IRAP · ASD-ENDORSED ASSESSORS

IRAP Assessment Services Australia

CCircle provides independent IRAP assessment services for Australian Government agencies, Defence organisations, government suppliers and organisations handling sensitive information.

Our ASD-endorsed IRAP Assessors assess ICT systems against applicable controls from the Australian Government Information Security Manual (ISM). Findings are evidence-based and support informed security risk and authorisation decisions; they are not certification or accreditation.

01

Independent IRAP Security Assessments

The Infosec Registered Assessors Program (IRAP) gives organisations access to ASD-endorsed professionals who provide independent security assessment services. An engagement begins by understanding the system, its boundary, information holdings, security requirements and assessment purpose.

We assess applicable ISM controls using credible evidence, interviews and technical validation. The Security Assessment Report records control effectiveness, security strengths and weaknesses, risks and recommendations. It informs organisational decisions; an IRAP Assessor does not accredit, certify, endorse or register a system for ASD.

02

Who Needs an IRAP Assessment?

Government and Defence

Australian Government agencies and Defence organisations operating systems that require independent security assurance.

Government suppliers

Industry partners and service providers storing, processing or transmitting sensitive government information.

Cloud and SaaS providers

Providers preparing services for Australian Government use or responding to customer assurance requirements.

Organisations preparing systems

Teams designing, changing or onboarding systems that need demonstrable, appropriately implemented security controls.

03

Our IRAP Assessment Approach

  1. Scope and assessment planning — confirm purpose, boundary, stakeholders, information classification and applicable controls.
  2. Documentation and evidence review — examine the SSP, policies, architecture, procedures, configurations and prior findings.
  3. Interviews and technical validation — test claims with system owners, administrators and observable evidence.
  4. Security control assessment — assess implementation and effectiveness against the agreed scope.
  5. Findings and risk analysis — document weaknesses, context, consequences and practical mitigation.
  6. Security Assessment Report — provide a clear record for system owners and decision-makers.
  7. Remediation and reassessment — validate addressed findings where required.
04

IRAP Readiness Assessment

Readiness work tests whether the system, documentation and evidence are prepared before a formal independent assessment. It can include ISM control gap analysis, evidence readiness, security architecture review, remediation planning, Essential Eight maturity, policies, the System Security Plan and supporting documentation.

Readiness is advisory work, not an IRAP assessment. Where independence requirements apply, CCircle separates advisory and assessment responsibilities, declares potential conflicts and agrees an appropriate delivery model before work starts.

05

What We Assess

Identity, authentication, privileged access and access governance

Networks, infrastructure, endpoints, cloud services and applications

Vulnerability management, patching, logging and monitoring

Cryptography, backups, recovery and incident response

Security governance, policies, risk management and Essential Eight

Physical security and system-specific ISM controls where applicable

06

IRAP and the Australian Government ISM

ASD, through IRAP, endorses individual assessors to provide independent security assessment services. The Australian Cyber Security Centre is part of ASD and publishes the authoritative IRAP guidance. ASD also produces the Information Security Manual, a cyber security framework organisations can apply through their risk management framework.

An assessment identifies the controls applicable to the system and evaluates their effectiveness. Scope matters: completion does not mean every ISM control was tested or that an Authority to Operate has been granted.

07

Why Choose CCircle for IRAP Assessments?

  • Independent Australian cyber security consultancy with ASD-endorsed IRAP assessment capability
  • Government and Defence-aware approach grounded in evidence and clear reporting
  • Knowledge of the ISM, PSPF, Essential Eight and supporting security documentation
  • Technical infrastructure and implementation experience, not compliance-only review
  • Ability to understand governance, architecture, operations and physical security together
  • Advice without unnecessary product sales bias

Planning the assessment scope?

Speak with an assessor early to clarify boundaries, evidence requirements and whether a readiness review is appropriate.

Discuss Your Requirements

08

IRAP Assessment Frequently Asked Questions

What is an IRAP assessment?

An IRAP assessment is an independent security assessment conducted by an ASD-endorsed IRAP Assessor. It examines the effectiveness of applicable security controls and documents strengths, weaknesses, risks and recommendations.

Who can conduct an IRAP assessment?

IRAP assessments are conducted by individual cyber security professionals endorsed by the Australian Signals Directorate through the Infosec Registered Assessors Program.

Is IRAP only for Australian Government agencies?

No. Government suppliers, cloud and SaaS providers, Defence industry participants and other organisations handling sensitive government information may require or benefit from an IRAP assessment.

What does an IRAP assessor assess?

The assessor confirms scope, identifies applicable ISM controls, reviews documentation and evidence, interviews personnel, performs technical validation and assesses whether implemented controls are effective.

What is an IRAP Security Assessment Report?

It is the principal assessment deliverable, recording scope, evidence, control findings, security risks and recommendations so the system owner and relevant decision-makers can make informed risk and authorisation decisions.

How should we prepare for an IRAP assessment?

Define the system boundary, identify applicable controls, ensure security documentation is current, gather credible evidence and resolve known gaps. A readiness review can test whether the organisation is prepared.

What is the relationship between IRAP and the ISM?

IRAP provides access to ASD-endorsed assessors. The ISM is ASD security guidance from which applicable controls are selected according to the system, its risks and its requirements.

Can CCircle help remediate issues identified during an assessment?

Yes. CCircle can support remediation planning and implementation. Where independence requirements apply, advisory and assessment roles are separated and conflicts are managed transparently.

09

Related IRAP Resources and Services

Understand the IRAP assessment process, work through our assessment preparation checklist, or read how to prepare for an IRAP assessment.

For ACT delivery, see our Canberra IRAP assessment services. Organisations preparing baseline controls may also need an Essential Eight maturity assessment or assistance from our Canberra Essential Eight consultants.

Preparing for an IRAP Assessment?

Whether you require an independent IRAP assessment, an IRAP readiness review or support addressing security gaps, speak with CCircle about your environment and requirements.