What is IRAP readiness software? (2026)

IRAP readiness software is tooling that keeps your ISM control posture continuously assessed, evidence-chained and SAR-shaped, so an ASD-endorsed IRAP assessor spends their paid days verifying your claims rather than excavating your filing. It does not perform the assessment — no software does — and there is no "IRAP certified" badge at the end. This page defines the category honestly: what the software does, what it cannot do, and how to evaluate it.

By Aneis Samaan, founder of CyberSentien · Last updated July 2026

First, what an IRAP assessment is — and why software cannot do one

IRAP is the Infosec Registered Assessors Program, run by the Australian Signals Directorate. An IRAP assessor is an ASD-endorsed individual — a person, not a product — who assesses your system against the controls in the Information Security Manual (ISM) and produces a security assessment report (SAR) that informs a government authorising officer's risk decision.

Two boundaries follow, and every honest vendor should state them up front:

No software performs an IRAP assessment. Only an ASD-endorsed IRAP assessor can. A tool that implies it can "do your IRAP" is selling something the program does not permit it to sell.

There is no "IRAP certified" badge. ASD is explicit that IRAP assessors do not accredit, certify, endorse or register systems on its behalf. The output of an assessment is a report, and the risk decision belongs to the accepting agency. Any vendor — of readiness software or anything else — claiming to be "IRAP certified" is using inaccurate shorthand. We unpack this in our IRAP assessment cost guide.

So the category name is precise: readiness software. It works on the side of the engagement you control — which happens to be where most of the cost and delay lives.

What IRAP readiness software actually does

Stripped of marketing, the category does five concrete jobs:

JobWhat it looks like in practice
Control applicabilityEvery ISM control marked in scope, out of scope or not applicable for your boundary and classification, with a reason per exclusion — the applicability statement an assessor asks for on day one.
Per-control evidence chainingEach in-scope control linked to its claim and a dated artefact — configuration export, log extract, policy — so "show me" is answered with a link, not a meeting.
ISM release ingestionASD revises the ISM on a quarterly cadence, and the releases are not cosmetic: the June 2026 release added roughly 20 new controls — including AI-related and cyber threat intelligence controls — and removed none. The software ingests each release so your catalogue is never a stale PDF export.
Delta re-assessmentWhen a release lands, the tool shows which in-scope controls changed, which new controls apply, and which evidence still holds — a targeted delta, not a restart. See our breakdown of the June 2026 ISM changes.
SAR-shaped reportingOutput structured the way a security assessment report is structured — control by control, implementation status, supporting evidence — so the handover from your preparation to the assessor's report is a translation of inches, not miles.

The economic logic is simple. Assessors are scarce specialists billed by the day, and every hour they spend chasing a missing artefact is an hour you pay for. Readiness software moves that work from assessor-time to your-time, done once and kept current.

What it cannot do

The category's failure mode is overclaiming, so here is the negative space, stated plainly:

It cannot assess you. The SAR that matters is written by the ASD-endorsed human who examined your system. Software output is an input to that engagement, never a substitute.

It cannot make an unimplemented control implemented. A dashboard can render a control green; only your engineers can make it true. This is why our own engine refuses the shortcut: a control with no evidence renders "manual assessment required", because a false green discovered by an assessor costs more than an honest gap ever did.

It cannot decide your classification or your boundary. Whether your buyers need OFFICIAL or PROTECTED handling, and where your system boundary sits, are decisions between you and your government customers. Software operationalises those decisions; it does not make them.

It cannot speak for the authorising officer. Even a flawless SAR is advice to a risk owner, and acceptance is theirs.

Spreadsheet, build, or buy

Here is the decision run honestly:

SpreadsheetBuild internallyBuy readiness software
Upfront costNear zeroHigh: engineering time against a moving standardLicence cost, live from week one
ISM currencyManual re-keying every quarterly release; drift is the normYours to maintain forever, four releases a yearVendor ingests each release; verify they actually do, and how fast
Evidence lineageFilenames and good intentions; unverifiable at assessment timePossible, but you are now building an evidence platform, not your productShould be native: timestamps and cryptographic lineage per artefact
Honest fitGenuinely fine for a first gap self-check on a small boundaryRational only if compliance tooling is your businessRational once assessor days, re-test cycles and quarterly drift cost more than the licence
Best forVery early triageVendors of GRC softwareTeams heading toward a real assessor engagement

The spreadsheet deserves respect: it is how most IRAP journeys legitimately begin. It fails at the same predictable point — the first quarterly ISM release after you filled it in, and the first time an assessor asks when an artefact was captured and by whom.

Where the assessor and the Hosting Certification Framework fit around it

Readiness software is one layer of a three-layer picture for anyone selling hosted services to Australian government:

The assessor examines your system against the ISM and writes the SAR. Good tooling makes that engagement shorter; it changes nothing about who holds the pen.

The Hosting Certification Framework, administered by the Department of Home Affairs, certifies hosting providers and data centres rather than your application, focusing on ownership, control and sovereignty of the hosting supply chain — and note that new certifications under the framework have been paused since 3 November 2025 while the Australian Government reforms it. IRAP does not certify your data centre; HCF does not assess your software. Agencies routinely want both questions answered.

Readiness software sits underneath both, keeping the ISM posture and evidence current between engagements, so the assessor's next visit — and the next quarterly release — is a delta, not an excavation.

How to evaluate IRAP readiness software

A disclosure before the advice: we build CyberSentien, so read this as a vendor's guidance — we have kept every claim about other tools to their own public positioning. The category spans tools built for different jobs. Vanta, for instance, positions itself primarily around automated compliance monitoring for frameworks like SOC 2, ISO 27001 and HIPAA; 6clicks, an Australian-built GRC platform, publicly focuses on ISM and IRAP content for government buyers and offers sovereign-cloud and appliance deployment. Whatever you shortlist, test five things:

1. Evidence lineage, not evidence storage. A folder of PDFs is storage. Lineage means every artefact carries a timestamp and a cryptographic fingerprint, so nobody can silently swap or backdate what the assessor relies on.

2. ISM currency you can date. Ask which ISM release the tool reflects today, and how quickly the catalogue updates after ASD publishes. A vague answer means a stale catalogue.

3. Delta re-assessment. When a release lands, does the tool show you precisely which of your in-scope controls changed — or do you diff two PDFs yourself?

4. Refusal behaviour. What does the tool render when a control has no evidence? If the answer is a green tick, you are buying the false confidence an assessor is paid to puncture.

5. Sovereignty of the tool itself. Your readiness platform will hold your system security plan, your control gaps and your evidence artefacts — a concentrated map of your weaknesses. An offshore-hosted readiness tool holding that PROTECTED-adjacent material is its own risk conversation, and one your assessor and agency buyers may well start. Ask where the tool runs and under whose law; our position is on the sovereignty page.

Where CyberSentien sits in this category

CyberSentien is an Australian sovereign-hosted GRC assurance platform that assesses Essential Eight, ISM/IRAP, APRA CPS 230/234, ISO 27001/42001 and SOC 2, and never marks a control compliant without timestamped, SHA-256-lineaged evidence. We are not IRAP assessors, we do not perform assessments, and we never will — that is the endorsed human's job. The engine does the five jobs above with the refusal behaviour built in: no evidence means "manual assessment required", never a fabricated pass, and every report is tamper-evident. Each quarterly ASD release is ingested — including June 2026 — with delta re-assessment against your existing posture.

Rather than take our word for it, the engine is on a live gated demo — real engine, synthetic sample library, watermarked outputs, no data retained. Pricing is on the pricing page; architecture is on the platform page.

See the live gated demo What an assessment actually costs

Frequently asked questions

Does IRAP readiness software perform the IRAP assessment?

No. Only an ASD-endorsed IRAP assessor — a person endorsed under the Australian Signals Directorate's program — can perform an IRAP assessment and produce the security assessment report. Readiness software prepares the material that assessor verifies: control applicability, evidence chains and SAR-shaped posture.

Is there an "IRAP certified" badge software can earn?

No. ASD states that IRAP assessors do not accredit, certify, endorse or register systems on its behalf. The output of an assessment is a report that informs an authorising officer's risk decision. Treat any "IRAP certified" claim, from any vendor, as inaccurate shorthand.

Can I just use a spreadsheet instead?

For a first gap self-check on a small system boundary, honestly, yes. Spreadsheets break down at ISM release time — ASD revises the manual quarterly, and the June 2026 release alone added roughly 20 new controls — and at assessment time, when an assessor asks when each artefact was captured and by whom, and a filename cannot answer.

How should readiness software handle quarterly ISM releases?

It should ingest each ASD release promptly, tell you exactly which of your in-scope controls changed, which new controls apply to your system, and which existing evidence still holds — a targeted delta re-assessment rather than a restart. Ask any vendor which ISM release their catalogue reflects today.

Does the readiness tool itself need to be sovereign-hosted?

There is no universal mandate, but consider what the tool holds: your system security plan, control gaps and evidence — a concentrated map of your weaknesses. Where that data lives, under whose jurisdiction, is a question your agency buyers and assessor may ask, so ask it of your tooling first.

Every capability referenced on this page is live on the CyberSentien engine — see it on the always-live gated demo. Nothing on this page is legal advice.