Scope check

Is my asset in scope?

Pick a sector and an asset class, then answer the questions. The verdict comes straight from the asset-class definitions. This is information, not a finding about your entity.

Important. General information only, not legal advice. This tool cannot tell you whether an obligation applies to your organisation. Current as at 7 August 2026 against SOCI Act Compilation No. 9 and CIRMP Rules Compilation No. 2 (F2026C00562) on legislation.gov.au. The Enhanced CIRMP Rules 2026 (LIN 26/075, F2026L00701) commenced on 10 June 2026. They add enhanced requirements for nine of the thirteen asset classes that carry a CIRMP. They also reach an asset privately declared under section 51 of the Act on or after that date. Enhanced requirements sit on top of the baseline requirements. They do not replace them. The baseline cyber framework table at section 8(4) is unchanged. The separate enhanced table at section 8A(3) names newer framework versions and higher levels, including Essential Eight Maturity Level 2. Grace periods delay parts of the enhanced regime. For an asset that was already a critical infrastructure asset on 10 June 2026, the Cyber and Infrastructure Security Centre gives the compliance date for sections 6A, 8A(2) and 9A(2) as 10 June 2027. For the remaining enhanced provisions it gives 10 June 2028. An asset that becomes a critical infrastructure asset after 10 June 2026 gets 12 months and 24 months from that later date instead. Check your own asset classification and read the latest compilation before you rely on any figure here.