
An operator that runs ports, energy assets or a data centre footprint across Asia-Pacific and the Gulf now answers to a critical infrastructure cyber regime in almost every country it operates in. Those regimes look similar from a distance: designate important assets, require a risk programme, demand incident reporting, and give the state powers to step in. Up close they differ in who is covered, what the board must do, how often compliance is audited, and how large the penalties are. This comparison sets out the position in September 2026 for seven jurisdictions and ends with a practical approach for running one programme that satisfies all of them. For the reporting deadlines in detail, see our companion guide to [cyber incident reporting deadlines](/blog/cyber-incident-reporting-deadlines-apac-gulf-2026).
Three models of critical infrastructure regulation

- Statute-led. Australia's SOCI Act, Singapore's Cybersecurity Act and Malaysia's Cyber Security Act 2024 (Act 854) define covered entities, obligations, regulator powers and penalties in legislation.
- Controls-led. Saudi Arabia, the UAE and Qatar set mandatory control catalogues and standards through national cyber authorities, backed by enforcement regulations or policy, rather than a single critical infrastructure statute.
- In design. New Zealand consulted on a mandatory regime from February to April 2026. No bill has been introduced.
The model matters for evidence. Statute-led regimes test whether you met a legal duty; controls-led regimes test control by control. A single control library can serve both, but only if each control records which legal duty or catalogue reference it satisfies.
Scope and designation
| Jurisdiction | Instrument | Who is covered |
|---|---|---|
| Australia | Security of Critical Infrastructure Act 2018, as amended to 2024; Enhanced CIRMP Rules from 10 June 2026 | Assets in 11 sectors; the Minister can declare Systems of National Significance |
| New Zealand | Proposed regime (DPMC discussion document, February 2026) | About 200 entities in seven sectors, with a national significance tier |
| Singapore | Cybersecurity Act 2018, amendments in force 31 October 2025; CCoP 2026 | Designated CII in 11 sectors, now including virtual CII, foundational digital infrastructure and entities of special cybersecurity interest |
| Malaysia | Cyber Security Act 2024 (Act 854), in force 26 August 2024 | Designated NCII entities in 11 sectors, including NCII partly in Malaysia |
| Saudi Arabia | NCA ECC-2:2024 and CSCC-1:2019; NCA Regulations 2024; NCNICC-1:2025 | Government bodies and CNI operators; since NCNICC, many other private companies too |
| UAE | Critical Information Infrastructure Protection Policy; UAE Information Assurance Standard | Designated CII operators in 10 sectors |
| Qatar | National Information Assurance Standard v2.1 | Government entities and organisations in critical sectors |
Two recent changes widen scope sharply. Singapore can now regulate cloud and data centre providers as foundational digital infrastructure. Saudi Arabia's NCNICC, reported by CMS in March 2026, applies mandatory controls to private companies outside critical infrastructure: 65 controls for larger firms and 26 for smaller ones.
Risk programmes, audits and board duties
| Jurisdiction | Risk programme | Audit or assessment | Board duties |
|---|---|---|---|
| Australia | All-hazards CIRMP; Enhanced CIRMP Rules add phishing-resistant MFA, segregation and supplier assessments for nine asset classes | Annual CIRMP report approved by the board, due 90 days after financial year end | July 2026 proposals would add board approval of the CIRMP itself and independent assurance every three years |
| Singapore | CCoP 2026 controls, most applying from 29 July 2027 | CII audit at least every two years; Cyber Trust Mark Tier 5 by 31 December 2027 for existing owners | Documented cyber resilience framework reviewed annually; board training every 12 months; threat briefings every six months |
| Malaysia | Codes of practice set by sector leads | Risk assessment yearly; audit at least every two years | No specific board duties in the Act; accountability sits with the designated NCII entity |
| Saudi Arabia | ECC and CSCC control sets | Self-assessment, NCA compliance reporting and field audits; CSCC risk assessment yearly | Cybersecurity steering committee and head of cybersecurity required under ECC |
| UAE | Sector plans under the CIIP Policy; UAE IA Standard | Self-assessment escalating to audit and commissioned testing | Not set out in statute |
| Qatar | NIAS controls | NCSA compliance certification | Not set out in statute |
| New Zealand (proposed) | Risk management programme aligned to NIST CSF or ISO/IEC 27001 | Third-party audit unlikely in the medium term | Directors personally responsible |
The direction is clear everywhere: boards are being asked to approve, understand and be briefed on cyber risk, not merely receive a report. Singapore's CCoP 2026 is the most prescriptive, with fixed intervals for training, briefings and posture reporting, as Stephenson Harwood summarises.
Penalties and government step-in powers
| Jurisdiction | Maximum penalties | Step-in powers |
|---|---|---|
| Australia | Civil penalties in penalty units; the 2026 proposals would raise core CIRMP penalties from 200 to 500 units | Information and action directions; intervention requests to ASD with Prime Minister and Defence Minister agreement |
| Singapore | Higher of 10% of Singapore turnover or S$500,000 for CII owners | Inspection, directions, and CSA-supported threat detection on request |
| Malaysia | Up to RM500,000, 10 years' imprisonment, or both, for failing to notify an incident or implement a code of practice | Binding directions; police-equivalent investigation powers |
| Saudi Arabia | Fines up to SAR 25 million, licence suspension and publication of decisions under the 2024 Regulations | Inspections and a violations committee |
| UAE | Not specified in a CII statute | National security intervention in extreme cases under the CIIP Policy |
| Qatar | Not specified in a CII statute | Not specified |
| New Zealand (proposed) | Up to NZ$5 million or 2% of turnover for entities; NZ$500,000 for directors | Ministerial direction as a last resort |
Figures for New Zealand are proposals from the February 2026 consultation and may change. The Australian penalty increase is also proposed, not law.
Running one programme across seven regimes

- Build one asset and entity register. Record, for each asset, which regimes designate it and which legal entity is responsible.
- Adopt the strictest control as the baseline. Where Singapore requires MFA for privileged accounts and Australia requires phishing-resistant MFA, implement the stronger control once.
- Map controls to every reference. Each control should carry its SOCI, CCoP, Act 854 code, ECC or CSCC, UAE IA and NIAS references, so one test produces evidence for each.
- Align the calendars. Annual CIRMP reports, biennial Singapore and Malaysia audits, and NCA reporting cycles can be scheduled from one plan.
- Brief the board once, properly. A single board pack on cyber risk, with jurisdiction annexes, meets most of the new board duties.
For deeper guides to individual regimes, see the Enhanced CIRMP Rules, Malaysia's Act 854 obligations, NCA OTCC and CSCC for Saudi critical infrastructure, and the framework pages for Singapore's CCoP, UAE IA and Qatar NIAS.
How GRCLens supports multi-country operators
GRCLens holds SOCI and AESCSF, Singapore's CCoP, Malaysia's NACSA requirements, NCA ECC, CSCC and NCNICC, UAE IA and Qatar NIAS on one shared control model. An operator records its assets and entities once, tests each control once, and sees compliance for every regime that applies. Board reports draw from the same records, and the platform can run on-premises where a national authority expects data to stay in country.
Frequently asked questions
Which countries have a dedicated critical infrastructure cyber law?
Australia (SOCI Act), Singapore (Cybersecurity Act 2018, amended) and Malaysia (Cyber Security Act 2024). Saudi Arabia, the UAE and Qatar regulate mainly through mandatory controls and standards. New Zealand has proposed a regime but not legislated.
What is the maximum penalty under Singapore's amended Cybersecurity Act?
For CII owners, a civil penalty of up to the higher of 10% of annual turnover in Singapore or S$500,000.
Does Saudi Arabia's NCA regulate companies outside critical infrastructure?
Yes. NCNICC-1:2025 applies mandatory cybersecurity controls to private companies outside critical national infrastructure, with separate control sets for larger and smaller firms.
When does Singapore's CCoP 2026 apply?
It was issued on 29 July 2026, and most obligations apply from 29 July 2027.
How Security Solution Consultants can help
Security Solution Consultants helps critical infrastructure operators across Australia, New Zealand, Singapore, Malaysia and the Gulf build a single control baseline, prepare CIRMP and CCoP programmes, and brief boards on their new duties. See our enterprise risk management and CIRMP advisory, our cyber maturity assessment and uplift service, and our pages for Saudi Arabia and Malaysia. GRCLens then keeps the register, controls and evidence current across every regime. Request a demonstration.
Keep reading

Autonomous Fleets Meet Critical Infrastructure Law: SOCI, New Zealand and the Gulf
Once an autonomous fleet moves freight or carries the public at scale, its operator starts to look like a critical infrastructure operator. What the SOCI Act, New Zealand's proposed regime and the Gulf rules ask for, and how to evidence it.

Enhanced CIRMP Rules 2026: What to Do and When
The enhanced CIRMP Rules commenced on 10 June 2026. What nine high-risk asset classes must do, which frameworks now qualify, and the deadlines.

Saudi OTCC and CSCC: Which NCA Controls Apply?
OTCC-1:2022 covers critical OT and ICS. CSCC-1:2019 covers other critical systems. Scope, control counts, facility levels and the ECC link.