IRAP readiness assessments for Australian government suppliers

Get a clear, independent and evidence-based security evaluation to verify that your organisation’s systems and controls meet the Australian Government security standards.

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance

All IRAP assessments are conducted by independent assessors who evaluate systems against the Information Security Manual (ISM) and the Protective Security Policy Framework (PSPF).

Why readiness matters before certification

  1. Reduce IRAP time and cost

    IRAP assessments can be complex, costly, and time‑consuming. An IRAP readiness assessment helps you avoid misinterpretation of ISM controls and reduces rework during the formal assessment.

  2. Improve first‑time IRAP success

    By identifying gaps early, readiness assessments significantly increase the likelihood of passing IRAP on the first attempt—saving both time and assessment costs.

  3. Clear remediation roadmap

    Receive a prioritised, unambiguous remediation plan with clearly defined actions, timelines, and effort estimates to guide your path to IRAP readiness.

  4. Executive‑ready security insight

    Gain a comprehensive view of your current security posture, including an executive‑level assurance report to support informed decision‑making ahead of IRAP assessment.

How we prepare you for IRAP success

Preparing for IRAP readiness
An IRAP Readiness Assessment is the first critical step for organisations to ensure they are prepared for an IRAP assessment.

When readiness is required 
Government agencies and private companies that handle sensitive data and Government cloud service providers. 

Readiness vs full assessment 

  • IRAP certification preparation assists an organisation to successfully complete and obtain IRAP certification
  • IRAP Assessment is the process of assessing the organisation, its policies, and procedures.  

Thales brings a unique combination of sovereign Australian delivery capability and access to Thales’ global cyber business line, providing both trusted local expertise and international best practices. We have hands-on experience designing, building, and operating secure IT and OT environments for Australian Government and critical infrastructure clients, and a proven track record delivering IRAP assessments, security architecture engagements, GRC uplift programs, and SOCI compliance initiatives in complex, high-assurance environments.  

A comprehensive process from planning to completion aligned to your operational and compliance context

Related solutions

Compliance with AusPayNet annual assessment

Driving trust and resilience through AusPayNet annual security assessments.

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance

APRA CPS 234 compliance services

Your path to CPS 234 compliance.

  • Cybersecurity
  • Cybersecurity services
  • Payment cards

Achieve AESCSF compliance with expert assessment service

Strategic cyber resilience through AESCSF excellence

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance

NSW IPART audits of CILC compliance

Independent assurance of Critical Infrastructure operating licence conditions compliance

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance

Book an IRAP Readiness Assessment

Frequently Asked Questions