Responsible entities for high-risk assets need to be strategic in addressing the enhanced critical infrastructure risk management program (CIRMP) requirements which commenced on 10 June 2026 and offer grace periods of only 12 and 24 months.
What you need to know
- The Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (Enhanced CIRMP Rules) impose significant new risk management obligations on the following nine critical infrastructure (CI) asset classes, across four sectors:
| Sector |
Asset classes |
| Energy |
Critical electricity asset; critical energy market operator asset; critical gas asset; critical liquid fuel asset |
| Communications |
Critical broadcasting asset; critical domain name system |
| Water and sewerage |
Critical water asset |
| Transport |
Critical freight infrastructure asset; critical freight services asset |
- By 10 June 2027, impacted responsible entities must address in their CIRMP:
- additional material risks (such as foreign ownership, control or influence (FOCI), offshore or remote access to critical components or business critical data, and impairment risks of national consequence);
- certain cyber security hazard requirements (such as timely patching, replacement of legacy tech, and deployment, hosting or counterparty use of advanced, novel or emerging tech); and
- additional material risks concerning personnel access to critical components or the CI asset.
- By 10 June 2028, impacted responsible entities must also address in their CIRMP:
- cyber security framework uplift;
- phishing-resistant MFA and credential compromise;
- network segregation and lateral movement controls;
- critical system inventory and availability of CI asset during critical system recovery;
- personnel suitability assessments (AusCheck or hold a Negative Vetting 1 (or higher) security clearance);
- supply chain mapping for major suppliers and critical components and supply chain risk to critical components or business critical data; and
- central management of physical security and natural hazard having regard to all hazards consequences and identifying locations of critical components and business critical data.
- For an asset that becomes a CI asset on or after commencement of the Enhanced CIRMP Rules, the 12-month and 24-month grace periods run from the date the asset first becomes a CI asset.
- Impacted responsible entities should assess their current compliance and begin implementation planning. Cross-functional coordination will be essential to ensuring compliance is met within the prescribed deadlines.
- While assessing gaps in their current CIRMP, impacted responsible entities will need to be mindful of a range of potential SOCI reforms as described in our earlier article Consultation on reforming the security of critical infrastructure laws, which will impact their uplift program.
What has happened?
The Enhanced CIRMP Rules amend the existing Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 (CIRMP Rules), made under section 61 of the Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act).
The reforms respond to an increasingly complex and persistent threat environment. The growing interconnectivity of critical infrastructure systems has heightened systemic risk. Disruption to a single asset can now affect multiple sectors, with the potential for broad economic and societal consequences. Since the introduction of the baseline CIRMP Rules, supply chain dependencies, cyber actors and insider threats, physical security vulnerabilities and emerging technologies have introduced additional risk vectors. These have exposed gaps in the consistency and maturity of risk management practices.
The Enhanced CIRMP Rules follow the independent review of the SOCI Act conducted by Dr Jill Slay AM, released in early 2026, which confirmed these findings and recommended enhanced risk management obligations for high-risk asset classes.
What are the key changes?
The Enhanced CIRMP Rules introduce obligations across the following key areas, each summarised below:
1. Additional material risks to address
Impacted responsible entities must establish and maintain systems or processes in their CIRMP to, as far as reasonably practicable, minimise or eliminate the following additional material risks:
- any impairment of the CI asset's functions that could prejudice the social stability, economic stability, national security or defence of Australia;
- compromise or impairment of the functions of the CI asset as a result of, or in connection with, FOCI;
- offshore or remote access to critical components; and
- offshore or remote access to business critical data.
The FOCI obligation requires entities to consider impacts to the availability, reliability, integrity and confidentiality of the asset from FOCI-associated risks. These risks may arise in connection with technology or non-technology vendors, major suppliers, managed service providers or contractors critical to the operation of the asset. For instance, a foreign-owned or foreign-influenced entity that provides critical systems or operational technology may be subject to foreign direction or coercion through its ownership structure. This requires the responsible entity to identify the risk of vulnerabilities being introduced, access being misused, or support services being withheld.
2. Updated cyber and information security requirements
Impacted responsible entities must establish and maintain processes in their CIRMP to minimise or eliminate each of the following material risks, so far as it is reasonably practicable to do so:
- failure to patch or update operating or security systems in a timely manner;
- failure to replace legacy systems, or adequately mitigate risks associated with components or technology that are redundant, unsupported, obsolete or discontinued;
- deployment or hosting of advanced, novel or emerging technology (including AI) in a manner that could prejudice the availability, integrity, reliability or confidentiality of the CI asset; and
- use of advanced, novel or emerging technology against the asset (e.g. frontier AI to rapidly scan for vulnerabilities in critical systems).
A responsible entity must establish and maintain a process or system in the entity's CIRMP to comply with one of the following cyber security frameworks:
- Australian Standard AS ISO/IEC 27001:2023;
- Essential Eight Maturity Model (ASD) (Maturity level 2);
- NIST Cybersecurity Framework (CSF) 2.0;
- Cybersecurity Capability maturity Model (C2M2) v2.1 (US DoE) (Maturity Indicator Level 2); or
- 2023 AESCSF Framework Core (AEMO) (Security Profile 2).
Alternatively, a responsible entity may comply with an equivalent framework, provided that framework meets certain conditions and achieves an equivalent level of security.
Even where a responsible entity's chosen cyber framework does not require phishing-resistant multi-factor authentication (MFA), the Enhanced CIRMP Rules require the entity to implement MFA controls. Specifically, the entity must:
- identify the systems and networks where MFA is required to authenticate access — including internet-connected computers, critical systems, privileged and unprivileged access, and remote access;
- implement MFA controls for those systems and centrally log, monitor and routinely review both successful and unsuccessful authentication attempts; and
- upon doing so, the entity is taken to have met its obligation to minimise or eliminate any material risk of a credential compromise hazard (being the risk that an unauthorised person obtains or exploits legitimate login credentials to access systems or data) having a relevant impact (that is, an impact on the availability, integrity, reliability or confidentiality of the CI asset) on the asset.
Separately, a responsible entity must establish and maintain a process or system in its CIRMP to address lateral movement risk, being the risk that a threat actor, having gained initial access to one system, moves through interconnected systems to reach higher-value targets. So far as is reasonably practicable, the entity must:
- identify and maintain an inventory of critical systems, including how those systems are interconnected with other critical systems and computers;
- recover and restore critical systems where an incident has had, or is having, a relevant impact on the asset;
- ensure the continued availability of the asset while rebuilding or restoring critical systems; and
- minimise or eliminate any material risk of lateral movement and mitigate the relevant impact of a lateral movement hazard on the CI asset.
Importantly, entities must ensure that critical systems can continue to operate for a minimum of three months while other computers are being restored or recovered. This is likely one of the most operationally demanding obligations as it requires entities to maintain sufficient operational independence of critical systems so that essential services continue to be delivered even during an extended incident response.
3. Addressing personnel hazards
A responsible entity must establish and maintain a process or system in its CIRMP to minimise or eliminate material risks associated with:
- unauthorised or unsupervised access to critical components;
- the compromise or misuse of credentials and privileged access;
- access to the CI asset by persons other than critical workers (being persons whose activities have a significant impact on, or who have access to critical component of, the CI asset); and
- incoming and outgoing critical workers.
To satisfy the personnel hazard obligations, a critical worker may only be assessed as suitable to access critical components if the critical worker:
- has been the subject of an AusCheck background check and, following the check, has been assessed as suitable by the responsible entity; or
- holds a Commonwealth security clearance of Negative Vetting 1 level or higher, at the time they were identified as a critical worker.
Where an AusCheck background check is used, it must be repeated at minimum every five years for any person requiring ongoing access to critical components.
Where a critical worker is unable to satisfy the AusCheck or security clearance requirements, the responsible entity may still permit access to critical components, provided it has documented in its CIRMP the risk associated with that worker's access and the actions taken to minimise or eliminate the risk to the asset. This will be particularly relevant for entities with offshore workforces or those experiencing delays in AusCheck processing.
4. What supply chain due diligence is required?
A responsible entity must establish and maintain a system or process in its CIRMP to map its supply chain, specifically, identifying major suppliers and critical components across the supply chain. In doing so, the CIRMP must:
- identify risks in the entity's supply chain that may affect the availability, integrity, reliability or confidentiality of critical components or compromise business critical data;
- determine the maximum acceptable outage for the CI asset or any of its critical components that could result from a disruption to the entity's supply chain, that is, the longest period the asset or component can be unavailable before a relevant impact occurs; and
- as far as is reasonably practicable, include measures to minimise or eliminate those risks, or mitigate the impact of an outage that exceeds the maximum acceptable outage.
Separately, responsible entities must establish and maintain a system or process to assess the risks posed by each existing or proposed major supplier for the CI asset. In effect, this requires a due diligence assessment of each major supplier. The assessment must identify:
- in relation to FOCI risks, legislative or other legal requirements to which the supplier is subject;
- restrictions, sanctions or other impediments affecting the jurisdiction in which the supplier operates;
- the access, influence and control the supplier has over the CI asset;
- the extent to which those matters, taken together, may present a material risk to the asset or could result in an outage exceeding the maximum acceptable outage; and
- steps to minimise or eliminate material risks and mitigate the relevant impact on the CI asset.
5. Managing physical security and natural hazards
A responsible entity must establish and maintain a process or system in its CIRMP to centrally manage physical security and natural hazards. As far as is reasonably practicable, the entity must identify and consider the physical security consequences that may arise from the occurrence of all hazards, including cyber, credential compromise, lateral movement, personnel and supply chain hazards.
For example, a malicious cyber incident that causes physical access controls (such as gates) to open, allowing unauthorised entry; or a supply chain disruption that forces changes to workplace operations, reducing the entity's ability to deter, detect, delay and defend against a physical security breach.
The entity's physical security plan must identify the location, ownership and nature of each site upon which the asset is located; the critical components of the CI asset; and the areas within the asset that hold business critical data or contain critical components.
What impacted responsible entities can do now
While impacted responsible entities will need to act promptly to update their CIRMP to meet the enhanced requirements, they also need to factor in proposed reforms into their current compliance planning.
This includes reforms being proposed to:
- the definition of critical component and critical worker;
- the definition of cyber security incident – to cover automated systems, software agents and AI;
- require cyber-specific assurance with major suppliers;
- introduce a new procedural obligation to consider and document responses to specified risk material through CIRMP processes;
- increase penalties for non-compliance with core CIRMP duties; and
- require regular independent assurance of CIRMPs, with reporting of findings to the regulator.
The detail of the reforms is not yet available, as it remains subject to consultation and consideration by government. Entities refining their CIRMP governance, personnel security and supply chain processes should design those processes with sufficient flexibility to accommodate the proposed reforms if enacted.
We recommend impacted responsible entities take the following steps:
- conduct a gap analysis against the new requirements;
- assess current cyber security maturity and develop a roadmap to achieve the required compliance level within the 24-month window;
- identify critical systems and maximum acceptable outages for the CI asset and critical components;
- commence supply chain mapping and vendor due diligence;
- commence review of supplier contracts to address additional measures which will need to be assessed or monitored;
- identify critical workers and plan for AusCheck implementation as well as enhanced on- and off-boarding processes;
- review physical security arrangements and location of critical components and business critical data;
- commence board and executive briefings to enable engagement and support to achieving compliance within the required timelines; and
- coordinate cross-functionally, as a siloed approach will impede achieving compliance.
Entities should monitor SOCI developments closely and factor the likely trajectory of reform into their compliance planning.
How we can help
MinterEllison provides full-service IT legal and consultancy services with extensive experience in SOCI laws, risk governance, privacy, data protection, software and IT service procurement. Please contact us if you would like assistance in understanding the enhanced risk management program requirements and with implementing a compliant risk management program under the enhanced CIRMP Rules.