IRAP Readiness
Stage-based preparation for IRAP assessment
IRAP readiness is separate from formal assessment. It is a structured, assessor-led process to prepare your organisation, identify gaps, and build confidence before committing to formal assessment.
Three Stages of Readiness
Start where you are. Each stage builds on the previous, but you can enter at any point based on your current preparation level.
1 Exploring IRAP
Orientation and expectation setting
For organisations beginning their IRAP journey. Get clarity on what IRAP involves, what assessors look for, and whether you are ready to proceed.
What is Included
- + Initial orientation session
- + High-level artefact review
- + IRAP pathway overview
- + Summary findings and recommendations
- + Next steps guidance
What is Not Included
- - Detailed document review
- - Evidence gap analysis
- - Remediation support
- - Formal assessment activities
Inputs Required
- • Existing security documentation (if any)
- • System architecture overview
- • Key stakeholder availability for orientation
Outcomes
- ✓ Clear understanding of IRAP requirements
- ✓ Realistic assessment of current readiness
- ✓ Recommended pathway forward
- ✓ Identified priority areas for preparation
2 Partially Prepared
Targeted review and gap identification
For organisations that have started preparation but need targeted guidance. Identify priority gaps and understand what evidence assessors will expect.
What is Included
- + Targeted document review
- + Priority gap identification
- + Evidence expectations briefing
- + Gap remediation roadmap
- + Readiness status report
What is Not Included
- - Formal IRAP assessment
- - Evidence creation or authoring
- - Technical implementation
- - Policy writing
Inputs Required
- • Current policies and procedures
- • System documentation
- • Existing risk assessments
- • Subject matter expert availability
Outcomes
- ✓ Prioritised gap analysis
- ✓ Clear evidence requirements
- ✓ Remediation roadmap with effort estimates
- ✓ Improved understanding of assessment expectations
3 Committed to IRAP
Pre-assessment preparation and validation
For organisations committed to IRAP assessment. Comprehensive preparation including mock walkthroughs and evidence validation before formal assessment.
What is Included
- + Comprehensive documentation review
- + Pre-assessment evidence support
- + Mock assessment walkthroughs
- + Evidence gap remediation guidance
- + Assessment readiness report
- + Assessor briefing pack
What is Not Included
- - Formal IRAP assessment (separate engagement)
- - Hands-on technical remediation
- - Policy or procedure authoring
- - Implementation of security controls
Inputs Required
- • Complete system documentation
- • All relevant policies and procedures
- • Evidence repository access
- • Technical staff availability for walkthroughs
- • Dedicated project lead
Outcomes
- ✓ Validation of assessment readiness
- ✓ Resolved evidence gaps
- ✓ Staff prepared for assessor interviews
- ✓ Confidence going into formal assessment
Not sure which stage fits?
Contact us and we will help you figure out where to start based on your current situation.
Get in Touch