Securing the Australian Government Software Supply Chain: JFrog Completes Protected Level IRAP Assessment

For Australian government agencies and regulated entities, software supply chain security is no longer an abstract architectural discussion- it’s a matter of national resilience

JFrog has reached a major milestone: An IRAP assessment at the Protected level, across the full JFrog Platform. Conducted by CyberCX, an Australian Signals Directorate (ASD)-endorsed assessor, against the ISM, it independently validates that the platform managing an agency’s software supply chain meets the bar for Australia’s most sensitive workloads. It reasserts a commitment that runs through everything we build: that security is not a feature bolted on at the end, but the foundation the platform stands on.

For years, “security assurance” meant checking the perimeter and the finished application. That is no longer where the risk lives. Attackers have moved upstream, into the binaries, dependencies, container images, and now the AI models that flow into production before anyone runs them. A single compromised component can put an entire system at risk, and for the government, an entire mission.

This is the shift that matters: securing the software supply chain has quietly stopped being a technical housekeeping task and become a governance obligation,  one that belongs in the same conversation as national resilience. Government is where that is clearest, and where the standards are highest.

What IRAP is – and what it is not

IRAP, the Infosec Registered Assessors Program, is how the Australian Government independently evaluates whether a system is secure enough to handle its data. ASD-endorsed assessors evaluate the system against the ISM – the government’s cybersecurity rulebook, built around four principles (Govern, Protect, Detect, Respond) and updated quarterly.

One distinction is worth getting right, because it changes how you read a vendor’s claims: IRAP is an assessment, not a certification. There is no IRAP certificate. The output is an independent report against the ISM, which each agency then uses to make its own Authority to Operate (ATO) decision. The assessor evaluates; the agency decides. So the accurate phrase is “IRAP-assessed,” not “IRAP-certified” – and one strong assessment can support many agencies’ ATO decisions without each starting from a blank page.

Why IRAP matters specifically for Australian government

Government teams face a real bind: they must deliver software at pace while meeting sovereign compliance requirements that do not bend. IRAP sits at that intersection. For any system handling government data classified at OFFICIAL or above, an assessment is effectively mandatory – without one at the right classification level, a vendor cannot clear procurement, regardless of its global credentials.

But reading IRAP as a procurement hurdle misses the point. It is an assurance gate: it exists so agencies can be confident a vendor’s controls are real and working before trusting it with sensitive data. And it does not stand alone – it works alongside the Hosting Certification Framework, which governs data sovereignty and hosting. That regime is tightening: in April 2026 the Department of Home Affairs moved to strengthen it further. The direction of travel is unmistakable – the assurance bar is rising, and supply chain is squarely in scope.

This is also why global certifications do not substitute for it. ISO 27001 and SOC 2 Type II establish and validate a security programme worldwide – and JFrog holds them, alongside ISO 27017, ISO 27701 and other standards – but the ISM carries prescriptive Australian Government controls neither addresses. IRAP is the layer that proves a programme meets Australia’s own bar.

Where JFrog fits – Securing the Software Supply Chain for Government

Securing the software supply chain is what JFrog is all about. In fact, Gartner recently published its first-ever Magic Quadrant for Software Supply Chain Security, and JFrog was named a Leader, placed highest for Ability to Execute. Today the JFrog Platform runs at scale for over 80% of the Fortune 100.

That is what makes this assessment significant. Where many vendors can show an assessment covering one part of the stack, JFrog puts its entire software supply chain platform through IRAP at the Protected level. From open-source ingestion and binary management, through vulnerability scanning and policy control, all the way through signed distribution and runtime monitoring.

Being assessed is not JFrog clearing a hurdle, it is a demonstration of what end-to-end software supply chain governance looks like when it is held to a national standard.

Platform-wide assurance

The assessment covered the entire JFrog Platform, spanning every critical phase of the software supply chain, on every major cloud – giving the Australian government a single, unbroken line of assurance.

It is important to note that assurance is not dependent on which infrastructure the workload is running, as JFrog delivers the same Protected-level assurance across AWS, Azure, and Google Cloud, in Australian sovereign regions. Agencies are not forced to trade security for hosting choice as multi-cloud and hybrid strategies stay open, and sovereignty stays intact. One platform, one assessment, the whole supply chain, on the cloud of your choice.

What it means for Australian public sector leaders

  • The evidence is ready. The independent, ASD-aligned assessment report is available on request through the JFrog Trust Center to support your own ATO decision – no months-long controls review from scratch.
  • Coverage is end-to-end. Software supply chain security cannot be solved with fragmented point tools; JFrog covers the full lifecycle under one unified assessment, reducing vendor sprawl and audit overhead.
  • Assurance is the accelerant. Because the heavy lifting is done, agencies move to their ATO decision faster – better assurance, less friction, quicker time to value.

 

Request the assessment report or talk to our team: The JFrog Platform IRAP assessment report is available to Australian government agencies and regulated organisations through the JFrog Trust Center. Contact your JFrog account manager to arrange access, or to speak with one of our public sector specialists about securing your software supply chain to meet IRAP Protected requirements.