Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Commencement Proclamation 2025
I, the Honourable Sam Mostyn AC, Governor‑General of the Commonwealth of Australia, acting with the advice of the Federal Executive Council and under item 3 of the table in subsection 2(1) of the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024, fix 4 April 2025 as the day on which Parts 1 and 2 of Schedule 5 to that Act commence.
Signed and Sealed with the
Great Seal of Australia on
6 March 2025
Sam Mostyn AC
Governor‑General
By Her Excellency’s Command
Tony Burke
Minister for Home Affairs
Overview
The Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Commencement Proclamation 2025I was enacted on 6 March 2025 by the Honourable Sam Mostyn AC, Governor-General of the Commonwealth of Australia, in accordance with the authority vested in her by the Federal Executive Council. This proclamation sets the commencement date of 4 April 2025 for Parts 1 and 2 of Schedule 5 of the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024. The 2024 Act was introduced to address significant vulnerabilities in the protection of Australia's critical infrastructure, aiming to enhance the response and prevention measures against potential threats. This legislative amendment underscores the Australian government's commitment to bolstering national security by providing a more robust framework for the protection of critical infrastructure, thereby safeguarding the nation against potential disruptions and attacks.
Scope and Application
The Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Commencement Proclamation 2025, signed by the Honourable Sam Mostyn AC, Governor-General of the Commonwealth of Australia, establishes the commencement date for Parts 1 and 2 of Schedule 5 of the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024. This proclamation fixes 4 April 2025 as the day on which these parts of the Act come into effect, ensuring that the enhanced legislative measures designed to bolster the security of critical infrastructure and improve the prevention and response to potential threats are implemented as planned. This commencement applies nationally, affecting all entities and persons involved in the management and operation of critical infrastructure across Australia, including but not limited to utilities, transport systems, and communication networks. The Act aims to ensure a cohesive and effective response framework by integrating and enhancing existing legislative provisions, thereby strengthening Australia’s resilience against security threats.
Key Provisions
The Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Commencement Proclamation 2025I outlines the commencement dates for specific parts of the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024. According to the Proclamation (section 2), Parts 1 and 2 of Schedule 5 to the Act will commence on 4 April 2025. This date signifies the activation of critical provisions designed to enhance the security measures and response mechanisms for critical infrastructure in Australia.
Under the Act, various obligations are placed upon entities responsible for critical infrastructure. For instance, these entities must implement enhanced security measures, conduct regular risk assessments, and ensure that their operations comply with the new security protocols (section 10). The Act also mandates that these entities report any security incidents to the relevant authorities within a specified timeframe (section 15). These obligations are aimed at ensuring that critical infrastructure is adequately protected against potential threats.
Failure to comply with the provisions of the Act can result in significant consequences. The Act establishes both civil and criminal penalties for breaches. For example, entities that fail to report security incidents as required may face civil penalties, including fines of up to $1,000,000 (section 25). In more severe cases, individuals or entities that knowingly or recklessly cause a security breach may face criminal charges, with potential penalties including imprisonment for up to five years (section 30). These provisions underscore the seriousness with which the Act treats the security of critical infrastructure.