Government Security

IRAP Assessment Readiness: 10 Things to Fix Before Your Assessor Arrives

Preparing for an IRAP assessment? Ten practical readiness steps — from system boundary and SSP quality to evidence and cloud responsibilities — that save time, cost and findings.

Muhammad Anwar
· 3 min read

An IRAP assessment is a significant investment of time and money. The difference between a smooth assessment and a painful one is almost always preparation. After supporting many organisations through IRAP readiness, these are the ten things I’d fix before the assessor walks in.

First, what IRAP is

The Infosec Registered Assessors Program (IRAP), run by the Australian Signals Directorate, endorses qualified assessors to independently assess systems against the ISM. Government entities use IRAP assessment reports to inform decisions about authorising systems and using cloud services.

An IRAP assessor assesses — they don’t build your controls or write your documents for you. The more ready you are, the more value you get from the assessment.

The readiness checklist

1. Define the system boundary

Agree exactly what’s in scope: components, environments, interfaces and external services. An unclear boundary is the fastest way to blow out an assessment.

2. Confirm the classification

The classification determines which ISM controls apply. Make sure business owners and security agree, and document the decision.

3. Use the current ISM release

Assessing against an outdated release creates rework. Check which release your assessment will use and update your control set accordingly.

4. Get the SSP into shape

A System Security Plan with specific implementation statements, a clear architecture and evidence references is the foundation of the whole assessment.

5. Justify every exclusion

Each control marked “not applicable” needs a risk-based rationale in the Statement of Applicability. Unjustified exclusions become findings.

6. Document shared responsibilities

For cloud and managed services, show which controls the provider delivers, which you deliver, and how you verify the provider’s side.

7. Organise evidence before day one

Build an evidence register mapping each control to screenshots, configurations, policies and logs. Assessors spend less time hunting and more time assessing.

8. Fix the obvious gaps

Run your own gap assessment first. Close quick wins — patching, logging, MFA coverage, admin privileges — before the assessor finds them.

9. Line up the right people

Make sure system owners, engineers and service providers are available for interviews and demonstrations during the assessment window.

10. Plan for the findings

Even well-prepared systems receive findings. Have a process ready to triage, assign and remediate them, and to record risk acceptance decisions where needed.

An IRAP assessment should validate your security — not be the first time anyone looks at it closely.

How long readiness takes

For a well-documented system, readiness can take a few weeks. For a system with no SSP, unclear boundaries and scattered evidence, it can take months. Starting with an independent readiness review is usually the cheapest way to find out where you stand.

Frequently asked questions

Can our IRAP assessor also help us prepare?

Independence matters. It’s common to use one party for readiness and uplift, and a separate IRAP assessor for the formal assessment, to avoid any conflict of interest.

Does an IRAP assessment mean our system is “certified”?

No. An IRAP assessment produces a report on how well controls are implemented. Authorisation decisions are made by the relevant government entity, informed by that report and their own risk assessment.

How often should systems be reassessed?

Systems should be reassessed periodically and when significant changes occur. Check the current guidance and your customers’ requirements for specific expectations.


Preparing for IRAP? Explore government assurance services or talk to my AI agent about a readiness review.

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader specialising in the ISM, PSPF, NIST SP 800-53, SOCI Act and AI governance (ISO 42001). Views are my own.