rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/irap-assessment-hosting-australian-government-data
Printed 28 August 2026
IRAP assessments and hosting Australian government data: the certification path
How an IRAP assessment works, what an IRAP assessor can and cannot give you, and how the Hosting Certification Framework sits alongside it (checked August 2026).
If a Commonwealth agency wants to put its data on your platform, sooner or later someone will ask for "your IRAP". The request is usually made as though IRAP were a certificate you either hold or do not. It is not. Understanding what an IRAP assessment actually produces is the difference between a saleable artefact and eighteen months of wasted effort.
What an IRAP assessment is — and is not
The Infosec Registered Assessors Program is run by the Australian Signals Directorate. ASD endorses individuals from the private and public sectors to provide independent security assessment services, and those endorsed assessors can assess systems at SECRET and below across ICT systems, cloud services, gateways and GovLink, per ASD's IRAP page.
ASD is explicit about the limits, and the limits are the whole point:
- IRAP assessors do not accredit, certify, endorse or register systems on behalf of ASD.
- An assessment generally will not cover every Information Security Manual control.
- A completed assessment does not inherently imply that a system is compliant with the controls that were tested.
What you get is a security assessment report or a letter of completion, describing what was tested and what was found. The authorisation decision belongs to the agency that wants to use your system, not to ASD and not to your assessor. ASD's own guidance tells customers to read the report to determine what a system has actually been tested against.
That has a direct commercial consequence: an IRAP report is an input to someone else's risk decision, not a pass mark. A vendor claiming to be "IRAP certified" is describing something that does not exist. See the IRAP glossary entry and the ASD regulator profile.
Who needs one
You need an IRAP assessment when a Commonwealth entity proposes to process, store or transmit its information on a system you operate, and its own authorising officer needs independent evidence about your controls before granting an authority to operate. In practice that means:
- Cloud and SaaS providers selling to federal agencies.
- Data centre and managed hosting providers.
- Gateway and network service providers.
- System integrators operating an agency environment under contract.
State and territory agencies are not bound by the Commonwealth framework but frequently borrow it in procurement, so the same request arrives from state buyers. Where the work is procured through a Commonwealth panel or open tender, the security requirement sits alongside your obligations under the Commonwealth Procurement Rules and the underlying procurement obligation.
The two frameworks an assessor works from
Two documents govern the substance of the assessment, and both are published and free.
The Information Security Manual. The ISM is ASD's control catalogue. It is updated regularly, and the applicable version is a scoping decision you make with your assessor at the start — assessing against a stale release is a classic finding. Our explainer on the Information Security Manual covers its structure.
The Protective Security Policy Framework. The PSPF sets the policy layer — governance, information, personnel and physical security — that agencies must apply and that flows down to their suppliers by contract. See our PSPF explainer and the corresponding obligation record.
The Essential Eight sits inside this picture rather than beside it. Federal suppliers handling OFFICIAL: Sensitive data are commonly required to demonstrate Essential Eight maturity, assessed under the Right Fit For Risk approach; that is covered separately in Essential Eight ML2 for federal contractors and in the maturity obligation.
How the assessment runs
The engagement is conventionally split into a scoping and design review followed by an effectiveness review, and the sequencing matters more than the labels.
- Scope definition. Draw the system boundary. Everything hangs off this: which components, which data classifications, which shared services, which subservice providers, and which ISM release applies. An over-broad scope is the single largest driver of both cost and failure.
- Documentation review. The assessor reads your System Security Plan, security risk management plan, incident response plan, continuous monitoring plan and standard operating procedures against the applicable controls.
- Effectiveness testing. The assessor tests whether controls operate — configuration review, sampling, demonstrations, and where appropriate technical verification.
- Reporting. You receive a security assessment report setting out control-by-control findings, together with a plan of action for anything not implemented.
- Agency authorisation. The sponsoring agency's authorising officer reads the report and decides whether to grant an authority to operate. This step is outside your control and outside your assessor's.
Two practical warnings. First, an assessor engaged to write your documentation cannot then independently assess it, so keep the readiness work and the assessment work separate. Second, ASD warns that people impersonate IRAP assessors — confirm an assessor's endorsement through ASD before engaging.
The Hosting Certification Framework and its current pause
The Hosting Certification Framework is a separate scheme and is frequently conflated with IRAP. It certifies the provider — ownership, control, operations and supply chain — rather than assessing a system. The framework supports the PSPF and the ISM and currently applies only to data centre providers and cloud service providers.
There are three levels:
| Level | What it gives government | Typical customer |
|---|---|---|
| Certified Strategic | Highest assurance; the provider allows government to specify ownership and control conditions, with additional security controls | Agencies with a high risk profile or data needing additional protection |
| Certified Assured | Safeguards against change of ownership or control, backed by financial penalties aimed at minimising Commonwealth transition costs | Agencies with a low risk profile holding sensitive data assessed as not needing additional protection |
| Uncertified | Minimal protections | Non-sensitive data, or where the agency's internal risk assessment permits |
The framework applies to Australian Government customers procuring hosting for sensitive government data, whole-of-government systems and systems classified at PROTECTED, and its requirements have applied to new contracts and extensions since 30 June 2022.
Important current status: the framework is undergoing reform, and the Department paused HCF certification registration for prospective service providers, and supplementary assessment for already-certified providers, from 3 November 2025 until the reforms are complete. Providers already certified are not affected (checked August 2026, per the Hosting Certification Framework site). If your go-to-market plan assumed you could obtain certification this financial year, verify the current position directly before committing to a customer.
Evidence and artefacts you must have ready
| Artefact | What the assessor checks | Common failure |
|---|---|---|
| System Security Plan | That it describes the actual system and maps each applicable ISM control to an implementation | Written against a system design that has since changed |
| Security Risk Management Plan | Risks identified, treatments assigned, residual risk accepted by a named authority | Risk acceptance with no named accepting officer |
| Statement of Applicability equivalent | Which controls apply, which do not, and why | Blanket exclusions with no justification |
| Incident response plan | Roles, notification paths, exercise records | Never exercised |
| Continuous monitoring plan | Vulnerability scanning, logging, review cadence, evidence of actual reviews | Plan exists, review records do not |
| Configuration baselines | Hardening applied and demonstrable on live systems | Baseline documented, drift not detected |
| Personnel security records | Clearances, screening and access appropriate to classification | Offshore support staff not disclosed in scope |
| Supply chain register | Subservice providers, their location and their own assessments | Undisclosed fourth parties |
Data location and offshore access deserve particular care. Agencies treat both as scoping facts, and discovering an offshore support team midway through an assessment is a reliable way to have the scope reopened.
Cost drivers and the re-assessment cycle
There is no fixed fee, and any figure quoted before scoping is guesswork. The drivers are:
- System boundary size — components, environments and interconnections in scope.
- Data classification — a PROTECTED assessment demands materially more than OFFICIAL: Sensitive.
- Control count — how many ISM controls the classification and system type pull in.
- Documentation maturity — remediating a thin System Security Plan is your cost, not the assessor's, and it is usually the largest one.
- Number of subservice providers — each one adds evidence collection.
- Re-testing — findings closed after the fieldwork window generally require re-testing.
There is no fixed statutory expiry on an assessment report, but agencies treat reports as ageing assets and commonly expect a current assessment — often re-performed annually or on material change. Treat a significant architecture change, a new region, a new subservice provider or a change of ISM release as triggering re-assessment, and budget for it as a recurring cost rather than a one-off. Providers that also hold an ISO/IEC 27001 certificate or a SOC 2 report will find the evidence overlaps substantially; the differences between those artefacts are set out in SOC 2 or ISO 27001.
Frequently asked
Is there such a thing as being IRAP certified?
No. ASD states that IRAP assessors do not accredit, certify, endorse or register systems on its behalf. An IRAP engagement produces a security assessment report or letter of completion describing what was tested and what was found. The decision to authorise a system to hold government data is made by the sponsoring agency's authorising officer, not by ASD and not by the assessor.
What classification levels can an IRAP assessor assess?
ASD's IRAP page states that endorsed IRAP assessors can provide security assessments of SECRET and below, covering ICT systems, cloud services, gateways and GovLink. The applicable control set is drawn from the Information Security Manual and scales with the classification of the data involved, so a PROTECTED assessment pulls in materially more controls than an OFFICIAL: Sensitive one.
How is the Hosting Certification Framework different from IRAP?
The Hosting Certification Framework certifies the provider — its ownership, control, operations and supply chain — while an IRAP assessment assesses a system against the Information Security Manual. The framework currently applies only to data centre providers and cloud service providers, and offers three levels: Certified Strategic, Certified Assured and Uncertified.
Can I apply for Hosting Certification right now?
Not for new registrations. The framework is undergoing reform and the Department paused HCF certification registration for prospective service providers, and supplementary assessment for already-certified providers, from 3 November 2025 until reforms are complete. Providers already certified are not impacted. Confirm the current position on hostingcertification.gov.au before making commitments to a customer (checked August 2026).
How often does an IRAP assessment need to be redone?
There is no fixed statutory expiry, but agencies treat assessment reports as ageing evidence and commonly expect a current one, often re-performed annually or on material change. Treat a significant architecture change, a new hosting region, a new subservice provider or an updated Information Security Manual release as a trigger for re-assessment.
Does an ISO 27001 certificate satisfy a Commonwealth agency?
Generally not on its own. Commonwealth systems are assessed against the Information Security Manual and governed by the Protective Security Policy Framework, and federal suppliers handling OFFICIAL: Sensitive data are commonly required to demonstrate Essential Eight maturity as well. An ISO/IEC 27001 certificate is useful supporting evidence and reduces the work, but it does not replace an IRAP assessment.
Related
Related reading
ASD's Information Security Manual: the controls AU government information systems must implement
The Australian Signals Directorate's Information Security Manual (ISM) is the federal cyber security controls framework. It's updated quarterly and extended via contracts to many businesses serving government.
The Protective Security Policy Framework: what PSPF requires of Commonwealth entities
The PSPF sets mandatory security requirements for non-corporate Commonwealth entities and a recommended framework for others. Here's the 16-policy structure and how it reaches government contractors.
Essential Eight ML2 for federal contractors: a guide to Right Fit For Risk
Federal subcontractors handling OFFICIAL: Sensitive data must meet ASD Essential Eight Maturity Level 2 under Right Fit For Risk. Here's what each of the 8 strategies actually means at ML2.
SOC 2 or ISO 27001: which security assurance artefact your customers actually want
SOC 2 is an attestation report; ISO 27001 is a certificate. How they differ in scope, evidence and renewal, and which Australian buyers ask for which.
Obligations covered
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/irap-assessment-hosting-australian-government-data