LastPass has announced it has successfully completed the Information Security Registered Assessors Program (IRAP) assessment at the PROTECTED level, underscoring its commitment to the rigorous security and compliance standards set by the Australian Government.
The IRAP program, overseen by the Australian Cyber Security Centre (ACSC), ensures that cloud services meet strict security controls aligned with the Australian Government Information Security Manual (ISM). With PROTECTED-level certification, LastPass is now recognised as suitable for use by government agencies and regulated sectors handling sensitive data.
Mario Platt, Chief Information Security Officer at LastPass, said the milestone reflected the company’s ongoing investment in security.
“Undergoing the IRAP assessment has sharpened our visibility and governance posture across systems and validated the strength of our overall security program. This reinforces our ability to meet evolving regulatory requirements while reassuring organisations and individuals that our security approach is both proactive and globally aligned,” Platt said.
The certification comes at a time when Australian organisations face growing compliance demands under frameworks such as APRA CPS 234, updates to the Security of Critical Infrastructure (SOCI) Act, and the Federal Government’s 2023–2030 Cyber Security Strategy.
For LastPass, achieving IRAP at PROTECTED level enables it to:
-
Support government agencies requiring robust identity and access management.
-
Expand into highly regulated industries such as healthcare, finance, and critical infrastructure.
-
Provide enterprise customers with assurance that sensitive information is protected under one of Australia’s most recognised security frameworks.








