Why choose Cyooda for your IRAP assessment?
Cyooda Security has Australia's most experienced and respected IRAP assessor. Our ASD endorsed assessor provides independent assessment of your security controls, processes and documentation aligned to the ISM and PSPF frameworks.
What makes our services different is the depth of experience gained from working across multiple industries in highly complex operational and senior business leadership positions. We don't just leave you with a report at the end, we partner with you every step of the way.
IRAP Assessment Investment
Professional IRAP assessments starting from $33,000 depending on scope and complexity. Contact us for a detailed quote tailored to your specific requirements.
What is IRAP (InfoSec Registered Assessors Program)?
The Information Security Registered Assessors Program (IRAP) is an Australian Signals Directorate (ASD) initiative to provide high quality information and communications technology (ICT) security assessment services to government and industry.
An IRAP assessment provides a framework for assessing the implementation and effectiveness of an organisation's security controls against the Australian government's security requirements, as outlined in the Information Security Manual (ISM) and Protective Security Policy Framework (PSPF).
Who are IRAP assessors?
How our IRAP services help you
What makes our services different from everyone else is the depth of experience gained from working across multiple industries in highly complex operational and senior business leadership positions. This depth of experience is what we bring to every engagement and we don't just leave you with a report at the end. We are here to partner with you and will be with you every step of the way and beyond if you need further help.
Our IRAP Assessment Process
Cyooda follow a comprehensive 4-step process that ensures thorough evaluation and compliance:
Plan and Prepare
Gather all relevant documentation and evidence to be validated ahead of the assessment. Review Systems Security Plan Annex or Cloud Controls Matrix.
Define the Scope
Cyooda work with you to establish an agreed scope for the IRAP assessment including relevant systems, networks and security controls to be evaluated.
Assess the Controls
Using interviews, documentation reviews and validation of controls, the in-scope environment is thoroughly assessed against ISM requirements.
Security Report
At the end of the assessment we deliver a comprehensive final report detailing technical findings, recommendations for improvement, and IRAP letter of completion.
Industries we serve
IRAP for Law Firms and Legal Services
Australian law firms increasingly require IRAP assessment to serve government clients, handle sensitive legal matters, and demonstrate robust cybersecurity practices for client data protection.
Legal Sector IRAP Packages
Specialised IRAP assessment packages for law firms, including legal sector risk assessment, document review systems, and client confidentiality controls evaluation.
IRAP Assessment Requirements and Documentation
To be ready for an IRAP assessment, you need these minimum documents and aligned controls:
- Systems Security Plan - Comprehensive overview of security architecture and controls
- Security Risk Management Plan - Risk identification, assessment and mitigation strategies
- Incident Response Plan - Procedures for detecting, responding to and recovering from security incidents
- Continuous Monitoring Plan - Ongoing security monitoring and compliance verification processes
- Plan of Actions and Milestones - Required for revalidation assessments only
Note: If we assist you with preparing any documentation or controls, we cannot assess you and you will need to seek services of another assessor to maintain independence.
IRAP Services Across Australia
Our ASD-endorsed assessor provides IRAP services across major Australian cities and regions:
- IRAP Assessment Sydney - Serving NSW government and enterprise clients
- IRAP Assessment Melbourne - Victoria government agencies and financial services
- IRAP Assessment Brisbane - Queensland government and healthcare organisations
- IRAP Assessment Canberra - Federal government departments and agencies
- IRAP Assessment Perth - WA government and mining sector clients
- IRAP Assessment Adelaide - SA government and critical infrastructure
Frequently Asked Questions About IRAP
Benefits
Complimentary Services
Achieve and maintain IRAP certification with these essential services that provide ongoing compliance management, technical validation, and strategic oversight for Australian government requirements.