JFrog Achieves IRAP PROTECTED-Level Assessment, Bringing Secure Software Supply Chain to Australian Government Agencies
PRESS RELEASE, August 27, 2026
Australian government agencies now have independently verified evidence to accelerate Authority to Operate (ATO) decisions using the JFrog Platform
SYDNEY – August 27, 2026 – JFrog Ltd. (NASDAQ: FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, the system of record for trusted software artifacts, binaries, and AI assets, today announced the successful completion of its InfoSec Registered Assessors Program (IRAP) assessment at the PROTECTED level. This allows Australian federal, state and territory government agencies – along with critical infrastructure operators in defence, health, finance and telecommunications – to confidently adopt JFrog as their single source of truth for software delivery. The assessment was conducted against the Australian Signals Directorate’s Information Security Manual (ISM), giving agencies the independently verified evidence they need to shorten Authority to Operate (ATO) timelines across every binary, model and AI artifact in their software development lifecycle.
“With software supply chain security and governance becoming an increasing focus for Australian government departments navigating DevSecOps modernization and rigorous security guidelines, completing our IRAP assessment – PROTECTED level is a significant achievement,” said Sunny Rao, SVP APAC, JFrog. “This milestone puts the JFrog Platform on a trusted path for public sector teams, delivering the independently verified evidence that government security teams need to make fast, confident risk-authorization decisions.”
Why Now: Australia’s Focus on Cyber Resilience and Software Security
According to the JFrog 2026 Software Supply Chain Security State of the Union report, 47% of Australian organizations now automatically block unapproved AI coding assistants and IDE extensions, and 68% self-host their AI models – showing a preference for automated enforcement and AI sovereignty across their software supply chains.
In addition, Australian federal and state governments are actively raising supply chain security expectations including NSW’s 2026-2028 Cyber Security Strategy and the national shift toward Essential Eight Maturity Level 2 as a baseline for critical sectors.
Buyers in these sectors face long procurement cycles and strict vendor eligibility requirements, where an IRAP assessment is often a mandatory gate.
“Completing an IRAP assessment at the PROTECTED level holds our own platform to the same standard we help our customers meet,’ said Aran Azarzar, CIO, JFrog. “It reasserts a commitment that runs through everything we build: that security is not a feature bolted on at the end, but the foundation the platform stands on.”
With the JFrog Platform independently assessed at the PROTECTED level, Australian government and regulated organisations can now:
- Shorten Authority to Operate timelines – the JFrog Platform IRAP assessment report gives agency security teams the independently verified evidence they need to make risk-authorisation decisions without starting from scratch.
- Govern AI with the same rigour as any other binary, applying continuous policy enforcement to AI models, generated code, and third-party dependencies.
- Replace manual approval workflows with automated policy gates and immutable evidence trails that stand up to audit.
- Consolidate on a single source of truth for every artifact – from developer through to production.
- Meet transparency and compliance requirements with detailed SBOMs and VEX support aligned to CycloneDX and SPDX 3.0 standards.
Scope of the Assessment
The assessment covered the JFrog Platform end-to-end – including JFrog Artifactory as the system of record and single source of truth for every binary, dependency, and build artifact, JFrog Curation for open-source ingestion control, and JFrog Advanced Security for automated security scanning, through AI model governance, verifiable policy enforcement, and SBOM evidence aligned to CycloneDX and SPDX 3.0.
For a deeper look at what the IRAP assessment means for Australian government software supply chains – and how JFrog’s PROTECTED-level controls map to ISM requirements – read the full blog.
The JFrog Platform IRAP assessment report is available to Australian government agencies and regulated organisations through the JFrog Trust Center. To obtain a copy, contact your JFrog account manager.
###
Like this Story? Share this on X: The @JFrog Software Supply Chain Platform has completed its #IRAP assessment at the Protected level! JFrog provides Australian government agencies and regulated entities with the validated evidence needed to secure their binary pipelines. Learn more: frog.com/trust #DevSecOps #DevGovOps #cybersecurity
About JFrog
JFrog Ltd. (NASDAQ: FROG), the creators of the unified DevOps, DevSecOps, DevGovOps, and MLOps platform, is on a mission to create a world of software delivered without friction from development to production. Driven by a “Liquid Software” vision, the JFrog Platform is a software supply chain system of record that is designed to power organisations as they build, manage, and distribute secure software with speed and scale. Holistic security features help identify, protect, and remediate against threats and vulnerabilities. The universal, hybrid, multi-cloud JFrog Platform is available as both SaaS services across major cloud service providers and self-hosted. Millions of users and approximately 6,600 organisations worldwide, including a majority of the Fortune 100, depend on JFrog solutions to securely embrace digital transformation in the AI era. Learn more at jfrog.com or follow us on X @JFrog.
Media Contact: Srishti Upadhyay, Communications Manager, APAC, JFrog, srishtiu@jfrog.com
Investor Contact: Jeff Schreiner, VP of Investor Relations, jeffS@jfrog.com
