The SOCI Act and the CIRMP obligation.
What the law requires of a critical infrastructure risk management program, stated from the instruments rather than from summaries of them.
Where the obligation sits
The governing legislation is the Security of Critical Infrastructure Act 2018 (Cth). The critical infrastructure risk management program obligation sits in Part 2A of that Act, and the detailed requirements are set by the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023, made under section 61.
Part 2A was inserted by the Security Legislation Amendment (Critical Infrastructure Protection) Act 2022, which received assent on 1 April 2022. But Part 2A does not apply to an asset class until the rules specify it. The CIRMP Rules were registered on 16 February 2023 and commenced on 17 February 2023, specifying thirteen asset classes, with a six-month grace period.
What a program has to address
The Rules require a program to address the hazard categories in Part 2. For entities under the baseline rules there are four.
- s 8Cyber and information security hazardsAdopt and maintain a process or system that complies with one of five named frameworks, and meet the condition attached to it.
- s 9Personnel hazardsIdentify critical workers, manage the risk they present, and cover on-boarding and off-boarding.
- s 10Supply chain hazardsIdentify and manage risk arising from suppliers and the services they provide into the asset.
- s 11Physical security and natural hazardsPhysical access to the asset, and the natural hazards its location exposes it to.
Since the enhanced CIRMP Rules commenced on 10 June 2026, responsible entities for nine specified asset classes carry additional requirements on top of these. Those are set out separately.
The five frameworks
Under section 8 of the CIRMP Rules, a responsible entity must adopt and maintain a process or system to comply with one of five named cyber frameworks, as in force from time to time, and meet any condition attached to it.
- AS ISO/IEC 27001:2015
- ASD Essential Eight Maturity Model, at maturity level one
- NIST Framework for Improving Critical Infrastructure Cybersecurity
- US Department of Energy C2M2, at Maturity Indicator Level 1
- AESCSF Framework Core 2020–21, at Security Profile 1
Section 8(5) allows an equivalent framework instead. This matters more than it looks: the section offers a choice with an equivalence route, not a mandate, and reading it as a mandate leads organisations to adopt a framework that fits their IT estate rather than their plant.
The annual report — and who approves it
Under section 30AG(2) of the SOCI Act, a responsible entity must, within 90 days after the end of the financial year, give an annual report on its CIRMP to the relevant Commonwealth regulator if there is one with functions relating to the security of those assets, and otherwise to the Secretary. "Financial year" is not defined in the Act, so the Acts Interpretation Act 1901 meaning applies — a period of 12 months starting on 1 July — which makes the deadline 28 September.
What this means for the architecture
A CIRMP is a document about risk, but the evidence behind it is architectural. The hazard categories in sections 8 to 11 are answered by artefacts: a zone and conduit model that shows what is segregated from what, a data-flow diagram across the IT/OT boundary, an asset and communications inventory, and a risk register that maps to the hazards rather than to a generic control list.
Where those artefacts do not exist, the program tends to describe intent rather than state. That is the gap a regulator's questions find, and it is the gap our work closes.
Sources
Every statement on this page traces to one of these. Position as at August 2026. This is architecture advice, not legal advice — check your own asset class and obligations.
- Security of Critical Infrastructure Act 2018 (Cth) — Compilation No. 9Operative text
- CIRMP Rules (LIN 23/006) 2023 — Compilation No. 2Operative text
- Security Legislation Amendment (Critical Infrastructure Protection) Act 2022Operative text
- Cyber and Infrastructure Security Centre — CIRMP guidanceRegulator guidance
Does your program describe intent, or state?
The difference usually shows up in whether the drawings exist. A thirty-minute call is enough to tell which side of that line you are on.
Or email info@radconsulting.au.