Surprisingly Useful AI Article Enhancements
Software supply chain platform vendor, JFrog, has completed an InfoSec Registered Assessors Program assessment at the PROTECTED level, giving Australian government agencies and critical infrastructure operators independently verified evidence to support Authority to Operate decisions.
The assessment was conducted against the Australian Signals Directorate’s Information Security Manual and covers the JFrog Platform end-to-end, spanning software binaries, open-source dependencies, AI models, security scanning, policy enforcement and software bill of materials generation.
The PROTECTED classification is relevant to Australian federal, state and territory government agencies, as well as operators in defence, health, finance and telecommunications. An IRAP assessment at this level is often a mandatory gate in public sector procurement, and completing it positions JFrog to shorten what can be a lengthy vendor eligibility process.
What the assessment means for agencies
For government security teams evaluating software supply chain tools, the practical effect of the IRAP assessment is that they no longer need to conduct their own ground-up security evaluation of the JFrog Platform before granting an Authority to Operate.
SVP APAC at JFrog, Sunny Rao, framed the assessment in the context of growing government interest in DevSecOps and software supply chain governance.
“With software supply chain security and governance becoming an increasing focus for Australian government departments navigating DevSecOps modernisation and rigorous security guidelines, completing our IRAP assessment – PROTECTED level is a significant achievement,” Rao remarked.
“This puts the JFrog Platform on a trusted path for public sector teams, delivering the independently verified evidence that government security teams need to make fast, confident risk-authorisation decisions.”
JFrog describes its platform as a system of record for software artefacts, binaries and AI assets, designed to consolidate what it calls a “single source of truth” for every artefact from development through to production.
Scope of the assessment
The IRAP assessment covered the full JFrog Platform, including JFrog Artifactory for managing binaries, dependencies and build artefacts, JFrog Curation for open-source ingestion control and JFrog Advanced Security for automated security scanning.
The scope also extended to AI model governance, policy enforcement and SBOM evidence generation aligned to CycloneDX and SPDX 3.0 standards.
CIO of JFrog, Aran Azarzar, positioned the assessment as consistent with the company’s broader approach to platform security.
“Completing an IRAP assessment at the PROTECTED level holds our own platform to the same standard we help our customers meet,” Azarzar commented.
“It reasserts a commitment that runs through everything we build: that security is not a feature bolted on at the end, but the foundation the platform stands on.”
Australian organisations tightening controls on AI and supply chains
The IRAP completion arrives against a backdrop of tightening software supply chain expectations across Australian government and regulated sectors.
According to JFrog’s own 2026 Software Supply Chain Security State of the Union report, 47 per cent of Australian organisations now automatically block unapproved AI coding assistants and IDE extensions. The same report found that 68 per cent self-host their AI models, pointing to a preference for automated enforcement and sovereignty over AI tooling.
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
At a policy level, NSW’s 2026-2028 Cyber Security Strategy and the broader national shift toward Essential Eight Maturity Level 2 as a baseline for critical sectors are raising the bar for vendors seeking to sell into government.
For platform vendors like JFrog, clearing an IRAP assessment removes a procurement obstacle that can otherwise delay adoption across agencies bound by strict eligibility requirements.
What agencies can do with the assessment
JFrog outlines several practical outcomes for government and regulated organisations following the IRAP assessment.
Agencies can use the IRAP assessment report to support Authority to Operate decisions without building a security case from scratch. The platform allows organisations to apply continuous policy enforcement to AI models, generated code and third-party dependencies in the same way they would govern any other binary.
The company also points to the ability to replace manual approval workflows with automated policy gates and immutable audit trails, and to meet transparency and compliance requirements through SBOM and VEX support aligned to CycloneDX and SPDX 3.0.
Access to the assessment report
The JFrog Platform IRAP assessment report is available to Australian government agencies and regulated organisations through the JFrog Trust Center. Agencies seeking a copy can contact their JFrog account manager.
JFrog claims approximately 6,600 organisations worldwide use its platform, including a majority of the Fortune 100. The company offers the platform as both a SaaS service across major cloud providers and as a self-hosted deployment.
Last Updated on August 27, 2026 by Nick Ross



