2026 Phase 1a IRAP report is now available on AWS Artifact for Australian customers
July 28, 2026 · AWS Security · Severity: MEDIUM
AWS has released its 2026 Phase 1a IRAP (Information Security Registered Assessors Program) report on AWS Artifact for Australian customers. An independent assessor certified by the Australian Signals Directorate (ASD) completed the evaluation in June 2026, adding four new AWS services—Amazon Bedrock AgentCore, AWS Parallel Computing Service, AWS Resilience Hub, and AWS Security Incident Response—to the PROTECTED level assessment. This brings the total number of IRAP-assessed services to 167. The report aligns with Australian government security standards, including the Information Security Manual (ISM), Protective Security Policy Framework (PSPF), and Secure Cloud Strategy. AWS also updated its IRAP documentation pack to help Australian customers and partners assess risks and architect workloads in compliance with ACSC guidelines. The pack includes the AWS Consumer Guide and whitepaper on PROTECTED workloads. AWS encourages customers to request additional services for future IRAP assessments. Patrick Chang, APJ Audit Specialist, oversees these compliance efforts, ensuring cloud security assurance for the region. This update strengthens AWS’s commitment to meeting Australian government security requirements.
Amazon Web Services (AWS) is excited to announce that the latest version of Information Security Registered Assessors Program (IRAP) report (Phase 1a – full assessment) is now available through AWS Artifact. An independent Australian Signals Directorate (ASD) certified IRAP assessor completed the IRAP assessment of AWS in June 2026.
The new IRAP report includes four additional AWS services that are now assessed at the PROTECTED level under IRAP. This brings the total number of services assessed at the PROTECTED level to 167.
The four newly assessed services are:
- Amazon Bedrock AgentCore
- AWS Parallel Computing Service
- AWS Resilience Hub
- AWS Security Incident Response
For the full list of services, see the IRAP tab on the AWS Services in Scope by Compliance Program page.
We have developed an IRAP documentation pack to help our Australian customers and their partners plan, architect, and assess risk for their workloads when they use AWS cloud services.
We developed this pack in accordance with the Australian Cyber Security Centre (ACSC) Cloud Security Guidance and Cloud Assessment and Authorisation framework, which addresses guidance within the Australian Government’s Information Security Manual (ISM, September 2025 version), the Department of Home Affairs’ Protective Security Policy Framework (PSPF), and the Digital Transformation Agency’s Secure Cloud Strategy.
The IRAP pack on AWS Artifact also includes newly updated versions of the AWS Consumer Guide and the whitepaper Reference Architectures for ISM PROTECTED Workloads in the AWS Cloud.
Reach out to your AWS representatives to let us know which additional services you want to see in scope for upcoming IRAP assessments. We strive to bring more services into scope at the PROTECTED level under IRAP to support your requirements.
Key Takeaways
- New IRAP Phase 1a report now available on AWS Artifact for Australian customers.
- Four additional AWS services assessed at PROTECTED level bring total to 167.
- Independent ASD certified IRAP assessor completed assessment in June 2026.