Winner, TechNews Fast 50 | ARN Innovation
IRAP Assessment & Advisory Services Australia
CyberPulse delivers IRAP assessments end to end for Australian government agencies and their suppliers. We scope the engagement, assess your systems against the ISM and the Essential Eight, remediate gaps, and run the formal assessment with an endorsed IRAP assessor, then package the evidence and documentation you need for authorisation to operate.
Trusted by leading Australian organisations
CyberPulse clients include Minter Ellison, Veolia, Sydney Roosters, Utopia Digital and Meshed.





Why IRAP?
IRAP compliance enables Australian organisations to build credibility with government agencies, strengthen trust across public sector supply chains, and demonstrate alignment with the Australian Signals Directorate’s Information Security Manual (ISM) and Protective Security Policy Framework (PSPF). It helps ensure that cloud, SaaS, and managed services meet rigorous security requirements, reducing procurement friction and accelerating due diligence. IRAP also supports maturity against the Essential Eight and reinforces assurance frameworks across critical digital environments.
Some of the frameworks we support
|
Free guide
The IRAP Assessment Readiness Guide
✓ What an IRAP assessment actually involves
✓ What the assessor looks for ✓ A readiness checklist before you engage |
Get your copy
No spam. Unsubscribe anytime.
|
Our IRAP Services
Readiness Assessment & Gap Analysis (aligned to ISM & PSPF)
Security Architecture Review & Hardening Support
Policy & Procedure Development (aligned to IRAP & Essential 8)
Evidence Collection & Control Validation
Remediation Support: Hands-on help to close gaps prior to formal assessment
IRAP Assessor Liaison & Audit Defence
Post-Assessment Managed Compliance: Ongoing control reviews & reporting support
Your End-to-End IRAP Assessment
One partner from the first scoping call to authorisation to operate, including the formal assessment, delivered with an endorsed IRAP assessor.
Scope & Advisory
Define the system boundary, security classification and assessment scope, and map your obligations against the ISM.
Readiness & Remediation
Assess your systems against the ISM and the Essential Eight, then close the gaps before the formal assessment begins.
Formal IRAP Assessment
Your security controls are independently assessed and the security assessment report is produced, delivered with an endorsed IRAP assessor.
Authorisation to Operate
Evidence, documentation and the assessment report are packaged to support your authority's decision to grant authorisation to operate.
The Business Value of IRAP Compliance (Australia)
- AUD 3.9 billion in government cloud contracts awarded to IRAP-assessed providers between 2020–2023 (DTA, 2023)
- 94% of government tenders for cloud services require IRAP assessment or equivalent (Australian Government Procurement, 2023)
- IRAP-assessed cloud services experience a 70% faster procurement cycle in government tenders (InfoSec Australia Cloud Report, 2023)
- ACSC audits and spot checks IRAP compliance annually across federal and state agencies (ACSC Annual Report, 2023)
- Non-compliance or expired IRAP assessments have resulted in project delays & loss of contracts (Defence Industry Security Office, 2023)
Why CyberPulse?
Expertise
Award Winning Consultants with deep ISO 27001, SOC 2, and PCI-DSS expertise
Fixed-Price
Fixed-price delivery model with predictable costs and timelines
Support
End-to-end support — from gap analysis to certification and beyond
Achieve IRAP Assessment Confidence
CyberPulse’s IRAP Assessment & Advisory Services ensure your systems meet the stringent requirements of the Australian Cyber Security Centre (ACSC), helping you gain market access and demonstrate compliance at the highest level.
Related Services
View all services →What They Say About Us
The managed service model delivers that, while freeing my team from the bulk of compliance coordination effort and lifting the quality of both controls and supporting evidence. The outcome is a programme with the capacity to mature further and to take on new certification frameworks proactively, ahead of client and regulatory triggers.
What stands out is the depth of expertise. CyberPulse brings real command of the standards and the threat landscape, and applies it with judgement rather than box-ticking. Year on year they strengthen our security and compliance maturity and give leadership confidence that risk is genuinely understood, not just documented.
CyberPulse gave us clarity we didn't have before, not just on where we stood but a practical path forward. The roadmap they delivered has become the foundation of how we think about security investment.
Their guidance was practical, clear, and always grounded in what actually mattered for our business. They didn't just help us tick boxes; they helped us build a security posture we're genuinely proud of. If you're serious about enterprise-grade security, I can't recommend Cyber Pulse highly enough.
Our track record in numbers
FAQ – IRAP Compliance
What is IRAP?
The Information Security Registered Assessors Program (IRAP) is an Australian Government initiative managed by the Australian Signals Directorate (ASD). It provides a framework for assessing the implementation and effectiveness of information security controls within systems and services. An IRAP assessment is often required for organisations providing services to Australian Government agencies, particularly in cloud and critical infrastructure environments.
Why is IRAP important?
IRAP ensures that organisations handling government data or operating in critical supply chains meet stringent security requirements aligned with the Australian Government Information Security Manual (ISM). Achieving IRAP compliance:
-
Builds trust with government agencies and regulated sectors.
-
Demonstrates alignment with ASD security requirements.
-
Enables eligibility for government tenders and contracts involving sensitive data.
-
Reduces risk by strengthening governance and technical controls.
Who needs an IRAP assesor?
Any organisation seeking to provide services to Australian Government agencies, or operating in critical sectors such as defence, energy, finance, and telecommunications, will likely require an IRAP assessment. Cloud service providers hosting government workloads must also undergo IRAP assessments to demonstrate compliance with ASD security guidelines.
What is the role of an IRAP assessor?
An IRAP assessor is an ASD-accredited professional authorised to evaluate an organisation’s systems against the ISM and related controls. The assessor provides an independent review of your security posture, identifies gaps, and delivers a report to support government accreditation processes.
What is the process for achieving IRAP compliance?
The typical IRAP process involves:
-
Readiness assessment – reviewing current security posture against ISM requirements.
-
Gap analysis and remediation planning – identifying and addressing control deficiencies.
-
Formal IRAP assessment – conducted by an accredited assessor.
-
Reporting and accreditation – findings are submitted to relevant agencies for approval.
CyberPulse provides support at every stage, from gap analysis to remediation and assessor engagement.
How does CyberPulse support IRAP compliance?
CyberPulse offers end-to-end IRAP services including:
-
Pre-assessment readiness reviews to benchmark your environment against ISM requirements.
-
Remediation support and policy documentation to close compliance gaps.
-
Collaboration with accredited IRAP assessors to streamline the formal assessment process.
-
Ongoing managed compliance services to ensure continuous alignment with ISM and ASD requirements.
How does IRAP align with other compliance frameworks like ISO 27001, SOC 2, and Essential Eight?
IRAP shares common controls with global standards such as ISO 27001 and SOC 2, and integrates closely with the Essential Eight maturity model. CyberPulse harmonises IRAP requirements with broader compliance efforts, reducing duplication, audit fatigue, and cost across multiple frameworks.
How do I get started with IRAP at CyberPulse?
CyberPulse begins with an IRAP readiness assessment. We review your current environment, identify compliance gaps, and create a remediation roadmap tailored to your business and government requirements.
How long does an IRAP assessment take?
A full IRAP assessment typically takes around six months from initial scoping through to the assessor’s report. The largest variable is readiness: preparation and gap remediation usually take longer than the formal assessment itself, so the timeline depends on the size and classification of the system and how complete your documentation and controls are before the assessor begins.
How much does an IRAP assessment cost?
Cost is driven by scope rather than a single published price. The main factors are the size and complexity of the system, its security classification, the number of Information Security Manual controls that apply, and the amount of remediation needed before an endorsed assessor can review the system. CyberPulse provides advisory and readiness support on a fixed-price basis, so your budget and milestones are predictable from scoping through to the assessor’s review.
Does an IRAP assessment certify my system?
No. An IRAP assessment is not a pass or fail certificate. The endorsed assessor evaluates your system against the controls in the Information Security Manual and produces a report on its security posture, including how well it aligns with the ISM and any residual risks. That report gives the system owner and government stakeholders the evidence they need to make an informed authorisation decision.
Who can perform an IRAP assessment?
Only an assessor endorsed under the Australian Signals Directorate’s Infosec Registered Assessors Program can perform a formal IRAP assessment. CyberPulse provides the advisory and readiness work, scoping the engagement, preparing evidence and closing gaps against the ISM, and delivers the assessment end to end with an endorsed IRAP assessor.
What is IRAP?
IRAP is an Australian Government initiative managed by the ACSC that enables accredited assessors to evaluate and certify an organisation’s security posture against the requirements of the Information Security Manual (ISM).
How much does an IRAP assessment cost, and how long does it take in Australia?
The cost and timeline of an IRAP assessment in Australia depend on the size and complexity of the system, its security classification, and how ready your documentation and controls are before the assessor begins. IRAP costs and timelines are driven by scope rather than a single published price. The main factors are the size and complexity of the system being assessed, the security classification involved such as OFFICIAL or PROTECTED, the number of Information Security Manual controls that apply, and the amount of remediation needed before an endorsed assessor can review the system. Preparation and gap remediation often take longer than the formal assessment itself, so readiness work is the largest variable in both cost and elapsed time. A full IRAP assessment typically takes around six months from initial scoping through to the assessor’s report, depending on scope and readiness. CyberPulse provides advisory and readiness support on a fixed-price basis, giving predictable costs and clear milestones from initial scoping through to the assessor’s review.
How an organisation gets IRAP assessed
An organisation gets IRAP assessed by engaging an ASD-endorsed assessor, agreeing the system scope, mapping controls to the Information Security Manual, and then undergoing the formal assessment. Getting IRAP assessed follows a clear sequence. First, the organisation engages an assessor endorsed under the Infosec Registered Assessors Program, since only ASD-endorsed assessors can perform a formal IRAP assessment. Next, the system scope and security classification are agreed, which define exactly what will be evaluated. The organisation then maps its systems and controls to the requirements of the Information Security Manual, prepares the supporting documentation, and remediates gaps before the assessor’s review. The assessor examines the controls and produces a report on the system’s security posture, including how well it aligns with the ISM and any residual risks; it is not a pass or fail certificate. CyberPulse helps you scope the engagement, prepare the required evidence, and close gaps against the ISM so the assessment runs efficiently.