Closed

ASD IRAP Assessor Market Availability

Tender ID: 599393


Tender Details

Tender #:
ASD-COM-2025-83-IRAP  
Status:
Closed
Publish Date:
5 November 2025
Closing Date:
5 January 2026
Closing Time:
12:00 PM (Australia/ACT)

Tender Description

The sole purpose of this Request For Information (RFI) is to obtain information in connection with ASD IRAP Assessor Market Availability, it is not a procurement and does not form part of any Commonwealth procurement process.

ASD is seeking a request for information (RFI) across the market on available Infosec Registered Assessors Program (IRAP) qualified individuals to act as a surge workforce in assessing a range of Australian Government ICT systems.

a. Systems range in classifications from OFFICIAL: Sensitive to TOP SECRET and will require assessors to hold current and active clearances.

b. Systems range in technical complexity and provision of services across government.

c. System assessments vary in duration pending system complexity.

STATEMENT OF NEEDS (CORE)

ASD requires suitably qualified IRAP individuals to test the effectiveness of security controls in ICT systems and identify security weaknesses.

ICT systems will be discrete capabilities, but will range from cloud-based services to on premise Microsoft Windows domains along with other bespoke systems. Systems are vetted to ensure sufficient documentation exists to support the IRAP assessment processes to begin.

The assessment will be required to document findings within the existing ASD governance, risk and compliance tooling and templates. This will include provisioning of detailed reports adhering to either the Cloud Security Report Template or the IRAP Assessment Report Template.

The assessment should include clear and actionable mitigations in order to mitigate identified security weaknesses.

ASD will co-ordinate and manage the assessment activities in line with existing internal arrangements.

Individuals should be:

a. TSPV

b. Hold an IRAP Certification

c. Have demonstrated IRAP experience

d. Hold other relevant cyber security certifications.