The research

Built on a published evidence base, not a hunch.

Three numbers that frame the obligation, the threat picture and the Essential Eight maturity gap. Each one is publicly sourced and dated. Open the source, read the original, draw your own line.

11 / 22 / 13

SOCI sectors, critical infrastructure asset classes, and the classes that carry a full CIRMP. Since 10 June 2026, nine of those thirteen also carry enhanced requirements under s.4A of the CIRMP Rules.

SOCI Act 2018 s.9 (C2026C00213) · CIRMP Rules ss.4 and 4A (F2026C00562)

13%

of the cyber security incidents ASD responded to in 2024-25 involved critical infrastructure, out of more than 1,200. Financial services, transport and logistics, and telecommunications were the most-targeted sectors.

ASD Annual Cyber Threat Report 2024-25

22%

of Commonwealth entities reached Essential Eight Maturity Level 2 in 2025, up from 15 per cent. 59 per cent cite legacy technology as a blocker, down from 71 per cent. CIRMP responsible entities sit at Maturity Level 1 under s.8(4), rising to Maturity Level 2 for the nine enhanced classes from 10 June 2028.

The Commonwealth Cyber Security Posture in 2025

See the regulatory stack on /policy.

Ready to look inside

See cirmp AI run on a real CIRMP cycle.

Three minutes inside the demo. A live walkthrough on request. You will see what the next CIRMP attestation looks like when it writes itself.

See the live demo Back to overview