IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
JFrog clears IRAP check for Australian government use

JFrog clears IRAP check for Australian government use

Fri, 28th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

JFrog has completed an IRAP assessment at the PROTECTED level for its software supply chain platform, giving Australian government agencies independently verified evidence to support security reviews.

The assessment was conducted against the Australian Signals Directorate's Information Security Manual, a framework widely used by public sector bodies and regulated industries when evaluating technology purchases and operational approvals.

That matters because buyers across federal, state and territory agencies often face lengthy procurement processes and strict security requirements before a system can be approved for use. An IRAP assessment is commonly treated as an important step in those reviews, particularly for departments handling more sensitive workloads.

JFrog says the result is also relevant to critical infrastructure operators in defence, health, finance and telecommunications, which are under growing pressure to tighten software supply chain controls. It positions the assessment as a way to reduce the work involved in Authority to Operate decisions.

Assessment scope

The review covered the JFrog Platform end to end, including Artifactory, Curation and Advanced Security. These products are used to store software components and build artefacts, control the intake of open-source packages, and scan code and dependencies for security issues.

The scope also included governance for AI models, policy enforcement, and software bill of materials evidence aligned with CycloneDX and SPDX 3.0. This reflects a broader shift in security practice as organisations apply the same controls to AI-related assets that they already use for conventional software components.

Australian organisations are showing a growing preference for tighter control in this area. JFrog cited its own research showing that 47% of Australian organisations automatically block unapproved AI coding assistants and IDE extensions, while 68% self-host their AI models.

Those figures point to a market leaning towards automated enforcement and data sovereignty in software development. They also coincide with a tougher policy environment, as governments raise cyber expectations through measures such as the move towards Essential Eight Maturity Level 2 as a baseline in critical sectors.

NSW's cyber strategy points in the same direction, with public sector bodies placing more emphasis on resilience, software integrity and audit readiness. For vendors seeking government business, security assurance is increasingly a commercial requirement as well as a technical one.

Government demand

In this environment, the main practical value of an IRAP assessment is often speed. Agencies still need to make their own risk decisions, but an independent assessment can give internal security teams a starting point instead of forcing them to build an evidence base from scratch.

JFrog says its platform supports policy-based controls across binaries, dependencies, generated code and AI artefacts. Customers can also use detailed SBOMs and VEX records to meet transparency and compliance requirements, an area that has gained prominence as software supply chain attacks have risen on the policy agenda.

Another selling point for public sector buyers is consolidation. Rather than relying on separate systems to store artefacts, apply security controls and record audit evidence, JFrog is pitching a single system of record across the development lifecycle.

That approach aligns with the needs of teams trying to replace manual approval steps with policy gates and traceable records. For departments under pressure to modernise software delivery without weakening oversight, those workflow changes can be as important as the security checks themselves.

Sunny Rao, Senior Vice President, APAC, JFrog, said the assessment reflects increased scrutiny of software supply chain security in government. "With software supply chain security and governance becoming an increasing focus for Australian government departments navigating DevSecOps modernization and rigorous security guidelines, completing our IRAP assessment - PROTECTED level is a significant achievement," Rao said.

He said the result should help public sector security teams reach decisions more quickly. "This milestone puts the JFrog Platform on a trusted path for public sector teams, delivering the independently verified evidence that government security teams need to make fast, confident risk-authorization decisions," Rao said.

Chief Information Officer Aran Azarzar framed the assessment as both an internal benchmark and a market requirement. "Completing an IRAP assessment at the PROTECTED level holds our own platform to the same standard we help our customers meet," Azarzar said. "It reasserts a commitment that runs through everything we build: that security is not a feature bolted on at the end, but the foundation the platform stands on."