IRAP
Government-grade assurance, independently validated.
The Information Security Registered Assessors Program enables Australian Government customers to validate that appropriate controls are in place, and to determine the right responsibility model for meeting the ACSC's Information Security Manual (ISM).
The program
What is an IRAP assessment?
An IRAP assessment is an activity undertaken by an IRAP Assessor to evaluate the security controls of a system and its environment, determining whether they have been implemented correctly and are operating as intended.
​
Assessments run in stages. The first is to plan and prepare, which includes agreement with the System Owner on resources, key people, milestones and timeframes, and security clearances.
​
It's important to note that assessors themselves do not issue accreditation or certification. They assess the controls, and the Accreditation Authority makes the accreditation decision.
Why IRAP matters
​Assurance that opens doors
Adopting IRAP offers real advantages, particularly for organisations involved in government projects or handling sensitive government information.
How it works
The IRAP assessment process
A structured, stage-by-stage assessment, from scoping and control evaluation through to the accreditation decision and ongoing monitoring.
Let's connect
Discover how SAMEC can assist you with your compliance goals
From scoping through to accreditation support, we'll guide you through the IRAP journey with clarity and confidence.

