Security of Critical Infrastructure (Application) Rules (LIN 22/026) 2022

Administered by Department of Home Affairs

Legislation au F2022L00562 Rules In force Legislative Instrument

Legislation content

 

Security of Critical Infrastructure (Application) Rules (LIN 22/026) 2022

Made under section 61 of the Security of Critical Infrastructure Act 2018 (the Act).

Compilation No. 1

Compilation date: 4 April 2025

Includes amendments: F2025L00324

About this compilation

This compilation

This is a compilation of the Security of Critical Infrastructure (Application) Rules (LIN 22/026) 2022 that shows the text of the law as amended and in force on 04/04/2025 (the compilation date).

The notes at the end of this compilation (the endnotes) include information about amending laws and the amendment history of provisions of the compiled law.

Uncommenced amendments

The effect of uncommenced amendments is not shown in the text of the compiled law. Any uncommenced amendments affecting the law are accessible on the Register (www.legislation.gov.au). The details of amendments made up to, but not commenced at, the compilation date are underlined in the endnotes. For more information on any uncommenced amendments, see the Register for the compiled law.

Application, saving and transitional provisions for provisions and amendments

If the operation of a provision or amendment of the compiled law is affected by an application, saving or transitional provision that is not included in this compilation, details are included in the endnotes.

Modifications

If the compiled law is modified by another law, the compiled law operates as modified but the modification does not amend the text of the law. Accordingly, this compilation does not show the text of the compiled law as modified. For more information on any modifications, see the Register for the compiled law.

Selfrepealing provisions

If a provision of the compiled law has been repealed in accordance with a provision of the law, details are included in the endnotes.

 

 

 

Contents

1  Name

3  Definitions

4  Application of Part 2 of the Act

5  Application of Part 2B of the Act

Endnotes

Endnote 1—About the endnotes

Endnote 2—Abbreviation key

Endnote 3—Legislation history

Endnote 4—Amendment history

 

 

 

 

1  Name

  This instrument is the Security of Critical Infrastructure (Application) Rules (LIN 22/026) 2022.

3  Definitions

  In this instrument:

Act means the Security of Critical Infrastructure Act 2018.

Aviation Transport Security Act means the Aviation Transport Security Act 2004.

Aviation Transport Security Regulations means the Aviation Transport Security Regulations 2005.

cargo terminal and cargo terminal operator have the meaning given by section 102B of the Customs Act 1901.

designated airport has the same meaning as in regulation 3.01B of the Aviation Transport Security Regulations.

prescribed air service has the meaning given by section 9 of the Aviation Transport Security Act.

regulated air cargo agent has the meaning given by regulation 4.42 of the Aviation Transport Security Regulations.

relevant carriage service provider asset is a critical infrastructure asset owned or operated by a carriage service provider where:

 (a) the asset is used in connection with the supply of at least 20,000 active total carriage services including any of the following:

 (i) broadband services;

 (ii) fixed telephone services;

 (iii) public mobile telecommunications services;

 (iv) voice only services; or

 (b) the responsible entity for the asset is aware that the asset is used in connection with carriage services supplied to a Commonwealth entity (other than a body corporate established by a law of the Commonwealth).

screened air service has the meaning given by regulation 4.02 of the Aviation Transport Security Regulations.

Note Expressions used in this instrument have the same meaning as in the Act from time to time—Legislation Act 2003, paragraph 13(1)(b).

4  Application of Part 2 of the Act

 (1) For paragraph 18A(1)(a) of the Act, each of the following assets, other than an asset mentioned in subsection (2), is specified:

 (a) a critical broadcasting asset;

 (b) a critical domain name system;

 (c) a critical data storage or processing asset;

 (d) a critical financial market infrastructure asset that is a payment system;

 (e) a critical food and grocery asset;

 (f) a critical hospital;

 (g) a critical freight infrastructure asset;

 (h) a critical freight services asset;

 (i) a critical public transport asset;

 (j) a critical liquid fuel asset;

 (k) a critical energy market operator asset;

 (l) a critical electricity asset that was not a critical infrastructure asset immediately before the commencement of section 18A of the Act;

 (m) a critical gas asset that was not a critical infrastructure asset immediately before the commencement of section 18A of the Act;

 (n) a critical telecommunications asset that is:

 (i) owned or operated by a carrier; or

 (ii) relevant carriage service provider asset.

Note 1 Under section 18A(1)(c) of the Act, Part 2 of the Act continues to apply to critical infrastructure assets that were critical infrastructure assets immediately before the commencement of section 18A.

Note 2 A data storage system that meets all of the requirements under subsection 9(7) of the Act in respect of a critical infrastructure asset specified in subsection (1) is taken to be part of the critical infrastructure asset.

 

 (2) An asset mentioned in an item the following table that is owned or operated by the entity mentioned in the item.

Item

Asset

Entity

1

Invicta Sugar Mill, Giru, Queensland

The Haughton Sugar Company Pty Ltd (ABN: 65 009 656 062)

2

Pioneer Sugar Mill, Brandon, Queensland

Pioneer Sugar Mills Pty Ltd (ABN: 63009889856)

3

Racecourse Sugar Mill, Racecourse, Mackay, Queensland

Mackay Sugar Ltd (ABN: 12 057 463 671)

4

South Johnstone Sugar Mill, South Johnstone, Queensland

MSF Sugar Pty Ltd (ABN: 11 009 658 708)

Grace period

 (3) For subsection 18A(3) of the Act, Part 2 of the Act does not apply to an asset mentioned in subsection (1) during the period beginning when the asset became a critical infrastructure asset and ending at the later of:

 (a) 6 months after the commencement of this instrument; and

 (b) 6 months after the asset became a critical infrastructure asset mentioned in subsection (1).

5  Application of Part 2B of the Act

 (1) For paragraph 30BB(1)(a) of the Act, each of the following assets, other than an asset mentioned in subsection (3) and (4), is specified:

 (a) a critical broadcasting asset;

 (b) a critical domain name system;

 (c) a critical data storage or processing asset;

 (d) a critical banking asset;

 (e) a critical superannuation asset;

 (f) a critical insurance asset;

 (g) a critical financial market infrastructure asset;

 (h) a critical food and grocery asset;

 (i) a critical hospital;

 (j) a critical education asset;

 (k) a critical freight infrastructure asset;

 (l) a critical freight services asset;

 (m) a critical public transport asset;

 (n) a critical liquid fuel asset;

 (o) a critical energy market operator asset;

 (p) a critical aviation asset mentioned in subsection (2);

 (q) a critical port;

 (r) a critical electricity asset;

 (s) a critical gas asset;

 (t) a critical water asset.

 (u) a critical telecommunications asset that is:

 (i) owned or operated by a carrier; or

 (ii) a relevant carriage service provider asset.

Note A data storage system that meets all of the requirements under subsection 9(7) of the Act in respect of a critical infrastructure asset specified in subsection (1) is taken to be part of the critical infrastructure asset.

 (2) A critical aviation asset that is any of the following:

 (a) a designated airport;

 (b) an asset used to perform an Australian prescribed air service operating screened air services that depart from a designated airport;

 (c) a cargo terminal that:

 (i) is owned or operated by a regulated air cargo agent that is also a cargo terminal operator; and

 (ii) is located at a designated airport.

 (3) An asset mentioned in an item the following table that is owned or operated by the entity mentioned in the item.

Item

Asset

Entity

1

Invicta Sugar Mill, Giru, Queensland

The Haughton Sugar Company Pty Ltd (ABN: 65 009 656 062)

2

Pioneer Sugar Mill, Brandon, Queensland

Pioneer Sugar Mills Pty Ltd (ABN: 63009889856)

3

Racecourse Sugar Mill, Racecourse, Mackay, Queensland

Mackay Sugar Ltd (ABN: 12 057 463 671)

4

South Johnstone Sugar Mill, South Johnstone, Queensland

MSF Sugar Pty Ltd (ABN: 11 009 658 708)

 (4) An asset that:

 (a) on or after the commencement of Part 1 of Schedule 3 to the Transport Security Amendment (Critical Infrastructure) Act 2022—is a critical aviation asset; or

 (b) on or after the commencement of Part 2 of Schedule 3 to the Transport Security Amendment (Critical Infrastructure) Act 2022—is a critical maritime asset.

Grace period

 (5) For subsection 30BB(3) of the Act, Part 2B of the Act does not apply to an asset mentioned in subsection (1) during the period beginning when the asset became a critical infrastructure asset and ending at the later of:

 (a) 3 months after the commencement of this instrument; and

 (b) 3 months after the asset became a critical infrastructure asset mentioned in subsection (1).


Endnotes

Endnote 1—About the endnotes

The endnotes provide information about this compilation and the compiled law.

The following endnotes are included in every compilation:

Endnote 1—About the endnotes

Endnote 2—Abbreviation key

Endnote 3—Legislation history

Endnote 4—Amendment history

Abbreviation key—Endnote 2

The abbreviation key sets out abbreviations that may be used in the endnotes.

Legislation history and amendment history—Endnotes 3 and 4

Amending laws are annotated in the legislation history and amendment history.

The legislation history in endnote 3 provides information about each law that has amended (or will amend) the compiled law. The information includes commencement details for amending laws and details of any application, saving or transitional provisions that are not included in this compilation.

The amendment history in endnote 4 provides information about amendments at the provision (generally section or equivalent) level. It also includes information about any provision of the compiled law that has been repealed in accordance with a provision of the law.

Misdescribed amendments

A misdescribed amendment is an amendment that does not accurately describe how an amendment is to be made. If, despite the misdescription, the amendment can be given effect as intended, then the misdescribed amendment can be incorporated through an editorial change made under section 15V of the Legislation Act 2003.

If a misdescribed amendment cannot be given effect as intended, the amendment is not incorporated and “(md not incorp)” is added to the amendment history.

 

Endnote 2—Abbreviation key

 

ad = added or inserted

orig = original

am = amended

par = paragraph(s)/subparagraph(s)

amdt = amendment

/subsubparagraph(s)

c = clause(s)

pres = present

C[x] = Compilation No. x

prev = previous

Ch = Chapter(s)

(prev…) = previously

def = definition(s)

Pt = Part(s)

Dict = Dictionary

r = regulation(s)/rule(s)

disallowed = disallowed by Parliament

reloc = relocated

Div = Division(s)

renum = renumbered

exp = expires/expired or ceases/ceased to have

rep = repealed

effect

rs = repealed and substituted

F = Federal Register of Legislation

s = section(s)/subsection(s)

gaz = gazette

Sch = Schedule(s)

LA = Legislation Act 2003

Sdiv = Subdivision(s)

LIA = Legislative Instruments Act 2003

SLI = Select Legislative Instrument

(md not incorp) = misdescribed amendment

SR = Statutory Rules

cannot be given effect

SubCh = SubChapter(s)

mod = modified/modification

SubPt = Subpart(s)

No. = Number(s)

underlining = whole or part not

o = order(s)

commenced or to be commenced

Ord = Ordinance

 

 

Endnote 3—Legislation history

 

Name

Registration

Commencement

Application, saving and transitional provisions

Security of Critical Infrastructure (Application) Rules (LIN 22/026) 2022

7 April 2022

8 April 2022

-

Security of Critical Infrastructure Amendment (2025 Measures No. 1) Rules 2025

13 March 2025

4 April 2025

-

 

Endnote 4—Amendment history

 

Provision affected

How affected

Section 2

rep LA s 48D

Section 3

am F2025L00324

Section 4

am F2025L00324

Section 5

am F2025L00324

 

Overview

The Security of Critical Infrastructure (Application) Rules (LIN 22/026) 2022 were enacted to provide specific rules and definitions for the application of the Security of Critical Infrastructure Act 2018. This legislative instrument, made under section 61 of the Act, serves to clarify the types of assets that are considered critical infrastructure, as well as to provide certain grace periods for the application of the Act. The enacting body for these rules is the Parliament of Australia, which aims to ensure that critical infrastructure is adequately protected and managed across the nation. The policy objective is to identify and regulate assets essential for the functioning of the country's critical infrastructure sectors, thereby enhancing national security and resilience. These rules specify particular assets that fall under the definition of critical infrastructure, such as critical broadcasting assets, critical domain name systems, and critical telecommunications assets, among others. They also outline exceptions to the application of the Act for certain assets during a grace period, ensuring a smooth transition for entities as they adapt to the new regulatory requirements. The rules are designed to be comprehensive and clear, facilitating compliance and enforcement of the Act's provisions.

Scope and Application

The Security of Critical Infrastructure (Application) Rules (LIN 22/026) 2022 is a legislative instrument made under section 61 of the Security of Critical Infrastructure Act 2018 (the Act). This instrument applies to specific critical infrastructure assets, defining them and specifying entities that own or operate these assets. The geographic or jurisdictional reach of the Act extends nationally, applying to critical infrastructure assets across Australia. Certain assets are excluded from the scope if they are already classified as critical infrastructure assets prior to the commencement of section 18A of the Act. Additionally, the Act allows for the specification of further exclusions through subordinate instruments. For instance, the rules provide a grace period during which Part 2 of the Act does not apply to newly designated critical infrastructure assets. The Act’s application can also be extended or restricted through amendments made by subordinate instruments, such as the Security of Critical Infrastructure Amendment (2025 Measures No. 1) Rules 2025, which came into effect on 4 April 2025.

Key Provisions

The Security of Critical Infrastructure (Application) Rules (LIN 22/026) 2022, as amended, is a legislative instrument made under section 61 of the Security of Critical Infrastructure Act 2018 (the Act). This compilation, effective as of 4 April 2025, consolidates the law, including amendments, and notes details of uncommenced amendments and modifications on the Register (www.legislation.gov.au). This compilation does not show text as modified by other laws, though such modifications are noted in the endnotes. Section 1 of the Rules identifies the instrument as the Security of Critical Infrastructure (Application) Rules (LIN 22/026) 2022. Section 3 provides definitions relevant to the interpretation of the Rules, clarifying terms such as "critical infrastructure asset," "carrier," and "relevant carriage service provider asset," among others. Section 4 specifies which assets are subject to Part 2 of the Act, listing assets such as critical broadcasting, financial, food and grocery, and telecommunications assets, among others. Certain assets, however, are excluded from this list if they are owned or operated by specified entities, as detailed in the subsection. Section 5 applies Part 2B of the Act to various critical infrastructure assets, including critical broadcasting, financial, and telecommunications assets, among others. The section also includes a grace period during which Part 2B does not apply to these assets. This grace period is the later of three months after the commencement of the Rules or three months after the asset became a critical infrastructure asset. The Rules impose obligations on entities owning or operating specified critical infrastructure assets, requiring them to comply with the provisions of Part 2 and Part 2B of the Act. This includes implementing security measures to protect these assets from potential threats. The Rules also require these entities to report any incidents or threats to the relevant authorities. The Rules may also mandate entities to develop and implement security plans for their assets, including risk assessments, security measures, and incident response plans. Failure to comply with the Rules may result in various civil and criminal consequences. Civil penalties may be imposed for non-compliance, with the maximum penalty varying depending on the offence. Criminal penalties may also apply, including fines and imprisonment, for serious breaches of the Rules. The specific penalties are detailed in the Act and may be subject to change with amendments to the legislation.

Legal classification tags

Area of Law
National Security Law
Instrument
Legislative Instrument
Concepts
Definitions & Interpretation
Licensing & Registration
Compliance Obligations
Reporting & Disclosure Obligations

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.