Australia’s Enhanced CIRMP Rules (2026)
The Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 commenced on 10 June 2026 under the Security of Critical Infrastructure (SOCI) Act 2018. These changes introduce more prescriptive and detailed obligations for operators of critical infrastructure assets, significantly raising expectations around risk management, cyber security, personnel security, supply chain resilience, and operational continuity.
What’s changed under the updated CIRMP rules
What does this mean for your organisation? Rather than a principles-based framework, CIRMP now requires operators to demonstrate structured, evidence-based controls across defined risk areas, with a stronger focus on national security and system resilience.
The updated CIRMP requirements represent a significant shift from a predominantly principles-based approach to a more prescriptive and enforceable compliance framework for responsible entities operating 9 critical infrastructure assets across multiple sectors.
Under the revised CIRMP Rules, responsible entities are expected to undertake a phased transition toward compliance, with initial implementation milestones occurring within 12 months and broader alignment with the enhanced requirements expected within 24 months.
These transition periods are intended to support entities in embedding the updated governance, risk management and security controls required under the strengthened CIRMP framework.
Who is affected
The Enhanced CIRMP Rules introduce an additional tier of requirements that must be met in developing a CIRMP for the following types of critical infrastructure assets:
- Electricity, gas, water, and liquid fuel systems
- Energy market operators
- Freight, transport infrastructure, and transport services
- Broadcasting services
- Domain name system providers
These asset classes were brought under strengthened requirements due to their importance to national continuity and essential services.
Key changes in the 2026 CIRMP update
Expanded risk categories
Operators must explicitly identify and manage a broader set of risks, including:
- Foreign ownership, control, or influence (FOCI)
- Offshore or remote access to critical components and business data
- Risks to national security, economic stability, and essential services
Stronger cyber security requirements
CIRMP introduces more detailed cyber security expectations:
- Phishing-resistant multi-factor authentication
- Centralised logging and monitoring across systems
- Stronger management of legacy and unpatched systems
- Network segmentation to contain incidents and maintain continuity
- Consideration of emerging risks such as AI-enabled threats
Enhanced personnel security requirements
Also effective under the June 2026 updates, operators must strengthen workforce assurance, including:
- Unauthorised or unsupervised access to critical components
- Compromise or misuse of credentials and privileged access used by individuals
- Access to the CI asset by persons other than critical workers
- In particular, the new CIRMP Rules require critical workers to undergo an AusCheck background check or hold a Negative Vetting 1 (or higher) security clearance to be deemed suitable for access to critical components of an asset.
Supply chain risk management obligations
The reforms expand expectations for third-party risk oversight, requiring operators to:
- Map critical suppliers and dependencies
- Identify associated risks to critical components and business-critical data
- Determine acceptable outage thresholds
- Strengthen redundancy and diversification of key inputs
- Improve oversight of outsourced services and components
Integration of cyber, physical, and supply chain security
The Enhanced CIRMP Rules require responsible entities to adopt an integrated, all-hazards approach to risk management. Physical security must be centrally managed alongside natural hazard risks, with organisations required to consider the physical security impacts arising from cyber, supply chain and other hazard domains. The rules also strengthen expectations for physical security planning, site security documentation, physical access controls and continuous monitoring to improve the resilience of critical infrastructure assets.
Compliance impact and timelines
The CIRMP updates that commenced in June 2026 significantly increase compliance obligations. Organisations are expected to:
- Update existing CIRMP documentation
- Undertake detailed gap assessments against new requirements
- Begin uplift planning immediately
While compliance deadlines are staged, with some obligations extending into 2027-2028 depending on asset class, regulators expect operators to start implementation planning without delay.
Mid-2027: First Tranche requirements: the first wave of enhanced obligations comes into force. This includes new patching measures, legacy technology management, initial security personnel checks, and addressing material risks from emerging hazards.
Mid-2028: Tranche 2 implementation commences as the extended transition periods expire, bringing the most complex cyber security requirements into effect. These include mandatory network segmentation to ensure critical systems can remain operational for at least three months during a cyber incident, and the implementation of phishing-resistant multi-factor authentication.
What this means for operators
The June 2026 CIRMP reforms mark a significant shift towards a more prescriptive, enforceable and resilience-focused regulatory framework for Australia’s critical infrastructure. The reforms apply to responsible entities for critical infrastructure assets across multiple sectors, with energy operators among those most significantly affected due to strengthened cyber security, personnel security, supply chain risk management and physical security obligations.
With the enhanced rules now in effect, organisations should already be advancing their compliance programs to meet strengthened requirements for governance, assurance and evidence-based compliance, including:
Governance: Increased Board and executive accountability for oversight, approval and ongoing management of the CIRMP.
Assurance: Greater emphasis on validating that security controls are implemented, tested, reviewed and demonstrably effective, not merely documented.
Evidence-based compliance: Responsible entities must maintain objective evidence that controls are operating as intended and support compliance through testing results, governance records, reviews and annual Board-approved attestations.
For relevant energy sector responsible entities, the enhanced rules require uplift against the Australian Energy Sector Cyber Security Framework (AESCSF), including achievement of Maturity Indicator Level 2 (MIL-2) across applicable domains by 30 June 2028.
This represents a substantial increase in governance, risk management and operational cyber security expectations across the sector.
BOOK 1-HOUR DISCOVERY SESSION
If your organisation is navigating Enhanced CIRMP obligations or broader SOCI Act compliance requirements, our team can help.
For a limited time, we’re offering a complimentary one-hour discovery session to help critical infrastructure organisations understand regulatory requirements, assess cybersecurity maturity, identify compliance gaps, and define practical, risk-based steps to strengthen resilience.