Most platforms can only point to their cloud host's IRAP assessment, not their own. That gap carries real weight in tenders, though exact requirements vary by procurement and agency. Kiteworks closed it in 2022, reassessed in 2024 and 2026, for the Kiteworks platform. A-LIGN, now home to AssurePoint's ASD-endorsed IRAP assessors, unpacks what's still open: getting your own environment independently assessed too.
Has held an application-level IRAP PROTECTED assessment since 2022, reassessed in 2024 and 2026, not one inherited from a cloud host. It covers the platform's own data handling, access control, and system management, the layer most vendor claims quietly skip. That assessment covers the Kiteworks platform itself, alongside SOC 2 Type II, FedRAMP High (In Process), and ISO 27001/17/18 certifications, and 90% of CMMC 2.0 Level 2 controls met out of the box.
Independently assesses your own environment and system boundary, implementation, integrations, and residual risk, through ASD-endorsed IRAP assessors added via its acquisition of AssurePoint, alongside FedRAMP, SOC 2, ISO 27001/42001, and CMMC assessments. One partner, one evidence set, across every framework you're already tracking. Because Kiteworks already meets so much of the underlying control set, that assessment moves faster for organizations already running the platform.
Shauneel and Rohan get into what actually separates an application-level assessment from an inherited one, and how to read a vendor's IRAP claim, or your own path to one, with that distinction in mind.
Moderated by Frank Balonis, CISO, Kiteworks.