EXPLANATORY STATEMENT
Issued by the authority of the Minister for Home Affairs and Minister for Cyber Security
Security of Critical Infrastructure Act 2018
Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026
Legislative authority
The Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (the Amendment Rules) are made under section 61 of the Security of Critical Infrastructure Act 2018 (the SOCI Act). The instrument amends the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 (CIRMP Rules).
The Amendment Rules are made in accordance with subsection 33(3) of the Acts Interpretation Act 1901. That subsection provides that a power to make a legislative instrument includes a power to amend or repeal that instrument in the same manner, and subject to the same conditions, as the power to make the instrument.
The Amendment Rules commence on the day after registration and are a legislative instrument for the purposes of the Legislation Act 2003.
Purpose
Australia’s defence, national and economic interests rely upon strong security to deflect possible threats that could cause harm to the Australian community in the event of an attack. However, Australia’s critical infrastructure is increasingly being targeted by sophisticated state-sponsored and malicious threat actors. Current obligations under the SOCI Act and the CIRMP Rules require updating to ensure they are commensurate with a threat landscape that is complex, challenging and continuously evolving. This threat landscape will continue to become more dynamic, diverse, and degraded over the next five years, as per the Director-General of ASIO’s Annual Assessment 2025.
For example:
- State-sponsored and malicious threat actors are using increasingly sophisticated methods to pre-position and access the networks and systems of critical infrastructure assets for compromise, disruption and sabotage.
- Supply chain vulnerabilities and the use of vendors that are deemed high-risk, particularly in sectors where there are limited suppliers, vendors, or service providers available may increase exposure to compromise, reduce resilience, and heighten the risk of disruption or sabotage across interdependent critical infrastructure sectors.
- The deployment and use of advanced and emerging technology poses a significant risk to the security of critical infrastructure assets, especially as artificial intelligence (AI) becomes increasingly capable and post-quantum cryptography draws closer. Given the rate of technological change, it is necessary to ensure critical infrastructure owners and operators are holistically considering the risks, enabling responsible entities to better secure their assets and build these considerations into future security uplifts and improvements.
- Heightened levels of espionage and foreign interference increase the possibility of compromise and exploitation of vulnerabilities in all-hazards security practices to access sensitive systems or information.
By the nature of their interdependence, assets in the energy, communications, transport, and water and sewerage sectors are attractive targets for disruption and sabotage, and failure to uplift their existing obligations under the CIRMP Rules will result in greater long-term exposure to threats.
The Amendment Rules aim to strengthen our nation’s resilience and security across all hazard vectors, including cyber and information security, personnel security, supply chain, physical security, natural hazards and newly introduced credential compromise and lateral movement hazards. The Amendment Rules achieve this aim by uplifting the security requirements of critical infrastructure assets so that they can reliably mitigate and eliminate more diverse and complex threats.
The measures that the Amendment Rules introduced include enhanced requirements across all hazard vectors. These new requirements include:
- additional all-hazard, cyber and information hazard and personnel hazard material risks;
- enhanced obligations for a cyber maturity framework;
- critical systems network segregation;
- phishing resistant multi-factor authentication;
- implementing adequate background checking and security clearances;
- the mapping of supply chains;
- the assessment of major suppliers; and
- central management of physical and natura hazards.
Taken together, these measures will help create a more secure critical infrastructure network that serves to protect Australia's national security, defence, economic interests and the safety of our communities.
Details of the instrument
Details of this instrument are set out in Attachment A.
Parliamentary scrutiny etc.
The instrument is subject to disallowance under section 42 of the Legislation Act 2003. A Statement of Compatibility with Human Rights has been completed in accordance with the Human Rights (Parliamentary Scrutiny) Act 2011. The overall assessment is that the instrument is compatible with human rights. The Statement is included at Attachment B.
Consultation
Part 2A
Section 30AL of the SOCI Act requires that, before making or amending rules under sections 30AH of the SOCI Act, the Minister must:
- cause a notice to be published on the Department’s website that sets out the draft rules or amendments, and invites persons to make submissions to the Minister;
- give a copy of the notice to each State and Territory First Minister; and
- consider any submissions received within the period specified in the notice.
Subsection 30AL(3) of the SOCI Act specifies that the period of the notice must be no shorter than 28 days.
The Department of Home Affairs (the Department) engaged industry stakeholders responsible for affected asset classes during the development of these amendments.
Before making this instrument, the Minister in accordance with section 30AL:
- published a notice on the Department’s website that set out the draft amendment made for the purposes of section 30ABA of the SOCI Act;
- invited persons to make submissions to the Minister about the draft rules within a period not shorter than 28 days (the notice specified a period of 37 days between 25 March and 1 May 2026); and
- provided a copy of the notice to the First Minister of each State and Territory.
Once the consultation period closed, the Minister considered all submissions received. All submissions were reviewed and considered in the making of the amendments.
Impact Analysis
The Office of Impact Analysis (OIA) was consulted during the preparation of these amendments. An addendum was drafted based the “2022 Regulation Impact Statement: A Risk Management Program Framework for Critical Infrastructure Assets” (2022 RIS or OPB22-02914). This addendum has been included at Attachment C.
Attachment A
Details of the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026
Section 1 Name
Section 1 provides that the title of this legislative instrument is the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (the Amendment Rules).
Section 2 Commencement
Section 2 provides for the commencement of the instrument.
Subsection 2(1) provides that each provision of the instrument specified in column 1 of the table commences, or is taken to have commenced, in accordance with column 2 of the table. Any other statement in column 2 has effect according to its terms.
The effect of table item 1 is that the whole of the instrument commences on the day after registration of the instrument on the Federal Register of Legislation.
Subsection 2(2) provides that information in column 3 of the table (“date/details”) is not part of the instrument and may be edited, or information inserted into the column, in any published version of the instrument.
Section 3 Authority
Section 3 provides that the Amendment Rules are made under section 61 of the Security of Critical Infrastructure Act 2018 (the SOCI Act).
Section 61 of the SOCI Act provides that the Minister may, by legislative instrument, make rules prescribing matters that are required or permitted by the Act to be prescribed by the rules, or necessary or convenient to be prescribed for carrying out or giving effect to the SOCI Act.
Subsection 33(3) of the Acts Interpretation Act 1901 relevantly provides that a power to make a legislative instrument includes a power to repeal, rescind, revoke, amend, or vary that instrument in the same manner, and subject to the same conditions, as the power to make the instrument.
Section 61 of the SOCI Act therefore authorises the Minister to amend the rules as provided for in this legislative instrument.
Section 4 Schedules
Section 4 provides that each instrument that is specified in a Schedule to this instrument is amended or repealed as set out in the applicable items in the Schedule concerned, and any other item in a Schedule to this instrument has effect according to its terms.
Schedule 1 – Amendments of the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023
Item 1 Section 3 (after paragraph (a) of the note to the heading)
This item inserts new paragraphs (aa) and (ab) into the note under the heading of section 3.
The effect of these new paragraphs is to insert the terms ‘computer’ and ‘connected’ into the list of expressions that are used in this instrument which are defined in the SOCI Act.
The expressions ‘computer’ and ‘connected’, which both have the meaning given by section 5 of the SOCI Act, are used in the context of defining, and prescribing requirements under the new hazard vectors at new sections 8B and 8C of this instrument.
Item 2 Section 3
This item amends section 3 of the CIRMP Rules to insert new defined terms to support the amendments of the CIRMP Rules made by the Amendment Rules.
The term baseline CIRMP requirement means any requirement specified in Part 2 of this instrument for the purpose of paragraph 30AH(2)(b) of the SOCI Act, other than an enhanced CIRMP requirement.. This definition is inserted to distinguish between general requirements that already exist within the CIRMP Rules, and new requirements being introduced by the Amendment Rules.
The term credential compromise hazard means where credentials associated with either internet-connected computers or critical components; or remote access to those internet-connected computers or critical components, are used as part of introducing vulnerabilities that could compromise the availability, integrity, reliability or confidentiality of the CI asset.
In contrast to the way that other hazard vectors are defined by using the word ‘includes’, the definition of credential compromise hazard is not intended to be expansive. The new credential compromise hazard vector is intended to be construed narrowly.
The term critical system means any system including operational technology or enabling systems that form critical components which are vital to the delivery of a CI asset’s function, or the compromise or degradation of which could have a relevant impact on the asset.
The term enhanced CIRMP requirement means a requirement specified in subsection 4A(5). This term is used in reference to the additional requirements that are being added to the CIRMP Rules through the Amendment Rules.
The term FOCI means foreign ownership, control or influence.
The term lateral movement hazard means where a computer is used by a user (whether that user is authorised or otherwise) to move between computer systems to critical systems; or between two critical systems, which could compromise the availability, integrity, reliability or confidentiality of a CI asset. This new hazard vector is intended to be construed narrowly.
The term maximum acceptable outage means the maximum period of time for which a critical component, service or any another thing for the CI asset can be unavailable without unreasonably disrupting the ongoing availability, integrity, reliability or confidentiality of the CI asset.
The term relevant security clearance means an active security clearance that is issued by an Australian Government entity that is authorised to undertake security and grant security clearances; and at a Negative Vetting 1 level or higher. At the time of writing, Australian Government agencies that are currently authorised to undertake security and grant security clearances under the Australian Government’s Protective Security Policy Framework Guidelines (PSPF Guidelines) include the Australian Federal Police, Australian Government Security Vetting Agency, Australian Security Intelligence Organisation, Australian Secret Intelligence Service, the Department of Foreign Affairs and Trade and the Office of National Intelligence.
Item 3 After paragraph 4(4)(a)
This item inserts new paragraph (aa) in subsection 4(4) of the CIRMP Rules.
Subsection 4(4) of the CIRMP Rules (Compliance with Part 2A obligations through other instruments) provides circumstances in which a responsible entity for an asset specified in subsection 4(1) (CIRMP Rule asset) may be compliant with their obligations under Part 2A of the SOCI Act other than by meeting the requirements set out in Part 2 of the CIRMP Rules.
Subsection 4(4), without amendment, has the practical effect that an entity who is the responsible entity for multiple critical infrastructure assets, at least one of which is a relevant critical telecommunications asset specified in the Security of Critical Infrastructure (Telecommunications Security and Risk Management Program) Rules 2025 (LIN 25/010) (TSRMP Rules) (which would be “another equivalent instrument for the purposes of paragraph 30AB(1)(a)” of the SOCI Act), may comply with Part 2A of the SOCI Act by applying the requirements specified in the TSRMP Rules to all the assets it is responsible for. The intention of existing subsection 4(4) acknowledges that it may be preferable for responsible entities for multiple assets to apply one set of requirements in respect of all their CI assets.
The effect of the insertion of new paragraph (aa) is to turn off this workaround with respect to assets in classes specified in new subsection 4A(1). Accordingly, an entity who is the responsible entity for an asset specified in new subsection 4A(1) and a CI asset specified in another instrument for the purposes of paragraph 30AB(1)(a) of the Act (e.g. a critical telecommunications asset specified in the TSRMP Rules), must comply with the TSRMP Rules with respect to their critical telecommunications asset, and must comply with the CIRMP Rules, as amended which includes all enhanced CIRMP requirements, in relation to the subsection 4A(1) asset. This achieves the policy intent that the responsible entities for assets specified under 4A(1) comply with enhanced obligations imposed by the Amendment Rules.
New paragraph (aa) preserves the operation of existing subsection 4(4) with respect to a CIRMP Rule asset that is not an asset specified in new subsection 4A(1) (baseline asset). Accordingly, an entity who is the responsible entity for a baseline asset and a CI asset specified in another instrument for the purposes of paragraph 30AB(1)(a) of the SOCI Act (e.g. a critical telecommunications asset specified in the TSRMP Rules) may acquit all their obligations under Part 2A of the SOCI Act by complying with the requirements in the TSRMP Rules with respect to both their critical telecommunications asset, and their baseline asset.
Item 4 Subsection 4(4) (note)
This item repeals the existing note after subsection 4(4) and replaces it with two new examples to demonstrate the effect of the provision after the insertion of new paragraph (4)(aa).
The first example provides that where one of the assets is specified in subsection 4A(1) of this instrument (subsection 4A(1) asset) and the other is a relevant critical infrastructure asset specified in another instrument, the entity is obligated to comply with requirements in the other instrument for the relevant critical infrastructure asset while complying with requirements in Part 2 of the CIRMP Rules, including the enhanced obligations imposed by the Amendment Rules, for the subsection 4A(1) asset.
The second example provides that where an entity is the responsible entity for two types of assets – one being an asset that is specified in subsection 4(1) but not specified in subsection 4A(1) (baseline asset) and the other is a relevant critical infrastructure asset that is specified in another instrument, the entity is able to apply the requirements in the other instrument to the baseline asset as if that asset were the relevant critical infrastructure asset.
These examples make it clear that the responsible entity for an asset that is subject to enhanced CIRMP obligations (i.e. a CI asset specified in new subsection 4A(1)) must comply with the enhanced CIRMP obligations in relation to the subsection 4A(1) asset.
Item 5 After section 4
This item inserts new section 4A pertaining to the application of enhanced CIRMP requirements which are inserted by the Amendment Rules.
Asset classes subject to enhanced CIRMP requirements
Subsection 4A(1) specifies the CI asset classes subject to enhanced CIRMP requirements for the purposes of paragraph 30AH(2)(b) of the SOCI Act. The following asset classes are prescribed:
(a) a critical broadcasting asset;
(b) a critical domain name system;
(c) a critical electricity asset;
(d) a critical energy market operator asset;
(e) a critical freight infrastructure asset;
(f) a critical freight services asset;
(g) a critical gas asset;
(h) a critical liquid fuel asset; and
(i) a critical water asset.
The note inserted at the end of subsection 4A(1) clarifies that requirements specified under paragraph 30AH(1)(c) of the SOCI Act may relate to one or more specified CI assets.
Enhanced CIRMP requirements
Subsection 4A(2) provides that the requirements specified in subsection (5) for paragraph 30AH(1)(c) and subsections 30AKA(1), (3) and (5) of the SOCI Act that apply to a CI asset that is specified in subsection (1) or covered by paragraph 30AB(1)(b) of the Act.
The reference to paragraph 30AB(1)(b) of the SOCI Act allows for the application of enhanced CIRMP obligations to assets privately declared under section 51 of the Act to be a critical infrastructure asset if that declaration also specifies that Part 2A of the SOCI Act applies to that asset.
Subsection 4A(3) provides that a responsible entity of a CI asset that is specified in subsection (1) must comply with both enhanced CIRMP requirements and baseline CIRMP requirements. This provision clarifies that the enhanced CIRMP obligations apply additionally to the baseline CIRMP requirements and do not replace them. For example, a responsible entity for a CI asset specified in subsection 4A(1) will have to comply with existing sections 6 and 7, which comprise of the baseline CIRMP requirement relevant to material risks, as well as new section 6A, which is the new enhanced CIRMP requirement prescribing additional material risks.
Subsection 4A(4) provides that to the extent of any inconsistences between a baseline CIRMP requirement and an enhanced CIRMP requirement, a responsible entity must comply with the enhanced CIRMP requirements. This provision clarifies the intention for an enhanced CIRMP requirement to override a baseline CIRMP requirement in the event of an inconsistency. This policy position is justified on the basis that the enhanced CIRMP requirements represent a higher level of security than baseline CIRMP requirements, and therefore to the extent that any inconsistency may arise, the enhanced CIRMP requirements should prevail.
Subsection 4A(5) provides that matters in the following provisions are enhanced CIRMP requirements:
- section 6A (Additional material risks – enhanced requirements);
- section 8A (Cyber and information security hazards — enhanced requirements), section 8B (Credential compromise hazards) and section 8C (Lateral movement hazards);
- section 9A (Personnel hazards— enhanced requirements);
- section 10A (Supply chain hazards—enhanced requirements);
- section 11A (Physical security hazards and natural hazards—enhanced requirements).
Grace Periods
Subsection 4A(6) provides grace periods during which the enhanced CIRMP requirements do not start applying to a CI asset specified in subsection 4A(1) of these Rules. The head of power for this provision derives from subsection 30AB(3) of the SOCI Act which states that the rules may provide that, if an asset becomes a critical infrastructure asset, Part 2A does not apply to the asset during the period beginning when the asset became a critical infrastructure asset; and ending at a time prescribed in the rules.
Paragraph 4A(6)(a) provides grace periods for the application of new section 6A and subsections 8A(2) and 9A(2) to CI assets specified in subsection 4A(1) of these Rules:
- Under subparagraph 4A(6)(a)(i), for an asset that is a CI asset before the commencement of the Amendment Rules, section 6A, and subsections 8A(2) and 9A(2) do not apply to that asset for the period beginning when the asset first became a CI asset and ending at the end of the last day of the period of 12 months after the commencement of the subsection.
- Under subparagraph 4A(6)(a)(ii), for an asset that becomes a CI asset on or after the commencement of the Amendment Rules, section 6A, and subsections 8A(2) and 9A(2) do not apply to that asset for the period beginning when the asset first becomes a CI asset and ending at the end of the last day of the period of 12 months after the asset becomes a CI asset.
Paragraph 4A(6)(b) provides grace periods for the application of sections 8A (other than subsection 8A(2)), 8B, 8C, 9A (other than subsection 9A(2)), 10A and 11A:
- Under subparagraph 4A(6)(b)(i), for an asset that is a CI asset before the commencement of the Amendment Rules, the above-specified provisions do not apply to that asset for the period beginning when the asset first became a CI asset and ending at the end of the last day of the period of 24 months after the commencement of the subsection.
- Under subparagraph 4A(6)(b)(ii), for an asset that becomes a CI asset on or after the commencement of the Amendment Rules, the above-specified provisions do not apply to that asset for the period beginning when the asset first becomes a CI asset and ending at the end of the last day of the period of 24 months after the asset becomes a CI asset.
The purpose of providing grace periods is to ensure responsible entities for CI assets specified in subsection 4A(1) have adequate time to comply with the enhanced CIRMP requirements. For instance, providing a 24 month grace period for section 9A (other than subsection 9A(2)) is intended to provide adequate time for a responsible entity to ensure their critical workers have been assessed as suitable in accordance with new subsection 9A(4) in order to permit them to have access to critical components after the 24 month grace period.
Item 6 After section 6
This item inserts new section 6A ‘Additional material risks—enhanced requirements’ after section 6 of the CIRMP Rules.
Subsection 6A(1) provides that for the purposes of paragraph 30AH(1)(c) of the SOCI Act, a responsible entity for a CI asset specified in subsection 4A(1), must establish and maintain a system or process in their CIRMP to, as far as reasonably practicable to do so, minimise or eliminate the additional material risks mentioned in subsection 6A(2).
Subsection 6A(2) provides that for subsection 30AH(8) of the SOCI Act, the following specified risks are taken to be a material risk:
- any impairment of the CI asset’s functions that could prejudice the social stability, economic stability, national security or defence of Australia (paragraph 6A(2)(a));
- compromise or impairment of the functions of the CI asset as a result of, or in connection with FOCI (paragraph 6A(2)(b));
- offshore or remote access to critical components (paragraph 6A(2)(c)); and
- offshore or remote access to business critical data (paragraph 6A(2)(d)).
Paragraph 6A(2)(a) specifically states that such impairments of the CI asset’s functions ‘could’ prejudice. The effect of this phrasing is to make clear that the risk need not be definitive, but entities are encouraged to consider scenarios where an impairment ‘could’ threaten social and economic suitability, national security or defence of Australia.
Paragraph 6A(2)(b) specifies the risk of compromise or impairment of the functions of the CI asset as a result of, or in connection with FOCI, as a material risk. The effect of this provision is to ensure that the material risk of compromise or impairment of the functions of the CI asset as a result of, or in connection with FOCI, is considered in a responsible entity’s CIRMP across all hazard domains. This should include consideration of impacts to the availability, reliability, integrity and confidentiality of the asset from FOCI associated risks with technology or non-technology vendors, major suppliers or managed service providers or contractors critical to the operation of the asset.
For instance, a foreign-owned or foreign-influenced entity that provides critical systems, operational technology, software, maintenance services or operational support may, through its ownership structure or governance arrangements, be subject to foreign direction or coercion. In such circumstances, the responsible entity identifies a risk that vulnerabilities could be introduced, access could be misused, or support services could be withheld in a manner that compromises the availability, integrity or reliability of the CI asset.
Paragraphs 6A(2)(c) and (d) specify offshore or remote access to critical components and business critical data as material risks. The intention of these paragraphs is to accurately reflect the current threat environment and operating environments of critical infrastructure assets. It seeks to capture the risk arising from remote access to critical components or business critical data, and from offshored critical components or business critical data. This acknowledges the reality that an individual does not need to be onsite or onshore to gain access to critical components or business critical data.
For instance, remote access arrangements may reduce the entity’s ability to enforce physical security controls, supervise activity, or rapidly detect and respond to misuse of privileged access. Where access is undertaken from offshore locations, additional risks may arise due to foreign jurisdiction, differing legal regimes, exposure to foreign intelligence services, or reduced assurance over personnel security. If exploited, such access pathways could enable unauthorised system manipulation, data compromise or service disruption that could impair the availability or integrity of the CI asset.
It is worth noting that, in accordance with paragraph 30AH(1)(b) of the SOCI Act, the overall effect of new section 6A requires responsible entities for a CI asset specified in subsection 4A(1) to identify each hazard where there is a material risk that could have a relevant impact on the asset if it occurred (as subparagraph 30AH(1)(b)(i) of the SOCI Act); and to establish and maintain a process or system in the CIRMP to - so far as it is reasonably practicable to do so – minimise or eliminate any material risk of the hazard occurring (subparagraph 30AH(1)(b)(ii) of the SOCI Act). Therefore, responsible entities for a CI asset specified in subsection 4A(1) must do the above in relation to all hazards identified by the responsible entity, not just those specified in the instrument (e.g. personnel hazards).
Finally, when taken together, the effect of section 6A and subsection 4A(3) means that responsible entities for CI assets specified in subsection 4A(1) are obliged to comply with both section 6A (which is specified as an enhanced CIRMP requirement in subsection 4A(5)), as well as the baseline CIRMP requirement as it relates to material risks and all hazards (see section 6 and 7 of the CIRMP Rules).
Item 7 Subparagraph 7(1)(c)(i)
This item omits “section 6” from the end of subparagraph 7(1)(c) of the CIRMP Rules and substitutes “sections 6 and 6A”. The purpose of this amendment is to account for additional material risks contained in new section 6A that are applicable to the CIRMP of a responsible entity for a CI asset specified in subsection 4A(1).
Item 8 After paragraph 7(1)(c)
This item inserts a new note after paragraph 7(1)(c).
The note clarifies the obligations for responsible entities in relation to the material risks for which they must, as far as is reasonably practicable to do so, minimise or eliminate. The note provides material risks that are applicable to CI assets specified in subsection 4(1) are found in section 6. CI assets that are specified in new subsection 4A(1) are further subject to enhanced CIRMP obligations and therefore will need to account for material risks specified in section 6 as well as any additional material risks that are introduced by the provisions listed in 4A(5).
Item 9 After section 8
Section 8A – Cyber and information security hazards – enhanced requirements
New section 8A sets out enhanced CIRMP requirements that a responsible entity for a CI asset specified in subsection 4A(1) must comply with in relation to cyber and information security hazards.
Subsection 8A(1) provides that subsections (2), (3) and (4), of the section specify enhanced requirements in relation to cyber and information security hazards for the purposes of paragraph 30AH(1)(c) of the SOCI Act.
Subsection 8A(2) provides that a responsible entity for a CI asset specified in subsection 4A(1), must establish and maintain a process in the entity’s CIRMP to minimise or eliminate each of the following material risks, so far as it is reasonably practicable to do so:
- failure to patch or update operating or security systems in a timely manner; (paragraph 8A(2)(a));
- failure to replace legacy systems, or adequately mitigate risks associated with components or technology that are redundant, unsupported, obsolete or discontinued; (paragraph 8A(2)(b));
- deployment or hosting of advanced, novel or emerging technology in a manner that could prejudice the availability, integrity, reliability or confidentiality of the CI asset; (paragraph 8A(2)(c)); and
- use of advanced, novel or emerging technology against the asset, in a manner that could prejudice the availability, integrity, reliability or confidentiality of the CI asset. (paragraph 8A(2)(d)).
Subsection 8A(2) applies a threshold of “so far as it is reasonably practicable to do so” in recognition that mitigations required to meet some of the obligations (such as replacing legacy systems) are difficult or unfeasible to achieve due to capacity, cost or a range of other factors. Importantly however, the overarching obligation remains that a responsible entity must minimise or eliminate the material risks specified in this subsection (so far as is reasonably practicable to do so). For example, where it may be impracticable to completely replace legacy systems, the overarching obligation remains that risks associated with redundant technology are minimised or mitigated in other ways.
In relation to the term “advanced, novel or emerging technology” in paragraphs 8A(2)(c) and (d), the drafting is intended to be broad and expansive to avoid unnecessarily limiting its scope. It is intended to capture technology that responsible entities may already be aware of and implementing (such as AI) and technology that is not yet available (such as quantum cryptography).
Paragraph 8A(2)(c) is intended to capture the risk of responsible entities embedding advanced, novel or emerging technology in their systems or computers, and requires the responsible entity to consider ways to eliminate or mitigate this risk. For example, where a responsible entity deploys AI within their organisation, they could consider implementing limitations on the application within their organisation or networks, to limit the risk of AI.
Paragraph 8A(2)(d) is intended to capture the risk of use of advanced, novel or emerging technology against the asset, to the extent that it could prejudice the availability, integrity, reliability or confidentiality of the asset, and requires the responsible entity to consider ways to eliminate or mitigate this risk. For example, the use of frontier AI technology to rapidly scan for vulnerabilities in critical systems, which can then be exploited at a rate that far exceeds human capability. Responsible entities may seek to reduce attack paths and surfaces and ensure they are patching systems in a timely manner.
Subsection 8A(3) provides that a responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to comply with a cyber security framework contained in a document specified in column 1 of an item in the table, as in force from time to time specified, as well as meeting any specific conditions outlined in column 2 of that item.
The documents specified in column 1 are five contemporary cyber security frameworks that are recognised industry standards:
- Australian Standard AS ISO/ IEC 27001:2023
- Essential Eight Maturity Model published by the Australian Signals Directorate
- The NIST Cybersecurity Framework (CSF) 2.0 published by the National Institute of Standards and Technology of the United States of America.
- Cybersecurity Capability Maturity Model (Version 2.1) published by the Department of Energy of the United States of America.
- The 2023 AESCSF Framework Core published by Australian Energy Market Operator Limited (ACN 072 010 327).
Column 2 specifies some conditions to be met in relation to the framework specified in column as per subsection 8A(3)(b):
- Those entities using the Australian Signals Directorate’s Essential Eight Maturity Model are required to meet maturity level two as indicated in that document.
- Those entities using the Cybersecurity Capability Maturity Model (Version 2.1) published by the Department of Energy of the United States of America must meet Maturity Indicator Level 2 as indicated in that document.
- Entities using The 2023 AESCSF Framework Core published by Australian Energy Market Operator Limited (ACN 072 010 327) are required to meet Security Profile 2 as indicated in that document.
The note under subsection 8A(3) provides that sections 30AN and 30ANA of the SOCI Act provide for the incorporation of the documents mentioned in the subsection as in force from time to time. This note clarifies that by virtue of these aforementioned sections in the SOCI Act, this subsection may, despite subsection 14(2) of the Legislation Act 2003, make provision in relation to a matter by applying, adopting or incorporating with or without modification any matter:
- Contained in a standard proposed or approved by Standards Australia as in force or existing from time to time (see subsection 30AN(3) of the SOCI Act);
- Contained in a relevant document as in force or existing from time to time (see subsection 30ANA(2) of the SOCI Act).
The purpose of this note is to refer to the head of powers in the SOCI Act that allows the displacement of subsection 14(2) of the Legislation Act, to enable the most up-to-date versions of all the documents prescribed in subsection 8A(3) to be incorporated by reference, including any versions of that document that have been amended post the commencement of this instrument.
Subsection 8A(4) provides that a responsible entity for a CI asset specified in subsection 4A(1) can meet its obligations under subsection (3) by establishing a and maintaining a process or system in their CIRMP to comply with another framework that is equivalent to a framework in a document mentioned in items 2, 4 and 5 of the table (including meeting the prescribed conditions in column 2 for those items). This recognises that there may be alternate cyber security frameworks that can achieve the desired uplift in cyber security, and provides responsible entities the flexibility to comply with an alternative framework that is equivalent to a document mentioned in subsection 8A(3) (including any relevant conditions), to comply with their obligations imposed by subsection 8A(3).
Subsection 8A(5) provides that for subsections 30AKA(1), (3) and (5) of the SOCI Act, a responsible entity for a CI asset specified in subsection 4A(1) must also have regard to whether the entity’s CIRMP includes appropriate measures that minimise or eliminate material risks to the asset including those specified in subsection (2).
Section 8B - Credential compromise hazards
New section 8B sets out requirements that a responsible entity for a CI asset specified in subsection 4A(1) must comply with in their CIRMP in relation to credential compromise hazards, which is a new hazard vector introduced through the Amendment Rules.
Subsection 8B(1) provides that this new section 8B applies if a responsible entity for a CI asset specified in subsection 4A(1) complies with a cyber framework specified under subsections 8A(3) or (4) which does not require the implementation of phishing resistant multi-factor authentication (MFA) controls. MFA is not defined as a term in the Amendment Rules, but it is a well understood term amongst industry as a method of authentication that requires independent verification steps in a manner that cannot be subverted, intercepted, relayed, duplicated or otherwise compromised by social-engineering or credential-harvesting techniques.
Subsection 8B(2) provides that for paragraph 30AH(1)(c) of the SOCI Act, the following subsection (3) specifies requirements for credential compromise hazards.
Subsection 8B(3) provides that a responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in their CIRMP to – so far as is reasonably practicable to do so:
- Outline the systems or networks where MFA is required to authenticate access to their organisation’s internet connected computers and critical systems; privileged and unprivileged access to critical components, and remote access to computer applications, systems or services (paragraph 8B(3)(a));
- Minimise or eliminate any material risk of a credential compromise hazard occurring; and (paragraph 8B(3)(b); and
- Mitigate the relevant impact of a credential compromise hazard on the CI asset. (paragraph 8B(3)(c)).
Subsection 8B(4) provides that for subsection 30AH(9) of the SOCI Act, the implementation of MFA controls as described in subsection 8B(5) is taken to be the action that minimises or eliminates any material risk that the credential compromise hazard could have a relevant impact on the asset. The effect of this subsection is that, if a responsible entity implements MFA controls as described in the following subsection (5), they have acquitted the obligation to minimise or eliminate any material risk that a credential compromise hazard could have a relevant impact on the asset, and won’t be required to take further action beyond the steps in subsection (5).
Subsection 8B(5) provides specific requirements for how MFA controls should be implemented for the purposes of subsection 8B(4). A responsible entity for a CI asset specified in subsection 4A(1) must implement MFA controls for the systems and networks outlined in paragraph (3)(a) (paragraph 8B(5)(a)), and also centrally log, monitor and routinely review both successful and unsuccessful multi-factor authentication attempts (paragraph 8B(5)(b)).
The note under subsection 8B(5) clarifies that where a responsible entity for a CI asset specified in subsection 4A(1) cannot implement the measures outlined in subsections 8B(4) and (5), they will still be subject to the general obligations in subsection 8B(3) to establish and maintain a process or system in the entity’s CIRMP to minimise or eliminate material risks that a credential compromise hazard could have a relevant impact on the asset.
Subsection 8B(6) provides that for subsections 30AKA(1), (3) and (5) of the SOCI Act, a responsible entity for a CI asset specified in subsection 4A(1) must also have regard to whether the entity’s CIRMP:
- includes a process or system capable of outlining all of the systems and networks where MFA is required under paragraph (3)(a);
- describes the credential compromise hazards that could have a relevant impact on the asset; and
- contains appropriate measures to minimise or eliminate material risks to the asset.
Section 8C - Lateral movement hazards
New section 8C sets out requirements that a responsible entity for a CI asset specified in subsection 4A(1) must comply with in their CIRMP in relation to lateral movement hazards, which is a new hazard vector introduced through the Amendment Rules.
Subsection 8C(1) provides that, paragraph 30AH(1)(c) of the SOCI Act, subsection (2) specifies requirements for lateral movement hazards.
Subsection 8C(2) provides the CIRMP obligations in relation to addressing lateral movement hazards. A responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in their CIRMP to – so far as is reasonably practicable to do so:
- Identify and maintain an inventory of critical systems and how they are connected with other critical systems and other computers (paragraph 8C(2)(a));
- Recover and restore critical systems in the event where an incident has had or is having a relevant impact on the asset (paragraph 8C(2)(b);
- Ensure the continued availability of the asset whilst rebuilding or restoring critical systems (paragraph 8C(2)(c)); and
- So far as reasonably practicable to do so - minimise or eliminate any material risk of a lateral movement hazard occurring, and mitigate the relevant impact of the lateral movement hazard on the CI asset (subparagraphs 8C(2)(d)(i) and (ii) respectively).
Subsection 8C(3) provides that for subsection 30AH(9) of the SOCI Act, the implementation of network segregation as described in subsection 8C(4) is taken to be the action that minimises or eliminates any material risk that the lateral movement hazard could have a relevant impact on the asset. The effect of this subsection is that, if a responsible entity implements network segregation as described in the following subsection (4), they have acquitted the obligation to minimise or eliminate any material risk that a lateral movement hazard could have a relevant impact on the asset, and won’t be required to take further action beyond those steps.
Subsection 8C(4) contains the elements that are required, for the purposes of subsection 8C(3), to achieve network segregation:
- ensuring critical systems can be segregated as between critical systems, and between critical systems and other computers (paragraph 8C(4)(a));
- ensuring critical systems can be operationally independent from other internet connected computers and critical systems (paragraph 8C(4)(b));
- ensuring critical systems can continue to be operational for a period of at least three months while other computers are in a state of restoration or recovery (paragraph 8C(4)(c));
- implementing logical access controls for network traffic between critical systems, and between critical systems and other computers (paragraph 8C(4)(d));
- centrally log, monitor and routinely review access logs for communication paths between critical systems, and between critical systems and other computers (paragraph 8C(4)(e)); and
- implementing principles of least privilege across computers that connect to critical systems (paragraph 8C(4)(f)).
The note under subsection 8C(4) clarifies that where a responsible entity for a CI asset specified in subsection 4A(1) cannot implement the measures outlined in subsections 8C(3) and (4), they will still be subject to the general obligations in subsection 8C(2), including the need to establish and maintain a process or system in the entity’s CIRMP to minimise or eliminate material risks that a lateral movement hazard could have a relevant impact on the asset.
Finally, subsection 8C(5) provides that for subsections 30AKA(1), (3) and (5) of the SOCI Act, a responsible entity for a CI asset specified in subsection 4A(1) must also have regard to whether the entity’s CIRMP:
- describes the lateral movement hazards that could have a relevant impact on the asset;
- includes a process or system capable of identifying the matters under paragraphs 8C(2)(a), (b) and (c); and
- contains appropriate measures to minimise or eliminate material risks to the asset.
Item 10 Subsection 9(2) (note)
This item repeals the current note after subsection 9(2), and substitutes a new note which provides, subject to the new subsection 9A(4), a responsible entity is not required to use the AusCheck scheme to assess the suitability of critical workers, unless the responsible entity is a responsible entity of an asset specified in subsection 4A(1).
The purpose of this amendment is to support the requirements inserted by the Amendment Rules particularly in relation to mandating the use of AusCheck by responsible entities for a CI asset specified in subsection 4A(1) to assess the suitability of critical workers.
Item 11 After section 9
New section 9A sets out enhanced CIRMP requirements that a responsible entity for a CI asset specified in subsection 4A(1) must comply with in relation to personnel hazards.
Subsection 9A(1) provides that for paragraph 30AH(1)(c) of the SOCI Act, subsections (2), (3), (4), (5), (6) and (7) specify enhanced requirements for personnel hazards.
Personnel security – access management
Subsection 9A(2) provides that a responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to minimise or eliminate material risks associated with:
- unauthorised or unsupervised access to critical components; (paragraph 9A(2)(a));
- the compromise or misuse of credentials and privileged access used by individuals to access the CI asset (paragraph 9A(2)(b));
- access to the CI asset by persons other than critical workers (paragraph 9A(2)(c)); and
- incoming and outgoing critical workers (paragraph 9A(2)(d)).
Suitability of critical workers
The provisions provided in subsections 9A(3) - (6) are intended to uplift the background checking requirements for responsible entities that are subject to subsection 4A(1), to be commensurate with the higher risk level and threat environment faced by those entities. These provisions build on existing suitability assessment provisions in section 9 of the CIRMP Rules, and mandate more stringent requirements for entities subject to subsection 4A(1). This is balanced with risk assessment measures and risk minimisation and elimination provisions in subparagraph 9A(3)(a)(ii).
Subsection 9A(3) provides that a responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to:
- permit a critical worker access to critical components only where the critical worker has been assessed to be suitable in accordance with subsection (4) (subparagraph 9A(3)(a)(i)); or
- if the critical worker is unable to meet the requirements outlined in subsection (4) – the responsible entity has outlined in their CIRMP the risk associated with the employment of the critical worker and actions taken, or actions that will be taken as soon as reasonably practicable, to minimise or eliminate the risk to the asset; (subparagraph 9A(3)(ii)) and
- proactively monitor, identify and take action in relation to any developments or changes that may affect the ongoing suitability of a critical workers (paragraph 9A(3)(b)).
The purpose of subsection 9A(3) is to create an imperative for the responsible entity to better protect their CI assets by ensuring the suitability of their critical workforce before giving them access to critical components. It also ensure through 9A(3)(b) that responsible entities have demonstrated in their CIRMP that they have taken a proactive role in monitoring, identifying and taking action in relation to any developments or changes that may affect the ongoing suitability of a critical worker.
It is not the intent that this measure be the only suitability requirement or replace standard suitability HR practices. This requirement provides the minimum standard that must be met by the responsible entity for a CI asset specified in subsection 4A(1) before giving a critical worker access to critical components.
Subparagraph 9A(3)(a)(ii) recognises the difficulty inherent in organising an AusCheck background check and the limitations in obtaining a relevant security clearance for critical workers (particularly offshore workers). It provides an alternative option for the responsible entity, where these steps cannot be taken. In line with this subparagraph, a responsible entity can still give critical workers access to critical components so long as the entity has outlined, in the CIRMP, the risks of their employment, and actions that will be taken to minimise the risk to the asset.
Subparagraph 9A(3)(a)(ii) also foresees the circumstance in which an AusCheck background check or relevant security clearance cannot be obtained due to processing times. This provision allows responsible entities to employ a risk assessment and risk minimisation and elimination approach in the interim while awaiting the finalisation of an AusCheck background check or relevant security clearance.
Subsection 9A(4) supplements paragraph 9A(3)(a) by providing how a responsible entity for a CI asset specified in subsection 4A(1) must assess the suitability of their critical workers. It provides that for paragraph (3)(a) and paragraph 30AH(4)(a) of the SOCI Act, a critical worker may be assessed as suitable only if:
- the critical worker has been the subject of an AusCheck background check and, following the completion of the AusCheck background check, they have been assessed as suitable by the responsible entity considering the matters in subsection 9(5) of the CIRMP Rules (paragraph 9A(4)(a)); or
- the critical worker holds a relevant security clearance at the time the person was identified to be a critical worker (paragraph 9A(4)(b)).
The note after subsection 9A(4) clarifies the interaction between a relevant security clearance and the requirement to undergo an AusCheck background check. It explains that a critical worker who already holds a relevant security clearance is not required to undertake an AusCheck background check for the purposes of these provisions. However, where a critical worker has applied for a relevant security clearance and their application is still pending, the note makes clear that the critical worker may only be permitted to access critical components if requirements in either paragraph (4)(a) or subparagraph (3)(a)(ii) are met.
Further matters relating to AusCheck background checks
Subsection 9A(5) provides mandatory considerations where an AusCheck background check is being used to assess the suitability of a critical worker in compliance with paragraph (4)(a). It provides that where a CIRMP permits an AusCheck background check to be conducted for the purposes of paragraph (4)(a), the background check must:
- include an assessment of the information outlined in subsection 9(3) of the CIRMP Rules (paragraph 9A(5)(a));
- be conducted in accordance with subsection 9(4) (paragraph 9A(5)(b)); and
- if the background check relates to a person requiring ongoing access to critical components – be conducted (at minimum) every 5 years (paragraph 9A(5)(c)).
Further matters relating to relevant security clearances
Subsection 9A(6) provides further requirements for a responsible entity where the suitability of a critical worker is assessed by their holding of a relevant security clearance for the purposes of paragraph (4)(b). It provides that if a CIRMP permits a critical worker access to critical components due to their being assessed as suitable by holding a relevant security clearance for the purposes of paragraph (4)(b), the responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the CIRMP to ensure that, before that clearance lapses, or expires the person has undergone a revalidation of their relevant security clearance; or has undergone an AusCheck background check and has been assessed as suitable considering the matters in subsection 9(5) of the CIRMP Rules.
The purpose of this amendment is to ensure that the responsible entity has processes in place to minimise disruptions to their business operations (and risks to their CI asset) caused by critical workers having expiring or expired security clearances.
Subsection 9A(7) provides that for subsections 30AKA(1), (3) and (5) of the SOCI Act, a responsible entity must also have regard to whether the entity’s CIRMP:
- contains appropriate measures that minimise or eliminate material risks to the CI asset, including those specified in subsection 9A(2);
- includes processes or systems capable of identifying the matters in subsections 9A(3) and (4) for their CI asset.
The effect of this amendment is that a responsible entity whose CIRMP lacks these measures in relation to managing access management and assessing suitability of critical workers should consider revising or varying their CIRMP. Responsible entities may need to identify existing personnel security measures, identify gaps, and update their CIRMP to include strengthened processes for access control and suitability assessment.
Item 12 After section 10
New section 10A sets out enhanced CIRMP requirements that a responsible entity for a CI asset specified in subsection 4A(1) must comply with in relation to supply chain hazards.
Subsection 10A(1) provides that for paragraph 30AH(1)(c) of the SOCI Act, subsections (2), (3), (4) and (5) specify enhanced requirements for supply chain hazards.
Supply chain mapping
Subsection 10A(2) provides that a responsible entity of a CI asset specified in subsection 4A(1) must establish and maintain a system or process in the entity’s CIRMP to map their supply chain for major suppliers and critical components across their supply chains.
Subsection 10A(3) supplements subsection 10A(2) and further provides that, in accordance with subsection (2), the entity’s CIRMP must:
- identify risks in the entity’s supply chain that may affect the availability, integrity, reliability or confidentiality of critical components or compromise business critical data (paragraph 10A(3)(a));
- identify the maximum acceptable outage for the CI asset or any of its critical components arising from the disruption to the entity’s supply chain (paragraph 10A(3)(b)); and
- as far as is reasonably practicable to do so, include measures to minimise or eliminate against those risks, or mitigate the impact of an outage that exceeds the maximum acceptable outage identified in paragraph (3)(b) (paragraph 10A(3)(c)).
Subsections 10A(2) and (3) emphasise the importance of considering vulnerabilities to the entity’s supply chain as part of securing CI assets, as well as preparing for any outages or disruptions to ensure that a CI asset can continue to deliver critical services and functions as needed.
For example, through mapping its supply chain, a responsible entity for a critical electricity asset may identify that a key operational technology component is supplied by a single overseas manufacturer. Through this process, the entity also identifies that the supplier is subject to foreign ownership, control or influence and that there are limited alternative suppliers available in the short term. In response, the entity updates its CIRMP to implement mitigating controls such as enhanced contractual protections, restrictions on remote access, increased monitoring of supplier access to systems, and contingency arrangements with an alternative supplier where practicable. These are reasonable steps that go towards minimising or eliminating the material risk of disruption, compromise or misuse arising from reliance on that single supplier.
The note under subsection 10A(3) provides that mitigation measures for the purpose of paragraph (3)(c) may include, but are not limited to supplier diversification, redundancy planning, recovery, resilience and restoration processes.
Vendor assessment
Subsection 10A(4) requires responsible entities for a CI asset specified in subsection 4A(1) to establish and maintain a system or process in the entity’s CIRMP to assess the risks associated with an existing or proposed major supplier for the CI asset. This focus on individual suppliers or vendors complements the previous measures, which require responsible entities to map supply chains for major suppliers and critical components in their supply chain.
Subsection 10A(5) provides that the system or processes that are outlined in the CIRMP for purposes subsection 10A(4) must identify a number of factors. These are:
- in relation to FOCI risks, legislative or other legal requirements to which the supplier is subject to (paragraph 10A(5)(a));
- restrictions, sanctions or other impediments affecting the jurisdiction in which the entity may be subject to (paragraph 10A(5)(b));
- the access, influence and control the supplier has over the CI asset in connection with the product or service the supplier provides (paragraph 10A(5)(c));
- the extent to which the matters in paragraphs 10A(5)(a), (b) and (c) together may present a material risk for the CI asset or could exceed a maximum acceptable outage of the service or product provided by the supplier (paragraph 10A(5)(d)); and
- as far as reasonably practicable to do so, steps to minimise or eliminate material risks and mitigate the relevant impact of the hazard on the CI asset (paragraph 10A(5)(e)).
For example, an engineering company is based overseas and engaged to design a critical component of an asset. Through the vendor management process, a FOCI risk is identified. To mitigate the identified risk, the entity considers diversifying options for delivery, but further market research clearly outlines that diversification is not an option. The entity considers options to mitigate this risk given no feasible alternative and implements contractual conditions to limit offshoring, through design and implementation phases, restrict access arrangements, and include remediation and step-in clauses.
Subsection 10A(6) provides that for subsections 30AKA(1), (3) and (5) of the SOCI Act, a responsible entity must have regard to whether the CIRMP includes a process or system capable of identifying the matters in paragraphs (3)(a), (b) and (c) for their CI asset (paragraph 10A(6)(a)); and whether the CIRMP includes a process or system capable of identifying the matters in paragraphs 10A(5)(a) to (e) (paragraph 10A(6)(b)). In effect, this means that a responsible entity whose CIRMP lacks these measures should consider revising or varying the CIRMP to address this shortfall.
Item 13 After section 11
New section 11A sets out enhanced CIRMP requirements that a responsible entity for a CI asset specified in subsection 4A(1) must comply with in relation to physical security hazards and natural hazards.
Subsection 11A(1) provides that for the purpose of paragraph 30AH(1)(c) of the SOCI Act, for physical security hazards and natural hazards, a responsible entity for a CI asset specified in subsection 4A(1) must establish and maintain a process or system in the entity’s CIRMP to:
- centrally manage physical security and natural hazards (paragraph 11A(1)(a)); and
- as far as it is reasonably practicable to do so, outline and consider the physical security consequences arising from the occurrence of all hazards, including cyber and information security hazards, credential compromise hazards, lateral movement hazards, other physical and natural hazards, personnel hazards and supply chain hazards (paragraph 11A(1)(b)).
Paragraph 11A(1)(b) realises that non-physical hazards can have physical security impacts and seeks to have responsible entities ensure their CIRMPs cover these eventualities. The threshold of reasonable practicability is appropriate to ensure that entities, while needing to comply with these obligations, are not compelled to do things that are not practicable or achievable.
The note after subsection 11A(1) provides examples of non-physical hazards that have physical security consequences to assist with illustrating the policy intention. The note provides that these include malicious cyber incidents that opens gates to allow unauthorised access, or a supply chain delay that results in changes to workplace operations that decrease the ability to deter, detect, delay and defend against a security breach.
Subsection 11A(2) applies in relation to paragraph 11A(1)(a), which requires a CIRMP to contain a system or process to centrally managing physical security and natural hazards. As part of complying with that obligation, subsection 11A(2) requires that the CIRMP must outline details such as the location, ownership, and nature of the site upon which their asset is located; the critical components of the CI asset, and areas within the asset that hold business critical data or contain critical components, including critical systems.
Subsection 11A(3) applies in relation to paragraph 11A(1)(b), which requires a CIRMP to contain a system or process to, as far as reasonably practicable, consider and outline the following the physical security consequences arising from the occurrence of hazards from any hazard vectors. As part of complying with this obligation, paragraph 11A(3)(a) requires the responsible entity to outline physical access controls to the CI asset for workers, official visitors, and the public. These controls could include (but are not limited to):
- access controls for critical components and critical systems to restrict access to critical workers or accompanied visitors;
- maintaining surveillance and security alarm systems, such that critical components and critical systems are subject to continuous monitoring.
- specific protective security measures for business hours and out-of-hours.
Paragraph 11A(3)(b) requires, for the purposes of complying with paragraph 11A(1)(b), the responsible entity to also consider other security measures that increase the ability to deter, detect, delay, respond to and recover from a breach in security for all critical components.
Finally, paragraph 11A(3)(c) further requires the responsible entity to outline mitigation and response measures to be taken where a physical security incident or a physical security consequence has been detected.
Subsection 11A(3) emphasises the importance of managing physical security and natural hazards and provides responsible entities with a set of detailed considerations that should be captured in their CIRMP.
Subsection 11A(4) clarifies and considers the purposes of subsections 30AKA(1), (3) and (5) of the SOCI Act, a responsible entity for a CI asset specified in subsection 4A(1) must have regard to whether the CIRMP contains systems or processes capable of identifying the matters in subsections 11A(1) – (3). In effect, a responsible entity of a CI asset should actively consider whether their CIRMP meets the enhanced CIRMP obligations in relation to relevant processes or systems in relation to physical security hazards and natural hazards in subsection 11A(1), and if they are lacking, the entity should consider revising or varying the CIRMP.
Application and transitional provisions
The Amendment Rules also insert a new Part 3 into the CIRMP Rules. This new part contains a new section 12 which provides for how the obligations in the Amendment Rules apply in relation to assets that have been declared under section 51 of the SOCI Act before the Amendment Rules commence.
Section 12 provides that the obligations in these Amendment Rules do not apply in relation to an asset that:
- was declared to be a critical infrastructure asset under section 51 of the SOCI Act prior to the commencement of the Amendment Rules;
- where that declaration states that the asset is subject to Part 2A of the SOCI Act; and
- where the declaration that was made before the commencement of the Amendment Rules continues to be in force.
The note after this provision explains that where an asset was declared to be a critical infrastructure asset under section 51 of the SOCI Act prior to the commencement of the Amendment Rules, and the declaration declares that asset is subject to Part 2A of the SOCI Act, that obligation does not automatically include compliance with the enhanced CIRMP requirements specified in subsection 4A(5).
The practical impact of the new section 12 is that the obligations in the Amendment Rules are not retrospectively applied to existing CI assets that were declared under section 51 of the SOCI Act, and to whom Part 2A of the SOCI Act applies. Where there is an intent for one of these existing CI assets to need to comply with the enhanced obligations in the Amendment Rules, that CI asset would need to have a new declaration made in relation to it.
Attachment B
Statement of Compatibility with Human Rights
Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011
Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026
This Disallowable Legislative Instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.
Overview of the Disallowable Instrument
The Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (the Amendment Rules) amend the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 (CIRMP Rules) to introduce enhanced obligations for specific critical infrastructure asset classes that are considered at higher risk of targeting, with the aim of strengthening governance, risk management, and resilience against evolving national security threats.
Operational and legislative context
Australia’s security and economic resilience depend on the integrity and availability of critical infrastructure. The increasing interconnectedness of Australia’s critical infrastructure creates efficiencies and fosters growth but also enables a compromise in one part of a network to rapidly cascade across multiple sectors. It is vital that the risks of such hazards impacting critical infrastructure in this manner are mitigated, and where possible, eliminated.
Accordingly, the CIRMP Rules puts a positive obligation on responsible entities to manage material risks across all hazard vectors, including cyber and information security, physical, personnel and supply chain domains, and to minimise or eliminate them, as far as is reasonably practicable. The Amendment Rules aim to strengthen these obligations further by introducing further, enhanced security obligations for critical infrastructure assets in sectors that Australia’s intelligence agencies have identified are most at risk.
This uplift is required in light of the evolving threat landscape and will ensure the asset classes it applies to can reliably mitigate and eliminate the more diverse and complex threats identified. These asset classes include:
o Energy sector: critical energy market operator asset, critical electricity asset, critical gas asset, critical liquid fuel asset;
o Communication sector: critical broadcasting asset, and domain name systems;
o Water and sewerage sector: critical water asset;
o Transport sector: critical freight service asset, and critical freight infrastructure asset.
Overview of measures
All hazards - Responsible entities subject to the Amendment Rules will be required to consider additional material risks in their CIRMP. These include risks associated with impairments of the asset’s functions that results in a prejudice to its availability, integrity, reliability or confidentiality of information; risks arising from foreign ownership, influence and control; and risks associated with offshore remote access to critical systems or business critical data.
Cyber security - Responsible entities will also be required to consider a number of additional cyber material risks in their CIRMP, including the risks relating to the availability, integrity and confidentiality arising from, but not limited to, the deployment of advanced and emerging technology in their asset, and the use of that same technology by malicious actors against their asset. Responsible entities will also need to consider the risk posed by a failure to replace or update critical systems and components, which would force them to use legacy systems, unsupported software or ageing hardware for which updates or patches are no longer available.
To promote a higher level of cyber security, the Amendment Rules apply will also specify higher (Level 2) maturity levels/profiles for specific cyber security frameworks, such as the Australian Signals’ Directorate’s Essential Eight Maturity Model, the Cybersecurity Capability Maturity Model or the 2023 AESCSF Framework Core. Responsible entities to whom the Amendment Rules apply will be required to comply with an alternative framework that achieves an equivalent level of security, or outline in their CIRMP how they are achieving an equivalent level when utilising a different framework.
Credential compromise and lateral movement - The Amendment Rules also introduce requirements to implement the ability to authenticate any online or internet facing networks, privileged and unprivileged users of critical systems and remote access to networks and systems (known as ‘multi-factor authentication’ or MFA) and segregating critical systems and other networks as network protection measure (known as network segregation). Should a responsible entity’s chosen cyber security framework not mandate phishing resistant, the responsible entity will need to implement this measure in addition to their chosen cyber security framework. These measures address material risks related to unauthorised access and credential compromise hazards, and the lateral movement hazard between systems of malicious activity, respectively. To be held as addressing these two hazards, the Amendment Rules provide that responsible entities whose CIRMPs provide a process or system to implement MFA and network segregation as outlined will be held to have minimised or eliminated the material risks associated with those hazards.
Personnel security - Responsible entities will be required to maintain a documented personnel security plan to address personnel hazard security risks and should incorporate existing personnel hazard obligations in the existing CIRMP Rules. This includes the development and maintenance of a process to minimise or eliminate the risk associated with unauthorised access to critical components, misuse/compromise of credentials and privileged access, workforce turnover, etc.
The Amendment Rules also mandate that all critical workers be subjected to AusCheck background checks or hold a relevant security clearance at Negative Vetting 1 level or higher, as issued by an Australian government agency who is authorised to do so. These processes are implemented to assist responsible entities with determining whether critical workers are suitable to have access to their critical infrastructure asset. Responsible entities will need to establish and maintain a process or system to proactively monitor, identify and then act to any changes or developments that may impact personnel to work in a critical worker role.
Supply chain - Responsible entities will be required to establish and maintain a system or process in their CIRMP to map their supply chains for major suppliers or critical systems. This will then enable them to identify vulnerabilities and risks in their supply chain and, as far as it is practicable to do so, have controls to mitigate these. As part of the supply chain portion of the CIRMP, the Amendment Rules will also require a responsible entity to identify the maximum tolerable outage for the CI asset or any of its critical components, and as far as it is practicable to do so have controls to mitigate the attendant risks.
Consideration of supply chain risks in the CIRMP will also extend to assessing the FOCI-related risks and how they might impact an entity’s supply chain. Where FOCI risks are detected and alternate vendors are not practicable, the Amendment Rules do not preclude the use of that vendor or product. Rather, the responsible entity should consider mitigations to minimise the potential impact for that FOCI risk to impact or disrupt the continued function and availability of their asset.
Physical and natural security - Finally, responsible entities will be required to establish and maintain a physical security and natural hazard security plan to minimise or eliminate impacts on their asset because of physical threats or other dangers, such as cyber and information security hazards, personnel hazards and supply chain hazards. This plan should consider and outline protective security mitigations and controls to prevent disruption or impact on an asset, accounting for defence in depth principles.
Human rights implications
This Disallowable Legislative Instrument engages the following rights:
- The right to work under conditions safeguarding fundamental political and economic freedoms to the individual in Article 6 of the International Covenant on Economic, Social and Cultural Rights (ICESCR).
- The right to an adequate standard of living, including food energy and water in Article 11 of the ICESCR.
- The right to privacy in Article 17 of the International Covenant on Civil and Political Rights (ICCPR).
- The right to equality and non-discrimination in Article 2(1) and Article 26 of the ICCPR, Article 2(2) of the ICESCR
The right to work
Article 6(1) of the ICESCR provides for the right to work, including the right to productive employment under conditions safeguarding fundamental political and economic freedoms to the individual. Article 6 commits State Parties to the Covenant to take measures to safeguard this right. The United Nations Committee on Economic Social and Cultural Rights has stated that this protection includes the right to not be unfairly deprived of work. Any limitations need to be reasonable, necessary and proportionate to the legitimate objective sought to be achieved.
The amendments provide that responsible entities must establish and maintain a process or system in the entity’s CIRMP to assess the suitability of critical workers that can access critical components, and permit those workers access only where they are assessed as suitable. Individuals seeking to undertake or continue employment as a critical worker for a responsible entity, will need to be capable of being assessed as suitable as part of an AusCheck background check or hold a relevant Australian security clearance. The individual will also need to undergo ongoing AusCheck background checking or maintain their relevant Australian security clearance as part of the responsible entity’s revalidation requirements. AusCheck background checks as part of these requirements includes a security check through the Australian Security Intelligence Organisation, to address insider threat risks. Mandatory AusCheck background checking is proportionate to the risk that compromise from trusted insiders could have on the critical infrastructure asset and is consistent with other frameworks under the Aviation Transport Security Act 2024 and the Maritime Transport and Offshore Security Act 2023.
Where a critical worker is unable to meet background checking or security clearance requirements, access to critical components may still be permitted where the responsible entity has identified and assessed the risks associated with the employment of that critical worker in its CIRMP and implements measures, as soon as reasonably practicable, to minimise or eliminate those risks.
The amendments engage the right to work by permitting critical workers access to critical components and critical systems only where they have been assessed to be suitable in accordance with relevant requirements. For critical workers, this requires responsible entities to conduct an AusCheck background check which includes a national intelligence-related background check or where they hold a relevant Security clearance. As a result, decisions relating to a person’s access to, or continuation in, critical worker roles may be influenced by the findings of this background check. The outcome of an AusCheck background check may lead to an assessment by a responsible entity to take a number of actions, including terminating a person's employment if the person has been convicted of a CIRMP level 1 offence or convicted of and sentenced to imprisonment for a CIRMP level 2 offence. Therefore AusCheck's advice could limit the right to work of some individuals, particularly if an individual has been convicted of a CIRMP level 1 offence, or convicted of and sentenced to imprisonment for a CIRMP level 2 offence, or where an adverse or qualified security assessment has been made in respect of the individual, if the result of advice from AusCheck is that the responsible entity considers the individual to be not suitable for a critical worker role.
Although this requirement may place limitations on an individual’s ability to obtain or retain employment in critical worker positions, the limitation is reasonable, necessary and proportionate in achieving the legitimate objective of protecting national security. The requirements are targeted only at roles requiring access to critical components and/or critical systems and therefore do not apply more broadly across the workforce. Background checking provides responsible entities with a structured, evidence and intelligence-based mechanism to identify personnel risks that may not otherwise be apparent, and reduces the likelihood of unauthorised access, insider threats, or compromise of critical systems. Additionally, where an individual is unable to meet background checking requirements a responsible entity may still facilitate access to critical components through the deployment of measures that minimise or eliminate the risks to the asset associated with the employment of that critical worker.
By ensuring that only suitable individuals are permitted access to critical infrastructure assets, the measure is rationally connected to the objective of protecting national security. Critical worker roles often involve access to systems, assets and components whose compromise could result in significant harm, including disruption to essential services and cascading impacts across the economy, ensuring the suitability of such personnel is essential at all stages of the employee lifecycle. To the extent that the right to work is engaged, such limitation is reasonable and proportionate. Limiting or controlling access to a critical component and/or critical system of a critical infrastructure asset only affects the person's access to that critical component and/or critical system and may not impact their ability to be employed within other areas of the business or the sector.
In accordance with section 12 of the Auscheck Act 2007 (AusCheck Act), the Secretary of the Department of Home Affairs must give written notice of a preliminary assessment that an individual has an unfavourable criminal history. In accordance with this process, an individual has the opportunity make representations to the Secretary before a final assessment is provided to a responsible entity. This built-in review and response mechanism ensures procedural fairness and contributes to the proportionality of the Amendment Rules.
This obligation is consistent with the Fair Work Act 2009, as the Amendment Rules do not mandate a responsible entity to terminate or decline to recruit an employee on the basis of an adverse background-check outcome. Responsible entities are required to consider the specific risks identified and determine how those risks can be mitigated or eliminated so far as is reasonably practicable. Employment decisions remain a matter for the responsible entity, which must ensure that any action taken is fair, proportionate and consistent with its broader workplace relations obligations. The Amendment Rules support both the protection of critical infrastructure and the preservation of fair and lawful employment practices. Nothing in the Amendment Rules, the AusCheck Act or the SOCI Act truncates or limits the rights of employees under the Fair Work Act 1999 or relevant State or Territory industrial relations legislation. Responsible entities will still need to comply with all requirements concerning dismissal or redundancy under that legislation.
The right to an adequate standard of living, including energy and water
Article 11 of the ICESCR provides for the right of everyone to an adequate standard of living, including adequate food, clothing and housing and the continuous improvement of living conditions. Article 11 commits States Parties to the Covenant to take measures to safeguard these standards.
The Amendment Rules require responsible entities of critical infrastructure assets to manage risks that hazards may pose to the continued operation of critical infrastructure assets, which may impact the supply of products and services essential to an adequate standard of living, such as access to energy and clean water. A comprehensive set of rules commensurate to the current threat environment to manage risks enhances an adequate standard of living by recognising the role that critical infrastructure assets may play in delivering essential supplies that maintain and sustain life.
For example, the instrument requires the responsible entities for critical electricity assets and critical water assets to manage supply chain risks. This is necessary to reduce the likelihood of supply chain disruptions both upstream and downstream of energy and water sector assets. Critically, the proposed supply chain mapping and vendor assessment will identify key vulnerabilities in supply chains to mitigate supply-based risks to energy and water availability. By, for example, stabilising supply chain shocks to critical electricity assets and critical water assets, the flow on impacts to other essential services including health and hygiene, and access to adequate food are better controlled and disruptions reduced.
Overall, requiring responsible entities to comply with Rules will reduce the likelihood of a disruption to distribution networks and other key operations of Australia’s major critical infrastructure assets, which could impact the availability of products and services that support an adequate standard of living, promoting the right to an adequate standard of living.
The right to privacy
Article 17(1) of the ICCPR provides that no one shall be subjected to arbitrary or unlawful interference with their privacy.
To the extent that the responsible entity submits a critical employee’s personal information for an AusCheck background check in accordance with enhanced requirements to assess their suitability to access critical systems and their components, the right to privacy will be engaged. However, it is reasonable, necessary and proportionate to limit the right to privacy in this way. Background checks on critical employees are reasonable where a responsible entity is assessing the suitability of a critical worker to have access to the critical components of the asset and necessary to pursue the objective of national security. This enables the responsible entity to ensure that only persons suitable to the role are engaged as critical workers. The requirement for background checks recognises that critical workers have responsibility, access, control or management of critical components of critical infrastructure assets. The fact that the absence or compromise of critical personnel may have a cascading impact on the proper functioning of the asset also demonstrates the role critical personnel may have in restoring the proper functioning of the asset during, for example, a cyber incident.
The protection of critical infrastructure is directly linked to national security, public safety and economic stability. These measures are targeted and limited to what is reasonably necessary, as they apply only to personnel in critical roles and only require information relevant to assessing and managing the identified risk. This represents the least restrictive means reasonably available to achieve the objective, as it enables a case-by-case, risk-based approach rather than imposing broader or more intrusive data collection requirements.
The collection, use and disclosure of personal information for the purposes of an AusCheck background check is authorised by the AusCheck Act and the AusCheck Regulations 2017 (AusCheck Regulations). The Amendment Rules require responsible entities to establish and maintain a process to assess the suitability of a critical worker to have access to critical components of a specified critical infrastructure asset. The instrument requires the responsible entity to conduct an AusCheck background check for all designated critical workers for that purpose. To the extent that a responsible entity discloses personal information to AusCheck, use of this information is reasonable and necessary to pursue the objective of mitigating against personnel hazards to critical infrastructure assets and the essential services delivered by them.
Accordingly, to the extent that the right to privacy is limited, the limitation is reasonable, necessary and proportionate, having regard to the significant national security risks involved and the targeted, safeguarded and risk-based nature of the measures.
Right to equality and non-discrimination
Article 2(1) of the ICCPR and Article 2(2) of the ICESCR provide that the rights in both covenants are to be exercised without discrimination of any kind as to race, colour, sex, language, religion, political or other opinion, national or social origin, property, birth or other status. Similarly, Article 26 of the ICCPR provides that the law shall prohibit any discrimination and guarantee to all persons equal and effective protection against discrimination on any ground such as race, colour, sex, language, religion, political or other opinion, national or social origin, property, birth or other status. The amendments pursue the objective of protecting national security by addressing risks arising from FOCI across all hazards which have been identified as a key vulnerability in the current threat environment.
The amendments require responsible entities to expressly consider the risk of FOCI across all hazards, including in their supply chains, and if present, reasonable mitigations to limit FOCI risk to their asset. To the extent that the amendments only apply to foreign vendors and contractors where they are individuals, they may engage and limit the right to equality and non-discrimination on the basis of ‘national origin’. For example, responsible entities must identify for each existing or proposed major supplier in relation to FOCI risks, legislative requirements to which the supplier is subject to and restrictions, sanctions or other impediments affecting the jurisdiction in which the supplier is based. Such differential treatment supports the objective of protecting national security, as identifying and assessing FOCI risks enables responsible entities to understand and mitigate vulnerabilities associated with foreign influence, coercion or control. These risks are particularly relevant in critical infrastructure contexts, where compromise to or undue influence of supply chains may result in significant disruption to essential services. To the extent that the right to equality and non-discrimination is limited, such limitation is reasonable and necessary in order to respond to the complex and challenging threat landscape (as outlined in the Director-General of ASIO’s Annual Assessment 2025), which includes supply chain vulnerabilities and use of vendors deemed high-risk, particularly in sectors where there are limited suppliers or vendors.
Where FOCI risk is detected and alternate vendors are not practicable, the Amendment Rules do not preclude the use of that vendor or product. Rather, the responsible entity should consider mitigations to minimise the potential impact for that FOCI risk to impact or disrupt the continued function and availability of their asset. Accordingly, the amendments are proportionate to supporting the legitimate objective of national security.
Conclusion
The Disallowable Legislative Instrument is compatible with human rights because it promotes the protection of human rights, and to the extent that it may limit human rights, those limitations are reasonable, necessary and proportionate to pursue the legitimate objective of national security.
The Honourable Tony Burke MP
Minister for Home Affairs
Minister for Cyber Security
Attachment C
Critical Infrastructure Risk Management Program
Addendum: Enhancement to risk management program rules in response to worsening threat environment
Table of Contents
Executive Summary
1. Background
1.1. Issues identified in the critical infrastructure environment
1.2. Targeted uplift for high-risk asset classes
1.3. Alignment with the current regulatory landscape
2. Options considered and preferred approach
2.1. Option 1: Status quo
2.2. Option 2: Improved awareness
2.3. Option 3: Enhanced CIRMP requirements
2.4. Regulatory burden and expected net benefit by option
2.5. Comparative assessment of options
2.6. Preferred option
3. Regulatory impact
3.1. Regulatory costing method
3.2. Economic benefits
4. Consultation
5. Implementation and evaluation
5.1. Implementation
5.2. Evaluation
Appendix A: RBE derivation, assumptions and preferred option mapping
Appendix B: Summary of initially proposed enhancements and identified gaps
Executive Summary
This Addendum to the 2022 Regulation Impact Statement: A Risk Management Program Framework for Critical Infrastructure Assets (2022 RIS or OBPR22-02914) assesses whether proposed enhancements to the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 (CIRMP Rules) are justified, proportionate, and effective in addressing identified gaps in current risk management practices.
Critical infrastructure is fundamental to Australia’s economic activity, national security, and the delivery of essential services. The increasing interconnectivity of infrastructure systems has improved efficiency and productivity, but has also increased systemic risk. Disruption to a single asset can cascade across sectors, resulting in broader economic and societal impacts.
Since the introduction of the CIRMP Rules, the threat environment has become more complex, persistent, and targeted. Cyber actors are increasingly seeking to establish long-term access to critical infrastructure systems to enable disruption. At the same time, supply chain dependencies, insider threats, physical security vulnerabilities, and emerging technologies have introduced additional risk vectors. These developments have exposed limitations in the consistency and maturity of current risk management practices across sectors.
While the existing CIRMP framework, established under the Security of Critical Infrastructure Act 2018 (SOCI Act) and amended by the Security Legislation Amendment (Critical Infrastructure Protection) Act 2022, sets out baseline obligations for responsible entities to identify and manage material risks and minimise or eliminate those risks so far as reasonably practicable, implementation maturity varies. Key gaps include inconsistent application of cyber security controls, limited visibility into critical supply chain dependencies, insufficient personnel and physical security governance, and a lack of structured assessment of emerging risks.
The proposed enhancements to the CIRMP Rules introduce targeted, risk-based uplift across key areas of vulnerability. The enhancements have been informed by multiple consultation rounds. The enhancements include: strengthening cyber security maturity and control expectations; improving the identification and management of supply chain risks; and vendor assessments of existing or proposed major suppliers; formalising personnel security and insider threat controls; introducing requirements for structured physical security planning; and requiring assessment of risks arising from emerging technologies.
Maintaining the current settings would avoid additional regulatory burden but would not address identified gaps in risk management practices or reflect the current threat environment. As a result, vulnerabilities would persist, and the likelihood and impact of disruptions to critical infrastructure would remain elevated.
By improving the consistency and maturity of risk management practices, the proposed enhancements are expected to reduce the likelihood and potential impact of disruptions to critical infrastructure. Given the interconnected nature of these assets, even marginal reductions in the probability or severity of disruption are expected to deliver substantial economic and societal benefits.
These benefits are difficult to value precisely because the avoided events are not directly observable. It isn’t feasible to identify which cyber intrusions, supply chain compromises, insider incidents, physical security breaches or outages would have occurred without the risk framework. The Addendum, therefore, does not rely on a single monetised benefit estimate. It uses regulatory burden costing, consultation evidence and break-even analysis to test whether the expected benefits are likely to justify the additional costs.
The Addendum does not reopen the policy decision made through the 2022 RIS or the development of the enhanced CIRMP Rules. Its purpose is to explain the incremental impact of the proposed enhancements against the existing CIRMP baseline. It does this by setting out the targeted scope of the enhanced requirements, the regulatory burden estimate (RBE), consultation evidence, break-even analysis, and implementation considerations. This provides a transparent basis for understanding the likely impacts of the enhanced CIRMP Rules, including the areas where costs, feasibility constraints and residual uncertainty will need to be managed through guidance, staged implementation and ongoing engagement with industry.
- Background
- Issues identified in the critical infrastructure environment
The CIRMP Rules came into effect in 2023 and operationalise the requirements in Part 2A of the SOCI Act. These Rules require responsible entities for certain critical infrastructure assets to establish, maintain and comply with a risk management program that identifies hazards which may give rise to material risks and minimises or mitigates their impact across cyber, physical, personnel and supply chain domains.
Since the establishment of the CIRMP Rules, the threat environment for critical infrastructure has become more severe and more complex. Intelligence indicates an increase in threats across all hazards, including cyber threats, supply chain compromise, foreign interference, and other disruptive activity targeting essential services. Hostile foreign state actors and their proxies are increasingly targeting critical infrastructure globally to gain strategic leverage, disrupt essential services, and position themselves for coercive advantage.[1]
This type of activity, including malicious cyber campaigns, supply chain compromises, manipulation of managed service providers, foreign interference, and vulnerabilities from hidden foreign ownership, control, and influence (FOCI) structures, is increasingly on the rise as many of these tactics are designed to remain undetected and gradually influence operational control. [2]
The Director-General of Security’s Annual Threat Assessment 2025 highlighted that nation-state actors are increasingly mapping and targeting critical infrastructure.[3] In 2024, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) joined Five Eyes intelligence partners in publicly attributing the compromise of multiple United States (US) critical infrastructure sectors to a state-sponsored group known as Volt Typhoon.[4]
The Annual Cyber Threat Report 2024-2025 from ASD’s ACSC reported that 13% of the over 1,200 cyber incidents in that period were reported by critical infrastructure. This is an increase of 2% from the previous year, with the most common types of cyber security incidents involving compromised assets and networks, compromised accounts and credentials, and Denial of Service (DoS)/Distributed DoS attacks.[5]
Threat actors are not limited to exploiting cyber vulnerabilities. FOCI arrangements within both critical infrastructure entities and throughout supply chains exacerbate cyber risks. [6] Incidents affecting critical infrastructure frequently start in the supply chain.[7] Recent reporting on undeclared communications equipment in foreign-made solar inverters illustrates how cyber, supply chain and physical technology risks can converge in energy infrastructure.[8] [9] The renewable energy transition has identified an over-reliance on high-risk vendors and suppliers due to limited manufacturing options. It is therefore necessary to ensure adequate controls and risk mitigations are implemented.
Espionage has become one of the most significant national security threats to Australia. Recent modelling by the Australian Institute of Criminology (AIC) for the Australian Security Intelligence Organisation (ASIO) in the Cost of Espionage report shows that the costs of this degraded environment could exceed $1 billion per espionage-enabled cyber incident affecting critical infrastructure, regardless of the vector. The same report indicated that insider threats involving state or state-sponsored actors impacting Australian businesses were estimated to cost up to $324.8 million.[10]
These threats are increasingly focused on critical infrastructure asset classes with the highest potential consequences. At the same time, growing interdependencies across sectors have increased the risk that disruption to one asset may cascade more broadly across the economy and the community.
Operational experience and engagement with industry have also identified increasing risks associated with supply chains, third-party service providers, and ownership and control arrangements. These risks can introduce vulnerabilities that are difficult to detect and manage, particularly when dependencies span jurisdictions or sectors. This has been reinforced through consultation with industry and Government stakeholders, which has highlighted the growing complexity of managing interconnected risks.
While the CIRMP framework established in 2022 has driven an uplift in baseline risk management practices, it was designed as a broad, sector-wide framework. The current threat environment has highlighted that, for some high-risk asset classes, baseline requirements alone may no longer be sufficient.
This has created a need for targeted enhancements to the CIRMP Rules to ensure that responsible entities for those asset classes are managing risks in a way that is proportionate to the consequences of disruption.
- Targeted uplift for high-risk asset classes
The proposed amendments to the CIRMP Rules are intended to increase risk management requirements for asset classes that pose the greatest potential consequences for Australia’s national security and economic stability. These amendments align with assessments by the National Intelligence Community (NIC), which have identified sectors and asset classes as at elevated risk. This reflects both the criticality of these assets to the delivery of essential services and their attractiveness as targets for hostile actors.
Under the proposed approach, enhanced CIRMP Rules requirements will apply to nine specified asset classes across four sectors.
Table 1: Specified Asset Classes in scope for enhanced CIRMP obligations
Sector | Asset classes |
Energy | Energy market operator assets Electricity assets Gas assets Liquid fuel assets |
Communications | Broadcasting assets Domain name systems |
Water and sewerage | Water assets |
Transport | Freight service assets Freight infrastructure assets |
For this Addendum’s RBE, the estimate is based on the identified population of the nine specified asset classes. The Departmental administrative data available for impact analysis identifies 627 CIRMP records across the in-scope asset classes as at 2 February 2026. The figures below serve as the basis for the regulatory burden estimate. They should be read as asset-class records or CIRMP population counts, not necessarily as counts of unique corporate groups, since some responsible entities may hold multiple assets or operate across multiple asset classes. The Department has also noted that entities that have not submitted annual attestations, although obligated to do so, are not included in the provided totals.
Table 2: CIRMP population
Sector | In-scope asset class | CIRMP population count |
Energy | Energy market operator assets | 11 |
Energy | Electricity assets | 348 |
Energy | Gas assets | 87 |
Energy | Liquid fuel assets | 47 |
Communications | Broadcasting assets | 3 |
Communications | Domain name systems | 17 |
Water and sewerage | Water assets | 31 |
Transport | Freight service assets | 56 |
Transport | Freight infrastructure assets | 27 |
Total | 627 | |
Source note: Based on Departmental data provided for impact analysis as at 2 February 2026.
- Alignment with the current regulatory landscape
All asset classes in scope are already required to develop and maintain a CIRMP under Part 2A of the SOCI Act. The proposed enhancements do not introduce a new obligation for these asset classes, but instead strengthen existing requirements to ensure a more consistent and proportionate level of risk management maturity.
This targeted scope is central to the impact analysis. The 2022 RIS costed the full CIRMP framework across a broader set of asset classes. The 2026 enhanced CIRMP package applies only to the asset classes identified as higher risk and higher consequence for this reform. It therefore imposes a smaller incremental regulatory burden than the original CIRMP framework, while targeting the areas where additional risk-management maturity is most needed. The enhancements maintain the CIRMP’s existing hazard-domain structure and do not introduce new asset classes. Compliance and assurance will continue to rely primarily on existing CIRMP governance and annual reporting arrangements.
This targeted approach recognises that not all critical infrastructure assets require the same level of enhanced rules under the CIRMP. It is designed to focus effort where it is required, avoiding unnecessary duplication and regulatory burden on other asset classes. In some cases, asset classes not captured by the enhanced CIRMP Rules are subject to alternative regulatory frameworks that impose comparable obligations. This includes asset classes regulated under:
- Aviation Transport Security Act 2004
- Maritime Transport and Offshore Facilities Security Act 2003
- APRA, specifically Prudential Standard CPS 230 – Operational Risk Management
- Defence Industry Security Program.
The proposed rule enhancements also recognise that responsible entities have obligations under other legislative frameworks that may mirror these obligations, including the Modern Slavery Act 2018 (Modern Slavery Act), the Foreign Acquisitions and Takeovers Act 1975, and the Corporations Act 2001 (Corporations Act).
- Options considered and preferred approach
Government has considered three options to address the need for enhanced risk management requirements for in-scope critical infrastructure asset classes. The options have been assessed against the current CIRMP Rules as the business-as-usual baseline. All asset classes in scope are already required to develop, maintain, comply with and annually report on a CIRMP under Part 2A of the SOCI Act. The question considered in this Addendum is therefore whether additional, targeted uplift is justified above the existing CIRMP baseline.
The options are assessed against effectiveness in addressing identified risks, proportionality, direct regulatory burden, implementation feasibility, consistency with the existing CIRMP architecture, consultation feedback and expected net benefit. This approach reflects the incremental nature of the proposed amendments and avoids double-counting the costs of activities already required under the existing CIRMP Rules.
- Option 1: Status quo
Under Option 1, no amendments would be made to the CIRMP Rules. Responsible entities for the nine in-scope asset classes would continue to comply with existing CIRMP requirements, including the obligation to identify, assess and manage material risks across cyber and information security, personnel, supply chain, and physical and natural hazard domains through a written all-hazards risk management program.
Government would continue business-as-usual threat engagement, sector engagement, guidance and regulatory oversight. However, no additional rule-based clarification or uplift would be introduced for the in-scope asset classes.
The existing CIRMP Rules have established a baseline level of risk management maturity and have driven an uplift in risk management practices. However, they were designed as a broad, multi-sector framework and do not provide additional specificity for high-risk asset classes operating in a more complex and interconnected threat environment. Responsible entities would continue to interpret and implement requirements with varying levels of maturity, resulting in inconsistent application of risk management practices across sectors.
Option 1 would avoid any new direct regulatory burden. However, it would not address identified gaps in the consistency, maturity and documentation of risk management practices for high-risk assets. It would also not address the increasing complexity and severity of the threat environment identified through intelligence assessments, operational experience and stakeholder feedback. Maintaining current settings would risk a widening gap between regulatory expectations and the nature of contemporary threats. As a result, this option is not preferred.
- Option 2: Improved awareness
Under Option 2, the CIRMP Rules would remain unchanged, but Government would seek to improve risk management practices through non-regulatory measures. These could include updated guidance, templates, advisory materials, threat briefings, best-practice materials, voluntary uplift pathways and continued engagement through the Trusted Information Sharing Network and other sector forums.
This option would allow responsible entities to adopt improved practices tailored to their operating context voluntarily. It would avoid imposing mandatory new compliance costs on responsible entities, provided the measures remained genuinely voluntary. It would involve some additional cost to Government in developing and delivering guidance and engagement activities.
While this approach may improve awareness and support incremental improvements, its effectiveness would depend on voluntary uptake by responsible entities. Consultation feedback indicates that guidance alone is unlikely to deliver consistent uplift across all in-scope asset classes. Voluntary measures may be adopted unevenly, particularly when implementation involves capital expenditure, legacy operational technology environments, constrained supplier markets, contractor workforces, or investments that require approval through regulated pricing or funding cycles.
Non-regulatory approaches would support awareness and voluntary uplift, but would not deliver consistent, enforceable or auditable improvements across the in-scope asset classes. Variability in capability and risk prioritisation would likely persist, particularly in sectors with constrained resources or complex operating environments. As a result, this option is not preferred.
- Option 3: Enhanced CIRMP requirements
Consistent with the targeted scope described in Section 1.3, under Option 3, the CIRMP Rules would be amended to introduce targeted enhanced requirements for the nine in-scope asset classes only. The enhancements build on the existing CIRMP framework rather than creating a new regulatory model. They clarify and strengthen how responsible entities for in-scope assets must identify, assess, document, govern and manage material risks in areas where the existing framework has not produced sufficiently consistent maturity.
Option 3 does not expand the CIRMP to new asset classes and does not apply enhanced obligations to all asset classes subject to the existing CIRMP. Responsible entities for in-scope assets would remain subject to existing baseline CIRMP obligations and also to enhanced requirements. The enhanced requirements would prevail to the extent of any inconsistency.
The Exposure Draft gives effect to this option through enhanced requirements in sections 6A, 8A, 8B, 8C, 9A, 10A and 11A. The final policy position has been refined following consultation. The previously consulted specified-risk-advice workflow is not treated as a standalone final measure. The remaining measures can be implemented in a risk-based manner and supported by guidance, implementation planning and proportional assurance.
Option 3 provides a clearer and more enforceable basis for uplift in high-risk asset classes while maintaining flexibility for responsible entities to tailor controls to asset criticality, operational context, legacy systems, supplier constraints and existing risk-management arrangements. It also provides pricing regulators with a clearer indication of the required uplift, which may support funding and cost-recovery decisions in economically regulated sectors.
Table 3: Enhanced requirements under Option 3
Draft rule section | Hazard Enhancement | Description |
Section 4A | Application of enhanced CIRMP requirements | Identifies the specified asset classes to which the enhanced requirements apply and clarifies the relationship between baseline and enhanced CIRMP obligations. |
Section 6A | Enhanced material risks | Requires responsible entities to consider material risks relating to impairment of asset functions affecting social stability, economic stability, national security or defence, and compromise or impairment connected with FOCI. |
Section 8A | Cyber and information security hazards | Requires processes or systems to address specified cyber material risks and comply with listed cyber frameworks and applicable conditions or an equivalent framework. |
Section 8B | Credential compromise hazard | Requires processes or systems to be implemented that achieve phishing-resistant MFA. |
Section 8C | Computer lateral movement hazard | Requires processes or systems to be implemented that identify, segregate, recover and restore critical systems. |
Section 9A | Personnel hazards | Requires processes or systems for personnel access management, critical worker suitability assessment, ongoing monitoring, incoming and outgoing critical worker risks, and AusCheck or equivalent arrangements for critical workers with access to critical components. |
Section 10A | Supply chain hazards | Requires processes or systems to map major suppliers and critical components across their supply chains, identify vulnerabilities and maximum tolerable outage, and assess risks associated with existing or proposed major suppliers. |
Section 11A | Physical security and natural hazards | Requires processes or systems to centrally manage physical security and natural hazards, including physical security consequences arising from cyber, lateral movement, credential compromise, personnel, supply chain or other hazards, and to outline site characteristics, critical components, sensitive areas, access controls, surveillance, alarms and response measures. |
In practice, this option is expected to yield a more consistent and mature risk management approach across critical infrastructure asset classes. Responsible entities may incur additional costs associated with developing more structured processes, improving documentation, enhancing governance arrangements and implementing targeted controls. Consistent with the 2022 RIS, the cost impacts of CIRMP obligations are justified where they are outweighed by the avoided costs of disruption and the resilience benefits of improved risk management.
- Regulatory burden and expected net benefit by option
The RBE comparison is summarised below. Detailed methodology, assumptions and sensitivity testing are set out in Section 3 and Appendix A.
For the purposes of the regulatory burden estimate, Options 1 and 2 have nil direct additional regulatory burden. Option 1 does not change existing regulatory requirements. Option 2 relies on voluntary guidance and engagement and therefore does not impose new mandatory obligations, provided it remains genuinely non-regulatory. This does not mean these options have no economic cost. Under Option 1, the cost is continued exposure to disruption risk and uneven risk maturity. Under Option 2, entities may voluntarily incur costs in response to guidance. Still, voluntary costs are not counted in the regulatory burden estimate unless the policy effectively requires regulated entities to act.
Option 3 has a central estimate of $57.5 million per year in average annual business regulatory burden. The central estimate applies a 10 per cent incremental uplift to the 2022 RIS average annual cost base for the asset classes now in scope of the enhanced CIRMP Rules. The low and high estimates apply 5 per cent and 15 per cent uplifts, respectively. These assumptions are not presented as a statistical confidence interval. They are transparent sensitivity scenarios designed to test the plausible incremental burden of the enhanced obligations against the best available reference-class cost base.
Table 4: Regulatory burden estimate by option
Average annual regulatory costs from business as usual | Business | Community organisations | Individuals | Total |
Option 1: Status quo | $0.0m | $0.0m | $0.0m | $0.0m |
Option 2: Improved awareness | $0.0m | $0.0m | $0.0m | $0.0m |
Option 3: Rules enhancement - central estimate | $57.5m | $0.0m | $0.0m | $57.5m |
Option 3 sensitivity | Business | Community organisations | Individuals | Total |
Low case: 5% incremental uplift | $28.7m | $0.0m | $0.0m | $28.7m |
Central case: 10% incremental uplift | $57.5m | $0.0m | $0.0m | $57.5m |
High case: 15% incremental uplift | $86.2m | $0.0m | $0.0m | $86.2m |
The benefits of Option 3 arise from reducing the expected annual cost of critical infrastructure disruption. This may occur through reducing the likelihood of incidents, reducing the severity or duration of incidents, improving preparedness and response, reducing cascading impacts across interconnected systems, and improving board and government visibility of material risks. These benefits are material but cannot be reliably monetised as a central expected value because the Department does not hold sufficiently robust evidence on the future frequency, severity and timing of avoided incidents or on the marginal effectiveness of each enhancement.
A break-even approach is therefore appropriate with the current evidence base. The preferred option will deliver a net benefit if it reduces expected annual disruption costs by at least the average annual regulatory burden. The reforms do not need to avoid a whole major incident each year to break even. The same result may be achieved by a small reduction in the probability of a high-impact event, a reduction in outage duration or severity, faster recovery, reduced cascading impacts, or avoidance or mitigation of multiple smaller incidents.
Table 5: Break-even implication under the central RBE
2022 RIS disruption scenario | Economy-wide cost | Break-even implication at $57.5m central RBE |
Moderate electricity disruption | $850.0m | Avoid one equivalent incident every 14.8 years |
Severe electricity disruption | $1.280b | Avoid one equivalent incident every 22.3 years |
Severe gas disruption | $1.913b | Avoid one equivalent incident every 33.3 years |
Severe water disruption | $4.099b | Avoid one equivalent incident every 71.3 years |
Severe liquid fuels disruption | $1.913b | Avoid one equivalent incident every 33.3 years |
Severe freight disruption | $724.1m | Avoid one equivalent incident every 12.6 years |
Moderate broadcasting/DNS disruption | $3.8m | This scenario alone would not break even; benefits would need to arise from multiple incidents or larger cross-sector impacts |
Given the scale of avoided harm associated with disruption to electricity, gas, water, liquid fuels and freight assets, Option 3 would break even if it produces even a small reduction in the expected frequency, duration or severity of high-consequence incidents affecting the in-scope asset classes. The break-even threshold is therefore proportionate to the risk being addressed. Detailed costing, distributional impacts and economic analysis are set out in Section 3.
- Comparative assessment of options
The comparative assessment below summarises the principal advantages and limitations of each option.
Table 6: Comparative assessment of options
Assessment criterion | Option 1: Status quo | Option 2: Improved awareness | Option 3: Enhanced CIRMP requirements |
Regulatory change | No change to the CIRMP Rules. | No change to the CIRMP Rules; Government would rely on guidance, templates, threat briefings and engagement. | Targeted amendments to the CIRMP Rules for the nine in-scope asset classes only. |
Effectiveness | Low. Existing baseline obligations would continue, but identified gaps in consistency, maturity and documentation would persist. | Moderate to low. Awareness may improve, but uplift would depend on voluntary uptake and would likely be uneven. | High. Provides clearer, enforceable and auditable requirements for risk areas with inconsistent maturity. |
Proportionality | Low in risk terms. Avoids burden but does not respond to the elevated risk profile of the in-scope asset classes. | Moderate. Low regulatory burden, but weaker alignment between risk level and required uplift. | High. Applies only to specified high-risk asset classes and preserves the existing CIRMP architecture, and so far as reasonably practicable principle. |
Direct regulatory burden | Nil additional direct regulatory burden. | Nil additional direct regulatory burden, provided measures remain genuinely voluntary. | Central estimate of $57.5 million per year, with a sensitivity range of $28.7 million to $86.2 million per year. |
Implementation feasibility | High immediate feasibility, but does not deliver the required uplift. | Moderate. Guidance can be delivered, but implementation depends on entity capability, funding cycles and willingness to invest. | Manageable with staged implementation, guidance, equivalent-framework recognition and flexibility for compensating controls where full technical remediation is not reasonably practicable. |
Consultation alignment | Does not respond to stakeholder acknowledgement of the need to strengthen resilience or to intelligence-driven risk concerns. | Responds to stakeholder requests for guidance, but does not respond to feedback that consistent uplift requires clearer regulatory expectations. | Best aligned with consultation when calibrated. Stakeholder feedback has informed extended grace periods, guidance and the principles-based implementation and refinement of prescriptive requirements. |
Assessment | Not preferred. | Not preferred. | Preferred option. |
- Preferred option
Option 3 is preferred because it delivers targeted uplift within the existing CIRMP architecture, while preserving the so far as reasonably practicable principle and staged implementation.
Option 1 would avoid additional regulatory burden but would not address the widening gap between current baseline CIRMP obligations and the contemporary threat environment. Option 2 would support awareness and voluntary uplift but would not deliver consistent, enforceable or auditable improvements across the in-scope asset classes.
Option 3 delivers targeted uplift while preserving the structure of the existing CIRMP framework. It does not expand the CIRMP to new asset classes and does not apply enhanced obligations to all asset classes subject to the existing CIRMP. It applies only to the nine specified asset classes identified as higher risk. It introduces clearer expectations in areas where consultation and operational experience identified inconsistent maturity: FOCI, cyber security; including credential compromise and lateral movement, supply chain, personnel security and physical security.
The preferred option is principles-based, incremental and targeted. It maintains the so far as reasonably practicable principle, supports equivalent or compensating controls where appropriate, and is supported by staged implementation periods and guidance. This design responds to stakeholder feedback on implementation feasibility, legacy operational technology environments, supplier concentration, contractor workforces, regulated funding cycles and the need to avoid unnecessary duplication with existing obligations.
The central regulatory burden estimate is materially lower than the original 2022 RIS cost base because the 2026 reforms are incremental to an existing framework, limited to specified asset classes and primarily require additional risk consideration, process uplift, documentation, governance and targeted controls. The preferred option is expected to deliver a net benefit if it reduces annual disruption costs by at least $57.5 million. Given the scale of economic and social harm associated with disruption to electricity, gas, water, liquid fuels and freight assets, this threshold is achievable through even a small reduction in the expected frequency, severity or duration of high-consequence incidents.
There is a residual risk that Option 3 may not go far enough to fully address the pace and complexity of the evolving threat environment, particularly as threat actors continue to adapt and exploit emerging technologies, supply chain dependencies and systemic vulnerabilities. The proposed enhancements are therefore not intended to be exhaustive or static. This risk will be mitigated through ongoing monitoring of the threat environment, continued engagement with the National Intelligence Community and industry, and regular review of the effectiveness of the CIRMP framework.
On balance, Option 3 provides the greatest net benefit because it targets additional obligations to high-risk asset classes, preserves the existing CIRMP architecture, maintains reasonable-practicability principles, and addresses the risk areas where consultation and operational experience indicate inconsistent maturity.
- Regulatory impact
- Regulatory costing method
The regulatory burden estimate measures the incremental direct regulatory cost of the proposed 2026 enhanced CIRMP Rules relative to business as usual. All responsible entities for the in-scope asset classes are already required to develop, maintain, comply with and annually report on a CIRMP. The 2026 enhancements are therefore costed as an incremental change to the existing CIRMP baseline from the 2022 RIS. This avoids double-counting the costs of activities required under the existing CIRMP Rules, including general risk identification, risk assessment, governance, review, board approval, annual reporting and maintenance of the risk management program.
The Department has adopted a calibrated top-down approach to estimate the incremental regulatory burden of the enhanced CIRMP Rules. Using the 2022 RIS as the reference-class cost base for the existing CIRMP framework and applying bounded incremental uplift factors to the 2022 cost base for the in-scope asset classes. This suggests that the 2026 amendments are a targeted uplift to an established framework, rather than the creation of a new CIRMP regime. The relevant 2022 RIS comparator is the average annual regulatory cost for the asset classes now in scope of the enhanced CIRMP Rules.
The central estimate scenario applies a 10 per cent incremental uplift to that in-scope 2022 RIS cost base. A low case of 5 per cent and a high case of 15 per cent are used to test uncertainty. This range reflects that the enhanced rules are a material but bounded uplift to an existing framework: more than guidance or ordinary business-as-usual, but materially less than establishing the original CIRMP framework. The calculation used is:
Incremental RBE = 2022 in-scope CIRMP average annual cost base × incremental uplift factor.
Table 7: Incremental RBE Scenarios
Scenario | Interpretation | Calculation | Average annual business RBE |
Low | Primarily additional risk assessment, documentation, governance, assurance and reporting | $574.5m × 5% | $28.7m |
Central | Material but bounded uplift, including some targeted substantive compliance | $574.5m × 10% | $57.5m |
High | Higher-burden case with greater substantive uplift in lower-maturity or legacy environments | $574.5m × 15% | $86.2m |
The 5 per cent, 10 per cent and 15 per cent assumptions are not presented as a statistical confidence interval. They are transparent sensitivity scenarios designed to test the plausible incremental burden of the enhanced obligations against the best available reference-class cost base.
- Treatment of consultation cost information
Consultation submissions provided valuable evidence on cost drivers, implementation constraints and cost-recovery issues. However, the submitted cost estimates are not suitable for direct national extrapolation as the central RBE. Submitted cost estimates were highly variable and often measure-specific, reflecting the circumstances of large entities with complex operational technology environments, regulated funding arrangements, or significant asset portfolios. Some estimates also combined mandatory compliance activities with broader remediation, already planned investments, or implementation choices that may not be required for every responsible entity under a principles-based framework.
The Addendum therefore uses consultation cost evidence to validate the direction and materiality of cost drivers and to inform the high-case sensitivity. The central RBE is instead calibrated to the 2022 RIS cost base for the in-scope asset classes. This provides a more stable and transparent benchmark, avoids over-extrapolating from a non-representative sample, and aligns the costing with the incremental nature of the enhanced CIRMP Rules.
- Costing boundary
The central RBE does not assume that every responsible entity will consider every possible technical, cyber, physical, supply chain or personnel remediation activity identified through its risk assessment. The CIRMP framework is risk-based. Its primary regulatory effect is to require responsible entities to identify, assess, document, govern and report material risks, and to minimise or eliminate those risks so far as reasonably practicable.
Accordingly, the RBE includes the incremental cost of mandatory risk consideration, documentation, process development, evidence keeping, governance review, assurance and annual reporting. Substantive compliance costs are included where the rules require a specific capability, process, standard or control, or where such activity is necessary to demonstrate compliance. Costs that reflect business-as-usual activity, voluntary remediation beyond what is required by the rules, indirect pass-through to consumers, direct financial charges payable to government, and enforcement or non-compliance costs are excluded in accordance with the Regulatory Burden Measurement Framework.
Cost layer | Treatment in RBE |
Risk consideration and documentation | Included for affected entities where mandatory. This is the core incremental CIRMP burden: assessment, documentation, governance, evidence and attestation. |
Process or plan requirements | Included where the rules require processes, systems or plans, including enhanced material-risk and FOCI assessment, supply chain mapping, major supplier assessment, personnel security processes, and physical security and natural hazard processes. |
Targeted substantive uplift | Included through the incremental scenario estimate where the rule requires a specific capability or control, such as cyber maturity uplift, MFA, network segregation or background-check administration. |
Broader remediation choices | Not automatically included in the central estimate. Included implicitly in the high scenario only, where broader uplift is more likely to be required. |
Consumer pass-through | Not included in the RBE because it is an indirect or distributional impact. It is discussed separately. |
- Break-even analysis
The RBE and break-even analyses serve different purposes. The RBE estimates the average annual direct regulatory burden imposed by the preferred option. The break-even analysis then assesses whether the expected benefits of the preferred option are likely to exceed that burden.
The benefits of the enhanced CIRMP Rules arise from reducing the expected annual cost of critical infrastructure disruption. This may occur through reducing the likelihood of incidents, reducing the severity or duration of incidents, improving preparedness and response, reducing cascading impacts across interconnected systems, and improving board and government visibility of material risks. These benefits are material but cannot be reliably monetised as a central expected value because of the difficulty in predicting future frequency, severity and timing of avoided incidents or the marginal effectiveness of each enhancement.
- Small- to medium-sized enterprises and large business impacts
A quantitative split between small- to medium-sized enterprises and large businesses’ costs has not been included because the available data does not support a defensible allocation. The current asset-class counts do not identify the responsible entity’s size, revenue, workforce or ownership structure. Consultation responses also did not provide a consistent size classification or representative sample that could be used to allocate aggregate burden between small, medium and large entities.
The Addendum acknowledges that cost incidence will not be uniform. Large businesses and regulated network or utility operators are likely to face higher absolute costs because of the scale, geographic dispersion and complexity of their assets. Smaller responsible entities, including some renewable generation, battery storage, DNS or specialised asset operators, may face lower absolute costs but higher proportional burden. This is because several compliance activities have fixed-cost characteristics, including CIRMP documentation, governance review, cyber maturity assessment, supplier due diligence, personnel security processes and audit readiness. Smaller entities may also have less internal cyber, legal, procurement and risk capability, and less bargaining power with original equipment manufacturers, operations and maintenance contractors, and global technology vendors.
This distributional effect is relevant to policy design even though it is not separately quantified in the RBE table. It supports retaining a principles-based approach, staged implementation, guidance, equivalent-framework recognition and flexibility for compensating controls where full technical remediation is not reasonably practicable.
- Distributional impacts and consumer pass-through
The proposed enhancements will impose direct compliance costs on responsible entities for the in-scope asset classes. The incidence of those costs will vary across sectors depending on market structure, pricing regulation, cost-recovery mechanisms and competitive conditions.
In economically regulated sectors, such as electricity networks and some water utilities, some efficient compliance costs may ultimately be recovered from customers through regulated pricing or funding processes. This means the reforms may have indirect distributional impacts on households and businesses through electricity, water or wastewater bills. These indirect pass-through impacts are not included in the RBE table because the Regulatory Burden Measurement Framework excludes indirect costs. Still, they are relevant to the overall impact assessment and policy design.
In competitive or trade-exposed markets, cost recovery may be more limited. Liquid fuel operators may have limited ability to pass costs through because pricing is affected by import parity and international competition. Freight operators identified potential competitive neutrality issues in which rail freight providers incur obligations that road freight competitors do not. Smaller energy-transition assets may face higher proportional costs if obligations are applied uniformly, even when they have lower systemic consequences or limited internal capability.
The final policy design mitigates these distributional impacts by limiting enhanced obligations to specified high-risk asset classes, retaining the so far as reasonably practicable principle, allowing equivalent or compensating controls where appropriate, and supporting implementation through guidance and staged compliance periods.
- Consultation cost evidence
The matrix at Table 5: Cost Implications of measures by sector from consultation, summarises the incremental cost profile of the enhanced CIRMP measures by sector and obligation category. It reflects the different operating environments, legacy technology constraints, workforce and regulatory settings, and supply‑chain exposures identified through consultations. It shows where costs are expected to concentrate, such as cyber maturity uplift and network segregation in OT-heavy sectors, versus areas where the burden is primarily administrative, such as enhanced material-risk assessment and FOCI processes or periodic vendor-of-concern assessments. The matrix should be read by sector (columns) and obligation category (rows), with each cell indicating relative cost impact using the defined severity scale.
Consultation feedback indicated that cyber uplift and system segregation represent the most significant cost drivers, particularly in OT-heavy sectors, driven by legacy environments, supply chain exposure and escalating threat activity. Stakeholders acknowledged that while uplift requires investment, it delivers strong system-wide benefits by reducing the likelihood and impact of major outages, strengthening recovery capability, and aligning practices with widely recognised frameworks such as those listed in the CIRMP Rules. Most stakeholders did not yet provide reliable dollar estimates for these measures, but consistently described them as multi-year, high-complexity uplifts with wide cost dispersion across sectors.
Table 8: Cost Implications of measures by sector from consultation
Hazard Domain | Energy | Water | Transport | Communications |
Cyber security framework uplift | VERY HIGH (!!!) Strongest concerns across all sectors. OT legacy systems, regulated pricing periods, long outage windows and workforce shortages. | HIGH (!!) Legacy OT and constrained regulator pricing periods limit the pace; costs are significant. | MEDIUM–HIGH (!) Cost is significant but variable; digital systems are fragmented; the sector asked for proportionality. | MEDIUM (!) Uplift needed, but many entities are already at a higher baseline. |
lateral movement | HIGH (!!) Operators said three-month isolation was not feasible; segmentation and recovery uplifted significantly across large OT estates. | HIGH (!!) Difficult to isolate treatment plants or networks for long periods, need for a recovery-based approach. | VERY HIGH (!!!) Three‑months of isolation are deemed incompatible with linear networks and safety-critical systems. | MEDIUM (!) Some reliance on cloud- or federated-based identity makes isolation more complex. |
Credential compromise | MEDIUM–HIGH (!) OT MFA constraints; remote field users; legacy systems. | MEDIUM (!) MFA is workable for IT, but harder on legacy SCADA; request for prioritisation. | MEDIUM (!) Contractor-heavy; MFA constraints for mobile/handheld systems. | MEDIUM (!) MFA constraints for machine-to-machine and DNS operations. |
Supply chain vulnerability mapping | HIGH (!!) Deep global supply chains with single‑supplier dependencies. | MEDIUM–HIGH (!) Global OEM dependency; mapping is feasible but costly. | MEDIUM (!) Extensive subcontractor chain; mapping possible but resource-intensive. | MEDIUM (!) Suppliers are globally distributed, which maps to a moderate burden. |
Supply chain vendor assessment | HIGH (!!) Heavy exposure to global vendors; strong need for compensating controls. | MEDIUM (!) Requires clearer thresholds for vendor concern; limited alternatives. | MEDIUM (!) Substitution often difficult; need for Commonwealth guidance. | MEDIUM (!) Concerns that FOCI rules might reduce transparency. |
Personnel security plan AND | MEDIUM–HIGH (!) Very large contractor workforces; regional/remote AusCheck challenges. | MEDIUM (!) Mixed contractor model; AusCheck scalability issues. | HIGH (!!) Heavy reliance on contractors; AusCheck is a significant burden. | LOW-MEDIUM (-) Smaller cohorts of critical workers. |
Physical security hazards and natural hazards | MEDIUM–HIGH (!) Significant costs for perimeter protection, substation hardening, improved access controls and monitoring for widely distributed assets, | MEDIUM (!) Ageing, geographically dispersed plants require upgrades to fencing, access systems, and intrusion detection. | HIGH (!!) Open, linear networks make physical security uplift costly and complex. | MEDIUM (!) Need for enhanced site hardening and monitoring of broadcast towers and communications sites. |
Severity scale:
- VERY HIGH (!!!): significant cost and feasibility constraints; immediate prioritisation required.
- HIGH (!!): substantial cost or complexity; prioritisation required.
- MEDIUM (!): moderate cost or implementation considerations.
- LOW (-): limited cost or indirect impact.
The costs outlined below at Table 6: Cost Item - Reported Costs per organisation show the range of costs estimated across all submissions received from the in-scope sectors.
Consultation input was inconsistent, and understanding of the proposed rules changes varied, leading to different estimates across submissions. The following table shows the range for which the offered values were substantiated by clear logic. It should also be noted that many submissions declined to provide costs, instead requesting further information on the exact substance of the rule changes.
Table 9: Cost Item - Reported Costs per organisation
Note - Credential compromise hazard and lateral movement hazard, were not consulted on as separate hazard vectors and the costs associated with these measures are reported below are part of the Cyber hazard domain.
Hazard Domain | Upfront Costs | Ongoing Costs (per annum) |
All-Hazards | $50,000 - $500,000 | $60,000 - $150,000 |
Cyber | $500,000 - $120,000,000 | $100,000 - $4,000,000 |
Supply Chain | $360,000 - $11,600,000 | $50,000 - $2,000,000 |
Personnel | $25,000 - $1,300,000 | $5,000 - $750,000 |
Physical | $2,000,000 - $3,000,000 | $500,000 - $2,000,000 |
- Economic benefits
Economic benefits arise primarily from avoided or mitigated disruption to critical infrastructure services. The enhanced requirements are expected to improve risk visibility, governance, preparedness, response and recovery across cyber, supply chain, personnel, physical security and natural hazard domains. The benefits are not confined to avoiding major incidents. Benefits may also arise through reduced outage duration, reduced severity, faster recovery, improved escalation to boards, better visibility of dependencies, and reduced cascading impacts across sectors.
Table 10: Economic Benefits
Benefit category | Economic benefit | Mechanism | Impact pathway | Timeframe |
System resilience | Reduced frequency and severity of service disruptions | Uplifted cyber, physical, personnel and supply chain controls reduce vulnerability exposure | Fewer outages across energy, water, transport and communications systems support uninterrupted economic activity | Medium to long term |
Productivity | Improved operational efficiency within critical infrastructure entities | Standardised and structured risk management processes reduce duplication and reactive responses | Lower operational inefficiencies and reduced downtime improve output across dependent industries | Medium term |
Investment confidence | Increased investor and insurer confidence in critical infrastructure sectors | Clear, consistent regulatory expectations reduce uncertainty and risk premiums | Greater capital inflows and more stable insurance pricing support infrastructure investment | Medium to long term |
Supply chain stability | Improved visibility and management of critical dependencies | Enhanced supply chain mapping and vendor assessment requirements identify concentration and disruption risks | Reduced cascading failures across interconnected sectors supports the continuity of goods and services | Medium term |
Labour market stability | Reduced workforce disruption from insider threats or security incidents | Strengthened personnel security and background checks reduce internal risk events | More stable workforce operations minimise productivity losses and service interruptions | Medium term |
Cost avoidance | Avoidance of high-cost incident response and recovery activities | Proactive risk mitigation reduces the likelihood of major incidents requiring emergency response | Lower unplanned expenditure on remediation, legal, reputational and recovery costs | Medium to long term |
Interoperability | Greater consistency across sectors and jurisdictions | Clarified and formalised requirements create a more uniform baseline of risk management maturity | Easier coordination between operators and Government during incidents reduces systemic impacts | Medium term |
Innovation enablement | Safer adoption of emerging technologies | Requirement to assess risks from emerging technologies enables managed innovation | Increased uptake of productivity-enhancing technologies without introducing unmanaged systemic risk | Medium to long term |
Asset longevity | Improved protection of physical infrastructure assets | Introduction of physical security planning reduces risks of theft, vandalism and sabotage | Extended asset life and reduced maintenance or replacement costs support long-term capital efficiency | Long term |
System-wide risk reduction | Reduced systemic and cascading economic shocks | Holistic, all-hazards risk management improves identification of interdependencies and shared risks | Greater national economic stability through reduced likelihood of multi-sector disruptions | Long term |
Overall, the proposed rule enhancements CIRMP supports a more consistent, mature and forward-looking risk management posture across critical infrastructure sectors. This underpins economic stability by reducing systemic vulnerabilities, improving operational efficiency, and enabling sustained investment and growth across the Australian economy. These benefits are consistent with the economic logic applied in the 2022 RIS, which identified avoided disruption costs, improved resilience and continuity of essential services as the primary sources of net economic benefit.
- Consultation
Consultation on the enhanced CIRMP Rules has occurred in stages. The first stage was a consultation on the proposed enhancements, including policy and impact analysis. Between 9 December 2025 and 13 February 2026, the Department consulted on the Enhancing the CIRMP Rules Consultation Paper. The Exposure Draft consultation document records that the Department received over 60 submissions and engaged more than 1,900 individuals through consultation activities, including two public town halls, two TISN briefings and five TISN impact analysis sessions. The engagement program included 11 online engagements, 1,910 attendees; 7 TISN engagements with 1,652 attendees; 2 public online town halls with 234 attendees; and 2 targeted engagements with utility regulators, with 24 attendees.
Feedback was broadly supportive of strengthening the CIRMP Rules, but consistently emphasised proportionality, reasonable practicability, staged implementation, guidance, alignment with existing frameworks and the practical limits of legacy OT environments, supplier concentration, contractor workforces and regulated funding cycles.
Consultation materially informed the design of the preferred option in this Addendum. In response to feedback, the Department extended grace periods for key obligations, engaged relevant price regulators, committed to developing best-practice guidance alongside the amended rules, retained a principles-based approach, and limited the enhanced requirements to asset classes with an elevated risk profile.
The second stage was consultation on the Exposure Draft of the amended CIRMP Rules from 30 March 2026 to 1 May 2026. The Exposure Draft process invited submissions on the design, implementation, sector impacts and alternative options and sought specific feedback on wording in certain draft provisions. This process enabled stakeholders to provide further comments on the legal implementation of the preferred option before the rules are finalised.
Submissions on the Exposure Draft broadly endorsed stronger requirements for FOCI, cyber maturity, operational technology, supply chain and physical security. There were themes addressing the need to consider proportional application, implementation timing, cost recovery, definitions, offshore and emergency access, supply chain mapping depth, worker impacts, and avoiding duplication with existing regulatory or assurance frameworks.
Table 11: Consultation themes and implications
Theme raised in consultation | Policy design response | Addendum implication |
Costs, timeframes and implementation feasibility | Analysis has been prepared; grace periods have been extended; price regulators have been engaged. | Cost uncertainty, regulated pricing cycles and staged implementation. |
Asset-class scope and proportionality | Enhanced obligations remain limited to nine specified asset classes identified as higher risk. | RBE and options must remain limited to those asset classes. |
Specified risk advice concerns | The original specified-risk-advice workflow is not treated as a standalone final measure; the Exposure Draft reflects enhanced material-risk provisions. | All-hazards 1 has not been costed as a standalone obligation. |
Need for guidance and principles-based implementation | Best-practice guidance will be developed; a principles-based CIRMP approach is maintained. | Central RBE does not assume prescriptive capital remediation in all cases. |
Cyber uplift, MFA and legacy OT constraints | Exposure draft includes staged implementation and reasonable-practicability language. | Distinguish process/framework uplift from wholesale legacy-system replacement. |
Supply chain mapping and major supplier assessment | Framework remains risk-based; government does not propose simple vendor whitelisting or blacklisting. | Include mapping and assessment processes; do not assume supplier replacement as the central case. |
Personnel security and AusCheck | Critical worker approach is retained; background-checking and portability issues are subject to co-design and process improvements. | Cost administration and process changes, not checks for all employees. |
Physical security plan | Requirement is principles-based and can be integrated with existing arrangements. | Cost plan development and review; capital works only where necessary. |
- Implementation and evaluation
- Implementation
The Enhanced CIRMP Rules provide staged grace periods for the enhanced CIRMP requirements. Sections 6A, 8A(2), and 9A(2), have a 12-month grace period. Sections 8A, other than subsection 8A(2), 8B, 8C, 9A, other than subsection 9A(2), 10A, and 11A, have a 24-month grace period.
This staged approach reflects consultation feedback that responsible entities have different starting points, budget cycles, asset lifecycles, supplier dependencies and operational technology constraints. It also reflects the evolving threat environment. The Department will support implementation through guidance and continued engagement with the TISN and relevant sector forums.
The Department will support implementation through guidance and continued engagement with the TISN and relevant sector forums. Guidance should clarify proportional application and documentation expectations, including equivalent-framework recognition, critical components (including systems) interpretation, compensating controls for legacy environments, supply chain mapping depth, FOCI assessment expectations, critical worker scope and physical security plan content.
- Evaluation
Evaluation of the enhanced CIRMP requirements should occur in two phases: implementation monitoring during the applicable grace periods, and effectiveness assessment after the relevant enhanced requirements have commenced. Success should be assessed by reference to improved clarity, consistency and maturity of risk management practices, rather than incident counts alone.
- Implementation monitoring
During the 12-month grace period for material risks, guidance and engagement will focus on how responsible entities intend to consider and address the risks associated with:
- impairments that could prejudice the social or economic stability, national security, or defence of Australia.
- compromise across all hazards as a result of FOCI.
- offshore or remote access to critical components
- offshore or remote access to business critical data
- failure to patch or update operating or security systems in a timely manner
- failure to replace legacy systems, or adequately mitigate risks associated with components or technology that are redundant, unsupported, obsolete or discontinued
- deployment or hosting of advanced, novel or emerging technology
- use of advanced, novel or emerging technology against the asset, in a manner that could prejudice the availability, integrity, reliability or confidentiality of the asset
- unauthorised or unsupervised access to critical components
- the compromise or misuse of credentials and privileged access used by individuals to access the CI asset
- access to the CI asset by persons other than critical workers for the CI asset
- incoming and outgoing critical workers.
During the 24-month grace periods, guidance and engagement will focus on whether responsible entities have:
- Incorporated documented cyber framework uplift plans within their CIRMP.
- Implemented phishing resistant MFA to minimise or eliminate credential compromise hazard occurring and mitigate the relevant impact to the CI asset.
- Implemented network segregation to minimise or eliminate lateral movement hazards occurring and mitigate the relevant impact to the CI asset.
- Strengthened background checking and continuous monitoring, including through critical worker mapping and appropriate intelligence background checks for all critical workers.
- Performed vulnerability mapping and vendor assessment, including by clearly identifying affected systems, suppliers, personnel and sites.
- Implemented appropriate security and access plans, including personnel security, physical security and natural hazard plans.
- Demonstrated a credible pathway to compliance by the end of the relevant grace period.
Annual CIRMP reporting and engagement through established regulatory channels will be used to assess whether entities are progressing toward the enhanced requirements. This approach recognises the staged implementation period and supports proportionate regulatory engagement where risks remain elevated.
- Effectiveness assessment
Following the attestation period, the evaluation will shift to assessing the effectiveness of the refinements in strengthening risk management maturity and consistency across affected asset classes. Indicators of effectiveness will include:
- Improved consistency and completeness of CIRMP documentation across in-scope asset classes.
- Increased maturity in cyber, supply chain, personnel and physical-security governance.
- Clearer treatment of FOCI, critical systems, critical workers and major suppliers.
- Evidence that entities are using compensating controls and staged implementation, where immediate technical uplift is not reasonably practicable.
- Improved regulator visibility of material risks and planned mitigations.
The evaluation will draw on annual reporting, attestation outcomes, regulatory assurance activities and sector-level trend analysis. The objective is to determine whether the refinements improve clarity, consistency and depth of risk management practice within the existing CIRMP architecture.
Given the dynamic threat environment, findings from ongoing monitoring and post-compliance review will inform future consideration of the CIRMP Rules to ensure they remain proportionate and aligned to national security risks.
Appendix A: Regulatory burden estimate methodology, assumptions and inputs
2022 RIS asset class now in enhanced CIRMP scope | 2022 RIS average annual cost ($m) |
Critical electricity assets | 257.9 |
Critical gas assets | 115.3 |
Critical water assets | 100.7 |
Critical broadcasting assets and critical domain name systems | 1.6 |
Critical liquid fuels assets | 13.2 |
Critical energy market operator assets | 33.0 |
Critical freight infrastructure and critical freight services assets | 52.8 |
Total in-scope 2022 RIS comparator | 574.5 |
Total 2022 RIS all asset classes | 1,150.4 |
The 2022 RIS estimated average annual regulatory costs of $1.1504 billion for the full CIRMP framework across all considered asset classes. The asset classes now in scope of the enhanced CIRMP Rules accounted for approximately $574.5 million of that annual average cost. This in-scope comparator is used as the cost base for the 2026 incremental estimate.
The 2026 enhanced CIRMP Rules are not a new risk-management program. They apply to entities already subject to the CIRMP and require incremental uplift in risk consideration, processes, systems, documentation, governance, assurance and targeted controls. The Addendum therefore applies a calibrated incremental uplift to the 2022 in-scope cost base. The low case applies 5 per cent, the central case applies 10 per cent, and the high case applies 15 per cent.
The formula is: average annual business RBE = 2022 in-scope average annual CIRMP cost base x incremental uplift percentage. The central estimate is $574.5 million x 10 per cent = $57.5 million per year. The low case is $574.5 million x 5 per cent = $28.7 million per year. The high case is $574.5 million x 15 per cent = $86.2 million per year.
Sensitivity | Calculation | Average annual RBE | Share of 2022 all-asset-class cost |
Low | $574.5m x 5% | $28.7m | 2.5% |
Central | $574.5m x 10% | $57.5m | 5.0% |
High | $574.5m x 15% | $86.2m | 7.5% |
The RBE is not derived from a new bottom-up estimate of hours per activity for each 2026 enhancement. A bottom-up hours model was not adopted because consultation responses did not provide a representative national dataset of marginal time costs, and many submitted estimates combined mandatory compliance activities with broader remediation, already planned investments, or entity-specific implementation choices. The 2022 RIS remains the most complete national activity-based cost base for CIRMP compliance. It incorporated marginal staff effort, labour costs, operating costs and capital costs for the CIRMP framework. This Addendum therefore uses that 2022 in-scope cost base as a reference-class benchmark and applies transparent low, central and high incremental uplift assumptions to estimate the additional burden of the 2026 enhancements. The table below identifies the incremental activity categories captured by the uplift.
RBE activity category | Treatment in the estimate |
Risk assessment and CIRMP updates | Included in the incremental uplift |
Governance, assurance and evidence keeping | Included in the incremental uplift |
Supplier/vendor review and mapping | Included in the incremental uplift |
Cyber maturity assessment, roadmaps and targeted uplift | Included in the incremental uplift |
Personnel security planning and critical worker processes | Included in the incremental uplift |
Physical security plan development and testing | Included in the incremental uplift |
Full remediation of every identified risk | Not assumed in the central estimate |
Supplier replacement or major capital works | Not assumed in the central estimate; reflected only in high-side uncertainty where relevant |
Consumer pass-through | Excluded from RBE and discussed as a distributional impact |
Key assumptions
- The enhanced CIRMP obligations are incremental to an existing CIRMP baseline.
- The 2022 RIS remains the most complete national cost base for the CIRMP framework.
- The relevant comparator is the 2022 cost for the nine asset classes now in scope, not the full 2022 cost across all asset classes.
- The central estimate reflects a meaningful but bounded uplift in compliance effort.
- The high case captures entities with lower baseline maturity, legacy OT, constrained supplier markets or more substantive uplift requirements
- Submitted consultation cost estimates are used for calibration and sensitivity analysis rather than being directly extrapolated, due to non-representative coverage and high variability.
Classification note: The RBE is presented under Business because the 2022 RIS treated responsible-entity costs as business costs, and the affected population is primarily businesses or government business enterprises.
Activities considered
The table below outlines the activities considered for the RBE for the enhanced CIRMP Rules.
Measure | Description | Main incremental RBE activities |
Enhanced material risks and FOCI | Responsible entities consider impairment of asset functions and compromise or impairment connected with FOCI. | Risk assessment, supplier/vendor review, CIRMP update, governance and evidence. |
Cyber framework uplift | Responsible entities demonstrate Level 2 or equivalent maturity under an accepted framework. | Gap assessment, roadmap, documentation, targeted uplift, assurance. |
|
|
|
Credential compromise | Responsible entities implement phishing-resistant MFA where reasonably practicable or manage associated risk through reasonable steps and compensating controls. | Access review, MFA deployment or compensating-control assessment, logging, governance. |
Lateral movement | Responsible entities identify critical systems and manage segregation, isolation and recovery planning. | Inventory, architecture review, IT/OT pathway review, recovery planning, documentation. |
Supply chain mapping | Responsible entities map major suppliers and critical systems across physical and cyber supply chains. | Supplier identification, data collection, criticality assessment, dependency mapping and evidence. |
Vendors of concern | Responsible entities assess and manage vendor risks, including FOCI, concentration, cyber and operational dependency risks. | Vendor-risk process, due diligence, procurement governance and contract review. |
Personnel security | Responsible entities maintain personnel security processes, including critical worker identification, access controls, monitoring and background checks. | Role mapping, personnel security plan, onboarding changes, records and AusCheck administration. |
Physical security plan | Responsible entities centrally manage physical security and natural hazards and document site, access, monitoring and response measures. | Plan development, site assessment, access-control review, surveillance, alarm review and testing. |
Appendix B: Summary of initially proposed enhancements and identified gaps
The proposed CIRMP Enhancements as consulted from 9 December 2025 to 13 February 2026.
Note All-hazard: Specified risk advice did not progress after the first consultation round.
Hazard domain | Current | Identified gap | Enhancement | Nature of change |
All-hazard: Specified risk advice | Entities must identify, assess and manage material risks across all hazards in their CIRMP. | Relies on entities’ existing review process. No clear requirement for entities to assess specified risk advice or document the response. | Requirement to consider specified risk advice from the Department, assess related material risks, and minimise or eliminate those risks where reasonably practicable. | Clarification and governance uplift within the existing all-hazards framework, not a new hazard domain or prescriptive control. |
All-hazard: Material risks – foreign ownership control and influence | Entities are required to consider supply chain and personnel risks in their CIRMP. | No clear requirement for a systematic assessment of FOCI risks across all hazards. Many entities do not apply structured, documented or repeatable FOCI processes. | Requirement to identify and assess FOCI risks, key suppliers and dependencies as part of material risk assessment. | Clarification and structured specification within the existing risk framework. |
Cyber: | Entities are required to maintain baseline maturity (maturity level 1) in their chosen cyber security framework. | Baseline controls are no longer sufficient. Maturity varies widely across sectors. Many entities remain at low maturity. | Uplift in cyber maturity to Maturity Level 2 of suitable cyber security frameworks. | Targeted uplift of cyber maturity expectations. |
Cyber: | Entities must minimise cyber risks to critical IT systems. | No clear standard for logical segregation, isolation or recovery planning for critical systems. | Introduction of clearer expectations regarding IT/OT system segregation, isolation and recovery planning for critical systems. | Specification of control expectations within existing cyber obligations. |
Cyber: | General obligation to minimise cyber risks. | Inconsistent use of MFA, particularly for privileged access, remote staff, vendors and machine environments. | Clearer expectations for MFA implementation. | Clarification of control expectation within existing obligation. |
Cyber: | Obligation to identify and manage material cyber risks. | Existing CIRMP Rules do not explicitly address AI, quantum computing or other advanced, novel, or emerging technology risks. | Requirement to assess and document material risks arising from emerging technologies. | Clarification and extension of material risk consideration. |
Supply chain: Supply chain vulnerability mapping | Entities must identify and manage supply chain hazards. | Limited visibility beyond first or second-tier suppliers. | Clearer expectation to identify, map and assess critical supply chain dependencies and vulnerabilities. | Specification of assessment depth and documentation. |
Supply chain: Vendors of concern | General obligation to consider supply chain risk. | No clear, consistent process for assessing vendors of concern, including FOCI and concentration risks. | Requirement to establish a documented process for identifying and managing vendors of concern. | Formalisation of governance process within supply chain risk. |
Personnel: Personnel security plan | Personnel hazards must be considered within a broader risk management program. | Risks of critical workers accessing sensitive information, including contractors and guests. | Requirement to maintain a documented personnel security plan addressing insider threat and workforce risks. | Formalisation and governance uplift. |
Personnel: Strengthened background checks | Entities must manage personnel-related risks. | Inconsistent use of background-checking mechanisms. Uncertainty about critical worker classification and contractor vetting. | Mandating expectations regarding background checks for critical workers and contractors. | Specification of screening expectation. |
Personnel: Enhancing personnel material risks | Entities must identify and manage material risks. | Inconsistent identification and documentation of coercion, privileged access misuse and insider risks. | Clearer expectations to identify and document personnel-related material risks. | Clarification of documentation and assessment expectations. |
Physical: Physical security hazards and natural hazards | Entities must consider physical and natural hazards in their risk management program. | No requirement to maintain a structured physical security plan comparable to PSPF[11] standards. Inconsistent controls and testing across sites. | Requirement to maintain and test a documented physical security plan. | Formalisation of physical security governance requirements. |
[1] https://www.asio.gov.au/director-generals-annual-threat-assessment-2025
[2] https://www.homeaffairs.gov.au/nat-security/files/foci-risk-assessment-guidance-without-appendices.pdf
[3] https://www.asio.gov.au/director-generals-annual-threat-assessment-2025
[4] https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/prc-state-sponsored-actors-compromise-and-maintain-persistent-access-us-critical-infrastructure
[5] https://www.cyber.gov.au/sites/default/files/2025-10/Annual%20Cyber%20Threat%20Report%202024-25.pdf
[6] https://www.homeaffairs.gov.au/nat-security/files/foci-risk-assessment-guidance-without-appendices.pdf
[7] https://www.cisc.gov.au/resources-subsite/Documents/critical-infrastructure-annual-risk-review-2024.pdf
[8] https://www.reuters.com/sustainability/climate-energy/ghost-machine-rogue-communication-devices-found-chinese-inverters-2025-05-14/
[9] https://www.aspistrategist.org.au/its-not-just-software-physical-critical-equipment-cant-be-trusted-either/
[10] https://www.aic.gov.au/sites/default/files/2025-08/the_cost_of_espionage.pdf
[11] https://www.protectivesecurity.gov.au/