Skip to main content
Rules Mate

IRAP assessments and hosting Australian government data: the certification path

Rules Mate Editorial7 min read

How an IRAP assessment works, what an IRAP assessor can and cannot give you, and how the Hosting Certification Framework sits alongside it (checked August 2026).

If a Commonwealth agency wants to put its data on your platform, sooner or later someone will ask for "your IRAP". The request is usually made as though IRAP were a certificate you either hold or do not. It is not. Understanding what an IRAP assessment actually produces is the difference between a saleable artefact and eighteen months of wasted effort.

What an IRAP assessment is — and is not

The Infosec Registered Assessors Program is run by the Australian Signals Directorate. ASD endorses individuals from the private and public sectors to provide independent security assessment services, and those endorsed assessors can assess systems at SECRET and below across ICT systems, cloud services, gateways and GovLink, per ASD's IRAP page.

ASD is explicit about the limits, and the limits are the whole point:

  • IRAP assessors do not accredit, certify, endorse or register systems on behalf of ASD.
  • An assessment generally will not cover every Information Security Manual control.
  • A completed assessment does not inherently imply that a system is compliant with the controls that were tested.

What you get is a security assessment report or a letter of completion, describing what was tested and what was found. The authorisation decision belongs to the agency that wants to use your system, not to ASD and not to your assessor. ASD's own guidance tells customers to read the report to determine what a system has actually been tested against.

That has a direct commercial consequence: an IRAP report is an input to someone else's risk decision, not a pass mark. A vendor claiming to be "IRAP certified" is describing something that does not exist. See the IRAP glossary entry and the ASD regulator profile.

Who needs one

You need an IRAP assessment when a Commonwealth entity proposes to process, store or transmit its information on a system you operate, and its own authorising officer needs independent evidence about your controls before granting an authority to operate. In practice that means:

  • Cloud and SaaS providers selling to federal agencies.
  • Data centre and managed hosting providers.
  • Gateway and network service providers.
  • System integrators operating an agency environment under contract.

State and territory agencies are not bound by the Commonwealth framework but frequently borrow it in procurement, so the same request arrives from state buyers. Where the work is procured through a Commonwealth panel or open tender, the security requirement sits alongside your obligations under the Commonwealth Procurement Rules and the underlying procurement obligation.

The two frameworks an assessor works from

Two documents govern the substance of the assessment, and both are published and free.

The Information Security Manual. The ISM is ASD's control catalogue. It is updated regularly, and the applicable version is a scoping decision you make with your assessor at the start — assessing against a stale release is a classic finding. Our explainer on the Information Security Manual covers its structure.

The Protective Security Policy Framework. The PSPF sets the policy layer — governance, information, personnel and physical security — that agencies must apply and that flows down to their suppliers by contract. See our PSPF explainer and the corresponding obligation record.

The Essential Eight sits inside this picture rather than beside it. Federal suppliers handling OFFICIAL: Sensitive data are commonly required to demonstrate Essential Eight maturity, assessed under the Right Fit For Risk approach; that is covered separately in Essential Eight ML2 for federal contractors and in the maturity obligation.

How the assessment runs

The engagement is conventionally split into a scoping and design review followed by an effectiveness review, and the sequencing matters more than the labels.

  1. Scope definition. Draw the system boundary. Everything hangs off this: which components, which data classifications, which shared services, which subservice providers, and which ISM release applies. An over-broad scope is the single largest driver of both cost and failure.
  2. Documentation review. The assessor reads your System Security Plan, security risk management plan, incident response plan, continuous monitoring plan and standard operating procedures against the applicable controls.
  3. Effectiveness testing. The assessor tests whether controls operate — configuration review, sampling, demonstrations, and where appropriate technical verification.
  4. Reporting. You receive a security assessment report setting out control-by-control findings, together with a plan of action for anything not implemented.
  5. Agency authorisation. The sponsoring agency's authorising officer reads the report and decides whether to grant an authority to operate. This step is outside your control and outside your assessor's.

Two practical warnings. First, an assessor engaged to write your documentation cannot then independently assess it, so keep the readiness work and the assessment work separate. Second, ASD warns that people impersonate IRAP assessors — confirm an assessor's endorsement through ASD before engaging.

The Hosting Certification Framework and its current pause

The Hosting Certification Framework is a separate scheme and is frequently conflated with IRAP. It certifies the provider — ownership, control, operations and supply chain — rather than assessing a system. The framework supports the PSPF and the ISM and currently applies only to data centre providers and cloud service providers.

There are three levels:

LevelWhat it gives governmentTypical customer
Certified StrategicHighest assurance; the provider allows government to specify ownership and control conditions, with additional security controlsAgencies with a high risk profile or data needing additional protection
Certified AssuredSafeguards against change of ownership or control, backed by financial penalties aimed at minimising Commonwealth transition costsAgencies with a low risk profile holding sensitive data assessed as not needing additional protection
UncertifiedMinimal protectionsNon-sensitive data, or where the agency's internal risk assessment permits

The framework applies to Australian Government customers procuring hosting for sensitive government data, whole-of-government systems and systems classified at PROTECTED, and its requirements have applied to new contracts and extensions since 30 June 2022.

Important current status: the framework is undergoing reform, and the Department paused HCF certification registration for prospective service providers, and supplementary assessment for already-certified providers, from 3 November 2025 until the reforms are complete. Providers already certified are not affected (checked August 2026, per the Hosting Certification Framework site). If your go-to-market plan assumed you could obtain certification this financial year, verify the current position directly before committing to a customer.

Evidence and artefacts you must have ready

ArtefactWhat the assessor checksCommon failure
System Security PlanThat it describes the actual system and maps each applicable ISM control to an implementationWritten against a system design that has since changed
Security Risk Management PlanRisks identified, treatments assigned, residual risk accepted by a named authorityRisk acceptance with no named accepting officer
Statement of Applicability equivalentWhich controls apply, which do not, and whyBlanket exclusions with no justification
Incident response planRoles, notification paths, exercise recordsNever exercised
Continuous monitoring planVulnerability scanning, logging, review cadence, evidence of actual reviewsPlan exists, review records do not
Configuration baselinesHardening applied and demonstrable on live systemsBaseline documented, drift not detected
Personnel security recordsClearances, screening and access appropriate to classificationOffshore support staff not disclosed in scope
Supply chain registerSubservice providers, their location and their own assessmentsUndisclosed fourth parties

Data location and offshore access deserve particular care. Agencies treat both as scoping facts, and discovering an offshore support team midway through an assessment is a reliable way to have the scope reopened.

Cost drivers and the re-assessment cycle

There is no fixed fee, and any figure quoted before scoping is guesswork. The drivers are:

  • System boundary size — components, environments and interconnections in scope.
  • Data classification — a PROTECTED assessment demands materially more than OFFICIAL: Sensitive.
  • Control count — how many ISM controls the classification and system type pull in.
  • Documentation maturity — remediating a thin System Security Plan is your cost, not the assessor's, and it is usually the largest one.
  • Number of subservice providers — each one adds evidence collection.
  • Re-testing — findings closed after the fieldwork window generally require re-testing.

There is no fixed statutory expiry on an assessment report, but agencies treat reports as ageing assets and commonly expect a current assessment — often re-performed annually or on material change. Treat a significant architecture change, a new region, a new subservice provider or a change of ISM release as triggering re-assessment, and budget for it as a recurring cost rather than a one-off. Providers that also hold an ISO/IEC 27001 certificate or a SOC 2 report will find the evidence overlaps substantially; the differences between those artefacts are set out in SOC 2 or ISO 27001.

Frequently asked

Is there such a thing as being IRAP certified?

No. ASD states that IRAP assessors do not accredit, certify, endorse or register systems on its behalf. An IRAP engagement produces a security assessment report or letter of completion describing what was tested and what was found. The decision to authorise a system to hold government data is made by the sponsoring agency's authorising officer, not by ASD and not by the assessor.

What classification levels can an IRAP assessor assess?

ASD's IRAP page states that endorsed IRAP assessors can provide security assessments of SECRET and below, covering ICT systems, cloud services, gateways and GovLink. The applicable control set is drawn from the Information Security Manual and scales with the classification of the data involved, so a PROTECTED assessment pulls in materially more controls than an OFFICIAL: Sensitive one.

How is the Hosting Certification Framework different from IRAP?

The Hosting Certification Framework certifies the provider — its ownership, control, operations and supply chain — while an IRAP assessment assesses a system against the Information Security Manual. The framework currently applies only to data centre providers and cloud service providers, and offers three levels: Certified Strategic, Certified Assured and Uncertified.

Can I apply for Hosting Certification right now?

Not for new registrations. The framework is undergoing reform and the Department paused HCF certification registration for prospective service providers, and supplementary assessment for already-certified providers, from 3 November 2025 until reforms are complete. Providers already certified are not impacted. Confirm the current position on hostingcertification.gov.au before making commitments to a customer (checked August 2026).

How often does an IRAP assessment need to be redone?

There is no fixed statutory expiry, but agencies treat assessment reports as ageing evidence and commonly expect a current one, often re-performed annually or on material change. Treat a significant architecture change, a new hosting region, a new subservice provider or an updated Information Security Manual release as a trigger for re-assessment.

Does an ISO 27001 certificate satisfy a Commonwealth agency?

Generally not on its own. Commonwealth systems are assessed against the Information Security Manual and governed by the Protective Security Policy Framework, and federal suppliers handling OFFICIAL: Sensitive data are commonly required to demonstrate Essential Eight maturity as well. An ISO/IEC 27001 certificate is useful supporting evidence and reduces the work, but it does not replace an IRAP assessment.

Related

Related reading