HomeBlogCritical Infrastructure
Critical Infrastructure

Enhanced CIRMP Rules 2026: What to Do and When

Sep 2026 · 10 min read

Isometric illustration of an electricity substation, water treatment plant, gas pipeline, port and data centre linked to one protected control hub

On 10 June 2026 the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 commenced. They raise the bar for nine of the thirteen asset classes that already run a critical infrastructure risk management program under the SOCI Act. Much of what has been written about them since is slightly wrong in ways that matter: which assets are covered, which cyber frameworks still qualify, and when the new obligations actually bite. This guide is built from the rule text itself.

What is a critical infrastructure risk management program?

Section 30AC of the Security of Critical Infrastructure Act 2018 requires a responsible entity for a covered asset to adopt and maintain a critical infrastructure risk management program, usually shortened to CIRMP. Section 30AE requires it to be reviewed on a regular basis.

The program is a written, all-hazards document. It must identify and manage material risks across four hazard vectors: cyber and information security, personnel, supply chain, and physical and natural hazards. The detail of what the program must contain sits in the Critical Infrastructure Risk Management Program Rules (LIN 23/006), not in the Act.

Which asset classes must have a CIRMP?

Rule 4 of the CIRMP Rules lists thirteen asset classes: broadcasting, domain name systems, data storage or processing, electricity, energy market operators, gas, designated hospitals, food and grocery, freight infrastructure, freight services, liquid fuel, certain financial market infrastructure, and water.

Telecommunications is handled separately under its own risk management program rules, which commenced on 4 April 2025. Assets declared under section 51 of the Act as subject to Part 2A are also covered.

What changed with the enhanced CIRMP Rules 2026?

The amending instrument (Federal Register of Legislation F2026L00701) inserted a new rule 4A and a set of enhanced requirements: additional material risks (6A), cyber (8A), credential compromise (8B), lateral movement (8C), personnel including AusCheck (9A), supply chain mapping and foreign ownership, control or influence assessment (10A), and physical security (11A).

Where a baseline requirement and an enhanced requirement conflict, the enhanced requirement prevails.

One citation point worth getting right: F2026L00701 was an amending instrument. Its changes have been merged into the principal rules, and the Register now shows it as no longer in force. The law you comply with is the compiled CIRMP Rules, F2023L00112, compilation dated 10 June 2026. Several published guides still cite the amending instrument as if it were the operative law.

Which assets are subject to the enhanced requirements?

Only nine of the thirteen classes: broadcasting, domain name systems, electricity, energy market operators, freight infrastructure, freight services, gas, liquid fuel and water.

Data storage or processing, designated hospitals, food and grocery, and financial market infrastructure keep the baseline requirements only. If you operate one of those four, the enhanced rules do not apply to you, whatever a vendor checklist may suggest.

Assets declared under section 51 before commencement do not automatically pick up the enhanced requirements.

When do the enhanced obligations start to apply?

There are two grace periods, both running from commencement on 10 June 2026 rather than from a financial year end.

Twelve months, to around 10 June 2027: the additional material risks in 6A, rule 8A(2), and rule 9A(2).

Twenty-four months, to around 10 June 2028: the rest of 8A, all of 8B and 8C, the rest of 9A, 10A and 11A. This is the one that includes the framework uplift, phishing-resistant MFA, the critical systems inventory and segregation.

Assets that become critical infrastructure assets after commencement get the same twelve and twenty-four month periods from the day they become covered. The rules describe the end point as the last day of the relevant period, so confirm the exact final date with counsel before building a plan around it.

Which cyber frameworks meet the CIRMP cyber requirement?

This is where most published summaries go wrong, so it is worth setting out both tables.

Baseline, rule 8(4), all thirteen classes: AS ISO/IEC 27001:2015; the Essential Eight at Maturity Level One; the NIST Framework for Improving Critical Infrastructure Cybersecurity; C2M2 at MIL1; or the 2020-21 AESCSF Framework Core at Security Profile 1. An equivalent framework is also acceptable.

Enhanced, rule 8A(3), the nine classes: AS ISO/IEC 27001:2023; the Essential Eight at Maturity Level Two; NIST CSF 2.0; C2M2 version 2.1 at MIL2; or the 2023 AESCSF Framework Core at Security Profile 2.

Two details matter. First, ISO/IEC 27001:2023 and NIST CSF 2.0 carry no maturity condition at all. It is not correct to say the enhanced rules require maturity level two under any framework. Second, under rule 8A(4) the equivalent-framework route is only available for equivalents of the Essential Eight, C2M2 or AESCSF. You cannot justify an alternative as equivalent to ISO 27001 or NIST CSF.

What do phishing-resistant MFA and segregation require?

Rule 8B applies only where your chosen framework does not already require phishing-resistant multi-factor authentication. Where it applies, you must implement it for internet-connected computers, critical systems, privileged and unprivileged access to critical components, and remote access, and you must centrally log and review both successful and failed attempts.

Rule 8C deals with lateral movement. Critical systems must be capable of being segregated, of operating independently, and of continuing to operate for at least three months while other systems are restored. It also requires logical access controls, central logging of communication paths, least privilege, and recovery processes that keep critical systems available while they are rebuilt.

What must be in the critical systems inventory?

Rule 8C(2)(a) requires an inventory of critical systems and of how they connect to other critical systems and other computers. It is not an inventory of asset classes, which is how it has been described in some commentary.

Critical system is defined to include operational technology and enabling systems that form critical components. Separately, rule 11A requires you to set out site locations, ownership, the critical components, and the areas that hold business-critical data or critical systems.

In practice this means a connected inventory rather than a spreadsheet of hosts: each critical system, what it talks to, and why. That is the same artefact that makes the segregation and recovery requirements in 8C testable.

What personnel and supply chain checks are now mandatory?

Rule 9A allows critical workers to access critical components only after an AusCheck background check and a suitability assessment, or where they hold an NV1 or higher clearance. AusCheck checks must be repeated at least every five years for ongoing access.

Rule 10A requires you to map major suppliers against critical components, identify a maximum acceptable outage, and assess each major supplier for foreign ownership, control or influence, sanctions exposure and the access it holds.

When is the CIRMP annual report due, and who approves it?

Section 30AG requires the annual report within 90 days after the end of the financial year. For a 30 June year end that is 28 September, so the 2025-26 report is due on 28 September 2026.

The report must be in the approved form and approved by the board, council or other governing body. It states whether the program was up to date, any hazard that had a significant relevant impact and how effective the program was in mitigating it, any variations made, and any direction received under section 30AI.

You do not have to submit the program itself. The report is also not admissible against the entity in civil penalty proceedings, which is a reason to be candid in it rather than defensive.

What are the penalties for getting CIRMP wrong?

Failing to adopt and maintain a program (s30AC) and failing to review it (s30AE) each carry a civil penalty of 200 penalty units. Failing to give the annual report (s30AG) carries 150 penalty units.

From 1 July 2026 a Commonwealth penalty unit is $364, which puts 200 units at $72,800 and 150 units at $54,600. Some vendor pages still quote older dollar figures calculated from earlier unit values, so do not reuse those. How the amounts apply to a body corporate should be confirmed with counsel.

What should a responsible entity do before June 2027?

Start with the twelve-month items. Document how the program addresses foreign ownership, control or influence and offshore or remote access risk. Address patching, legacy technology and emerging technology risk explicitly. Put access management in place for critical components, including how critical workers come in and leave.

Then plan the twenty-four month items as a program of work rather than a scramble in 2028. The framework uplift to Essential Eight Maturity Level Two or AESCSF Security Profile 2 is typically the longest pole. Choosing ISO/IEC 27001:2023 or NIST CSF 2.0 changes the shape of that work, because neither carries a maturity condition, so make that framework decision early and record why.

Finally, build the critical systems inventory now. It feeds 8C, 11A and your supply chain mapping, and every one of those is harder without it.

How GRCLens supports CIRMP

GRCLens implements SOCI CIRMP and AESCSF alongside ISO/IEC 27001, the Essential Eight and NIST CSF on one shared control model, so evidence collected for one framework is reused for the others. Board attestation, the annual report and the variation log sit in the same place as the controls that support them. It can run as SaaS or fully inside your own infrastructure, which matters for operators whose program itself is sensitive.

Primary sources

Critical Infrastructure Risk Management Program Rules (LIN 23/006), F2023L00112, compilation dated 10 June 2026. Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026, F2026L00701. Security of Critical Infrastructure Act 2018, sections 30AC, 30AE and 30AG. Cyber and Infrastructure Security Centre, CIRMP factsheet and annual report form. Crimes (Amount of Penalty Unit) Instrument, F2026N00424.

This article is general information, not legal advice. Confirm dates and obligations for your specific assets with counsel.

This article is general information, not legal advice. Regulations change, so confirm current requirements with the relevant regulator before relying on them. Questions?info@grclens.net.

← All articles