Country guide · Australia

Cyber security compliance in Australia

Australia's obligations come from several directions at once: the Protective Security Policy Framework for Commonwealth entities, the SOCI Act for critical infrastructure, APRA's prudential standards for financial services, the Privacy Act for almost everyone, and a separate policy in each state. Several of them changed in 2025 and 2026, and a lot of what ranks online has not caught up. This page sets out what applies to whom, and the reporting clocks that go with it.

At a glance
  • Frameworks listed13
  • Issuing bodies11
  • Framework pages5
  • Platform languagesEnglish and Arabic
  • DeploymentSaaS, private cloud or on-premises
AustraliaChecked Sep 2026
What applies

Cybersecurity and data protection frameworks in Australia

Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.

Department of Home Affairs

Protective Security Policy Framework (PSPF), Release 2026

Non-corporate Commonwealth entities must apply it. Better practice for corporate Commonwealth entities. State and territory agencies apply it to Australian Government classified information

Open the framework page →
Australian Signals Directorate (ASD)

Information Security Manual (ISM) and IRAP

Commonwealth entities through the PSPF. Cloud providers to Commonwealth entities need an IRAP assessment against the latest ISM within the previous 24 months

Open the framework page →
Australian Signals Directorate (ASD)

Essential Eight

Maturity Level Two for Commonwealth entities under the PSPF and for all Defence Industry Security Program members. One of the framework options under SOCI CIRMP

Cyber and Infrastructure Security Centre (CISC)

SOCI Act: critical infrastructure risk management program (CIRMP)

Responsible entities for 13 asset classes. Enhanced rules for 9 classes since 10 June 2026, with obligations from June 2027 and June 2028

Open the framework page →
ASD and CISC

SOCI Act: mandatory cyber incident reporting

Responsible entities for critical infrastructure assets: 12 hours for a significant impact, 72 hours for a relevant impact

Department of Home Affairs and ASD

Cyber Security Act 2024: ransomware payment reporting

Businesses with turnover above $3 million, and SOCI responsible entities, that make a ransomware payment: report within 72 hours

APRA

CPS 234 Information Security

All APRA-regulated entities. Material incidents within 72 hours, material control weaknesses within 10 business days

APRA

CPS 230 Operational Risk Management

Banks and other ADIs, insurers, private health insurers and RSE licensees. In force since 1 July 2025, amended from 1 July 2026

Office of the Australian Information Commissioner (OAIC)

Privacy Act 1988 and the Notifiable Data Breaches scheme

APP entities, including every health service provider. Automated decision-making disclosure required from 10 December 2026

Read the guide →
AEMO

Australian Energy Sector Cyber Security Framework (AESCSF) V2

Energy sector participants. Recognised for SOCI risk management programs

Open the framework page →
Office of the Victorian Information Commissioner

Victorian Protective Data Security Standards (VPDSS) V2.0

Victorian public sector bodies under Parts 4 and 5 of the Privacy and Data Protection Act 2014

Open the framework page →
Digital NSW

NSW Cyber Security Policy 2026-2027

NSW departments, public service agencies and statutory authorities. Includes Essential Eight Maturity Level One

Queensland Government

Queensland Information and Cyber Security Policy (IS18) v10

Queensland government agencies. ISO 27001-based ISMS, Essential Eight with agency-set targets, annual return by 30 September

Which cybersecurity frameworks apply in Australia?

It depends on who you are. Commonwealth entities work to the PSPF, which brings in the ISM and the Essential Eight. Critical infrastructure operators work to the SOCI Act and its CIRMP rules. APRA-regulated entities work to CPS 234 and CPS 230. Almost every organisation with turnover above $3 million, and every health service provider, is covered by the Privacy Act. State agencies follow their own state's policy, and suppliers inherit parts of all of these through contracts.

The current PSPF is Release 2026, issued on 1 July 2026. It replaced the old 16 policies with numbered requirements in 2024, so guides still describing 16 PSPF policies are out of date.

Is the Essential Eight mandatory?

Not for every business. It is mandated at Maturity Level Two for Commonwealth entities under the PSPF and for all Defence Industry Security Program members, and it is one of the framework options for SOCI critical infrastructure. NSW and Western Australian agencies work to Maturity Level One, and Queensland agencies set their own targets.

The current maturity model is the November 2023 edition. ASD consulted in June and July 2026 on a successor series, which it calls Essentials for enterprise IT. As of late September 2026 no replacement had been published and the Essential Eight remains current.

What changed for critical infrastructure in 2026?

The enhanced CIRMP rules commenced on 10 June 2026 for nine asset classes: broadcasting, domain name systems, electricity, energy market operators, freight infrastructure, freight services, gas, liquid fuel and water. They add foreign ownership and remote access risk, phishing-resistant MFA, network segregation, background checks for critical workers and supply chain mapping. They also raise the framework bar, for example to Essential Eight Maturity Level Two or AESCSF Security Profile 2.

The first obligations apply from 10 June 2027 and the rest from 10 June 2028. In September 2026 the Cyber and Infrastructure Security Centre also announced a tougher compliance posture, including non-compliance and infringement notices.

What has to be reported, and how fast?

Critical infrastructure cyber incidents go to ASD within 12 hours for a significant impact and 72 hours for a relevant impact. APRA-regulated entities notify material information security incidents within 72 hours under CPS 234, and operational risk incidents within 72 hours under CPS 230. Ransomware payments are reported within 72 hours under the Cyber Security Act 2024.

Personal data breaches work differently. Under the Notifiable Data Breaches scheme you have up to 30 days to assess a suspected breach, then notify as soon as practicable. It is not a 72-hour rule, although it is often described as one.

What do APRA-regulated entities need?

Both CPS 234 and CPS 230. CPS 234 on information security remains in force. CPS 230 replaced the outsourcing and business continuity standards, CPS 231 and CPS 232 and their equivalents, and it expressly requires CPS 234 compliance, so claims that CPS 230 replaced CPS 234 are wrong. APRA's amendments to CPS 230 took effect on 1 July 2026.

What is changing in privacy law?

The Privacy and Other Legislation Amendment Act 2024 is arriving in stages. The statutory tort for serious invasions of privacy commenced on 10 June 2025. From 10 December 2026, privacy policies must describe automated decision-making that significantly affects individuals. A Children's Online Privacy Code must be registered by the same date.

Penalties for serious or repeated interferences reach the greater of $50 million, three times the benefit obtained or 30 percent of adjusted turnover for companies.

How GRCLens runs Australian frameworks together

The PSPF, ISM, Essential Eight, SOCI CIRMP, AESCSF, CPS 234 and CPS 230 share one control model in GRCLens with ISO/IEC 27001 and NIST CSF, so an energy business with SOCI obligations, a bank with CPS 234 and CPS 230 duties, or a Commonwealth supplier holding IRAP evidence captures each control once. Reporting clocks are tracked as their own indicators. GRCLens can be hosted in Australia or run fully on-premises.

Official portals and publications

Questions

Cyber compliance in Australia: common questions

Is the Essential Eight mandatory for private businesses in Australia?

No. It is mandated at Maturity Level Two for Commonwealth entities and Defence Industry Security Program members, and is one option for SOCI critical infrastructure. Other businesses adopt it voluntarily or through contracts.

Has APRA CPS 230 replaced CPS 234?

No. CPS 230 replaced the outsourcing and business continuity standards and expressly requires CPS 234 compliance. CPS 234 remains in force.

What is the current PSPF release?

PSPF Release 2026, issued on 1 July 2026. It is mandatory for non-corporate Commonwealth entities.

Does IRAP certify or accredit systems?

No. IRAP assessors assess systems and cloud services. ASD states that they do not accredit, certify, endorse or register them.

How fast must a critical infrastructure cyber incident be reported in Australia?

Within 12 hours for a significant impact and 72 hours for a relevant impact, under the SOCI Act.

Sources

Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run Australia's frameworks on one platform

See GRCLens with your own frameworks loaded.