IRAP Readiness for Web Applications & Cloud, Australia
Discover
Map goals, users, constraints, existing systems, and the business case before scope locks in.
Design
Shape the architecture, delivery plan, risk register, and success measures around your operating reality.
Build
Ship focused increments with working demos, testing, accessibility checks, and security review.
Support
Monitor, maintain, document, and improve the platform so your team can rely on it long term.
Nano Solutions gets web applications and the cloud environments under them ready for an IRAP assessment: ISM-aligned architecture, the controls implemented, and the evidence assembled. We are not an assessor, and we say so on this page rather than in the fine print. Fremantle-based, WA Government CUAICTS2021 ICT panel supplier (Contractor #225).
What we cover, and what we don't
We build and operate web applications and the cloud infrastructure they run on. That is the layer we can take responsibility for, so it is the only layer we offer here.
We cover:
- The web application itself — identity and access, session handling, encryption in transit and at rest, logging, secure development practice.
- The cloud environment it runs in — segmentation, hardening, patching, backup and restore, administrative access.
- ISM control selection and the documentation and evidence an assessor will ask for.
- Remediating what an assessment finds, on the systems we can reach.
We do not cover:
- The assessment itself. We are not an ASD-endorsed IRAP assessor. The assessment must be performed by one, and it should not be performed by whoever built the system.
- Gateway systems and ICT outsourced service provider assessments. Both must be assessed by an ASD-endorsed assessor and neither is our work.
- SECRET and above. Our experience is at OFFICIAL, OFFICIAL: Sensitive and PROTECTED.
- Physical security, personnel vetting and facilities. These fall inside an assessment boundary and we are not the people to advise on them.
If your problem is mostly one of the things in the second list, the honest answer is that you want somebody else, and we will say so on the first call.
What an IRAP assessment actually is
IRAP — the Infosec Registered Assessors Program, run by the Australian Signals Directorate — is the process under which an ASD-endorsed assessor evaluates a system's security controls against the Australian Government Information Security Manual (ISM). Cloud services, ICT outsourced service providers and gateway systems have to be assessed this way, and Commonwealth entities also procure assessor services for their own systems deployed to cloud.
Worth being precise about one thing, because it is widely misunderstood: an IRAP assessment is not a certification and not an accreditation. ASD does not accredit, certify, endorse or register systems under IRAP, and neither do assessors. The output is an independent assessment of a system's security posture against the ISM, which the responsible authority then uses to make its own risk decision. Any vendor telling you they will make your system "IRAP certified" is describing something that does not exist.
What "scope" means
An assessment covers a defined system boundary, not a company. That boundary includes the environments in play — production, pre-production, test and development — the classification of the data being handled, and the people, processes, technologies and facilities the system relies on. Which is why the answer to "how much of this is your part?" is usually "the application and its cloud environment, and not the rest".
How IRAP relates to the ISM and the Essential Eight
These three fit together: the ISM is the control catalogue; the Essential Eight is a prioritised baseline of mitigations within it; and IRAP is the assessment process that evaluates a system against the ISM. Getting your Essential Eight maturity and ISM alignment right is most of the readiness work, so that is where we start.
How we work
- Gap analysis — assess the application and its environment against the relevant ISM controls and your target classification; produce a clear findings register.
- Roadmap — a prioritised, costed remediation plan to reach assessment readiness.
- Remediation (we do it) — implement the controls: identity and access, network segmentation, encryption, logging, hardening, backups.
- Evidence & documentation — assemble the System Security Plan inputs and evidence an assessor expects for our part of the boundary.
- Assessment support — work alongside your chosen ASD-endorsed IRAP assessor and remediate the findings that belong to us.
Who this is for
Australian government entities and their suppliers running web applications that handle government data, typically at OFFICIAL: Sensitive or PROTECTED. As a WA Government CUAICTS2021 panel supplier working with government agencies, this is core ground for us — with Australian-resident engineers and Australian data sovereignty throughout.
It fits best when we also built or now operate the system, because readiness work is mostly engineering rather than paperwork, and the team that can change the code is the team that can close the gaps.
Typical investment
- ISM gap analysis & readiness roadmap: from $8,000, scoped to the application, its environment and your target classification.
- Remediation & control implementation: scoped from the roadmap.
- Assessment support & ongoing compliance: retainer-based.
All prices AUD, exclude GST. Every engagement starts with a free 30-minute scoping call. Book an IRAP readiness conversation.
Frequently Asked Questions
What is an IRAP assessment?
IRAP (the Infosec Registered Assessors Program) is the ASD process under which an ASD-endorsed assessor evaluates a system's security controls against the Australian Government Information Security Manual (ISM). Cloud services, ICT outsourced service providers and gateway systems must be assessed this way, and Commonwealth entities also procure assessor services for their own systems deployed to cloud.
Is an IRAP assessment a certification?
No, and it is worth being clear about. ASD does not accredit, certify, endorse or register systems under IRAP, and neither do assessors. An assessment is an independent evaluation of a system's security posture against the ISM; the responsible authority then makes its own risk decision. Nobody can make a system "IRAP certified", so treat that phrase as a warning sign.
Does Nano perform the IRAP assessment itself?
No. We are not an ASD-endorsed IRAP assessor. We do the readiness and remediation: ISM-aligned architecture, control implementation, and the evidence an assessor asks for. The assessment is performed by an endorsed assessor you engage. That separation is healthy, because the people who built a system should not be the people assessing it.
What parts of a system does Nano cover?
The web application and the cloud environment it runs in: identity and access, encryption, logging, segmentation, hardening, patching, backup and restore, and the documentation for those controls. We do not cover gateway systems, ICT outsourced service provider assessments, SECRET-level work, or the physical security, facilities and personnel vetting that also sit inside an assessment boundary.
What does the scope of an assessment include?
A system boundary rather than a company: the environments in play (production, pre-production, test and development), the classification of the data handled, and the people, processes, technologies and facilities the system relies on. Our part is usually the application and its cloud environment, which is one component of that boundary.
How does IRAP relate to the Essential Eight and the ISM?
The ISM is the control catalogue; the Essential Eight is a prioritised baseline within it; IRAP is the assessment process that evaluates a system against the ISM. We align you to the ISM and Essential Eight first, which is most of the readiness work.
How long does IRAP readiness take?
It depends on the system's size and current maturity. We start with a gap analysis against the ISM, then a costed remediation roadmap; most readiness programmes run over several weeks to a few months before the formal assessment.
Have a question that's not listed here? We're happy to help.
Ask Us AnythingFurther Reading
- Cyber security consulting — the full security advisory practice.
- Essential Eight compliance — the baseline most of IRAP readiness builds on.
- Government — how we work with Australian government agencies.
Last reviewed: August 2026
Ready to Get Started?
Book a free discovery call to discuss your project. No obligation, no jargon — just a conversation about what you need.