HomeBlogCritical Infrastructure
Critical Infrastructure

Critical Infrastructure Cyber Laws Compared: Australia, New Zealand, Singapore, Malaysia, Saudi Arabia, the UAE and Qatar

Sep 2026 · 12 min read

Aerial miniature of a coastline with a wind farm, solar field, water treatment plant, container port and data centre linked by glowing cables

An operator that runs ports, energy assets or a data centre footprint across Asia-Pacific and the Gulf now answers to a critical infrastructure cyber regime in almost every country it operates in. Those regimes look similar from a distance: designate important assets, require a risk programme, demand incident reporting, and give the state powers to step in. Up close they differ in who is covered, what the board must do, how often compliance is audited, and how large the penalties are. This comparison sets out the position in September 2026 for seven jurisdictions and ends with a practical approach for running one programme that satisfies all of them. For the reporting deadlines in detail, see our companion guide to [cyber incident reporting deadlines](/blog/cyber-incident-reporting-deadlines-apac-gulf-2026).

Three models of critical infrastructure regulation

Isometric illustration of three distinct platforms, one with a legal statute scroll, one with a control catalogue, one with a blueprint under construction, each supporting critical infrastructure assets
Statute, mandatory controls, or a regime still in design: the three models across the region.
  • Statute-led. Australia's SOCI Act, Singapore's Cybersecurity Act and Malaysia's Cyber Security Act 2024 (Act 854) define covered entities, obligations, regulator powers and penalties in legislation.
  • Controls-led. Saudi Arabia, the UAE and Qatar set mandatory control catalogues and standards through national cyber authorities, backed by enforcement regulations or policy, rather than a single critical infrastructure statute.
  • In design. New Zealand consulted on a mandatory regime from February to April 2026. No bill has been introduced.

The model matters for evidence. Statute-led regimes test whether you met a legal duty; controls-led regimes test control by control. A single control library can serve both, but only if each control records which legal duty or catalogue reference it satisfies.

Scope and designation

JurisdictionInstrumentWho is covered
AustraliaSecurity of Critical Infrastructure Act 2018, as amended to 2024; Enhanced CIRMP Rules from 10 June 2026Assets in 11 sectors; the Minister can declare Systems of National Significance
New ZealandProposed regime (DPMC discussion document, February 2026)About 200 entities in seven sectors, with a national significance tier
SingaporeCybersecurity Act 2018, amendments in force 31 October 2025; CCoP 2026Designated CII in 11 sectors, now including virtual CII, foundational digital infrastructure and entities of special cybersecurity interest
MalaysiaCyber Security Act 2024 (Act 854), in force 26 August 2024Designated NCII entities in 11 sectors, including NCII partly in Malaysia
Saudi ArabiaNCA ECC-2:2024 and CSCC-1:2019; NCA Regulations 2024; NCNICC-1:2025Government bodies and CNI operators; since NCNICC, many other private companies too
UAECritical Information Infrastructure Protection Policy; UAE Information Assurance StandardDesignated CII operators in 10 sectors
QatarNational Information Assurance Standard v2.1Government entities and organisations in critical sectors

Two recent changes widen scope sharply. Singapore can now regulate cloud and data centre providers as foundational digital infrastructure. Saudi Arabia's NCNICC, reported by CMS in March 2026, applies mandatory controls to private companies outside critical infrastructure: 65 controls for larger firms and 26 for smaller ones.

Risk programmes, audits and board duties

JurisdictionRisk programmeAudit or assessmentBoard duties
AustraliaAll-hazards CIRMP; Enhanced CIRMP Rules add phishing-resistant MFA, segregation and supplier assessments for nine asset classesAnnual CIRMP report approved by the board, due 90 days after financial year endJuly 2026 proposals would add board approval of the CIRMP itself and independent assurance every three years
SingaporeCCoP 2026 controls, most applying from 29 July 2027CII audit at least every two years; Cyber Trust Mark Tier 5 by 31 December 2027 for existing ownersDocumented cyber resilience framework reviewed annually; board training every 12 months; threat briefings every six months
MalaysiaCodes of practice set by sector leadsRisk assessment yearly; audit at least every two yearsNo specific board duties in the Act; accountability sits with the designated NCII entity
Saudi ArabiaECC and CSCC control setsSelf-assessment, NCA compliance reporting and field audits; CSCC risk assessment yearlyCybersecurity steering committee and head of cybersecurity required under ECC
UAESector plans under the CIIP Policy; UAE IA StandardSelf-assessment escalating to audit and commissioned testingNot set out in statute
QatarNIAS controlsNCSA compliance certificationNot set out in statute
New Zealand (proposed)Risk management programme aligned to NIST CSF or ISO/IEC 27001Third-party audit unlikely in the medium termDirectors personally responsible

The direction is clear everywhere: boards are being asked to approve, understand and be briefed on cyber risk, not merely receive a report. Singapore's CCoP 2026 is the most prescriptive, with fixed intervals for training, briefings and posture reporting, as Stephenson Harwood summarises.

Penalties and government step-in powers

JurisdictionMaximum penaltiesStep-in powers
AustraliaCivil penalties in penalty units; the 2026 proposals would raise core CIRMP penalties from 200 to 500 unitsInformation and action directions; intervention requests to ASD with Prime Minister and Defence Minister agreement
SingaporeHigher of 10% of Singapore turnover or S$500,000 for CII ownersInspection, directions, and CSA-supported threat detection on request
MalaysiaUp to RM500,000, 10 years' imprisonment, or both, for failing to notify an incident or implement a code of practiceBinding directions; police-equivalent investigation powers
Saudi ArabiaFines up to SAR 25 million, licence suspension and publication of decisions under the 2024 RegulationsInspections and a violations committee
UAENot specified in a CII statuteNational security intervention in extreme cases under the CIIP Policy
QatarNot specified in a CII statuteNot specified
New Zealand (proposed)Up to NZ$5 million or 2% of turnover for entities; NZ$500,000 for directorsMinisterial direction as a last resort

Figures for New Zealand are proposals from the February 2026 consultation and may change. The Australian penalty increase is also proposed, not law.

Running one programme across seven regimes

Isometric illustration of a single control library tower feeding colour-coded lines to energy, water, port and data centre assets across several countries
One control library, mapped to each regime's references, serves every jurisdiction.
  1. Build one asset and entity register. Record, for each asset, which regimes designate it and which legal entity is responsible.
  2. Adopt the strictest control as the baseline. Where Singapore requires MFA for privileged accounts and Australia requires phishing-resistant MFA, implement the stronger control once.
  3. Map controls to every reference. Each control should carry its SOCI, CCoP, Act 854 code, ECC or CSCC, UAE IA and NIAS references, so one test produces evidence for each.
  4. Align the calendars. Annual CIRMP reports, biennial Singapore and Malaysia audits, and NCA reporting cycles can be scheduled from one plan.
  5. Brief the board once, properly. A single board pack on cyber risk, with jurisdiction annexes, meets most of the new board duties.

For deeper guides to individual regimes, see the Enhanced CIRMP Rules, Malaysia's Act 854 obligations, NCA OTCC and CSCC for Saudi critical infrastructure, and the framework pages for Singapore's CCoP, UAE IA and Qatar NIAS.

How GRCLens supports multi-country operators

GRCLens holds SOCI and AESCSF, Singapore's CCoP, Malaysia's NACSA requirements, NCA ECC, CSCC and NCNICC, UAE IA and Qatar NIAS on one shared control model. An operator records its assets and entities once, tests each control once, and sees compliance for every regime that applies. Board reports draw from the same records, and the platform can run on-premises where a national authority expects data to stay in country.

Frequently asked questions

Which countries have a dedicated critical infrastructure cyber law?

Australia (SOCI Act), Singapore (Cybersecurity Act 2018, amended) and Malaysia (Cyber Security Act 2024). Saudi Arabia, the UAE and Qatar regulate mainly through mandatory controls and standards. New Zealand has proposed a regime but not legislated.

What is the maximum penalty under Singapore's amended Cybersecurity Act?

For CII owners, a civil penalty of up to the higher of 10% of annual turnover in Singapore or S$500,000.

Does Saudi Arabia's NCA regulate companies outside critical infrastructure?

Yes. NCNICC-1:2025 applies mandatory cybersecurity controls to private companies outside critical national infrastructure, with separate control sets for larger and smaller firms.

When does Singapore's CCoP 2026 apply?

It was issued on 29 July 2026, and most obligations apply from 29 July 2027.

How Security Solution Consultants can help

Security Solution Consultants helps critical infrastructure operators across Australia, New Zealand, Singapore, Malaysia and the Gulf build a single control baseline, prepare CIRMP and CCoP programmes, and brief boards on their new duties. See our enterprise risk management and CIRMP advisory, our cyber maturity assessment and uplift service, and our pages for Saudi Arabia and Malaysia. GRCLens then keeps the register, controls and evidence current across every regime. Request a demonstration.

This article is general information, not legal advice. Regulations change, so confirm current requirements with the relevant regulator before relying on them. Questions?info@grclens.net.

← All articles