Government Security
IRAP Assessment Readiness: 10 Things to Fix Before Your Assessor Arrives
Preparing for an IRAP assessment? Ten practical readiness steps — from system boundary and SSP quality to evidence and cloud responsibilities — that save time, cost and findings.
An IRAP assessment is a significant investment of time and money. The difference between a smooth assessment and a painful one is almost always preparation. After supporting many organisations through IRAP readiness, these are the ten things I’d fix before the assessor walks in.
First, what IRAP is
The Infosec Registered Assessors Program (IRAP), run by the Australian Signals Directorate, endorses qualified assessors to independently assess systems against the ISM. Government entities use IRAP assessment reports to inform decisions about authorising systems and using cloud services.
An IRAP assessor assesses — they don’t build your controls or write your documents for you. The more ready you are, the more value you get from the assessment.
The readiness checklist
1. Define the system boundary
Agree exactly what’s in scope: components, environments, interfaces and external services. An unclear boundary is the fastest way to blow out an assessment.
2. Confirm the classification
The classification determines which ISM controls apply. Make sure business owners and security agree, and document the decision.
3. Use the current ISM release
Assessing against an outdated release creates rework. Check which release your assessment will use and update your control set accordingly.
4. Get the SSP into shape
A System Security Plan with specific implementation statements, a clear architecture and evidence references is the foundation of the whole assessment.
5. Justify every exclusion
Each control marked “not applicable” needs a risk-based rationale in the Statement of Applicability. Unjustified exclusions become findings.
6. Document shared responsibilities
For cloud and managed services, show which controls the provider delivers, which you deliver, and how you verify the provider’s side.
7. Organise evidence before day one
Build an evidence register mapping each control to screenshots, configurations, policies and logs. Assessors spend less time hunting and more time assessing.
8. Fix the obvious gaps
Run your own gap assessment first. Close quick wins — patching, logging, MFA coverage, admin privileges — before the assessor finds them.
9. Line up the right people
Make sure system owners, engineers and service providers are available for interviews and demonstrations during the assessment window.
10. Plan for the findings
Even well-prepared systems receive findings. Have a process ready to triage, assign and remediate them, and to record risk acceptance decisions where needed.
An IRAP assessment should validate your security — not be the first time anyone looks at it closely.
How long readiness takes
For a well-documented system, readiness can take a few weeks. For a system with no SSP, unclear boundaries and scattered evidence, it can take months. Starting with an independent readiness review is usually the cheapest way to find out where you stand.
Frequently asked questions
Can our IRAP assessor also help us prepare?
Independence matters. It’s common to use one party for readiness and uplift, and a separate IRAP assessor for the formal assessment, to avoid any conflict of interest.
Does an IRAP assessment mean our system is “certified”?
No. An IRAP assessment produces a report on how well controls are implemented. Authorisation decisions are made by the relevant government entity, informed by that report and their own risk assessment.
How often should systems be reassessed?
Systems should be reassessed periodically and when significant changes occur. Check the current guidance and your customers’ requirements for specific expectations.
Preparing for IRAP? Explore government assurance services or talk to my AI agent about a readiness review.