IRAP Readiness

Stage-based preparation for IRAP assessment

IRAP readiness is separate from formal assessment. It is a structured, assessor-led process to prepare your organisation, identify gaps, and build confidence before committing to formal assessment.

Three Stages of Readiness

Start where you are. Each stage builds on the previous, but you can enter at any point based on your current preparation level.

1 Exploring IRAP

Orientation and expectation setting

For organisations beginning their IRAP journey. Get clarity on what IRAP involves, what assessors look for, and whether you are ready to proceed.

What is Included

  • + Initial orientation session
  • + High-level artefact review
  • + IRAP pathway overview
  • + Summary findings and recommendations
  • + Next steps guidance

What is Not Included

  • - Detailed document review
  • - Evidence gap analysis
  • - Remediation support
  • - Formal assessment activities

Inputs Required

  • • Existing security documentation (if any)
  • • System architecture overview
  • • Key stakeholder availability for orientation

Outcomes

  • ✓ Clear understanding of IRAP requirements
  • ✓ Realistic assessment of current readiness
  • ✓ Recommended pathway forward
  • ✓ Identified priority areas for preparation
Typical effort
1-2 days(adjusted by scope)

2 Partially Prepared

Targeted review and gap identification

For organisations that have started preparation but need targeted guidance. Identify priority gaps and understand what evidence assessors will expect.

What is Included

  • + Targeted document review
  • + Priority gap identification
  • + Evidence expectations briefing
  • + Gap remediation roadmap
  • + Readiness status report

What is Not Included

  • - Formal IRAP assessment
  • - Evidence creation or authoring
  • - Technical implementation
  • - Policy writing

Inputs Required

  • • Current policies and procedures
  • • System documentation
  • • Existing risk assessments
  • • Subject matter expert availability

Outcomes

  • ✓ Prioritised gap analysis
  • ✓ Clear evidence requirements
  • ✓ Remediation roadmap with effort estimates
  • ✓ Improved understanding of assessment expectations
Typical effort
3-6 days(adjusted by scope)

3 Committed to IRAP

Pre-assessment preparation and validation

For organisations committed to IRAP assessment. Comprehensive preparation including mock walkthroughs and evidence validation before formal assessment.

What is Included

  • + Comprehensive documentation review
  • + Pre-assessment evidence support
  • + Mock assessment walkthroughs
  • + Evidence gap remediation guidance
  • + Assessment readiness report
  • + Assessor briefing pack

What is Not Included

  • - Formal IRAP assessment (separate engagement)
  • - Hands-on technical remediation
  • - Policy or procedure authoring
  • - Implementation of security controls

Inputs Required

  • • Complete system documentation
  • • All relevant policies and procedures
  • • Evidence repository access
  • • Technical staff availability for walkthroughs
  • • Dedicated project lead

Outcomes

  • ✓ Validation of assessment readiness
  • ✓ Resolved evidence gaps
  • ✓ Staff prepared for assessor interviews
  • ✓ Confidence going into formal assessment
Typical effort
6-12 days(adjusted by scope)

Not sure which stage fits?

Contact us and we will help you figure out where to start based on your current situation.

Get in Touch