JFrog has successfully completed its InfoSec Registered Assessors Program (IRAP) assessment at the PROTECTED level.
This allows Australian federal, state and territory government agencies - along with critical infrastructure operators in defence, health, finance and telecommunications - to adopt JFrog as their single source of truth for software delivery, the company stated.
The assessment was conducted against the Australian Signals Directorate's Information Security Manual, giving agencies the independently verified evidence they need to shorten Authority to Operate timelines across every binary, model and AI artifact in their software development lifecycle.
The assessment covered the JFrog Platform end-to-end – including JFrog Artifactory as the system of record and single source of truth for every binary, dependency, and build artifact, JFrog Curation for open-source ingestion control, and JFrog Advanced Security for automated security scanning, through AI model governance, verifiable policy enforcement, and SBOM evidence aligned to CycloneDX and SPDX 3.0.
"With software supply chain security and governance becoming an increasing focus for Australian government departments navigating DevSecOps modernisation and rigorous security guidelines, completing our IRAP assessment - PROTECTED level is a significant achievement," said Sunny Rao, SVP of APAC for JFrog.
“This milestone puts the JFrog Platform on a trusted path for public sector teams, delivering the independently verified evidence that government security teams need to make fast, confident risk-authorisation decisions."




