Overview · for boards and procurement

If you sign the attestation, this is for you.

cirmp AI is an Australian-owned compliance engine being built to write the Critical Infrastructure Risk Management Program (CIRMP) pack the board signs every year. It reads the security and IT tool exports you already produce. It assembles the four-hazard report. Your CISO signs. The board attests.

What is this, in plain English?

The regulation. The problem today. What cirmp AI does.

01

The regulation

SOCI Act 2018, s.30AC, requires responsible entities of covered asset classes to adopt and maintain a written Critical Infrastructure Risk Management Program. The responsible entity gives an annual report under s.30AG, and the board approves it first. Failing to give the report carries a civil penalty. Knowingly giving false or misleading information is a criminal offence under the Criminal Code.

02

The problem today

The pack is assembled by hand. Spreadsheets, SharePoint folders, vendor exports, a consultancy retainer. Cost lands somewhere between an annual audit and a small refurb. Same scramble next year.

03

What cirmp AI does

It is being built to read the security and IT tool exports you already produce, draft the four-hazard CIRMP report with a citation for every line, and let your CISO and board sign the SHA-256-sealed PDF. Continuous, not annual. Watch the engine demo run a pack end to end.

What you walk away with

One signed PDF. Four hazard domains.

One pack. Every line cited. The board attests to a single signed artefact your regulator can verify offline.

● Illustrative · pre-release preview

Illustrative pack · Energy entity

CIRMP attestation · Q3 FY26

Northern Water Authority
s.30AG annual attestation

p. 1 / 84

14 Mar 2026

4.2   Cyber and information security hazard

The responsible entity maintains a cyber security framework aligned to AESCSF[A]covering its operational technology estate. Identity controls enforce multi-factor authentication for users of the organisation's online services that hold sensitive data per Essential Eight Maturity Level 1[B], evidenced by Microsoft Entra exports dated 11 Mar 2026[C]. Patch cadence for internet-facing services remains within 48 hours (CrowdStrike Falcon, March cycle)[D].

4.2.1   Material risks identified

  • Legacy SCADA at Mt Crawford. Vendor support to Dec 2027. Compensating control: segregated VLAN, OT firewall ruleset frozen.
  • Third-party SIEM access reduced from 7 to 2 named operators following Mar 4 review.
SHA-256 · 9f3c…b14e● sealed

Reasoning trail · 4 citations

A

AESCSF framework mapping

aescsf-v2-mapping.xlsx

IDM 02:14

B

Entra ID. MFA policy

entra-export-2026-03-11.json

IDM 02:21

C

Entra ID. Privileged users

priv-users-2026-03-11.csv

IDM 02:21

D

CrowdStrike Falcon. March cycle

falcon_posture_export_apr_2026.csv

IDM 02:28

offline-verifiableview all 271 →

Cyber and information security

The risks of an attack or breach landing on the asset's systems.

Personnel

The risks from people inside or close to the operation. Insider threat, hiring practice, training gaps.

Supply chain

The risks from suppliers and vendors that touch the asset.

Physical and natural

The risks from physical attack, sabotage, fire, flood, and other natural hazards.

Enhanced Rules 2026

What changed on 10 June 2026.

The Enhanced CIRMP Rules 2026 were registered on 9 June 2026 and commenced the day after. They keep the four hazard categories. They make the obligations inside them more prescriptive. They reach nine of the thirteen asset classes that carry a CIRMP, not all of them. If your CIRMP was written before 10 June 2026, it does not yet evidence the new credential, access and network-segregation controls. Grace periods hold the enhanced provisions back. The annual report for FY2025-26, due within 90 days after 30 June 2026, does not need to carry the enhanced material. The first report that can speak to sections 6A, 8A(2) and 9A(2) is FY2026-27. The full enhanced set lands in FY2027-28.

Cyber and information security (ss.8A, 8B and 8C)

Phishing-resistant multi-factor authentication with central logging, at s.8B(3) and (5). Network segregation of critical systems, at s.8C(3) and (4). Legacy systems, and advanced, novel or emerging technology risk, at s.8A(2)(b) to (d). A separate framework table at s.8A(3), which names AS ISO/IEC 27001:2023, the Essential Eight at Maturity Level 2, NIST CSF 2.0, C2M2 version 2.1 at Maturity Indicator Level 2, and the 2023 AESCSF Framework Core at Security Profile 2.

Personnel (s.9A)

A critical worker may be permitted access to critical components only if assessed suitable following an AusCheck background check, or if they hold an active Australian Government security clearance at Negative Vetting 1 or higher. Where a worker cannot meet that test, the responsible entity must record in its CIRMP the risk of employing them. Ongoing-access checks are redone at least every 5 years. Unauthorised, unescorted or privileged access to critical components is minimised.

Supply chain (s.10A)

Mapping major suppliers and critical components. A foreign ownership, control or influence (FOCI) assessment. Supply chain risks identified, with a maximum acceptable outage and measures to minimise or eliminate them.

Physical and natural (s.11A)

Access to critical components restricted to critical workers or accompanied visitors, with surveillance and alarm systems giving continuous monitoring of critical components and critical systems.

Section 4A(6) gives 12 months from commencement for sections 6A, 8A(2) and 9A(2), and 24 months for the rest of the enhanced set. For an asset that was already a critical infrastructure asset on 10 June 2026, that is 10 June 2027 and 10 June 2028. cirmp AI is being built to evidence these obligations and produce an attestation-ready pack. It does not make you compliant. That accountability stays with the responsible entity and its board.

Engine demo

See the engine assemble a pack →

Pick an entity. Watch ingest, four-hazard assembly, and SHA-256 seal run end to end in real time.

Try the engine

What it costs you

Continuous engagement. Not a one-off audit.

Two parts. Implementation up front, sized to your environment. Then four CIRMP cycles a year, engine always on between them. We don't publish dollar figures on this page. Talk to us about pricing.

Talk to us about pricing

The next cycle

Twenty minutes.
See it assemble itself.

See a sample CIRMP pack assembled live from real-world exports.

Book a walkthrough See the live demo