M&A

A-LIGN Acquires AssurePoint, Expanding IRAP Cybersecurity Services Into Australia

September 22, 2026

Cybersecurity

M&A

Key Facts

Signal Type

M&A

Industry

Cybersecurity

Companies

A-LIGN, AssurePoint, Pathfynder

Date

September 22, 2026

What Happened

A-LIGN, a US-based cybersecurity compliance and audit firm, acquired AssurePoint, an Australian cloud security assessment company specializing in IRAP (Information Security Registered Assessors Program) assessments. The acquisition gives A-LIGN the ability to offer IRAP alongside its existing SOC 2, ISO 27001, and FedRAMP services, and provides a direct operating presence in Australia.

This is A-LIGN's second acquisition announced this month, following the addition of Pathfynder for penetration testing. Earlier in 2026, A-LIGN also opened a London office to expand into EMEA.

Who Is Affected

Current and prospective A-LIGN customers—especially international cloud providers and technology companies seeking Australian government or commercial business—will now have a single provider for IRAP plus existing compliance frameworks. AssurePoint's existing clients gain access to A-LIGN's broader portfolio (SOC 2, ISO 27001, CMMC, PCI, HITRUST).

Vendors selling compliance automation, audit management, GRC platforms, or cloud security tools should target A-LIGN as it integrates AssurePoint and scales IRAP operations.

Market Impact

A-LIGN's acquisition reflects growing demand for multi-framework compliance across jurisdictions, particularly in Australia and the broader Asia-Pacific region.

  • IRAP is often a prerequisite for cloud providers pursuing Australian government contracts.
  • A-LIGN plans to combine IRAP with existing SOC 2 and ISO 27001 services to reduce audit overlap for customers.
  • This purchase follows A-LIGN's acquisition of Pathfynder and London office opening, signaling an aggressive expansion phase.

What to Watch

Watch for A-LIGN's integration strategy—how quickly it merges AssurePoint's IRAP assessments with its existing platform, and whether it expands local Australian headcount or partnerships. Also monitor for further acquisitions targeting other international compliance frameworks or adjacent security services.

Related coverage

Source:

citybiz

Get cybersecurity signals in your CRM

Data breaches, ransomware events, funding rounds, and M&A across security vendors and targets.

Book a 15 min call
Dominykas Rukas - Revenanas