---
title: "Securing the Australian Government Software Supply Chain: JFrog Completes Protected Level IRAP Assessment"
url: https://daily.dev/posts/securing-the-australian-government-software-supply-chain-jfrog-completes-protected-level-irap-asses-3mlpk8apn
source_url: https://jfrog.com/blog/securing-the-australian-government-software-supply-chain-jfrog-completes-protected-level-irap-assessment
type: article
source: "JFrog"
published: 2026-08-27T01:32:59.754Z
updated: 2026-08-27T01:33:26.352Z
tags: ["compliance", "devsecops", "jfrog"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Securing the Australian Government Software Supply Chain: JFrog Completes Protected Level IRAP Assessment

**[JFrog](https://daily.dev/sources/jfrog)** · 5 min read · 0 upvotes · 0 comments

## Summary

JFrog announced it completed an IRAP (Infosec Registered Assessors Program) assessment at the Protected level for the entire JFrog Platform, conducted by CyberCX against Australia's ISM standard. The assessment covers the full software supply chain lifecycle - from open-source ingestion and binary management to vulnerability scanning, policy control, signed distribution, and runtime monitoring - across AWS, Azure, and Google Cloud in Australian sovereign regions. The post explains that IRAP is an assessment (not a certification), distinct from global certifications like ISO 27001 and SOC 2, and is effectively mandatory for vendors handling government data classified OFFICIAL or above. The assessment report is available to Australian government agencies and regulated organizations through the JFrog Trust Center to support their own Authority to Operate decisions.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://jfrog.com/blog/securing-the-australian-government-software-supply-chain-jfrog-completes-protected-level-irap-assessment>

## Questions this post answers

### What is the difference between IRAP-assessed and IRAP-certified?

IRAP is an assessment, not a certification, so there is no IRAP certificate to earn. ASD-endorsed assessors evaluate a system against Australia's Information Security Manual and produce an independent report, which each government agency then uses to make its own Authority to Operate decision. The accurate phrasing is therefore 'IRAP-assessed' rather than 'IRAP-certified,' and one strong assessment can support multiple agencies' ATO decisions.

_Teams navigating vendor compliance claims can track supply chain security standards like IRAP on daily.dev._

### Why don't ISO 27001 or SOC 2 Type II satisfy Australian government security requirements?

ISO 27001 and SOC 2 Type II validate a security program globally, but they don't address the prescriptive controls in Australia's Information Security Manual (ISM) that IRAP assessments check against. For systems handling government data classified OFFICIAL or above, an IRAP assessment at the right level is effectively mandatory for procurement regardless of what global certifications a vendor already holds.

_Engineers comparing compliance frameworks for regulated markets can follow standards coverage on daily.dev._

## Similar posts on daily.dev

- [Datadog achieves IRAP’s PROTECTED status in Australia](https://daily.dev/posts/datadog-achieves-irap-s-protected-status-in-australia-1z7yi5lum) · Datadog · 0 upvotes · 0 comments
- [Using JFrog to Align Your Systems for ISO 27001 Compliance](https://daily.dev/posts/using-jfrog-to-align-your-systems-for-iso-27001-compliance-4t2rnyr6d) · JFrog · 2 upvotes · 0 comments

---

Tags: [#compliance](https://daily.dev/tags/compliance), [#devsecops](https://daily.dev/tags/devsecops), [#jfrog](https://daily.dev/tags/jfrog)

[View this post on daily.dev](https://daily.dev/posts/securing-the-australian-government-software-supply-chain-jfrog-completes-protected-level-irap-asses-3mlpk8apn)
