Quest wins IRAP status for Australian government sales
Thu, 13th Aug 2026 (Today)
Quest Software has achieved IRAP assessed status in Australia for its Quest Trusted Data Management Platform and Quest Security Management Platform. The assessment covers PROTECTED workloads under the Australian Government's security framework.
The designation means both platforms have been independently evaluated against the Australian Government's Information Security Manual, maintained by the Australian Signals Directorate through the Infosec Registered Assessors Program.
For government departments, public sector bodies, and regulated industries, the status can remove a procurement step that often requires agencies to conduct their own security review of a supplier's platform before approval. Quest says that process can take much of a year and impose a six-figure cost on buyers.
The assessment also covers the OFFICIAL and PROTECTED classification levels used by most Commonwealth agencies. This gives Quest a path to sell the two products into a broader range of federal projects where buyers need formal evidence that a platform has been reviewed against Australian Government security controls.
Government focus
Quest already has an installed base in Australian Government technology environments, particularly in tools for Active Directory security monitoring, auditing, recovery, and governance. The new certification extends that position into hybrid systems and cloud deployments.
"Many of Australia's largest government agencies already run Quest Software technology in their on-premises environments for Active Directory security monitoring, change auditing, recovery, and governance," said Richard Kulkarni, Head of APAC, Quest Software.
"This IRAP assessed status does not introduce Quest to government. Rather, it extends an existing relationship into hybrid and cloud-first territory, with independent assurance attached.
"That matters because the modernisation agencies are undertaking rarely looks like a single clean lift-and-shift. It looks like Active Directory and Entra ID modernisation running alongside Machinery of Government changes, cybersecurity uplift programs, and legacy platform retirement, often at the same time, with strict governance requirements and close to zero tolerance for downtime."
The Security Management Platform is aimed at identity oversight, including monitoring, auditing, recovery, and privileged access supervision. In government networks, identity systems are a frequent target for attackers, making those controls central to compliance and incident response.
Quest says the platform is designed to support Essential Eight alignment and a Zero Trust security model for both human and non-human identities. It can also help agencies managing Machinery of Government changes by detecting identity threats and helping contain compromised accounts across hybrid directory environments.
Automated recovery is another part of the offer. Quest says the platform can reduce the time needed to restore trusted operations after a security incident. That matters in environments where assessors increasingly expect controls and recovery processes to be documented and tested, not simply described.
Data governance
The second platform covered by the assessment, Quest Trusted Data Management Platform, focuses on data discovery, governance, modelling, and cataloguing. Quest is positioning it for agencies that want to create reusable data products for analytics and artificial intelligence while maintaining control over classification, sovereignty, and access rules.
According to the company, the platform includes an Automated Data Product Factory that can turn siloed datasets into governed data products with lineage, ownership, and trust scoring. The aim is to give agencies a record of how a data product was built and who approved it for use.
That positioning reflects a broader shift in public sector technology programs, where departments are trying to build AI and analytics services on top of modernised infrastructure while facing tighter scrutiny over data handling. In that context, security accreditation is not only about infrastructure resilience but also about whether data can be managed in a way that stands up to audit.
For Quest's partner channel, the assessment could also simplify sales into high-assurance tenders. A completed IRAP assessment gives resellers and integrators a documented security benchmark they can use in bids, instead of relying on each agency to repeat the review.
Quest says the assessment makes both platforms easier to evaluate and procure, and easier for partners to sell into high-assurance bids.