×
Register
LIVE WEBINAR · THU, OCT 29, 2026 · 9:00 AM AEDT · 45 MINUTES

The IRAP gap: what "assessed" should actually mean

Most platforms can only point to their cloud host's IRAP assessment, not their own. That gap carries real weight in tenders, though exact requirements vary by procurement and agency. Kiteworks closed it in 2022, reassessed in 2024 and 2026, for the Kiteworks platform. A-LIGN, now home to AssurePoint's ASD-endorsed IRAP assessors, unpacks what's still open: getting your own environment independently assessed too.

Reserve my seat →

2x the cost
What unprepared organizations end up paying for one IRAP assessment, once remediation and a second round of testing get added after failing the first pass
12 to 18 mo
Runway to budget for a first IRAP assessment in 2026, even as the assessor market keeps growing
Often Required
A current IRAP report, expected before shortlisting on many Commonwealth and state tenders for PROTECTED-level SaaS, though exact requirements vary by procurement and agency
WHY KITEWORKS AND A-LIGN ARE RUNNING THIS SESSION
Kiteworks

Has held an application-level IRAP PROTECTED assessment since 2022, reassessed in 2024 and 2026, not one inherited from a cloud host. It covers the platform's own data handling, access control, and system management, the layer most vendor claims quietly skip. That assessment covers the Kiteworks platform itself, alongside SOC 2 Type II, FedRAMP High (In Process), and ISO 27001/17/18 certifications, and 90% of CMMC 2.0 Level 2 controls met out of the box.

A-LIGN

Independently assesses your own environment and system boundary, implementation, integrations, and residual risk, through ASD-endorsed IRAP assessors added via its acquisition of AssurePoint, alongside FedRAMP, SOC 2, ISO 27001/42001, and CMMC assessments. One partner, one evidence set, across every framework you're already tracking. Because Kiteworks already meets so much of the underlying control set, that assessment moves faster for organizations already running the platform.


Shauneel Kumar
Founder, AssurePoint (part of A-LIGN)
Rohan Dutt
Director, APAC Sales Engineering, Kiteworks

Shauneel and Rohan get into what actually separates an application-level assessment from an inherited one, and how to read a vendor's IRAP claim, or your own path to one, with that distinction in mind.

Moderated by Frank Balonis, CISO, Kiteworks.

IN 45 MINUTES, YOU'LL LEARN
01How to tell an application-level IRAP assessment from an infrastructure-only one, and the questions that expose the difference.
02What the Hosting Certification Framework's registration pause and the ISM's quarterly control updates mean for your reassessment timeline, not just your first one.
03How to consolidate IRAP, FedRAMP, SOC 2, ISO 27001/42001, and CMMC onto one evidence set and one assessment partner, instead of five audits and five vendors.
04Why an already-assessed platform still leaves your own implementation, integrations, and risk-acceptance decision needing independent evidence, and why that evidence comes faster if you're already running Kiteworks.

Save your seat

Thursday, October 29, 2026 · 9:00 AM AEDT (Sydney / Melbourne / Canberra). Calendar invite sent on registration.
No spam. Just this webinar and directly related follow-ups. By registering, you agree to Kiteworks' Privacy Policy.