conduct independent security assessments under the Infosec Registered Assessors Program. To be endorsed, an assessor must:

    • Professional experience and certifications: hold relevant experience and certifications in information security and audit.
    • ASD training and examination: complete the ASD IRAP assessor training and examination.
    • Experience validation: have relevant professional experience independently validated.
    • Security clearance — hold a minimum NV1 security clearance.

    An endorsed IRAP assessor is authorised to assess systems and services up to SECRET classification.

  • What will an Artefakt IRAP assessor do during an assessment?

    Artefakt IRAP assessors are senior professionals who take ownership of the assessment process from start to finish. The engagement is structured across four phases:

    1. Plan and Prepare — Understand the system and the system owner's security requirements.

    2. Define the scope — Identify the assessment boundary and the applicable controls from the Information Security Manual (ISM).

    3. Assess the controls — Evaluate both the presence and effectiveness of selected controls.

    4. Produce the Security Assessment Report — Deliver a report that outlines the system's security strengths and weaknesses, the outcomes of the controls assessment, and recommendations for improving the system's security posture.

  • What value will I get from an IRAP Assessment?

    An IRAP Security Assessment Report is designed to be consumed by government agencies as part of their internal risk and procurement processes. It reduces the need for duplicative security assessments across multiple agencies, drives cost efficiencies, and provides government with the information needed to accelerate adoption of services.

    For suppliers, an IRAP report demonstrates security credibility, builds stakeholder confidence, and is increasingly required to access government cloud, gateway, and managed services procurement.

  • What should I expect as output from an IRAP Assessment?

    The primary output is the IRAP Security Assessment Report, which includes:

    1. An overview of the system and environment types such as, development, test, staging and production.
    2. The assessment details, including the defined assessment boundary.
    3. The system's security strengths and weaknesses.
    4. The governance arrangements for the system and supporting services.
    5. Detailed findings with supporting information and evidence.
    6. Recommended remediation activities.
    7. The completed assessment controls matrix (SSP-A) as an annexure.

  • What does an IRAP assessment NOT do?

    IRAP assessors do not, and are not authorised to, certify, accredit, endorse, or register systems on behalf of the ASD.

    An IRAP Security Assessment Report is a point-in-time view of security control status. The presence of an IRAP report does not mean a system or service is certified, compliant, or approved for use.

    Government agencies must read and evaluate the report to determine whether a solution meets their specific cyber security requirements. The Authority to Operate (ATO) decision remains with the relevant agency's authorising officer.

  • What does an IRAP assessment cost?

    The investment in an IRAP assessment reflects the scope and complexity of the environment being assessed rather than a fixed service price. Key factors include the assessment boundary, systems and services in scope, classification level, and the maturity of your existing security documentation.

    It's worth considering that an IRAP Security Assessment Report is consumed by government agencies to make risk and procurement decisions, and its credibility with authorising officers depends directly on the depth and experience of the assessors behind it. Within Australian Government security circles, the Artefakt name carries its own weight - built on our permanent team of ASD-endorsed assessors averaging more than 20 years of senior cyber practitioner experience, and a formal quality review process applied to every deliverable.

    We are happy to provide an indicative scope and cost estimate following an obligation-free discussion. If you have received other quotes, we are equally happy to talk through what an assessment of your specific environment should involve, so you can compare on an informed basis.

  • How long does an IRAP assessment take?

    The time required for an IRAP Assessment varies depending on system complexity, assessment scope, size, and the availability of relevant documentation and resources.

    The most significant variable is preparation - organisations that commence an assessment with well-organised, evidence-backed security documentation will complete the process faster and at lower cost.

    Artefakt's free IRAP Accelerator™ tool can help gauge your current readiness position and identify where preparation effort should be focused before the assessment begins.

    Artefakt IRAP Accelerator™

  • Our organisation already uses ISO 27001 or FedRAMP/NIST. Will this help with our IRAP assessment?

    Existing security frameworks such as ISO 27001, FedRAMP, or NIST can be advantageous because they provide an organised, documented view of security controls that can inform an IRAP assessment.

    However, they cannot replace an IRAP report. The evidentiary requirements specific to the Australian Government's Information Security Manual (ISM) must still be met independently.

    An existing framework is a helpful starting point, not a substitute for a formal IRAP assessment.

  • My solution has been built on an IRAP assessed platform. Can I just rely on the platform assessment?

    In most cases, no. An IRAP assessment represents an environment or service offering, and the resulting report can be shared with multiple government customers consuming that same service.

    However, if you are delivering a bespoke or customised service for each individual customer, a separate IRAP assessment may be required for the bespoke components.

    Contact us to discuss your specific environment and how to optimise your IRAP investment.

  • As a Supplier to Government, do I need IRAP assessment for every consumer?

    In most cases, No. The IRAP assessment represents an environment or service and can be provided to multiple customers.

    However, if you are providing a bespoke service for each customer, a separate IRAP may be required for the bespoke components.

    Contact Artefakt today to discuss your specific environment and how to optimise your IRAP investment.

  • Where can I find more information about the IRAP program?

    The Australian Cyber Security Centre (ACSC) maintains the official IRAP program information at:
    https://www.cyber.gov.au/irap
    The Consumer Guide available from the ACSC website, provides detailed guidance on how government agencies should use and interpret IRAP Security Assessment Reports when making procurement and risk decisions.
    IRAP Consumer Guide

ARTEFAKTS

Insights, updates and perspectives from the experts…

Speak with an Assessor

Whether you have a defined requirement or are still working out where to start, our assessors will give you a clear, honest picture of your position and what a sensible next step looks like. No obligation.

*First Name: *Surname: *e-mail: *Contact tel: *Company /Org: *How can we help?

*Tell us a little more about your IRAP requirement or project:

* I have read and understood the privacy policy and consent to receiving contact from the Artefakt team.

You may also be interested in...