IRAP Readiness and Assessment Preparation
Structured preparation for organisations approaching an IRAP assessment for the first time, or preparing for reassessment.
We help SaaS, cloud and technology providers prepare for IRAP assessment by clarifying scope, information classification, ISM applicability, supplier responsibilities, evidence gaps, RACI and remediation priorities before the external assessment.
Why preparation matters?
Arriving at an IRAP assessment without adequate documentation, clear scope definition, or evidence-mapped controls extends timelines, increases cost, and produces findings that could have been resolved beforehand. Many organisations discover gaps during the assessment itself rather than before it — at the point when addressing them is most disruptive.
IRAP readiness preparation closes that gap. It is not an assessment. It is the structured work that reduces avoidable delay, evidence rework and assessment uncertainty.
Who needs to prepare for an IRAP assessment?
Organisations approaching their first IRAP assessment who are unfamiliar with ISM requirements or what evidence an assessor will need to see. Technology companies building government-facing platforms who need to understand what controls will be assessed before design and build decisions are locked in. Organisations preparing for reassessment after significant system changes, a new classification target, or a gap in maintenance of their previous evidence package. Agencies procuring a new system and wanting to understand what their vendor will need to demonstrate before the assessment begins.
What readiness preparation includes?
- Pre-assessment gap analysis. A structured review of your current security controls, documentation, and evidence against the relevant ISM requirements for your system’s target classification level. We identify what is in place, what is partial, and what is missing before the formal assessment begins.
- Scope definition support. Assistance defining your authorisation boundary, identifying which ISM controls apply to your system, and documenting the rationale for any controls assessed as not applicable.
- Evidence preparation guidance. A clear picture of what evidence is required for each applicable control, how to structure it, and how to organise your evidence package so an assessor can work through it efficiently.
- Control remediation guidance. Prioritised recommendations for addressing identified gaps before the assessment. We work with your technical and security teams to resolve deficiencies rather than simply documenting them.
- Pre-assessment readiness review. A final review of your evidence package and control documentation before the formal assessment begins. This reduces the likelihood of findings that extend the assessment timeline or require remediation work mid-assessment.
What you receive?
- Gap analysis report documenting your current ISM control coverage against your target classification level, with findings rated by assessment risk and recommended actions.
- Evidence checklist tailored to your system scope, mapping each applicable ISM control to the specific evidence an assessor will expect to see.
- Remediation plan with prioritised actions, effort estimates, and recommended sequencing before your assessment date.
- Readiness summary confirming which controls are assessment-ready and which require further work, suitable for sharing with your assessment team or agency stakeholder.
Timeline
Typically 6 to 8 weeks depending on the size of your system boundary, the maturity of your existing documentation, and the availability of your technical team.
Pricing
Priced based on system complexity and documentation maturity. Contact us to discuss your scope and we will respond with a proposal within one business day.
Based in Australia. Available Globally.
Listed on BuyICT and selected Australian government procurement panels, including NSW SCM0020.
Our practitioners bring senior CISO experience across SMBs, Government, education, healthcare, not-for-profit, financial services, and technology. Every engagement is led by an experienced practitioner from scoping through to delivery.
Talk to Our Experts
We provide a large range of security services.
Reach out to us for a no obligation confidential conversation.
Please do not share any sensitive information in this form.
"*" indicates required fields
By clicking Submit, you agree to our Terms and Conditions and Privacy Policy.