What you actually have to comply with.
Most of what circulates about critical-infrastructure obligations in Australia is second-hand — repeated from an exposure draft, a vendor blog, or another summary. These pages work from the instruments themselves, quote them, and link them.
Two things worth correcting
Both of these are stated the other way round across a good deal of published commentary. Both matter, because both change what you have to do.
Board approval attaches to the report, not the program
Section 30AG(2)(f) of the SOCI Act requires the annual report on a CIRMP to be approved by the board, council or other governing body. Neither the Act nor the CIRMP Rules attaches an approval requirement to the program document itself. Many boards approve the program anyway, as a matter of governance — but that is a choice, not an obligation, and it is worth knowing which is which before you build a sign-off process around it.
Read the detailThe enhanced rules do not single out energy
Section 8A names five frameworks and requires one of them at a stated condition, with an equivalence route besides. An energy asset owner that elects the AESCSF route does move from Security Profile 1 to Security Profile 2 — but AESCSF is one option among five, equally available to non-energy entities, and an energy entity can satisfy the section another way.
Read the detailSources
Every statement on this page traces to one of these. Position as at August 2026. This is architecture advice, not legal advice — check your own asset class and obligations.
- Security of Critical Infrastructure Act 2018 (Cth) — current compilationOperative text
- Enhanced CIRMP Rules 2026 (F2026L00701)Operative text
- Cyber and Infrastructure Security CentreRegulator guidance
Obligations are an architecture problem before they are a paperwork problem.
A program is only as good as the drawings underneath it. If you are working out what your asset class actually requires, thirty minutes is usually enough to tell.
Or email info@radconsulting.au.