Kiteworks and A-LIGN Bring IRAP-Assessed Data Protection & Multi-Framework Assurance to Australia’s Public Sector

Partnership extension pairs Kiteworks’ IRAP PROTECTED platform with A-LIGN’s independent assessment across IRAP and adjacent frameworks

Extending our work with A-LIGN into the Australian market gives our customers one relationship that produces independent evidence across IRAP & every adjacent framework their own customers ask about.”
— Kieran O'Shaughnessy, General Manager, APAC, Kiteworks
SAN MATEO, CA, UNITED STATES, October 6, 2026 /EINPresswire.com/ -- Kiteworks, which empowers organizations to effectively manage risk in every send, share, receive, and use of private data, today announced an extension of its strategic partnership with A-LIGN, a leading global cybersecurity compliance and assessment firm, to bring IRAP-aligned data protection to Australian government agencies and regulated enterprises, alongside the global assurance frameworks their supply chains already require.

Australian public sector agencies and regulated enterprises face a widening gap between what their technology vendors claim and what those vendors can prove. Most vendors selling into the Australian government can point only to their cloud host’s IRAP assessment, not an assessment of the application itself, the layer where sensitive data is shared, governed, and exchanged.

The extension builds on the strategic partnership Kiteworks and A-LIGN first announced in July 2026 to support CMMC 2.0 Level 2 readiness in the U.S. defense industrial base and follows A-LIGN's acquisition of AssurePoint, an Australian IRAP-specialist assessment firm, which adds IRAP to A-LIGN’s own service portfolio alongside SOC 2 and ISO 27001, and expands its assessor capacity and local presence across Australia and the broader Asia-Pacific region.

Under the extended partnership, organizations running on the Kiteworks platform can start from an application that has already been independently assessed against PROTECTED-level IRAP controls, rather than a roadmap commitment. Kiteworks has held that application-level assessment since 2022, with the most recent reassessment completed in July 2026. Existing assessment evidence may support control-specific inheritance and help reduce duplicate effort, but that inheritance is not automatic. A-LIGN’s assessors independently validate the report's scope, currency, and findings, then assess the customer’s own configuration, integrations, shared responsibilities, and residual risk, alongside SOC 2, ISO 27001, ISO 42001, and CMMC, with no consulting or remediation work that would compromise its independence.

Kiteworks holds a broad independent assurance portfolio: the platform has a SOC 2 Type II report, is FedRAMP High In Process and Moderate Authorized, and holds ISO 27001, 27017, and 27018 certifications, covering security, cloud security, and privacy, respectively. Kiteworks Compliant AI also governs AI agent access to sensitive data, the area ISO 42001 addresses. The platform additionally offers FIPS 140-3 validated encryption, single-tenant deployment, and sole ownership of encryption keys. These certifications and security features provide assessors like A-LIGN concrete, verifiable controls to test, not a policy binder describing intent.

“Being IRAP assessed at the application level, not just inheriting a cloud host’s status, is the difference between telling a customer ‘we’re covered’ and showing them the report,” said Kieran O'Shaughnessy, General Manager, APAC, Kiteworks. “Extending our work with A-LIGN into the Australian market gives our customers one relationship that produces independent evidence across IRAP and every adjacent framework their own customers ask about.”

The firm’s independent, assessment-only model, without consulting or remediation services that could compromise its objectivity, is central to the partnership. A-LIGN independently assesses customer organizations pursuing IRAP, CMMC, and adjacent frameworks. That same independent model is what A-LIGN now brings to Australian buyers directly, with its own Australian-based IRAP assessment capability alongside the adjacent frameworks those buyers' vendor-risk reviews typically also require, rather than referring that work elsewhere.

“Our acquisition of AssurePoint gives A-LIGN a materially larger presence on the ground in Australia, right as organizations there are being asked to prove compliance across more frameworks than ever, often to different auditors who never talk to each other,” said Nick Ludy, Chief Growth Officer, A-LIGN. “Pairing that expanded regional reach with a platform that already holds its own IRAP PROTECTED assessment lets us close the gap for organizations without asking them to manage it themselves.”

Join Kiteworks and A-LIGN on October 29, 2026 (9:00 AM AEDT, Sydney) to learn what an application-level IRAP PROTECTED assessment, held by Kiteworks since 2022 and most recently reassessed in July 2026, adds beyond infrastructure-only coverage, and how A-LIGN's independent IRAP assessment of a customer's own environment completes the picture, alongside the SOC 2, ISO, and FedRAMP assessments many of the same organizations are already tracking. For Australian public sector and regulated-enterprise leaders in security, compliance, and procurement. Register here.


About Kiteworks
Kiteworks' mission is to empower organizations to effectively manage risk in every send, share, receive, and use of private data. The Kiteworks platform provides customers with a secure data exchange that delivers data governance, compliance, and protection in a unified control plane. Kiteworks unifies, tracks, controls, and secures sensitive data moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all private data exchanges. Headquartered in Silicon Valley, Kiteworks protects over 100 million end-users and thousands of global enterprises and government agencies.

About A-LIGN
A-LIGN is the leading cybersecurity compliance partner, trusted by over 6,400 organizations worldwide to navigate the complexities of compliance, audit, and risk. With a tech-enabled delivery model and deep domain expertise, A-LIGN has completed more than 36,000 audits. It is the #1 issuer of SOC 2 reports and a top three FedRAMP assessor. Founded in 2009, A-LIGN delivers high-quality, efficient audits across frameworks including IRAP, SOC 2, ISO 27001, FedRAMP, CMMC, ISO 42001, PCI, and HITRUST.

David Schutzman
Kiteworks
203-550-8551
david.schutzman@kiteworks.com
Visit us on social media:
LinkedIn
Facebook
YouTube
TikTok
X

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

American Financial Tribune

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.