Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023
Made under section 61 of the Security of Critical Infrastructure Act 2018 (the Act)
Compilation No. 2
Compilation date: 10 June 2026
Includes amendments: F2026L00701
About this compilation
This compilation
This is a compilation of the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 that shows the text of the law as amended and in force on 10 June 2026 (the compilation date).
The notes at the end of this compilation (the endnotes) include information about amending laws and the amendment history of provisions of the compiled law.
Uncommenced amendments
The effect of uncommenced amendments is not shown in the text of the compiled law. The details of amendments made up to, but not commenced at, the compilation date are underlined in the endnotes. Any uncommenced amendments affecting the law are accessible on the Register (www.legislation.gov.au).
Application, saving and transitional provisions
If the operation of a provision or amendment of the compiled law is affected by an application, saving or transitional provision that is not included in this compilation, details are included in the endnotes.
Modifications
If the compiled law is modified by another law, the compiled law operates as modified but the modification does not amend the text of the law. Accordingly, this compilation does not show the text of the compiled law as modified. Any modifications affecting the law are accessible on the Register.
Self‑repealing provisions
If a provision of the compiled law has been repealed in accordance with a provision of the law, details are included in the endnotes.
Contents
Part 1 Preliminary
1 Name
3 Definitions
4 Application of Part 2A of the Act
4A Application of enhanced CIRMP requirements
5 Relevant Commonwealth Regulator
Part 2 Requirements for a critical infrastructure risk management program
6 Material risk
6A Additional material risks—enhanced requirements
7 General—all hazards
8 Cyber and information security hazards
8A Cyber and information security hazards—enhanced requirements
8B Credential compromise hazards
8C Lateral movement hazards
9 Personnel hazards
9A Personnel hazards—enhanced requirements
10 Supply chain hazards
10A Supply chain hazards—enhanced requirements
11 Physical security hazards and natural hazards
11A Physical security hazards and natural hazards—enhanced requirements
Part 3 Application and transitional provisions
12 Application of LIN 26/075
Schedule 1—Designated hospitals
Endnotes
Endnote 1—About the endnotes
Endnote 2—Abbreviation key
Endnote 3—Legislation history
Endnote 4—Amendment history
Part 1 Preliminary
1 Name
This instrument is the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023.
3 Definitions
Note A number of expressions used in this instrument are defined in in the Act, including:
- business critical data;
(aa) computer;
(ab) connected;
(b) critical component;
(c) critical hospital;
(d) critical infrastructure asset;
(e) critical worker;
(f) relevant impact;
(g) responsible entity;
(h) security.
In this instrument:
Act means the Security of Critical Infrastructure Act 2018.
AusCheck Act means the AusCheck Act 2007.
AusCheck Regulations means the AusCheck Regulations 2017.
background check means a background check under the AusCheck Act.
baseline CIRMP requirement means any requirement specified in Part 2 of this instrument for the purpose of paragraph 30AH(2)(b) of the Act, other than an enhanced CIRMP requirement.
CI asset means a critical infrastructure asset.
CIRMP is short for critical infrastructure risk management program.
CIRMP criminal record has the same meaning as defined in the AusCheck Regulations.
credential compromise hazard means a hazard where credentials associated with:
(a) internet-connected computers or critical components; or
(b) remote access to those internet-connected computers or critical components;
are used to introduce vulnerabilities that could compromise the availability, integrity, reliability or confidentiality of the CI asset.
criminal history criteria means the assessment of:
(a) whether the person has a CIRMP criminal record; and
(b) the nature of the offence.
critical system means any systems including operational technology or enabling systems that form critical components which are vital to the delivery of a CI asset’s function, or the compromise or degradation of which could have a relevant impact on the asset.
cyber and information security hazard includes where a person, whether authorised or not:
(a) improperly accesses or misuses information or computer systems about or related to the CI asset; or
(b) uses a computer system to obtain unauthorised control of, or access to the CI asset that might impair its proper functioning.
designated hospital means a critical hospital mentioned in Schedule 1.
enhanced CIRMP requirement means a requirement specified in subsection 4A(5).
FOCI means foreign ownership, control or influence.
lateral movement hazard means a hazard where a computer is used by a user (whether authorised or otherwise) to move between computer systems to critical systems, or between two critical systems, which could compromise the availability, integrity, reliability or confidentiality of the CI asset.
major supplier means any vendor that by nature of the product or service they offer, has a significant influence over the security of a responsible entity’s CI asset.
maximum acceptable outage means the maximum period of time for which a critical component, service or any other thing for the CI asset can be unavailable without unreasonably disrupting the ongoing availability, integrity, reliability or confidentiality of the CI asset.
natural hazard includes fire, flood, cyclone, storm, heatwave, earthquake, tsunami, space weather or biological health hazard (such as a pandemic).
personnel hazard includes where a critical worker acts, through malice or negligence:
(a) to compromise the proper function of the asset; or
(b) to cause significant damage to the asset.
physical security hazard includes the unauthorised access to, interference with, or control of CI assets, to compromise the proper function of the asset or cause significant damage to the asset.
relevant security clearance means an active security clearance that is:
(a) issued by an Australian Government entity that is authorised to undertake security and grant security clearances; and
(b) at a Negative Vetting 1 level or higher.
Secretary has the same meaning as defined in the AusCheck Act.
supply chain hazard includes malicious people both internal and external exploiting, misusing, accessing or disrupting the supply chain and over-reliance on particular suppliers.
4 Application of Part 2A of the Act
(1) For paragraph 30AB(1)(a) of the Act, each of the following is specified:
(a) a critical broadcasting asset;
(b) a critical domain name system;
(c) a critical data storage or processing asset;
(d) a critical electricity asset;
(e) a critical energy market operator asset;
(f) a critical gas asset;
(g) a designated hospital;
(h) a critical food and grocery asset;
(i) a critical freight infrastructure asset;
(j) a critical freight services asset;
(k) a critical liquid fuel asset;
(l) a critical financial market infrastructure asset mentioned in paragraph 12D(1)(i) of the Act;
(m) a critical water asset.
Note A data storage system that satisfies all of the requirements under subsection 9(7) of the Act in respect of a critical infrastructure asset specified in subsection (1) is taken to be part of the critical infrastructure asset.
(2) For subsection 30AB(3) of the Act, Part 2A of the Act does not apply to a CI asset mentioned in subsection 4(1) during the period beginning when the asset became a CI asset and ending the later of:
(a) 6 months after the commencement of this instrument; and
(b) 6 months after the asset became a CI asset.
(3) The requirements specified in this instrument for paragraph 30AH(1)(c), and subsections 30AKA(1), (3) and (5) of the Act, apply to a CI asset:
(a) that is:
(i) specified in subsection 4(1); and
(ii) not specified in another instrument for paragraph 30AB(1)(a) of the Act; or
(b) referred to in paragraph 30AB(1)(b) of the Act.
Compliance with Part 2A obligations through other instruments
(4) Part 2 of this instrument does not apply in relation to a CI asset specified in subsection 4(1) (CIRMP Rule asset) if:
(a) an entity is the responsible entity for the CIRMP Rule asset; and
(aa) the CIRMP Rule asset is not an asset specified in subsection 4A(1); and
(b) that entity is also the responsible entity for a CI asset specified in another instrument for the purposes of paragraph 30AB(1)(a) of the Act (other asset); and
(c) a CIRMP that applies to the entity for the CIRMP Rule asset complies with the requirements specified for paragraph 30AH(1)(c) in the other instrument relating to the other asset (as if those requirements relate to the CIRMP Rule asset); and
(d) the entity complies with the requirements specified for subsections 30AKA(1),(3) and (5) in the other instrument (as if those requirements relate to the CIRMP Rule asset).
Example: Where an entity is the responsible entity for two types of assets—one is an asset specified in subsection 4A(1) of this instrument (subsection 4A(1) asset), and the other is a relevant critical infrastructure asset, that is specified in another instrument—the entity will need to comply with the requirements in the other instrument for the relevant critical infrastructure asset, while complying with the requirements in Part 2 of this instrument for the subsection 4A(1) asset.
Example: Where an entity is the responsible entity for two types of assets—one being an asset that is not specified in subsection 4A(1) (baseline asset), and the other is a relevant critical infrastructure asset that is specified in another instrument—the entity applies the requirements in the other instrument to the baseline asset as if that asset were the relevant critical infrastructure asset. If the entity complies with the requirements in the other instrument for both assets, it is taken to have complied with the requirements in this instrument.
4A Application of enhanced CIRMP requirements
Asset classes subject to enhanced CIRMP requirements
(1) For the purpose of paragraph 30AH(2)(b) of the Act, the following CI assets are specified to be subject to enhanced CIRMP requirements:
(a) a critical broadcasting asset;
(b) a critical domain name system;
(c) a critical electricity asset;
(d) a critical energy market operator asset;
(e) a critical freight infrastructure asset;
(f) a critical freight services asset;
(g) a critical gas asset;
(h) a critical liquid fuel asset;
(i) a critical water asset.
Note: Requirements specified under paragraph 30AH(1)(c) of the Act may relate to one or more specified CI assets.
Enhanced CIRMP requirements
(2) For the purposes of paragraph 30AH(2)(b) of the Act, the requirements specified under subsection (5) for paragraph 30AH(1)(c) and subsections 30AKA(1), (3) and (5) of the Act, apply to a CI asset that is:
(a) specified in subsection (1); or
(b) covered by paragraph 30AB(1)(b) of the Act.
(3) A CIRMP for a responsible entity of a CI asset that is specified in subsection (1) must comply with both enhanced CIRMP requirements and baseline CIRMP requirements.
(4) To the extent that any inconsistency may arise between a baseline CIRMP requirement and an enhanced CIRMP requirement, the responsible entity must comply with the enhanced CIRMP requirement.
(5) For the purpose of subsection (2), and for paragraph 30AH(1)(c) and subsections 30AKA(1), (3) and (5) of the Act, the matters specified in the following provisions of this instrument are enhanced CIRMP requirements:
(a) section 6A;
(b) sections 8A, 8B and 8C;
(c) section 9A;
(d) section 10A;
(e) section 11A.
Grace periods
(6) For the purposes of subsection 30AB(3) of the Act, the following provisions do not apply to a CI asset specified in subsection (1) during the period:
(a) for section 6A and subsections 8A(2) and 9A(2):
(i) for an asset that is a CI asset before the commencement of this instrument—beginning when the asset becomes a CI asset and ending at the end of the last day of the period of 12 months after the commencement of this instrument;
(ii) for an asset that becomes a CI asset on or after the commencement of this instrument beginning when the asset first becomes a CI asset and ending at the end of the last day of the period of 12 months after the asset has become a CI asset;
(b) for sections 8A (other than subsection 8A(2)), 8B, 8C, 9A (other than subsection 9A(2)), 10A and 11A:
(i) for an asset that is a CI asset before the commencement of this instrument—beginning when the asset becomes a CI asset and ending at the end of the last day of the period of 24 months after the commencement of this instrument;
(ii) for an asset that becomes a CI asset on or after the commencement of this instrument—beginning when the asset first becomes a CI asset and ending at the end of the last day of the period of 24 months after the asset has become a CI asset.
5 Relevant Commonwealth Regulator
For subparagraph (b)(ii) of the definition of relevant Commonwealth regulator in section 5 of the Act, the Reserve Bank of Australia is specified for a critical financial market infrastructure asset mentioned in paragraph 12D(1)(i) of the Act.
Part 2 Requirements for a critical infrastructure risk management program
6 Material risk
For subsection 30AH(8) of the Act, material risk includes:
(a) a stoppage or major slowdown of the CI asset’s function for an unmanageable period;
(b) a substantive loss of access to, or deliberate or accidental manipulation of, a critical component of the CI asset;
Example The position, navigation and timing systems affecting provision of service or functioning of the asset.
(c) an interference with the CI asset’s operational technology or information communication technology essential to the functioning of the asset;
Example A Supervisory Control and Data Acquisition (SCADA) system.
(d) the storage, transmission or processing of sensitive operational information outside Australia, which includes:
(i) layout diagrams;
(ii) schematics;
(iii) geospatial information;
(iv) configuration information;
(v) operational constraints or tolerances information;
(vi) data that a reasonable person would consider to be confidential or sensitive about the asset;
(e) remote access to operational control or operational monitoring systems of the CI asset;
(f) impact to the availability, integrity, reliability or confidentiality of the data storage system holding business critical data.
6A Additional material risks—enhanced requirements
(1) For the purposes of paragraph 30AH(1)(c) of the Act, a responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to, as far as reasonably practicable to do so minimise or eliminate the additional material risks mentioned in subsection (2).
(2) For subsection 30AH(8) of the Act, the following specified risks are additional material risks:
(a) any impairment of the functions of the CI asset that could prejudice the social stability, economic stability, national security or defence of Australia;
(b) compromise or impairment of the functions of the CI asset as a result of, or in connection with FOCI;
(c) offshore or remote access to critical components; and
(d) offshore or remote access to business critical data.
7 General—all hazards
(1) For paragraph 30AH(1)(c) of the Act, a responsible entity must establish and maintain a process or system in the entity’s CIRMP:
(a) to identify the operational context of the CI asset; and
(b) to identify the material risks to the CI asset; and
(c) as far as it is reasonably practicable to do so:
(i) to minimise or eliminate the material risks, which may include those mentioned in sections 6 and 6A; and
(ii) to mitigate the relevant impact of each hazard on the CI asset; and
Note: Material risks that are applicable to CI assets specified in subsection 4(1) are found in section 6. CI assets that are specified in subsection 4A(1) are further subject to enhanced CIRMP obligations and will need to account for the material risks specified in section 6 as well as the additional material risks that are introduced in the provisions listed in 4A(5), which includes section 6A.
(d) to review the CIRMP to ensure compliance with section 30AE of the Act; and
(e) to keep the CIRMP current to ensure it complies with section 30AF of the Act.
(2) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must have regard to whether the entity’s CIRMP:
(a) describes the outcome of the process or system mentioned in paragraph (1)(a);
(b) describes interdependencies between the entity’s CI asset and other CI assets;
(c) identifies each position within the entity:
(i) that is responsible for developing and implementing the CIRMP; and
(ii) for the processes mentioned in paragraph (1)(d)—that is responsible for reviewing the CIRMP or keeping the CIRMP up to date;
(d) contains the contact details for the positions described under paragraph (c);
(e) contains a risk management methodology;
(f) describes the circumstances in which the entity will review the CIRMP.
8 Cyber and information security hazards
(1) For paragraph 30AH(1)(c) of the Act, subsections (2) and (3) specify requirements for cyber and information security hazards.
(2) A responsible entity must establish and maintain a process or system in the CIRMP to—as far as it is reasonably practicable to do so:
(a) minimise or eliminate any material risk of a cyber and information security hazard occurring; and
(b) mitigate the relevant impact of a cyber and information security hazard on the CI asset.
(3) Within 12 months after the end of the applicable period mentioned in subsection 4(2), a responsible entity must comply with subsection (4) or (5).
(4) A responsible entity must establish and maintain a process or system in the CIRMP to:
(a) comply with a framework contained in a document mentioned in the following table as in force from time to time; and
(b) meet any conditions mentioned in the table for the document.
Item | Document | Condition |
1 | Australian Standard AS ISO/IEC 27001:2015 |
|
2 | Essential Eight Maturity Model published by the Australian Signals Directorate | Meet maturity level one as indicated in the document |
3 | Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology of the United States of America |
|
4 | Cybersecurity Capability Maturity Model published by the Department of Energy of the United States of America | Meet Maturity Indicator Level 1 as indicated in the document |
5 | The 2020‑21 AESCSF Framework Core published by Australian Energy Market Operator Limited (ACN 072 010 327) | Meet Security Profile 1 as indicated in the document |
Note Sections 30AN and 30ANA of the Act provide for the incorporation of the documents mentioned in this subsection as in force from time to time.
(5) A responsible entity must establish and maintain a process or system in the entity’s CIRMP to comply with a framework that is equivalent to a framework in a document mentioned in subsection (4), including any conditions.
(6) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must have regard to whether the entity’s CIRMP describes the cyber and information security hazards that could have a relevant impact on the asset.
8A Cyber and information security hazards—enhanced requirements
(1) For paragraph 30AH(1)(c) of the Act, subsections (2), (3) and (4) of this section specify enhanced requirements in relation to cyber and information security hazards.
(2) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process in the entity’s CIRMP to—so far as it is reasonably practicable to do so—minimise or eliminate each of the following material risks:
(a) failure to patch or update operating or security systems in a timely manner;
(b) failure to replace legacy systems, or adequately mitigate risks associated with components or technology that are redundant, unsupported, obsolete or discontinued;
(c) deployment or hosting of advanced, novel or emerging technology in a manner that could prejudice the availability, integrity, reliability or confidentiality of the CI asset; and
(d) use of advanced, novel or emerging technology against the asset, in a manner that could prejudice the availability, integrity, reliability or confidentiality of the CI asset.
(3) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to:
(a) comply with a framework contained in a document specified in column 1 of an item in the following table as in force from time to time; and
(b) meet any conditions mentioned in column 2 of the same table item in relation to the framework specified in column 1 of the item.
| Column 1 | Column 2 |
1 | Australian Standard AS ISO/IEC 27001:2023 |
|
2 | Essential Eight Maturity Model published by the Australian Signals Directorate | Meet maturity level two as indicated in the document |
3 | The NIST Cybersecurity Framework (CSF) 2.0 published by the National Institute of Standards and Technology of the United States of America. |
|
4 | Cybersecurity Capability Maturity Model (Version 2.1) published by the Department of Energy of the United States of America | Meet Maturity Indicator Level 2 as indicated in the document |
5 | The 2023 AESCSF Framework Core published by Australian Energy Market Operator Limited (ACN 072 010 327) | Meet Security Profile 2 as indicated in the document |
Note: Section 30AN and 30ANA of the Act provide for the incorporation of the documents mentioned in this subsection as in force from time to time.
(4) A responsible entity for a CI asset specified in subsection 4A(1) may otherwise comply with subsection (3) of this section by establishing and maintaining a process or system in their CIRMP to comply with another framework, that achieves a level of security equivalent to a framework contained in a document specified in column 1 of items 2, 4 or 5 of subsection (3), and including any relevant conditions specified in column 2.
(5) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity for a CI asset specified in subsection 4A(1) must also have regard to whether the CIRMP contains appropriate measures that minimise or eliminate material risks to the asset including those specified in subsection (2).
8B Credential compromise hazards
(1) This section applies if a responsible entity for a CI asset specified in subsection 4A(1) complies with a framework specified under subsection 8A(3) or (4) which does not require the implementation of phishing resistant multi-factor authentication controls.
(2) For paragraph 30AH(1)(c) of the Act, subsection (3) specifies requirements for credential compromise hazards.
(3) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the CIRMP to—so far as is reasonably practicable to do so:
(a) outline the systems or networks where phishing resistant multi-factor authentication is required to authenticate;
(i) access to their organisation’s internet connected computers and critical systems;
(ii) privileged and unprivileged access to critical components;
(iii) remote access to computer applications, systems or services; and
(b) minimise or eliminate any material risk of a credential compromise hazard occurring; and
(c) mitigate the relevant impact of the credential compromise hazard on the CI asset.
(4) For subsection 30AH(9) of the Act, the implementation of phishing resistant multi-factor authentication controls, as provided for in subsection (5), is taken to be the action that minimises or eliminates any material risk that the credential compromise hazard could have a relevant impact on the asset.
(5) For the purposes of subsection (4), a responsible entity for a CI asset specified in subsection 4A(1) must:
(a) implement phishing resistant multi-factor authentication controls for the systems and networks outlined in paragraph (3)(a); and
(b) centrally log, monitor and routinely review both successful and unsuccessful multi-factor authentication attempts.
Note: Where a responsible entity for a CI asset specified in subsection 4A(1) cannot implement the measures outlined in subsections 8B(4) and (5), they should still include a process or system in their CIRMP containing reasonable steps that must be taken to minimise or eliminate the material risks associated with the occurrence of a credential compromise hazard, in line with the general obligation in subsection 8B(3).
(6) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity for a CI asset specified in subsection 4A(1) must also have regard to whether the CIRMP:
(a) includes a process or system capable of outlining all of the systems and networks where phishing resistant multi-factor authentication is required under paragraph (3)(a);
(b) describes the credential compromise hazards that could have a relevant impact on the asset; and
(c) contains appropriate measures to minimise or eliminate material risks to the asset.
8C Lateral movement hazards
(1) For paragraph 30AH(1)(c) of the Act, subsection (2) specifies requirements for lateral movement hazards.
(2) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to:
(a) identify and maintain an inventory of critical systems and how they are connected with other critical systems and other computers; and
(b) recover and restore critical systems in the event where an incident has had or is having a relevant impact on the asset; and
(c) ensure the continued availability of the asset whilst rebuilding or restoring critical systems; and
(d) as far as it is reasonably practicable to do so:
(i) minimise or eliminate any material risk of a lateral movement hazard occurring; and
(ii) mitigate the relevant impact of the lateral movement hazard on the CI asset.
(3) For subsection 30AH(9) of the Act, the implementation of network segregation that complies with subsection (4), is taken to be the action that minimises or eliminates any material risk that the occurrence of a lateral movement hazard could have a relevant impact on the CI asset.
(4) For the purposes of subsection (3), the following elements are required to achieve network segregation of critical systems:
(a) ensuring critical systems can be segregated as between critical systems, and between critical systems and other computers;
(b) ensuring critical systems can be operationally independent from other internet connected computers and critical systems;
(c) ensuring critical systems can continue to be operational for a period of at least three months while other computers are in a state of restoration or recovery;
(d) implementing logical access controls for network traffic between critical systems, and between critical systems and other computers;
(e) centrally logging, monitoring and routinely reviewing access logs for communication paths between critical systems, and between critical systems and other computers; and
(f) implementing principles of least privilege across computers that connect to critical systems.
Note: Where a responsible entity for a CI asset specified in subsection 4A(1) cannot implement the measures outlined in subsections 8C(3) and (4), they should still include a process or system in their CIRMP containing reasonable steps that must be taken to minimise or eliminate the material risks associated with the occurrence of a lateral movement hazard, in line with their general obligation in subsection 8C(2).
(5) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity for a CI asset specified in subsection 4A(1) must also have regard to whether the CIRMP:
(a) describes the lateral movement hazards that could have a relevant impact on the asset;
(b) includes a process or system capable of identifying the matters at paragraphs (2)(a), (b) and (c); and
(c) contains appropriate measures to minimise or eliminate material risks to the asset.
9 Personnel hazards
(1) For paragraph 30AH(1)(c) of the Act, for personnel hazards, a responsible entity must establish and maintain a process or system in the entity’s CIRMP:
(a) to identify the entity’s critical workers; and
(b) to permit a critical worker access to critical components of the CI asset only where the critical worker has been assessed to be suitable to have such access; and
(c) as far as it is reasonably practicable to do so—to minimise or eliminate the following material risks:
(i) arising from malicious or negligent employees or contractors; and
(ii) arising from the off-boarding process for outgoing employees and contractors.
(2) For paragraph (1)(b) and paragraph 30AH(4)(a) of the Act, the process or system for assessing the suitability of a critical worker may be a background check conducted under the AusCheck scheme.
Note: Subject to subsection 9A(4), a responsible entity is not required to use the AusCheck scheme to assess the suitability of critical workers, unless the responsible entity is a responsible entity of an asset specified in subsection 4A(1).
(3) If a CIRMP permits a background check to be conducted under subsection (2), the background check must include assessment of information relating to the matters mentioned in paragraphs 5(a), (b), (c) and (d) of the AusCheck Act; and
(a) for paragraph 30AH(4)(c) of the Act—the criteria against which the information must be assessed are the criminal history criteria; and
(b) for paragraph 30AH(4)(d) of the Act—the assessment must consist of both an electronic identity verification check and an in person identity verification check.
(4) A responsible entity must notify the Secretary if a background check is no longer required for a critical worker.
(5) In making a suitability assessment mentioned in paragraph (1)(b), a responsible entity must consider the following:
(a) any advice from the Secretary under the following provisions of the AusCheck Regulations:
(i) paragraph 21DA(2)(a);
(ii) paragraph 21DA(2)(b);
(iii) subsection 21DA(4);
(iv) subsection 21DA(5); and
(b) whether permitting a critical worker to have access to critical components of the CI asset would be prejudicial to security; and
(c) any other information that may affect the person’s suitability to have access to the critical components of the CI asset.
Note A responsible entity may be required to inform the Secretary of a decision to grant or revoke access to a critical infrastructure asset, in certain circumstances—see AusCheck Regulations, section 21ZA.
(6) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must have regard:
(a) to whether the CIRMP lists the entity’s critical workers; and
(b) to whether the CIRMP describes the personnel risks, the occurrence of which could have a relevant impact on the asset.
9A Personnel hazards—enhanced requirements
(1) For paragraph 30AH(1)(c) of the Act, subsections (2), (3), (4), (5), (6) and (7) specify enhanced requirements for personnel hazards.
Personnel security—access management
(2) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to minimise or eliminate the material risk associated with:
(a) unauthorised or unsupervised access to critical components;
(b) the compromise or misuse of credentials and privileged access used by individuals to access the CI asset;
(c) access to the CI asset by persons other than critical workers for the CI asset; and
(d) incoming and outgoing critical workers.
Suitability of critical workers
(3) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to:
(a) permit a critical worker access to critical components only where:
(i) the critical worker has been assessed to be suitable in accordance with subsection (4); or
(ii) if the critical worker is unable to meet the requirements outlined in subsection (4) –the responsible entity has outlined in their CIRMP the risk associated with the employment of the critical worker and actions taken, or actions that will be taken as soon as reasonably practicable to do so, to minimise or eliminate the risk to the asset; and
(b) proactively monitor, identify and take action in relation to any developments or changes that may affect the ongoing suitability of a critical worker.
(4) For paragraph (3)(a) of this instrument and paragraph 30AH(4)(a) of the Act, a critical worker may be assessed as suitable only if:
(a) the critical worker has:
(i) been the subject of an AusCheck background check; and
(ii) following the completion of the AusCheck background check, has been assessed as suitable by the responsible entity considering the matters in subsection 9(5); or
(b) the critical worker holds a relevant security clearance at the time the person was identified to be a critical worker.
Note: Where a critical worker holds a relevant security clearance they will not be required to undergo an AusCheck background check. However, where that worker is yet to receive their relevant security clearance as their application is pending, the critical worker will still need to be assessed as suitable under paragraph (4)(a). Only after the critical worker has been assessed as suitable under either paragraphs (4)(a) or (b), or if subparagraph (3)(a)(ii) applies, can a critical worker be permitted access to critical components.
Further matters relating to the AusCheck background check
(5) If a CIRMP permits an AusCheck background check to be conducted for the purposes of paragraph (4)(a), the background check must:
(a) include an assessment of the information outlined in subsection 9(3);
(b) be conducted in accordance with subsection 9(4); and
(c) if the background check relates to a person requiring ongoing access to critical components—be conducted (at minimum) every 5 years.
Further matters relating to relevant security clearances
(6) If a CIRMP permits a critical worker access to critical components where the critical worker has been assessed as suitable by holding a relevant security clearance for the purposes of paragraph (4)(b), the responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in their CIRMP to ensure that, before that clearance lapses or expires, the person has:
(a) undergone a revalidation of their relevant security clearance; or
(b) undergone an AusCheck background check and has been assessed as suitable by the responsible entity considering the matters in subsection 9(5).
(7) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must also have regard to whether the entity’s CIRMP:
(a) contain appropriate measures that minimise or eliminate material risks to the CI asset, including those specified in subsection (2) of this section.
(b) includes processes or systems capable of identifying the matters in subsections (3) and (4) of this section for their CI asset.
10 Supply chain hazards
(1) For paragraph 30AH(1)(c) of the Act, for supply chain hazards, a responsible entity must establish and maintain in the entity’s CIRMP a process or system to:
(a) as far as it is reasonably practicable to do so—minimise or eliminate the following material risks:
(i) unauthorised access, interference or exploitation of the asset’s supply chain; and
(ii) misuse of privileged access to the asset by any provider in the supply chain; and
(iii) disruption of the asset due to an issue in the supply chain; and
(iv) arising from threats to people, assets, equipment, products, services, distribution and intellectual property within supply chains; and
(v) arising from major suppliers; and
(vi) any failure or lowered capacity of other assets and entities in the entity’s supply chain; and
(b) as far as it is reasonably practicable to do so—mitigate the relevant impact of a supply chain hazard on the asset.
(2) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must have regard:
(a) to whether the CIRMP lists the entity’s major suppliers; and
(b) to whether the CIRMP describes the supply chain hazards, which could have a relevant impact on the asset.
10A Supply chain hazards—enhanced requirements
(1) For paragraph 30AH(1)(c) of the Act, subsections (2), (3), (4) and (5) specify enhanced requirements for supply chain hazards.
Supply chain mapping
(2) A responsible entity of a CI asset specified in subsection 4A(1) must establish and maintain a system or process in the entity’s CIRMP to map their supply chain for major suppliers and critical components across their supply chains.
(3) In accordance with subsection (2), the entity’s CIRMP must:
(a) identify risks in the entity’s supply chain that may affect the availability, integrity, reliability or confidentiality of critical components or compromise business critical data; and
(b) identify the maximum acceptable outage for the CI asset or any of its critical components arising from the disruption to the entity’s supply chain; and
(c) as far as is reasonably practicable to do so—include measures to minimise or eliminate those risks, or mitigate the impact of an outage that exceeds the maximum acceptable outage identified in paragraph (3)(b).
Note: Mitigation measures for the purpose of paragraph (3)(c) may include, but are not limited to, supplier diversification, redundancy planning, recovery, resilience and restoration processes.
Vendor assessment
(4) A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a system or process in the entity’s CIRMP to assess the risks associated with an existing or proposed major supplier for the CI asset.
(5) The system or process outlined in subsection (4) must identify, for each existing or proposed major supplier:
(a) in relation to FOCI risks—legislative or other legal requirements to which the supplier is subject to; and
(b) restrictions, sanctions or other impediments affecting the jurisdiction to which the entity may be subject to; and
(c) the access, influence and control the supplier has over the CI asset in connection with the product or service the supplier provides; and
(d) the extent to which the matters in paragraphs (a), (b) and (c) together may present a material risk for the CI asset, or could exceed a maximum acceptable outage of the service or product provided by the supplier; and
(e) as far as reasonably practicable to do so—steps to minimise or eliminate material risks and mitigate the relevant impact of the hazard on the CI asset.
(6) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must have regard to:
(a) whether the CIRMP includes a process or system capable of identifying the matters in paragraphs (3)(a), (b) and (c) for their CI asset; and
(b) whether the CIRMP includes a process or system capable of identifying the matters in paragraphs (5)(a) to (e).
11 Physical security hazards and natural hazards
(1) For paragraph 30AH(1)(c) of the Act, for physical security hazards and natural hazards, a responsible entity must establish and maintain a process or system in the entity’s CIRMP:
(a) to identify the physical critical components of the CI asset; and
(b) as far as it is reasonably practicable to do so—to minimise or eliminate a material risk, and mitigate a relevant impact, of:
(i) a physical security hazard on a physical critical component; and
(ii) a natural hazard on the CI asset; and
(c) to respond to incidents where unauthorised access to a physical critical component occurs; and
(d) to control access to physical critical components, including restricting access to only those individuals who are critical workers or accompanied visitors; and
(e) to test that security arrangements for the asset are effective and appropriate to detect, delay, deter, respond to and recover from a breach in the arrangements.
(2) For subsections 30AKA(1), (3) and (5) of the Act, a responsible entity must have regard to whether:
(a) the asset’s critical components are described in the CIRMP; and
(b) the physical security hazards, the occurrence of which could have a relevant impact on a physical critical component, are described in the CIRMP; and
(c) the security arrangements for the asset are described in the CIRMP; and
(d) the CIRMP describes the natural hazards, the occurrence of which could have a relevant impact on the physical critical component.
11A Physical security hazards and natural hazards—enhanced requirements
(1) For the purpose of paragraph 30AH(1)(c) of the Act, for physical security hazards and natural hazards, a responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to:
(a) centrally manage physical security and natural hazards; and
(b) as far as it is reasonably practicable to do so—outline and consider the physical security consequences arising from the occurrence of all hazards, including cyber and information security hazards, credential compromise hazards, lateral movement hazards, other physical and natural hazards, personnel hazards and supply chain hazards.
Note: Some examples of non-physical hazards that have physical security consequences could include malicious cyber incidents that opens gates to allow unauthorised access, or a supply chain delay that results in changes to workplace operations that decrease the ability to deter, detect, delay, respond to and recover from a breach in security.
(2) For the purposes of paragraph (1)(a), the responsible entity for a CI asset specified in subsection 4A(1) must outline:
(a) the location, ownership, and nature of the site upon which their asset is located; and
(b) the critical components of the CI asset; and
(c) areas within the asset that hold business critical data or contain critical components including critical systems.
(3) For the purposes of paragraph (1)(b), the responsible entity for a CI asset specified in subsection 4A(1) must, as far as reasonably practicable, consider and outline the following:
(a) any physical access controls to the CI asset for workers, official visitors, and the public, including but not limited to:
(i) access controls for critical components and critical systems to restrict access to critical workers or accompanied visitors;
(ii) maintaining surveillance and security alarm systems, such that critical components and critical systems are subject to continuous monitoring;
(iii) specific protective security measures for business hours and out-of-hours; and
(b) other security measures that increase the ability to deter, detect, delay, respond to and recover from a breach in security for all critical components; and
(c) mitigation and response measures to be taken where a physical security incident or a physical security consequence has been detected.
(4) For the purposes of subsections 30AKA(1), (3) and (5) of the Act, a responsible entity for a CI asset specified in subsection 4A(1) must have regard to whether the CIRMP contains systems or processes capable of identifying the matters in subsections (1), (2) and (3).
Part 3 Application and transitional provisions
12 Application of LIN 26/075
The amendments of this instrument made by the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (LIN 26/075) do not apply in relation to an asset:
(a) that was declared to be a critical infrastructure asset under section 51 of the Act before the commencement of LIN 26/075; and
(b) where the declaration provides that the asset is subject to Part 2A of the Act; and
(c) where the declaration as made before the commencement of LIN 26/075 continues to be in force.
Note: Where an asset was declared to be a critical infrastructure asset under section 51 of the Act prior to the commencement of this provision, and the declaration declares that asset is subject to Part 2A of the Act, that obligation does not automatically include compliance with the enhanced CIRMP requirements specified in subsection 4A(5).
Schedule 1—Designated hospitals
(section 3)
A designated hospital means a critical hospital mentioned in an item in the following table located in the State or Territory mentioned in the item.
Item | Hospital | State or Territory |
1 | Bankstown-Lidcombe Hospital Blacktown Hospital Calvary Mater Newcastle Campbelltown Hospital Children's Hospital Westmead Coffs Harbour Health Campus Concord Repatriation General Hospital Dubbo Base Hospital Gosford Hospital Hornsby Ku-Ring-Gai Hospital John Hunter Hospital Lake Macquarie Private Hospital Lismore Base Hospital Liverpool Hospital Nepean Hospital Northern Beaches Hospital Northern Beaches Hospital Orange Base Hospital Port Macquarie Base Hospital Prince of Wales Hospital Royal North Shore Hospital Royal Prince Alfred Hospital St George Hospital St Vincent's Hospital (Darlinghurst) Sydney Children's Hospital Tamworth Hospital The Sutherland Hospital The Tweed Hospital Wagga Wagga Base Hospital Westmead Hospital Wollongong Hospital | New South Wales |
2 | Austin Hospital – Austin Health Box Hill Hospital – Eastern Health Cabrini Malvern Dandenong Hospital – Monash Health Frankston Hospital – Peninsula Health Knox Private Hospital Monash Children’s Hospital – Monash Health Monash Medical Centre (Clayton) – Monash Health Northern Hospital – Northern Health Royal Melbourne Hospital – Melbourne Health St Vincent’s Hospital (Melbourne) Limited The Alfred – Alfred Health The Royal Children's Hospital The Royal Women's Hospital University Hospital (Geelong) – Barwon Health | Victoria |
3 | Bundaberg Base Hospital Caboolture Hospital Cairns Base Hospital Gold Coast University Hospital Greenslopes Private Hospital Hervey Bay Hospital Ipswich Hospital Logan Hospital Mackay Base Hospital Mater Adult Hospital Mater Hospital Brisbane Princess Alexandra Hospital Queen Elizabeth II Jubilee Hospital Queensland Children's Hospital Redcliffe Hospital Robina Hospital Rockhampton Hospital Royal Brisbane & Women's Hospital Sunshine Coast Public University Hospital The Prince Charles Hospital The Wesley Hospital Toowoomba Hospital Townsville University Hospital | Queensland |
4 | Armadale Hospital Bunbury Regional Hospital Fiona Stanley Hospital Hollywood Private Hospital Joondalup Health Campus Joondalup Health Campus King Edward Memorial Hospital Perth's Children’s Hospital Rockingham General Hospital Royal Perth Hospital Sir Charles Gairdner Hospital St John of God Midland Public Hospital | Western Australia |
5 | Calvary Hospital Adelaide Flinders Medical Centre Lyell McEwin Hospital Royal Adelaide Hospital The Queen Elizabeth Hospital Women's and Children's Hospital | South Australia |
6 | Launceston General Hospital Royal Hobart Hospital | Tasmania |
7 | Canberra Hospital | Australian Capital Territory |
8 | Alice Springs Hospital Royal Darwin Hospital | Northern Territory |
Endnotes
Endnote 1—About the endnotes
The endnotes provide information about this compilation and the compiled law.
The following endnotes are included in every compilation:
Endnote 1—About the endnotes
Endnote 2—Abbreviation key
Endnote 3—Legislation history
Endnote 4—Amendment history
Abbreviation key—Endnote 2
The abbreviation key sets out abbreviations that may be used in the endnotes.
Legislation history and amendment history—Endnotes 3 and 4
Amending laws are annotated in the legislation history and amendment history.
The legislation history in endnote 3 provides information about each law that has amended (or will amend) the compiled law. The information includes commencement details for amending laws and details of any application, saving or transitional provisions that are not included in this compilation.
The amendment history in endnote 4 provides information about amendments at the provision (generally section or equivalent) level. It also includes information about any provision of the compiled law that has been repealed in accordance with a provision of the law.
Misdescribed amendments
A misdescribed amendment is an amendment that does not accurately describe how an amendment is to be made. If, despite the misdescription, the amendment can be given effect as intended, then the misdescribed amendment can be incorporated through an editorial change made under section 15V of the Legislation Act 2003.
If a misdescribed amendment cannot be given effect as intended, the amendment is not incorporated and “(md not incorp)” is added to the amendment history.
Endnote 2—Abbreviation key
ad = added or inserted | orig = original |
am = amended | p = page(s) |
amdt = amendment | para = paragraph(s)/subparagraph(s) |
C[x] = Compilation No. x | /sub‑subparagraph(s) |
ch = Chapter(s) | pres = present |
cl = clause(s) | prev = previous |
cont. = continued | (prev…) = previously |
def = definition(s) | pt = Part(s) |
Dict = Dictionary | r = regulation(s)/Court rule(s) |
disallowed = disallowed by Parliament | reloc = relocated |
div = Division(s) | renum = renumbered |
exp = expires/expired or ceases/ceased to have | rep = repealed |
effect | rs = repealed and substituted |
gaz = gazette | s = section(s)/subsection(s) |
LA = Legislation Act 2003 | /rule(s)/subrule(s)/order(s)/suborder(s) |
LIA = Legislative Instruments Act 2003 | sch = Schedule(s) |
(md not incorp) = misdescribed amendment | SLI = Select Legislative Instrument |
cannot be given effect | SR = Statutory Rules |
mod = modified/modification | sub ch = Sub‑Chapter(s) |
No. = Number(s) | sub div = Subdivision(s) |
Ord = Ordinance | sub pt = Subpart(s) |
| underlining = whole or part not |
| commenced or to be commenced |
Endnote 3—Legislation history
Name | Registration | Commencement | Application, saving and transitional provisions |
Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023) | 16 February 2023 | 17 February 2023 | - |
Security of Critical Infrastructure Amendment (2025 Measures No. 1) Rules 2025 | 13 March 2025 | 04 April 2025 | - |
Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 | 9 June 2026 | 10 June 2026 | - |
Endnote 4—Amendment history
Provision affected | How affected |
Section 2 Section 3 | rep LA s 48D am F2025L00324; F2026L00701 |
Section 4 | ad F2025L00324 am F2026L00701 |
Section 4A Section 6 | ad F2026L00701 ad F2025L00324 |
Section 6A | ad F2026L00701 |
Section 7 | am F2026L00701 |
Section 8A | ad F2026L00701 |
Section 8B | ad F2026L00701 |
Section 8C | ad F2026L00701 |
Section 9 | am F2026L00701 |
Section 9A | ad F2026L00701 |
Section 10A | ad F2026L00701 |
Section 11A | ad F2026L00701 |
Section 12 | ad F2026L00701 |