Search "IRAP assessment cost" and you get a wall of consultancy quote forms and ranges wide enough to be useless. This page explains what an IRAP assessment actually is, what genuinely moves the price, what the reported market ranges look like, and the ten questions that tell you whether you should be spending assessor money yet.
IRAP is the Infosec Registered Assessors Program, run by the Australian Signals Directorate (ASD). An IRAP assessor is an ASD-endorsed individual who assesses your system against the controls in the Information Security Manual (ISM) and produces a security assessment report (SAR). That report tells a government authorising officer, in structured detail, which controls are implemented, which are not, and what residual risk they are being asked to accept.
Two things follow from that, and both matter for cost:
An IRAP assessment is not a certification. There is no "IRAP certified" badge issued by ASD. The output is an assessment report that informs someone else's risk decision. Any vendor claiming to be "IRAP certified" is using inaccurate shorthand, and assessors notice.
The assessor assesses; they do not remediate. You are paying a scarce, endorsed specialist by the day to examine evidence. Every hour they spend chasing missing evidence, deciphering an out-of-date system security plan, or re-testing after a remediation cycle is an hour you pay for. That single fact explains most of the cost variance in the market.
If you are a SaaS provider selling to government, there is a second layer: agencies procuring hosted services also look at the Hosting Certification Framework (HCF), which certifies hosting providers rather than your application. IRAP and HCF answer different questions and buyers frequently want both answered. More on that below.
Publicly reported quotes for IRAP assessments range roughly from A$25,000 for a narrow, well-prepared system at OFFICIAL, up to A$250,000 or more for a large, complex environment at PROTECTED with multiple remediation cycles. Treat those as reported market ranges, not a menu: they come from published tenders, vendor disclosures and practitioner commentary, and any individual quote depends entirely on your scope and readiness.
To be clear about our own position: CyberSentien does not sell IRAP assessments and these are not our prices. We are not IRAP assessors. Our engine sits on the other side of the equation, the side you control: how prepared you are when the assessor arrives. Our pricing for that is on the pricing page.
Reported figures are indicative only. Assessors quote on scope, and two organisations buying "an IRAP assessment" can legitimately pay an order of magnitude apart.
| Cost driver | Why it moves the price | What you control |
|---|---|---|
| Scope and system boundary | Every extra environment, integration and shared service pulls more ISM controls into scope and more days of assessor time. | Draw the boundary deliberately before requesting quotes. A crisp boundary with documented exclusions is the cheapest scoping decision you will ever make. |
| Classification level | PROTECTED brings substantially more applicable controls and deeper scrutiny than OFFICIAL, including OFFICIAL: Sensitive handling. | Assess at the level your buyers actually need. Paying for PROTECTED "to be safe" when your pipeline is OFFICIAL is a common and expensive mistake. |
| Evidence readiness | Assessors bill for time spent locating, requesting and re-requesting evidence. Assertion-only compliance ("we do patch, trust us") multiplies their days on site. | Arrive with per-control evidence already chained: the control, the implementation claim, and the dated artefact that proves it, in one place. |
| Remediation cycles | Each round of "fix and re-test" reopens assessor engagement. Organisations that walk in unready often pay for the assessment twice in effect. | Run an honest internal gap assessment first and close the known gaps before the assessor does it for you at assessor rates. |
Notice that three of the four levers are readiness questions, not procurement questions. The market range is wide because readiness varies wildly, not because assessors price arbitrarily.
The ISM applies controls by classification. A system handling OFFICIAL data faces a meaningful but manageable control set; PROTECTED expands the applicable controls significantly and raises the evidentiary bar for each one. Since assessor effort scales with the number of applicable controls and the depth of verification, classification is the largest single step-change in cost. Get an explicit answer from your government buyers about the classification of data they will actually put in your service before you scope anything.
For SaaS providers, the Hosting Certification Framework, administered by the Department of Finance, adds a complementary layer. HCF certifies hosting providers and data centres (Certified Assured and Certified Strategic) with a focus on ownership, control and sovereignty of the hosting supply chain. It does not assess your application; IRAP does not certify your data centre. A government buyer evaluating your SaaS will typically want your service assessed against the ISM via IRAP and your underlying hosting within HCF-certified facilities. If you are choosing infrastructure now, that pairing should shape the decision, which is exactly why CyberSentien runs on Australian-sovereign infrastructure by design (see our sovereignty page).
Before you request a single quote, answer these ten questions honestly. No tool, no scoring theatre, just yes or no.
A rough reading, offered as practitioner judgement rather than science: eight or more yes answers and you are ready to get quotes and should get competitive ones. Five to seven, and a preparation phase first will likely cost you less than the extra assessor days would. Fewer than five, and money spent on an assessment today is largely money spent on a very expensive gap list you could have produced yourself.
You cannot negotiate down the ISM. You cannot make PROTECTED cheaper by wishing. The one lever entirely in your hands is how much assessor time your organisation consumes per control, and that is a function of evidence discipline.
When every control claim links directly to its artefact, the assessor verifies instead of investigates. The difference between "here is the dated configuration export for this control" and "we'll get that to you next week" is the difference between days and weeks of billable engagement.
Assessors write security assessment reports. If your internal posture is already structured the way a SAR is structured, control by control with implementation status and supporting evidence, the assessor's writing job shrinks and so does your invoice.
Continuous internal assessment surfaces gaps months before the assessor would, when fixing them is a sprint ticket rather than a contract variation. One avoided re-test cycle can outweigh the entire cost of the preparation tooling.
Honest planning numbers, offered as estimates because every engagement differs: the preparation phase is usually the long pole, and for an organisation starting from partial readiness it is commonly measured in months. The assessment itself typically involves weeks of assessor effort spread across a longer elapsed window for evidence review, interviews and report drafting, with PROTECTED engagements sitting at the longer end. Remediation and re-testing, if needed, add further cycles. Organisations that treat IRAP as a scheduled milestone at the end of a readiness programme consistently report a smoother, shorter engagement than those that book the assessor first and prepare in a panic afterwards. Budget elapsed time in months, not weeks, and challenge anyone who promises otherwise.
CyberSentien is an Australian-sovereign, evidence-led compliance assurance engine. We do not perform IRAP assessments and we never will; that is the assessor's job. What the engine does is make you the client every assessor hopes to get:
The complete ISM control catalogue lives on the engine's OSCAL spine, kept current with ASD's ISM releases, so your applicability statement and per-control posture are structured data, not a spreadsheet archaeology project. See ISM & IRAP on CyberSentien.
Every control carries its own evidence chain: the claim, the artefact, the date, the owner. When an assessor asks "show me", the answer is a link, not a meeting.
Reports come out shaped the way a security assessment report is shaped, so the handover from your preparation to the assessor's report is a translation of inches, not miles.
Essential Eight maturity is assessed per strategy across maturity levels one to three, with the same evidence discipline, because IRAP conversations reliably start there.
The engine runs the same way we advise you to build: evidence-led, deterministic where determinism is possible, and hosted on Australian-sovereign infrastructure (details on the sovereignty page and the platform page). Rather than take our word for any of it, the demo is live and gated, and it shows the actual engine, not a slide deck.
Publicly reported quotes range roughly from A$25,000 for a narrow, well-prepared OFFICIAL system to A$250,000 or more for large PROTECTED environments with remediation cycles. These are reported market ranges, not our prices; the honest answer is that your readiness and scope decide where in that range you land.
No. IRAP assessors produce a security assessment report against the ISM; the accepting agency's authorising officer makes the risk decision. ASD does not issue an "IRAP certified" credential, and vendors who claim one are overstating what the report is.
There is no single universal mandate, but in practice agencies handling OFFICIAL and above routinely expect an IRAP assessment report as part of their authorisation process, and tenders increasingly ask for one up front. Ask your target buyers what classification they will hold in your service and what assurance artefacts their authorising officer requires.
IRAP assesses your system against the ISM and produces an assessment report. The Hosting Certification Framework certifies hosting providers and facilities, with a focus on sovereignty and control of the hosting supply chain. They are complementary: one covers your service, the other covers where it physically and legally lives.
As a planning estimate: months of elapsed time end to end, with preparation usually the longest phase. The assessor's engagement itself typically spans weeks of effort within a longer window, and PROTECTED runs longer than OFFICIAL. Unready organisations add remediation and re-test cycles on top.
No. Only an ASD-endorsed IRAP assessor can perform an IRAP assessment. What software can legitimately do is compress the expensive part you control: maintaining the ISM control set, chaining evidence to every control, and keeping your posture SAR-shaped so the assessor spends their days verifying rather than excavating. That preparation layer is what CyberSentien provides.
Every capability referenced on this page is live on the CyberSentien engine — see it on the always-live gated demo. Nothing on this page is legal advice.