Skip to main content

MyMoney® is reviewing its service model in light of evolving ASIC regulatory guidance. Some features are temporarily unavailable.

AFSL 222640 · Global Mutual Funds Pty Ltd
Cyber Consultant
SOCI Act
CIRMP rules 2026
critical infrastructure

SOCI Act Enhanced CIRMP Rules 2026: A Cyber Consultant Guide for Australian Critical Infrastructure Operators

SOCI Act Enhanced CIRMP Rules commenced June 2026, imposing strict new cyber obligations on 9 critical infrastructure asset classes. Here is what to do.

MyMoney® Editorial16 August 2026 8 min read

On 10 June 2026, the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 — known as the Enhanced CIRMP Rules — commenced in Australia. This landmark regulatory shift transforms the SOCI Act compliance framework from a principles-based approach into a prescriptive, evidence-based model with specific technical mandates, board accountability requirements, and staggered implementation deadlines extending to 2028. For the nine affected critical infrastructure asset classes, the compliance challenge is substantial — and the role of an experienced cyber consultant has never been more important.

What Are the Enhanced CIRMP Rules?

The Critical Infrastructure Risk Management Program (CIRMP) has been a core obligation under the Security of Critical Infrastructure Act 2018 (SOCI Act) since 2023. Under the original framework, responsible entities were required to develop and maintain a risk management program addressing four hazard domains: cyber and information security, personnel security, supply chain security, and physical and natural hazards.

The Enhanced CIRMP Rules, which commenced on 10 June 2026, significantly raise the bar. Rather than allowing entities to define their own controls within broad principles, the new rules mandate specific, measurable security controls aligned to recognised cybersecurity frameworks, with defined maturity levels that must be achieved by set deadlines.

Which Asset Classes Are Affected?

The Enhanced CIRMP Rules apply to responsible entities operating nine specific critical infrastructure asset classes:

  • Critical broadcasting assets
  • Critical domain name systems
  • Critical electricity assets
  • Critical energy market operator assets
  • Critical freight infrastructure and services assets
  • Critical gas assets
  • Critical liquid fuel assets
  • Critical water assets
  • Critical data storage or processing assets (in certain configurations)

Entities operating these asset classes must now comply with the enhanced requirements in addition to their existing CIRMP obligations. The Cyber and Infrastructure Security Centre (CISC) within the Department of Home Affairs is the primary regulator responsible for administering the SOCI Act and the Enhanced CIRMP Rules.

Key Cyber Security Requirements Under the Enhanced Rules

The cyber and information security domain has received the most significant uplift under the Enhanced CIRMP Rules. The new requirements move well beyond general risk management principles to mandate specific technical controls.

Framework Alignment and Maturity Levels

Entities must align their cyber security program with one of five recognised frameworks:

  • The ASD Essential Eight — the Australian Signals Directorate's baseline mitigation strategies
  • ISO/IEC 27001 — the international information security management standard
  • The NIST Cybersecurity Framework (CSF)
  • The Cybersecurity Capability Maturity Model (C2M2)
  • The Australian Energy Sector Cyber Security Framework (AESCSF) — mandatory for energy sector entities

High-risk assets must achieve Maturity Level 2 (or equivalent) within their chosen framework by June 2028. This is a significant uplift for many operators currently operating at lower maturity levels.

Specific Technical Mandates

Beyond framework alignment, the Enhanced CIRMP Rules introduce specific technical requirements that entities must implement:

  • Phishing-resistant multi-factor authentication (MFA) — Required for access to critical systems, with standard SMS-based MFA no longer sufficient for high-risk access scenarios
  • Centralised logging and monitoring — Entities must implement centralised security event logging with sufficient retention to support incident investigation and regulatory reporting
  • Network segregation — Critical systems must be architecturally segregated so they can maintain independent operations for at least three months during a cyber incident affecting other parts of the network
  • Legacy technology management — Entities must identify, document, and actively manage risks from unpatched or end-of-life systems
  • AI-enabled threat management — The rules explicitly require entities to address risks from emerging technologies, including AI-enabled attacks

Personnel Security and Supply Chain Obligations

The Enhanced CIRMP Rules extend compliance obligations well beyond the IT department. Personnel security and supply chain resilience are now subject to specific, enforceable requirements.

Personnel Security

Critical workers — those with access to critical components of the infrastructure — must now undergo formal background checking. Depending on the sensitivity of the role and the asset class, this may include:

  • AusCheck background checks — Administered by the Attorney-General's Department, covering criminal history, security, and integrity assessments
  • Negative Vetting 1 (NV1) security clearances — Required for workers with access to the most sensitive components
  • Ongoing monitoring and reassessment — Suitability must be reassessed at least every five years for workers with access to critical components

Supply Chain Resilience

The supply chain provisions represent one of the most operationally complex aspects of the Enhanced CIRMP Rules. Entities must:

  • Map their supply chains for major suppliers and critical components, identifying dependencies and single points of failure
  • Assess Foreign Ownership, Control, or Influence (FOCI) risks — Vendor assessments must explicitly evaluate whether suppliers are subject to foreign government influence that could compromise the security of the infrastructure
  • Monitor remote access — Entities must identify and control all instances of offshore or remote access to business-critical data or control systems
  • Apply jurisdictional sanctions screening — Suppliers must be assessed against applicable sanctions regimes

These supply chain obligations effectively extend the compliance burden to third-party vendors and service providers. Entities should expect their major suppliers to face increased scrutiny and due diligence requirements as a result.

Board Accountability and Annual Reporting

The Enhanced CIRMP Rules introduce explicit board-level accountability for CIRMP compliance. The risk management program must be board-approved, and the board must receive regular reporting on the program's effectiveness.

An annual report on the CIRMP must be submitted to the CISC within 90 days of the end of each financial year. This report must demonstrate that the entity has assessed its risks across all four hazard domains, implemented the required controls, and identified any gaps or areas for improvement.

The shift to board-level accountability means that cyber security is no longer solely an IT or operational matter — it is a governance obligation that directors must actively oversee. Boards that lack the technical expertise to assess CIRMP compliance should consider engaging independent cyber consultants to provide assurance on the program's effectiveness.

Implementation Timelines: What Must Be Done and When

The Enhanced CIRMP Rules provide staggered implementation deadlines to allow entities time to reach full compliance. Understanding these timelines is essential for planning your compliance program.

  • 10 June 2026 (Commencement) — The Enhanced CIRMP Rules take effect. Existing CIRMP obligations remain in force. Entities should begin gap assessments immediately
  • 10 June 2027 — Deadline for compliance with the "New Material Risks" category, including FOCI assessments, offshore access controls, core cyber security risk management, and initial personnel security measures
  • 10 June 2028 — Deadline for all remaining enhanced requirements, including phishing-resistant MFA, network segregation for three-month independent operations, advanced personnel vetting, full supply chain mapping, and achievement of Maturity Level 2 in the chosen cybersecurity framework

While the 2027 and 2028 deadlines may appear distant, the operational complexity of achieving compliance — particularly for network segregation and supply chain mapping — means that entities should begin implementation planning immediately.

How a Cyber Consultant Can Help

The transition from a principles-based CIRMP to the Enhanced CIRMP Rules requires a structured, expert-led compliance program. A qualified cyber consultant can provide critical support across every phase of the compliance journey.

  • Gap analysis — Assessing your current security controls against the specific requirements of the Enhanced CIRMP Rules to identify compliance gaps and prioritise remediation
  • Framework selection and alignment — Advising on the most appropriate cybersecurity framework for your asset class and helping you achieve the required maturity level
  • Network architecture design — Designing network segregation solutions that meet the three-month independent operations requirement without disrupting operational continuity
  • Supply chain due diligence — Developing vendor assessment processes that address FOCI risks, remote access controls, and sanctions screening requirements
  • Board reporting and governance — Preparing board-ready CIRMP reports and establishing governance frameworks that meet the board accountability requirements
  • Annual CISC reporting — Preparing and submitting the annual CIRMP report to the CISC within the required 90-day timeframe

How MyMoney® Can Help

The Enhanced CIRMP Rules represent one of the most significant expansions of cyber security obligations in Australian regulatory history. For critical infrastructure operators, the stakes of non-compliance are high — CISC has broad enforcement powers under the SOCI Act, including the ability to issue directions, conduct inspections, and refer matters for civil penalty proceedings.

At MyMoney®, we connect Australian critical infrastructure operators and their advisers with experienced cyber consultants who understand the SOCI Act framework, the Enhanced CIRMP Rules, and the practical challenges of achieving compliance in complex operational environments. Whether you need a gap assessment, a full CIRMP implementation program, or ongoing compliance support, our marketplace helps you find the right expert.

Post a Brief to receive tailored proposals from cyber consultants with SOCI Act and critical infrastructure experience. Or Browse Cyber Consultants on the MyMoney® Marketplace to explore qualified professionals and compare their expertise in critical infrastructure security and regulatory compliance.

This article provides general information only and does not constitute personal financial advice. Consider whether the information is appropriate for individual circumstances before acting on it. MyMoney® Marketplace is operated by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640).

Need Professional Help?

Post a brief and let verified professionals compete with transparent, scored proposals.