Winner, TechNews Fast 50 | ARN Innovation

IRAP Assessment & Advisory Services Australia

CyberPulse delivers IRAP assessments end to end for Australian government agencies and their suppliers. We scope the engagement, assess your systems against the ISM and the Essential Eight, remediate gaps, and run the formal assessment with an endorsed IRAP assessor, then package the evidence and documentation you need for authorisation to operate.

Trusted by leading Australian organisations

CyberPulse clients include Minter Ellison, Veolia, Sydney Roosters, Utopia Digital and Meshed.

Minter Ellison - CyberPulse clientVeolia - CyberPulse clientSydney Roosters - CyberPulse clientUtopia Digital - CyberPulse clientMeshed - CyberPulse client

Why IRAP?

IRAP compliance enables Australian organisations to build credibility with government agencies, strengthen trust across public sector supply chains, and demonstrate alignment with the Australian Signals Directorate’s Information Security Manual (ISM) and Protective Security Policy Framework (PSPF). It helps ensure that cloud, SaaS, and managed services meet rigorous security requirements, reducing procurement friction and accelerating due diligence. IRAP also supports maturity against the Essential Eight and reinforces assurance frameworks across critical digital environments.

Talk to an Expert

Some of the frameworks we support

ISO 27001ISO 42001AICPA SOC 2PCI DSSACSC Essential EightAPRA CPS 234NIST
Free guide
The IRAP Assessment Readiness Guide
✓  What an IRAP assessment actually involves
✓  What the assessor looks for
✓  A readiness checklist before you engage
Get your copy
No spam. Unsubscribe anytime.

Our IRAP Services

h

Readiness Assessment & Gap Analysis (aligned to ISM & PSPF)

~

Security Architecture Review & Hardening Support

i

Policy & Procedure Development (aligned to IRAP & Essential 8)

>

Evidence Collection & Control Validation

Remediation Support: Hands-on help to close gaps prior to formal assessment

IRAP Assessor Liaison & Audit Defence

Post-Assessment Managed Compliance: Ongoing control reviews & reporting support

Your End-to-End IRAP Assessment

One partner from the first scoping call to authorisation to operate, including the formal assessment, delivered with an endorsed IRAP assessor.

1

Scope & Advisory

Define the system boundary, security classification and assessment scope, and map your obligations against the ISM.

2

Readiness & Remediation

Assess your systems against the ISM and the Essential Eight, then close the gaps before the formal assessment begins.

3

Formal IRAP Assessment

Your security controls are independently assessed and the security assessment report is produced, delivered with an endorsed IRAP assessor.

4

Authorisation to Operate

Evidence, documentation and the assessment report are packaged to support your authority's decision to grant authorisation to operate.

CyberPulse manages the entire IRAP engagement, so your team works with one partner from the first scoping call through to authorisation to operate.

 

The Business Value of IRAP Compliance (Australia)

  • AUD 3.9 billion in government cloud contracts awarded to IRAP-assessed providers between 2020–2023 (DTA, 2023)
  • 94% of government tenders for cloud services require IRAP assessment or equivalent (Australian Government Procurement, 2023)
  • IRAP-assessed cloud services experience a 70% faster procurement cycle in government tenders (InfoSec Australia Cloud Report, 2023)
  • ACSC audits and spot checks IRAP compliance annually across federal and state agencies (ACSC Annual Report, 2023)
  • Non-compliance or expired IRAP assessments have resulted in project delays & loss of contracts (Defence Industry Security Office, 2023)

Why CyberPulse?

Expertise

Award Winning Consultants with deep ISO 27001, SOC 2, and PCI-DSS expertise

Fixed-Price

Fixed-price delivery model with predictable costs and timelines

Support

End-to-end support — from gap analysis to certification and beyond

Achieve IRAP Assessment Confidence

CyberPulse’s IRAP Assessment & Advisory Services ensure your systems meet the stringent requirements of the Australian Cyber Security Centre (ACSC), helping you gain market access and demonstrate compliance at the highest level.

What They Say About Us

The managed service model delivers that, while freeing my team from the bulk of compliance coordination effort and lifting the quality of both controls and supporting evidence. The outcome is a programme with the capacity to mature further and to take on new certification frameworks proactively, ahead of client and regulatory triggers.
Sunil SaaleChief Information Security Officer, MinterEllison
What stands out is the depth of expertise. CyberPulse brings real command of the standards and the threat landscape, and applies it with judgement rather than box-ticking. Year on year they strengthen our security and compliance maturity and give leadership confidence that risk is genuinely understood, not just documented.
Raghu GandhyChief Information Security Officer, Veolia
CyberPulse gave us clarity we didn't have before, not just on where we stood but a practical path forward. The roadmap they delivered has become the foundation of how we think about security investment.
Jimmy O'ReganHead of IT, Major NRL Club & Hospitality Group
Their guidance was practical, clear, and always grounded in what actually mattered for our business. They didn't just help us tick boxes; they helped us build a security posture we're genuinely proud of. If you're serious about enterprise-grade security, I can't recommend Cyber Pulse highly enough.
Aaron TraylenCo-Founder, Utopia Digital

Our track record in numbers

350+
Satisfied clients
500+
Certifications achieved
400+
Security assessments conducted

FAQ – IRAP Compliance

What is IRAP?

The Information Security Registered Assessors Program (IRAP) is an Australian Government initiative managed by the Australian Signals Directorate (ASD). It provides a framework for assessing the implementation and effectiveness of information security controls within systems and services. An IRAP assessment is often required for organisations providing services to Australian Government agencies, particularly in cloud and critical infrastructure environments.

Why is IRAP important?

IRAP ensures that organisations handling government data or operating in critical supply chains meet stringent security requirements aligned with the Australian Government Information Security Manual (ISM). Achieving IRAP compliance:

  • Builds trust with government agencies and regulated sectors.

  • Demonstrates alignment with ASD security requirements.

  • Enables eligibility for government tenders and contracts involving sensitive data.

  • Reduces risk by strengthening governance and technical controls.

Who needs an IRAP assesor?

Any organisation seeking to provide services to Australian Government agencies, or operating in critical sectors such as defence, energy, finance, and telecommunications, will likely require an IRAP assessment. Cloud service providers hosting government workloads must also undergo IRAP assessments to demonstrate compliance with ASD security guidelines.

What is the role of an IRAP assessor?

An IRAP assessor is an ASD-accredited professional authorised to evaluate an organisation’s systems against the ISM and related controls. The assessor provides an independent review of your security posture, identifies gaps, and delivers a report to support government accreditation processes.

What is the process for achieving IRAP compliance?

The typical IRAP process involves:

  1. Readiness assessment – reviewing current security posture against ISM requirements.

  2. Gap analysis and remediation planning – identifying and addressing control deficiencies.

  3. Formal IRAP assessment – conducted by an accredited assessor.

  4. Reporting and accreditation – findings are submitted to relevant agencies for approval.

CyberPulse provides support at every stage, from gap analysis to remediation and assessor engagement.

How does CyberPulse support IRAP compliance?

CyberPulse offers end-to-end IRAP services including:

  • Pre-assessment readiness reviews to benchmark your environment against ISM requirements.

  • Remediation support and policy documentation to close compliance gaps.

  • Collaboration with accredited IRAP assessors to streamline the formal assessment process.

  • Ongoing managed compliance services to ensure continuous alignment with ISM and ASD requirements.

How does IRAP align with other compliance frameworks like ISO 27001, SOC 2, and Essential Eight?

IRAP shares common controls with global standards such as ISO 27001 and SOC 2, and integrates closely with the Essential Eight maturity model. CyberPulse harmonises IRAP requirements with broader compliance efforts, reducing duplication, audit fatigue, and cost across multiple frameworks.

How do I get started with IRAP at CyberPulse?

CyberPulse begins with an IRAP readiness assessment. We review your current environment, identify compliance gaps, and create a remediation roadmap tailored to your business and government requirements.

How long does an IRAP assessment take?

A full IRAP assessment typically takes around six months from initial scoping through to the assessor’s report. The largest variable is readiness: preparation and gap remediation usually take longer than the formal assessment itself, so the timeline depends on the size and classification of the system and how complete your documentation and controls are before the assessor begins.

How much does an IRAP assessment cost?

Cost is driven by scope rather than a single published price. The main factors are the size and complexity of the system, its security classification, the number of Information Security Manual controls that apply, and the amount of remediation needed before an endorsed assessor can review the system. CyberPulse provides advisory and readiness support on a fixed-price basis, so your budget and milestones are predictable from scoping through to the assessor’s review.

Does an IRAP assessment certify my system?

No. An IRAP assessment is not a pass or fail certificate. The endorsed assessor evaluates your system against the controls in the Information Security Manual and produces a report on its security posture, including how well it aligns with the ISM and any residual risks. That report gives the system owner and government stakeholders the evidence they need to make an informed authorisation decision.

Who can perform an IRAP assessment?

Only an assessor endorsed under the Australian Signals Directorate’s Infosec Registered Assessors Program can perform a formal IRAP assessment. CyberPulse provides the advisory and readiness work, scoping the engagement, preparing evidence and closing gaps against the ISM, and delivers the assessment end to end with an endorsed IRAP assessor.

What is IRAP?

IRAP is an Australian Government initiative managed by the ACSC that enables accredited assessors to evaluate and certify an organisation’s security posture against the requirements of the Information Security Manual (ISM).

How much does an IRAP assessment cost, and how long does it take in Australia?

The cost and timeline of an IRAP assessment in Australia depend on the size and complexity of the system, its security classification, and how ready your documentation and controls are before the assessor begins. IRAP costs and timelines are driven by scope rather than a single published price. The main factors are the size and complexity of the system being assessed, the security classification involved such as OFFICIAL or PROTECTED, the number of Information Security Manual controls that apply, and the amount of remediation needed before an endorsed assessor can review the system. Preparation and gap remediation often take longer than the formal assessment itself, so readiness work is the largest variable in both cost and elapsed time. A full IRAP assessment typically takes around six months from initial scoping through to the assessor’s report, depending on scope and readiness. CyberPulse provides advisory and readiness support on a fixed-price basis, giving predictable costs and clear milestones from initial scoping through to the assessor’s review.

How an organisation gets IRAP assessed

An organisation gets IRAP assessed by engaging an ASD-endorsed assessor, agreeing the system scope, mapping controls to the Information Security Manual, and then undergoing the formal assessment. Getting IRAP assessed follows a clear sequence. First, the organisation engages an assessor endorsed under the Infosec Registered Assessors Program, since only ASD-endorsed assessors can perform a formal IRAP assessment. Next, the system scope and security classification are agreed, which define exactly what will be evaluated. The organisation then maps its systems and controls to the requirements of the Information Security Manual, prepares the supporting documentation, and remediates gaps before the assessor’s review. The assessor examines the controls and produces a report on the system’s security posture, including how well it aligns with the ISM and any residual risks; it is not a pass or fail certificate. CyberPulse helps you scope the engagement, prepare the required evidence, and close gaps against the ISM so the assessment runs efficiently.