IRAP readiness software is tooling that keeps your ISM control posture continuously assessed, evidence-chained and SAR-shaped, so an ASD-endorsed IRAP assessor spends their paid days verifying your claims rather than excavating your filing. It does not perform the assessment — no software does — and there is no "IRAP certified" badge at the end. This page defines the category honestly: what the software does, what it cannot do, and how to evaluate it.
By Aneis Samaan, founder of CyberSentien · Last updated July 2026
IRAP is the Infosec Registered Assessors Program, run by the Australian Signals Directorate. An IRAP assessor is an ASD-endorsed individual — a person, not a product — who assesses your system against the controls in the Information Security Manual (ISM) and produces a security assessment report (SAR) that informs a government authorising officer's risk decision.
Two boundaries follow, and every honest vendor should state them up front:
No software performs an IRAP assessment. Only an ASD-endorsed IRAP assessor can. A tool that implies it can "do your IRAP" is selling something the program does not permit it to sell.
There is no "IRAP certified" badge. ASD is explicit that IRAP assessors do not accredit, certify, endorse or register systems on its behalf. The output of an assessment is a report, and the risk decision belongs to the accepting agency. Any vendor — of readiness software or anything else — claiming to be "IRAP certified" is using inaccurate shorthand. We unpack this in our IRAP assessment cost guide.
So the category name is precise: readiness software. It works on the side of the engagement you control — which happens to be where most of the cost and delay lives.
Stripped of marketing, the category does five concrete jobs:
| Job | What it looks like in practice |
|---|---|
| Control applicability | Every ISM control marked in scope, out of scope or not applicable for your boundary and classification, with a reason per exclusion — the applicability statement an assessor asks for on day one. |
| Per-control evidence chaining | Each in-scope control linked to its claim and a dated artefact — configuration export, log extract, policy — so "show me" is answered with a link, not a meeting. |
| ISM release ingestion | ASD revises the ISM on a quarterly cadence, and the releases are not cosmetic: the June 2026 release added roughly 20 new controls — including AI-related and cyber threat intelligence controls — and removed none. The software ingests each release so your catalogue is never a stale PDF export. |
| Delta re-assessment | When a release lands, the tool shows which in-scope controls changed, which new controls apply, and which evidence still holds — a targeted delta, not a restart. See our breakdown of the June 2026 ISM changes. |
| SAR-shaped reporting | Output structured the way a security assessment report is structured — control by control, implementation status, supporting evidence — so the handover from your preparation to the assessor's report is a translation of inches, not miles. |
The economic logic is simple. Assessors are scarce specialists billed by the day, and every hour they spend chasing a missing artefact is an hour you pay for. Readiness software moves that work from assessor-time to your-time, done once and kept current.
The category's failure mode is overclaiming, so here is the negative space, stated plainly:
It cannot assess you. The SAR that matters is written by the ASD-endorsed human who examined your system. Software output is an input to that engagement, never a substitute.
It cannot make an unimplemented control implemented. A dashboard can render a control green; only your engineers can make it true. This is why our own engine refuses the shortcut: a control with no evidence renders "manual assessment required", because a false green discovered by an assessor costs more than an honest gap ever did.
It cannot decide your classification or your boundary. Whether your buyers need OFFICIAL or PROTECTED handling, and where your system boundary sits, are decisions between you and your government customers. Software operationalises those decisions; it does not make them.
It cannot speak for the authorising officer. Even a flawless SAR is advice to a risk owner, and acceptance is theirs.
Here is the decision run honestly:
| Spreadsheet | Build internally | Buy readiness software | |
|---|---|---|---|
| Upfront cost | Near zero | High: engineering time against a moving standard | Licence cost, live from week one |
| ISM currency | Manual re-keying every quarterly release; drift is the norm | Yours to maintain forever, four releases a year | Vendor ingests each release; verify they actually do, and how fast |
| Evidence lineage | Filenames and good intentions; unverifiable at assessment time | Possible, but you are now building an evidence platform, not your product | Should be native: timestamps and cryptographic lineage per artefact |
| Honest fit | Genuinely fine for a first gap self-check on a small boundary | Rational only if compliance tooling is your business | Rational once assessor days, re-test cycles and quarterly drift cost more than the licence |
| Best for | Very early triage | Vendors of GRC software | Teams heading toward a real assessor engagement |
The spreadsheet deserves respect: it is how most IRAP journeys legitimately begin. It fails at the same predictable point — the first quarterly ISM release after you filled it in, and the first time an assessor asks when an artefact was captured and by whom.
Readiness software is one layer of a three-layer picture for anyone selling hosted services to Australian government:
The assessor examines your system against the ISM and writes the SAR. Good tooling makes that engagement shorter; it changes nothing about who holds the pen.
The Hosting Certification Framework, administered by the Department of Home Affairs, certifies hosting providers and data centres rather than your application, focusing on ownership, control and sovereignty of the hosting supply chain — and note that new certifications under the framework have been paused since 3 November 2025 while the Australian Government reforms it. IRAP does not certify your data centre; HCF does not assess your software. Agencies routinely want both questions answered.
Readiness software sits underneath both, keeping the ISM posture and evidence current between engagements, so the assessor's next visit — and the next quarterly release — is a delta, not an excavation.
A disclosure before the advice: we build CyberSentien, so read this as a vendor's guidance — we have kept every claim about other tools to their own public positioning. The category spans tools built for different jobs. Vanta, for instance, positions itself primarily around automated compliance monitoring for frameworks like SOC 2, ISO 27001 and HIPAA; 6clicks, an Australian-built GRC platform, publicly focuses on ISM and IRAP content for government buyers and offers sovereign-cloud and appliance deployment. Whatever you shortlist, test five things:
1. Evidence lineage, not evidence storage. A folder of PDFs is storage. Lineage means every artefact carries a timestamp and a cryptographic fingerprint, so nobody can silently swap or backdate what the assessor relies on.
2. ISM currency you can date. Ask which ISM release the tool reflects today, and how quickly the catalogue updates after ASD publishes. A vague answer means a stale catalogue.
3. Delta re-assessment. When a release lands, does the tool show you precisely which of your in-scope controls changed — or do you diff two PDFs yourself?
4. Refusal behaviour. What does the tool render when a control has no evidence? If the answer is a green tick, you are buying the false confidence an assessor is paid to puncture.
5. Sovereignty of the tool itself. Your readiness platform will hold your system security plan, your control gaps and your evidence artefacts — a concentrated map of your weaknesses. An offshore-hosted readiness tool holding that PROTECTED-adjacent material is its own risk conversation, and one your assessor and agency buyers may well start. Ask where the tool runs and under whose law; our position is on the sovereignty page.
CyberSentien is an Australian sovereign-hosted GRC assurance platform that assesses Essential Eight, ISM/IRAP, APRA CPS 230/234, ISO 27001/42001 and SOC 2, and never marks a control compliant without timestamped, SHA-256-lineaged evidence. We are not IRAP assessors, we do not perform assessments, and we never will — that is the endorsed human's job. The engine does the five jobs above with the refusal behaviour built in: no evidence means "manual assessment required", never a fabricated pass, and every report is tamper-evident. Each quarterly ASD release is ingested — including June 2026 — with delta re-assessment against your existing posture.
Rather than take our word for it, the engine is on a live gated demo — real engine, synthetic sample library, watermarked outputs, no data retained. Pricing is on the pricing page; architecture is on the platform page.
No. Only an ASD-endorsed IRAP assessor — a person endorsed under the Australian Signals Directorate's program — can perform an IRAP assessment and produce the security assessment report. Readiness software prepares the material that assessor verifies: control applicability, evidence chains and SAR-shaped posture.
No. ASD states that IRAP assessors do not accredit, certify, endorse or register systems on its behalf. The output of an assessment is a report that informs an authorising officer's risk decision. Treat any "IRAP certified" claim, from any vendor, as inaccurate shorthand.
For a first gap self-check on a small system boundary, honestly, yes. Spreadsheets break down at ISM release time — ASD revises the manual quarterly, and the June 2026 release alone added roughly 20 new controls — and at assessment time, when an assessor asks when each artefact was captured and by whom, and a filename cannot answer.
It should ingest each ASD release promptly, tell you exactly which of your in-scope controls changed, which new controls apply to your system, and which existing evidence still holds — a targeted delta re-assessment rather than a restart. Ask any vendor which ISM release their catalogue reflects today.
There is no universal mandate, but consider what the tool holds: your system security plan, control gaps and evidence — a concentrated map of your weaknesses. Where that data lives, under whose jurisdiction, is a question your agency buyers and assessor may ask, so ask it of your tooling first.
Every capability referenced on this page is live on the CyberSentien engine — see it on the always-live gated demo. Nothing on this page is legal advice.