Uncrimping the CIRMP: risk-management changes for Critical Infrastructure, with more on the way
Market Insights
The Security of Critical Infrastructure Act 2018 (Cth) (SoCI Act) contains a range of obligations on entities responsible for critical infrastructure assets, like power generation facilities, major hospitals, key freight networks, and data centres. Many of the key operational requirements derive from an obligation to adopt, comply with and report on a critical infrastructure risk management program (CIRMP). An entity’s CIRMP should address all hazards that might impact the asset, but specifically must cover risks associated with:
- cyber and information security hazards;
- personnel hazards;
- supply chain hazards; and
- physical security and natural hazards.
You can read more about what needs to be addressed in a CIRMP in our original article on the topic available here.
The Security of Critical Infrastructure (Critical Infrastructure Risk Management Program) Rules (LIN 23/006) 2023 (Cth) (CIRMP Rules) were amended on 10 June 2026 to introduce a two-tier system under which certain critical infrastructure assets are subject to enhanced obligations. Entities will be required to meet these enhanced obligations once the grace period (which is between 12 and 24 months depending on the relevant obligation) ends.
The Department of Home Affairs has also released a consultation paper addressing proposed streamlining and modernising of the SoCI Act (Consultation Paper). The Consultation Paper proposes 21 measures for improving the SoCI Act, a number of which impact CIRMPs. You can read more about the proposed measures as a whole in our article on the Consultation paper available here. Interestingly, the Consultation Paper has proposed significant amendments to how CIRMPs interact with governance, assurance and accountability.
In this article, we will discuss the amendments to the CIRMP Rules and the proposed changes in the Consultation Paper as they relate to governance, assurance and accountability of CIRMPs.
Enhanced CIRMP requirements
Applicable entities
Under June’s changes to the CIRMP Rules, a new set of ‘enhanced requirements’ apply above and beyond the baseline CIRMP requirements to responsible entities for:
- critical broadcasting assets;
- critical domain name systems;
- critical electricity assets;
- critical energy market operator assets;
- critical freight infrastructure assets;
- critical freight services assets;
- critical gas assets;
- critical liquid fuel assets; and
- critical water assets.
These assets are said to be, by ‘the nature of their interdependence’, to be ‘attractive targets for disruption and sabotage’.
Other critical assets continue to carry baseline CIRMP obligations, and are not currently subject to the enhanced requirements, though this scope can be varied by further rule-making.
Enhanced requirements
For in-scope entities, the enhanced requirements add new, more demanding obligations layered on top of the baseline CIRMP framework.
In addition to the matters already required to be covered in a CIRMP, the enhanced requirements require responsible entities to address additional material risks in their CIRMPs, being:
- impairment of the asset’s functions that could prejudice Australia’s social stability, economic stability, national security or defence;
- compromise or impairment of the asset’s functions arising from, or in connection with, foreign ownership, control or influence (FOCI); and
- offshore or remote access to critical components or business critical data.
Responsible entities in these sectors are also required to meet uplifted cyber and information security benchmarks, by addressing risks from unpatched systems, legacy technology, and advanced or emerging technology (such as AI or post-quantum cryptography). These entities are also required to comply with a more robust recognised cyber security frameworks, such as a higher level of maturity under the Essential Eight than would otherwise be required by the baseline CIRMP requirements.
Entities in enhanced categories are also required to address a specific vector for cyber intrusion, and a specific mitigation to minimise cyber-attack surface area. CIRMPs must set out how they will address ‘credential compromise’, where stolen, lost or otherwise compromised passwords are used to access systems. This might be via the content of a cyber security framework, or via other phishing resistant multi-factor authentication methods. CIRMPs must also address ‘lateral movement’ hazards, where access to one computer can be leveraged to access other interconnected systems. The CIRMP Rules list a set of steps that can be taken to appropriately achieve proper network segmentation to address ‘lateral movement’, though it is open to responsible entities to implement other suitably effective measures.
The uplifted CIRMP Rules also apply a stricter personnel security model, including mandatory AusCheck background checks (repeated at least every five years) or an active security clearance at Negative Vetting 1 level or higher for critical workers before they are given access to critical components – or, where that is not achievable, documenting the residual risk and any mitigating steps in the CIRMP.
Assets subject to enhanced requirements will also be required to have their CIRMP set out a process for mapping supply chains and completing vendor assessments, by identifying major suppliers and critical components across the supply chain, the maximum acceptable outage arising from supply chain disruption, and, for each major supplier, any FOCI-related legal exposure, jurisdictional restrictions or sanctions, and the level of access, influence and control the supplier has over the asset.
The enhanced requirements also require each applicable to CIRMP to set out a process or system to centrally manage physical security and natural hazard risk, including by considering the physical security consequences that can flow from any hazard (not just physical events), and outlining the asset’s site, critical components and business-critical data areas, together with access controls, surveillance, out-of-hours security measures, and incident mitigation and response measures.
Grace period
While the updated CIRMP Rules came into effect on 10 June 2026, the enhanced requirements are subject to a grace period. The additional material risks, enhanced cyber security obligations, and enhanced personnel requirements are subject to a 12-month grace period, and the other enhanced obligations are subject to a 24-month grace period.
Entities affected by these new obligations will need to ensure that they meet these requirements by the end of the relevant grace period. Boards and risk teams responsible for enhanced-tier assets should confirm whether their asset classes are captured, and begin gap-assessing their CIRMPs against the enhanced requirements well ahead of the 12 and 24-month deadlines.
Proposed further changes to CIRMP requirements
In addition to the recent changes to the CIRMP Rules, the Government is flagging potential further changes to CIRMP requirements that would require Parliament to amend the underlying SOCI Act.
Strengthening governance controls
The current SoCI Act framework requires CIRMPs to be reviewed ‘regularly’ and kept ‘up to date’, without specifying what these actually require or specifically demanding that senior management to engage with the CIRMP. The Consultation Paper proposes changing these requirements by:
- requiring senior leadership to approve the establishment, review, update and variation of the CIRMP;
- prescribing a minimum review cycle of at least once every 24 months, or sooner if certain events occur; and
- establishing clearer criteria for when a CIRMP is not up to date.
The intention behind these proposed changes is to make CIRMP governance easier to understand and demonstrate.
Establishing criteria for when a CIRMP is not up to date and setting out the minimum review cycle will help accomplish this. The requirement to have senior leadership more involved with the CIRMP is unlikely to make the process more efficient, but does help reinforce that one of the purposes behind all of these changes is to highlight that responsible entities should be treating the CIRMP seriously and not as an afterthought.
Independent CIRMP assurance
The current CIRMP compliance framework relies on entities self-attesting as to their compliance with the SoCI Act, without demanding independent review.
The Consultation Paper proposes to address this by requiring entities to obtain periodic independent assurance in relation to their CIRMP at least once every three years, and to prepare and follow a remediation plan to address any deficiencies identified. There is also a proposition of having more regular or stringent requirements in relation to higher risk entities.
From a regulatory perspective, requiring regular independent assurance will help strengthen the overall security of critical infrastructure. However, this is likely to be a material additional cost that will have to be borne by responsible entities and may affect the viability of owning or acquiring critical infrastructure assets. This is especially the case in relation to smaller or less commercially viable critical infrastructure assets.
Cooperation within corporate groups
The SoCI Act places responsibility for complying with obligations around CIRMP solely on the relevant ‘responsible entity’. This does not align with the practical reality of how critical infrastructure assets are operated, as they are often a collaboration between multiple entities within a corporate group who may each have separate responsibilities in relation to the critical infrastructure asset.
There is no mechanism in the SoCI Act that provides for direct cooperation between a corporate group. This can make risk management harder, slow response times, and make it unclear who is responsible for important dependencies.
The Consultation Paper proposes to impose a statutory obligation on connected entities:
- not to take action, or fail to take action, that they know or ought reasonably to know would materially prevent or undermine CIRMP compliance;
- to provide information, access, or assistance to the responsible entity to meet its CIRMP compliance; and
- to notify responsible entities of incidents, changes, or circumstances that could materially affect the security of the asset or ability to manage CIRMP risks,
if the responsible entity has a material dependency on the connected entity. This would be met if the responsible entity relies on the connected entity ‘to provide, manage or control a function that is material to the responsible entity’s ability to comply with its CIRMP obligations’.
Noting that there is a gap between how critical infrastructure assets are managed and the single entity responsibility provided for in the SoCI Act, including obligations on related entities in a corporate group to assist with CIRMP compliance goes some way to addressing this gap. However, it does pose a risk to corporate groups and potentially open new avenues of liability in relation to CIRMP compliance. Addressing this will require collaboration across corporate groups and parent companies to take an active role in ensuring that connected entities are working together.
Consideration of other risks
Third parties (such as governments or standard bodies) regularly publish information relevant to entities’ CIRMPs. There is currently no obligation in the SoCI Act for entities to consider and address this information. There is also no explanation on what responsible entities should do to assess cyber risks from major suppliers.
The Consultation Paper proposes creating a targeted mechanism for the Secretary to identify specific published material that responsible entities must consider. The intention is that this would require entities to:
- consider the specified material;
- assess whether it is relevant and poses a material risk; and
- record an appropriate response.
This framework provides a method for the Secretary to ensure that CIRMPs address specific risks, but creates an additional obligation that responsible entities will need to meet and that may prove challenging (especially for smaller less sophisticated entities).
The Consultation Paper also proposes that the CIRMP framework should address cyber-specific assurance for major suppliers and service providers. The intention is that this would assist responsible entities in assessing and managing cyber risks arising from these suppliers.
This proposed framework is not dissimilar from the way APRA regulates banking and insurance providers under CPS 230, which also creates a framework for assessing and managing cyber risks arising from critical service providers and fourth parties. Having this framework will assist responsible entities with managing these risks, although it may also add additional costs and administrative processes for those arrangements.
Admissibility restrictions
The SoCI Act does not currently allow mandatory annual compliance reports to be used as evidence in civil penalty proceedings, even in proceedings relating to non-compliance with the annual compliance report. This means that the regulator is required to obtain the relevant evidence through other compulsory information gathering powers rather than simply using the annual compliance report.
The Consultation Paper proposes removing this restriction and allowing annual compliance reports to be relied on in civil penalty proceedings. The proposition is not to make non-compliance action compulsory for the regulator, just to make it simpler for the regulator to take this action.
From the regulator’s perspective, this proposed change is a logical way to reduce administrative cost and to allow it to take enforcement action in relation to mandatory annual compliance reports. However it does now heighten the risk of enforcement action, and may also potentially serve as a disincentive for responsible entities to be frank in their reporting.
Next steps
If implemented, the measures proposed in the Consultation Paper would substantially alter how CIRMPs have to be addressed by responsible entities and their surrounding corporate groups. These changes would strengthen Australia’s security posture, but would also impose additional burdens on responsible entities. Separately, entities responsible for the specified higher-risk asset classes should note that the enhanced CIRMP requirements described above are not proposals — they are already in force, subject to the transitional periods discussed, and require action now rather than only once the Consultation Paper measures are settled.
Many of the key day-to-day obligations under the SoCI Act are given effect through the CIRMP, and these proposed measures highlight the importance that the Department of Home Affairs is placing on CIRMPs. Responsible entities should take the opportunity before these measures come into force (if they do) to ensure that their CIRMPs are fit for purpose.
Our IP and IT team has extensive experience in advising businesses regarding SoCI Act obligations, contract and common law. If you are concerned about SoCI Act obligations, please contact us for further information on how we can assist you.
This article was written by Dan Kiley, Partner, Ashlee Broadbent, Associate, and Maximilian Soulsby, Associate.
Subscribe for publications + events
HWLE regularly publishes articles and newsletters to keep our clients up to date on the latest legal developments and what this means for your business. To receive these updates via email, please complete the subscription form and indicate which areas of law you would like to receive information on.
* indicates required fields
