Read the regime as a funnel
11 sectors. 22 asset classes. 13 carry the full CIRMP.
sectors named in the Act.
critical asset classes defined.
classes carry the full CIRMP.
Section 9 of the Act names 22 critical infrastructure asset classes across 10 of those sectors. The 11th sector, Space Technology, is named at section 8D of the Act but currently has no critical asset class defined. The Definitions Rules (LIN 21/039) prescribe the thresholds and detail for a subset of them. The CIRMP Rules (LIN 23/006) switch the full risk management program obligation on for 13. Since 10 June 2026, 9 of those 13 also carry enhanced requirements under section 4A of the CIRMP Rules, in addition to the baseline.
Run the scope check →Three activities
Check scope. Test yourself. Spot the gaps.
Is my asset in scope?
Walk the decision tree for an asset class and get a scope verdict with the obligations that apply.
Open →Test your understanding
A short quiz on obligations, penalties, hazards and frameworks, with an explanation and a source for every answer.
Open →Spot what is missing
Read a worked annual report with sections withheld, then identify the required sections that are absent.
Open →The regime in context
The rest of the regime, in one line each.
The site already covers these in full. Follow the link for the detail.
Four hazards
A CIRMP must address cyber, personnel, supply chain, and physical and natural hazards. The failure patterns for each live in the anti-patterns guide.
Anti-patterns →Framework selection
The cyber-hazard requirement can be met against a recognised framework. See how the choice plays out on the home page.
Frameworks →Penalties and the stack
Civil penalties attach to the program, the annual report, incident reporting and directions, alongside the wider regulatory stack.
Policy →A finished CIRMP
One signed pack across four hazard domains, every line cited. See what the finished artefact looks like.
Overview →How the regime grew
A chronology, 2018 to 2026.
- 2018
The original SOCI Act. Narrow scope: a register of critical infrastructure assets and an information-gathering power, covering a handful of sectors (electricity, gas, water, ports).
- 2021
SLACI Act (Security Legislation Amendment (Critical Infrastructure) Act 2021). First major expansion: from four sectors to eleven, mandatory cyber incident reporting, and government assistance (step in) powers. The 22 asset classes are named in section 9 of the Act. Definitions Rules LIN 21/039 prescribe the thresholds and detail for a subset of them.
- 2022
SLACIP Act (Security Legislation Amendment (Critical Infrastructure Protection) Act 2022). Added the two heavyweight obligations: the CIRMP (s.30AC) and enhanced obligations for Systems of National Significance (Part 2A and ECSO).
- 2023
CIRMP Rules (LIN 23/006) switched on. The risk management program obligation became live on 17 February 2023, with a grace period. The 13 CIRMP asset classes are set by the Rules, not the Act.
- 2024
ERP Act (Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024), commenced 20 December 2024. Consequence management, protected information reforms, business critical data brought into scope, a written direction power against a deficient program, and the lead-in to the 2025 rules. Penalty unit rose to $330 from 7 November 2024.
- 2025
2025 Measures No. 1 Rules and the telecommunications rules. From 4 April 2025, amendments clarified CIRMP obligations. A dedicated telecommunications security regime sits in Part 2D and the Security of Critical Infrastructure (Telecommunications Security and Risk Management Program) Rules 2025 (LIN 25/010, F2025L00325), commenced 11 March 2025.
- 2026
Enhanced CIRMP Rules 2026 (LIN 26/075, F2026L00701). Made 4 June 2026, registered 9 June 2026, commenced 10 June 2026. A new section 4A splits the 13 CIRMP asset classes into 9 that carry enhanced requirements and 4 that do not. The 9 are broadcasting, domain name system, electricity, energy market operator, freight infrastructure, freight services, gas, liquid fuel and water. Enhanced applies in addition to baseline, and where the two conflict the enhanced requirement wins. New sections 6A, 8A, 8B, 8C, 9A, 10A and 11A add material-risk, cyber, credential compromise, lateral movement, personnel, supply chain and physical requirements. The enhanced cyber framework table lifts Essential Eight to Maturity Level 2. For an asset that was already a critical infrastructure asset on 10 June 2026, the Cyber and Infrastructure Security Centre gives the compliance date for sections 6A, 8A(2) and 9A(2) as 10 June 2027, and for the remaining enhanced provisions as 10 June 2028.
Important. General information only, not legal advice. This tool cannot tell you whether an obligation applies to your organisation. Current as at 7 August 2026 against SOCI Act Compilation No. 9 and CIRMP Rules Compilation No. 2 (F2026C00562) on legislation.gov.au. The Enhanced CIRMP Rules 2026 (LIN 26/075, F2026L00701) commenced on 10 June 2026. They add enhanced requirements for nine of the thirteen asset classes that carry a CIRMP. They also reach an asset privately declared under section 51 of the Act on or after that date. Enhanced requirements sit on top of the baseline requirements. They do not replace them. The baseline cyber framework table at section 8(4) is unchanged. The separate enhanced table at section 8A(3) names newer framework versions and higher levels, including Essential Eight Maturity Level 2. Grace periods delay parts of the enhanced regime. For an asset that was already a critical infrastructure asset on 10 June 2026, the Cyber and Infrastructure Security Centre gives the compliance date for sections 6A, 8A(2) and 9A(2) as 10 June 2027. For the remaining enhanced provisions it gives 10 June 2028. An asset that becomes a critical infrastructure asset after 10 June 2026 gets 12 months and 24 months from that later date instead. Check your own asset classification and read the latest compilation before you rely on any figure here.
The next cycle
Twenty minutes.
See it assemble itself.
See a sample CIRMP pack assembled live from real-world exports.