SOCI Act CIRMP Supply Chain Cyber Risk Management in Australia 2026
The 2026 CIRMP Rules under Australia's SOCI Act impose new supply chain cyber risk obligations. Learn what businesses and cyber consultants must do now.
Australia's critical infrastructure protection regime entered a new era on 10 June 2026, when the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 commenced. For businesses operating in or supplying to critical infrastructure sectors — and for the cyber consultants who advise them — these reforms represent the most significant uplift in supply chain cyber risk obligations in Australian history.
Understanding the SOCI Act and the CIRMP Framework
The Security of Critical Infrastructure Act 2018 (SOCI Act) is the cornerstone of Australia's critical infrastructure protection regime. It covers 11 sectors and 22 asset classes, including energy, communications, financial services, healthcare, water, and data storage and processing.
At the heart of the SOCI Act is the Critical Infrastructure Risk Management Program (CIRMP) — a structured, board-approved program that responsible entities must maintain to identify, manage, and mitigate risks across four hazard domains: cyber and information security, personnel security, supply chain security, and physical security.
The June 2026 amendments transformed the CIRMP from a principles-based framework into a prescriptive, evidence-based regime. Responsible entities can no longer rely on documented policies alone — they must demonstrate that controls are operating effectively, supported by testing results, audit trails, and independent assurance.
What the 2026 CIRMP Rules Require
The Enhanced CIRMP Rules introduced a phased uplift pathway for nine high-risk asset classes. Key obligations now include:
- Board-level accountability — The CIRMP must be formally approved by the board or senior management, with explicit accountability for program effectiveness.
- Independent assurance — Responsible entities must obtain periodic independent assurance of CIRMP design and effectiveness at least every three years.
- Phased maturity uplift — Entities must achieve Essential Eight Maturity Level 2 by mid-2028, with interim milestones requiring phishing-resistant MFA and network segmentation by mid-2027.
- Incident reporting timelines — Critical cyber incidents must be reported to the Australian Cyber Security Centre (ACSC) within 12 hours of awareness; non-critical but relevant incidents within 72 hours.
- Increased civil penalties — Penalties for core risk management breaches have increased from 200 to 500 penalty units (currently $165,000 per breach).
These obligations apply to responsible entities directly, but their practical effect extends throughout the supply chain — because the rules require entities to manage risks arising from third-party operators and major suppliers.
Supply Chain Cyber Risk: The New Frontier
Supply chain risk is the defining focus of the 2026 reforms. The Enhanced CIRMP Rules require responsible entities to identify and manage risks from two categories of third parties: relevant operators (those with operational influence over critical assets) and major suppliers (those whose failure or compromise could materially affect asset availability or security).
Mapping Your Supply Chain Dependencies
The first obligation is identification. Responsible entities must map their supply chains to identify third parties that have the ability to configure, maintain, or influence the security or availability of critical infrastructure assets. This includes cloud service providers, managed security service providers, industrial control system vendors, and telecommunications carriers.
For many organisations, this mapping exercise reveals dependencies that were previously undocumented or poorly understood. A cyber consultant can assist by conducting structured supply chain dependency assessments using frameworks such as the ASD's Cyber Supply Chain Risk Management guidance and the NIST SP 800-161 standard.
Implementing Cyber-Specific Due Diligence
Once dependencies are mapped, entities must implement cyber-specific due diligence and contractual controls for major suppliers. This includes:
- Requiring suppliers to maintain and evidence their own cybersecurity controls (e.g., ISO 27001 certification or Essential Eight compliance).
- Incorporating cybersecurity obligations, audit rights, and incident notification requirements into supplier contracts.
- Conducting periodic supplier security assessments, including questionnaire-based reviews and, for high-risk suppliers, on-site or remote technical assessments.
- Establishing processes to respond to supplier security incidents, including the ability to isolate or replace a compromised supplier rapidly.
The government is also developing supplier certification and accreditation frameworks to assist entities in conducting due diligence — a development that cyber consultants should monitor closely as these frameworks mature.
Common Mistakes and Red Flags
Many organisations underestimate the scope of their CIRMP obligations, particularly in relation to supply chain risk. Common mistakes include:
- Treating CIRMP as a documentation exercise — The 2026 rules require evidence of operating effectiveness, not just written policies. Regulators will look for testing results, audit logs, and assurance reports.
- Failing to register relevant operators — Some entities have not identified all third parties with operational influence over their assets, leaving significant gaps in their risk management programs.
- Underestimating incident reporting timelines — The 12-hour reporting clock for critical cyber incidents is extremely tight. Most standard incident response plans are not designed for this timeline, and organisations that have not rehearsed it will struggle to comply.
- Siloed hazard management — The CIRMP must integrate cyber, physical, and supply chain risks. Treating these as separate programs creates gaps — for example, failing to consider the physical security implications of a supply chain cyber compromise.
- Ignoring the maturity uplift timeline — The mid-2027 and mid-2028 milestones are approaching rapidly. Organisations that have not begun gap assessments risk being unable to achieve the required maturity levels in time.
Australian Regulatory Context
The SOCI Act is administered by the Department of Home Affairs, with the Australian Cyber Security Centre (ACSC) — part of the Australian Signals Directorate (ASD) — providing technical guidance and receiving incident reports. The ACSC's Information Security Manual (ISM) and the Essential Eight Maturity Model are the primary technical frameworks referenced in the CIRMP Rules.
The Cyber Security Act 2024 operates alongside the SOCI Act, introducing mandatory ransomware payment reporting obligations for businesses with annual turnover above $3 million. Cyber consultants advising critical infrastructure entities must ensure their clients understand both regimes and how they interact.
For entities in the financial services sector, APRA's CPS 234 Information Security and CPS 230 Operational Risk Management standards impose additional, overlapping obligations. A cyber consultant with expertise in both the SOCI Act and APRA prudential standards is essential for regulated financial institutions that also qualify as critical infrastructure responsible entities.
The ASD publishes regular threat intelligence and guidance specifically for critical infrastructure sectors. Responsible entities should subscribe to the ACSC's Critical Infrastructure Uplift Program (CI-UP) and engage with sector-specific information sharing groups to stay current with emerging threats.
Practical Checklist: CIRMP Supply Chain Compliance
Businesses subject to the SOCI Act should work through the following checklist with their cyber consultant:
- Confirm asset registration — Verify that all critical infrastructure assets are correctly registered with the Department of Home Affairs.
- Complete supply chain dependency mapping — Identify all relevant operators and major suppliers with operational influence over registered assets.
- Conduct a CIRMP gap assessment — Benchmark current controls against the Enhanced CIRMP Rules and the Essential Eight Maturity Model to identify gaps.
- Update supplier contracts — Incorporate cybersecurity obligations, audit rights, and incident notification requirements into all major supplier agreements.
- Test incident reporting processes — Conduct tabletop exercises specifically testing the 12-hour and 72-hour reporting timelines.
- Develop a maturity uplift roadmap — Create a phased plan to achieve Essential Eight Maturity Level 2 by mid-2028, with interim milestones for mid-2027.
- Arrange independent assurance — Engage a qualified independent assessor to review CIRMP design and effectiveness.
- Obtain board approval — Ensure the CIRMP is formally approved by the board or senior management and that accountability is clearly assigned.
Questions to Ask a Cyber Consultant
When engaging a cyber consultant to assist with SOCI Act CIRMP compliance, ask the following questions to assess their suitability:
- Do you have direct experience with SOCI Act CIRMP assessments and the 2026 Enhanced Rules?
- Are you familiar with the ASD's Essential Eight Maturity Model and can you conduct a formal maturity assessment?
- Can you assist with supply chain dependency mapping and supplier security assessments?
- Do you have experience with the ACSC's incident reporting requirements and can you help us design a compliant incident response process?
- Can you provide or coordinate independent assurance of our CIRMP as required by the 2026 rules?
- Do you hold relevant certifications such as IRAP assessor accreditation, CISSP, or CISM?
How MyMoney® Can Help
Navigating the SOCI Act's Enhanced CIRMP Rules — particularly the supply chain cyber risk obligations — requires specialist expertise that goes well beyond general IT security. The right cyber consultant will have deep knowledge of Australian critical infrastructure regulation, the ASD's Essential Eight framework, and the practical experience to translate complex obligations into actionable programs.
MyMoney® connects Australian businesses with qualified, vetted cyber consultants who specialise in SOCI Act compliance, supply chain risk management, and critical infrastructure security. Whether you need a CIRMP gap assessment, a supply chain dependency mapping exercise, or end-to-end program implementation support, our marketplace makes it easy to find the right expert.
Post a Brief to describe your SOCI Act compliance needs and receive proposals from specialist cyber consultants. Or Browse Cyber Consultants to explore qualified professionals available to help your organisation meet its 2026 obligations.
This article provides general information only and does not constitute personal financial advice. Consider whether the information is appropriate for individual circumstances before acting on it. MyMoney® Marketplace is operated by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640).