Regulation

The enhanced CIRMP rules.

In force since 10 June 2026 for nine asset classes. What the instrument requires, when each part bites, and which widely repeated claims about it are not in the text.

Who is in scope

The enhanced requirements apply to nine specified critical infrastructure asset classes, listed at section 4A(1). The Explanatory Statement describes these as the classes identified as higher risk.

  • Critical broadcasting assets
  • Critical domain name systems
  • Critical electricity assets
  • Critical energy market operator assets
  • Critical freight infrastructure assets
  • Critical freight services assets
  • Critical gas assets
  • Critical liquid fuel assets
  • Critical water assets

Whether a particular business is captured still turns on the asset meeting the definitions and thresholds in the SOCI Act and the Definitions Rules — and there are special rules for assets privately declared under section 51. Check your asset class before assuming you are in or out.

What the enhanced requirements cover

They are set out across seven sections rather than as a single list.

  1. s 6AAdditional material risks, including foreign ownership, control or influence, and offshore or remote access.
  2. s 8ACyber and information security: timely patching, legacy and unsupported technology, advanced and emerging technology, and compliance with a named framework at a stepped-up maturity level.
  3. s 8BCredential compromise.
  4. s 8CLateral movement and network segregation.
  5. s 9APersonnel security, including background checking arrangements.
  6. s 10ASupply chain requirements.
  7. s 11APhysical security requirements.

The five frameworks

Section 8A(3) requires a responsible entity for any of the nine classes to comply with one of five named frameworks and meet its stated condition.

  • AS ISO/IEC 27001:2023as named
  • ASD Essential Eight Maturity Modelat maturity level two
  • NIST Cybersecurity Framework 2.0as named
  • C2M2 v2.1at Maturity Indicator Level 2
  • AESCSF Framework Core 2023at Security Profile 2

Section 8A(4) allows an equivalent framework instead, benchmarked against the Essential Eight, C2M2 or AESCSF items.

When each part bites

Section 4A(6) provides two grace periods, split by provision rather than by theme.

12 monthss 6A, and subsections 8A(2) and 9A(2)
24 monthsss 8A (other than 8A(2)), 8B, 8C, 9A (other than 9A(2)), 10A and 11A

For an asset that was already a critical infrastructure asset when the rules commenced on 10 June 2026, that puts the first tranche around June 2027 and the second around June 2028. For an asset that becomes a critical infrastructure asset on or after 10 June 2026, the same 12 and 24 months run from the date that asset became a critical infrastructure asset — not from commencement. Two organisations in the same sector can therefore be on different clocks.

What this asks of the architecture

Read as an engineering brief rather than a compliance list, the sections cluster into three questions the drawings have to answer. Section 8C asks what is segregated from what, and how that is enforced rather than asserted. Sections 8A and 8B ask what happens where a device cannot be patched and where a credential cannot be made phishing-resistant — which, in a plant, is a design question about placement and mediation, not a policy question. Sections 6A and 10A ask who can reach the asset from outside it, including the vendors you have already granted access to.

None of those are answerable from a policy document. They are answerable from a zone and conduit model, a data-flow diagram, and an honest inventory of remote access.

Sources

Every statement on this page traces to one of these. Position as at August 2026. This is architecture advice, not legal advice — check your own asset class and obligations.

Two clocks, and the drawings decide how long the work takes.

If your asset is in one of the nine classes, the useful question is not which framework to name — it is whether the segregation, remote access and patching positions can be evidenced from what you already have.

Or email info@radconsulting.au.