What is this, in plain English?
The regulation. The problem today. What cirmp AI does.
The regulation
SOCI Act 2018, s.30AC, requires responsible entities of covered asset classes to maintain a written Critical Infrastructure Risk Management Program. The board attests once a year under s.30AG. False or misleading attestation carries civil penalty exposure.
The problem today
The pack is assembled by hand. Spreadsheets, SharePoint folders, vendor exports, a consultancy retainer. Cost lands somewhere between an annual audit and a small refurb. Same scramble next year.
What cirmp AI does
It is being built to read the security and IT tool exports you already produce, draft the four-hazard CIRMP report with a citation for every line, and let your CISO and board sign the SHA-256-sealed PDF. Continuous, not annual. Watch the engine demo run a pack end to end.
What you walk away with
One signed PDF. Four hazard domains.
One pack. Every line cited. The board attests to a single signed artefact your regulator can verify offline.
Reasoning trail · 4 citations
AESCSF framework mapping
IDM 02:14
Entra ID. MFA policy
IDM 02:21
Entra ID. Privileged users
IDM 02:21
CrowdStrike Falcon. March cycle
IDM 02:28
●Cyber and information security
The risks of an attack or breach landing on the asset's systems.
●Personnel
The risks from people inside or close to the operation. Insider threat, hiring practice, training gaps.
●Supply chain
The risks from suppliers and vendors that touch the asset.
●Physical and natural
The risks from physical attack, sabotage, fire, flood, and other natural hazards.
Enhanced Rules 2026
What changed on 10 June 2026.
The Enhanced CIRMP Rules 2026 were registered on 9 June 2026 and commenced the day after. They keep the four hazard categories. They make the obligations inside them more prescriptive. If your CIRMP was written before 10 June 2026, it does not yet evidence the new credential, access and network-segregation controls. The next board attestation is signed against the enhanced rules.
●Cyber and information security (s8)
Phishing-resistant MFA with central logging. Network segregation of critical systems. Addressing legacy and emerging technology risk, including AI. A lift to MIL-2 of a prescribed maturity framework.
●Personnel (s9)
Tighter control of credentials and privileged access. Less unauthorised or unescorted access to critical components. The enhanced rules are reported to introduce stronger vetting of onshore critical workers.
●Supply chain (s10)
Mapping major suppliers and critical components. A foreign ownership, control or influence (FOCI) assessment. Diversification and recovery planning.
●Physical and natural (s11)
A physical security plan with continuous access monitoring.
Grace periods of 12 and 24 months from commencement apply to different obligations. Entities working towards MIL-2 are reported to be working to a 2028 compliance window, with the exact dates being confirmed. cirmp AI is being built to evidence these obligations and produce an attestation-ready pack. It does not make you compliant. That accountability stays with the responsible entity and its board.
Engine demo
See the engine assemble a pack →
Pick an entity. Watch ingest, four-hazard assembly, and SHA-256 seal run end to end in real time.
What it costs you
Continuous engagement. Not a one-off audit.
Two parts. Implementation up front, sized to your environment. Then four CIRMP cycles a year, engine always on between them. We don't publish dollar figures on this page. Talk to us about pricing.
Talk to us about pricing →The next cycle
Twenty minutes.
See it assemble itself.
See a sample CIRMP pack assembled live from real-world exports.