K

Kiteworks and A-LIGN expand IRAP-assessed protection to Australia’s public sector

–

Extended alliance combines Kiteworks’ IRAP PROTECTED platform with A-LIGN’s autonomous evaluation across IRAP and complementary frameworks

Expanding our collaboration with A-LIGN into the Australian region enables our clients to have a single relationship that delivers independent verification across IRAP & every related framework their own clients inquire about.”— Kieran O'Shaughnessy, General Manager, APAC, KiteworksSAN MATEO, CA, UNITED STATES, October 6, 2026 /EINPresswire.com/ — Kiteworks, which enables organizations to efficiently handle risk during every transmission, sharing, reception, and utilization of confidential information, today revealed an expansion of its strategic collaboration with A-LIGN, a premier international cybersecurity compliance and auditing firm, to deliver IRAP-aligned data protection to Australian governmental bodies and regulated businesses, together with the worldwide assurance frameworks their supply chains currently demand.

Australian public-sector organizations and regulated enterprises are encountering an increasing divide between what their technology suppliers assert and what those suppliers can demonstrate. Many vendors selling into the Australian government can only refer to their cloud host’s IRAP evaluation, not an evaluation of the software itself, the layer where confidential information is exchanged, managed, and controlled.

This expansion builds on the strategic alliance Kiteworks and A-LIGN originally declared in July 2026 to facilitate CMMC 2.0 Level 2 preparedness in the U.S. defense industrial base and follows A-LIGN's purchase of AssurePoint, an Australian IRAP-specialist auditing company, which incorporates IRAP into A-LIGN’s own offerings alongside SOC 2 and ISO 27001, and increases its auditor capacity and local footprint throughout Australia and the wider Asia-Pacific region.

Under this broadened partnership, entities operating on the Kiteworks platform can begin with an application that has already undergone independent evaluation against PROTECTED-level IRAP criteria, rather than relying on a roadmap promise. Kiteworks has held that application-level evaluation since 2022, with its latest reassessment finished in July 2026. Current evaluation evidence may facilitate control-specific inheritance and assist in minimizing duplicated effort, but such inheritance is not automatic. A-LIGN’s auditors independently confirm the report's scope, timeliness, and conclusions, then evaluate the client’s own setup, integrations, shared duties, and leftover risk, together with SOC 2, ISO 27001, ISO 42001, and CMMC, without any consulting or corrective work that could impair their impartiality.

Kiteworks possesses a wide-ranging independent assurance portfolio: the platform boasts a SOC 2 Type II report, is FedRAMP High In Process and Moderate Authorized, and holds ISO 27001, 27017, and 27018 certifications, addressing security, cloud security, and privacy, respectively. Kiteworks Compliant AI also manages AI agent access to confidential information, the domain ISO 42001 covers. The platform additionally provides FIPS 140-3 validated encryption, single-tenant deployment, and exclusive ownership of encryption keys. These certifications and security attributes give auditors like A-LIGN concrete, verifiable controls to examine, not a policy binder describing intentions.

“Having IRAP assessment at the application level, rather than merely inheriting a cloud host’s status, is the distinction between informing a client ‘we’re covered’ and presenting them the report,” said Kieran O'Shaughnessy, General Manager, APAC, Kiteworks. “Expanding our collaboration with A-LIGN into the Australian region enables our clients to have a single relationship that delivers independent verification across IRAP and every related framework their own clients inquire about.”

The company’s independent, assessment-only model, devoid of consulting or remediation services that could undermine its neutrality, is fundamental to the alliance. A-LIGN autonomously evaluates client organizations pursuing IRAP, CMMC, and related frameworks. That same independent model is what A-LIGN now provides directly to Australian buyers, utilizing its own Australian-based IRAP assessment capability together with the related frameworks those buyers' vendor-risk evaluations typically also demand, instead of referring that work elsewhere.

“Our acquisition of AssurePoint gives A-LIGN a substantially larger on-the-ground presence in Australia, precisely when organizations there are being required to demonstrate compliance across more frameworks than ever before, often to different auditors who never interact with each other,” said Nick Ludy, Chief Growth Officer, A-LIGN. “Combining that expanded regional reach with a platform that already maintains its own IRAP PROTECTED evaluation allows us to close the gap for organizations without requiring them to manage it themselves.”

Join Kiteworks and A-LIGN on October 29, 2026 (9:00 AM AEDT, Sydney) to discover what an application-level IRAP PROTECTED evaluation, maintained by Kiteworks since 2022 and most recently reassessed in July 2026, adds beyond infrastructure-only coverage, and how A-LIGN's independent IRAP assessment of a client's own environment completes the picture, together with the SOC 2, ISO, and FedRAMP evaluations many of those same organizations are already monitoring. For Australian public-sector and regulated-enterprise leaders in security, compliance, and procurement. Register here.

About Kiteworks
Kiteworks' mission is to enable organizations to efficiently handle risk during every transmission, sharing, reception, and utilization of confidential information. The Kiteworks platform provides clients with a secure data exchange that delivers data governance, compliance, and protection in a unified control plane. Kiteworks unifies, tracks, controls, and secures confidential data moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all confidential data exchanges. Headquartered in Silicon Valley, Kiteworks protects over 100 million end-users and thousands of global enterprises and government agencies.

About A-LIGN
A-LIGN is the premier cybersecurity compliance partner, relied upon by over 6,400 organizations worldwide to navigate the complexities of compliance, audit, and risk. With a tech-enabled delivery model and deep domain expertise, A-LIGN has completed more than 36,000 audits. It is the #1 issuer of SOC 2 reports and a top three FedRAMP assessor. Founded in 2009, A-LIGN delivers high-quality, efficient audits across frameworks including IRAP, SOC 2, ISO 27001, FedRAMP, CMMC, ISO 42001, PCI, and HITRUST.

David Schutzman
Kiteworks
203-550-8551
david.schutzman@kiteworks.com
Visit us on social media:
LinkedIn
Facebook
YouTube
TikTok
X


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.