Courtroom Dispatches

New Rules Bolster Protection of Critical Infrastructure

By 16/07/2026 4 min read 8 views
New Rules Bolster Protection of Critical Infrastructure - critical infrastructure rules
New Rules Bolster Protection of Critical Infrastructure

Australia’s Department of Home Affairs has registered enhanced Critical Infrastructure Risk Management Program (CIRMP) rules that significantly strengthen security obligations for high-risk critical infrastructure assets. The new framework introduces stricter requirements for cyber security, personnel vetting, supply chain management, and physical security across sectors including energy, telecommunications, water, and transport.

The enhanced CIRMP Rules commenced on 10 June 2026, and responsible entities have either 12 or 24 months to implement the uplifted requirements (depending on the particular requirement). The rules build upon the existing CIRMP framework and apply to a sub-set of high-risk asset classes already required to maintain a CIRMP under Part 2A of the Security of Critical Infrastructure Act 2018 (SOCI Act).

The following asset classes are covered:

Related: Corporate fraud cases rise in July 2026

      • Critical data storage or processing asset
      • Critical energy market operator asset
      • Critical telecommunications assets (via separate rules and telecommunications guidance)
      • Critical food and grocery assets
      • Critical freight infrastructure assets
      • Critical freight services assets
      • Critical financial market infrastructure assets used in the operation of a payment system
      • Assets declared to be critical infrastructure assets under s 51 of the Act

For assets that become critical infrastructure (CI) assets on or after 10 June 2026, the relevant grace period will run from the date the asset becomes a CI asset.

Under s 6A of the enhanced CIRMP Rules, entities are now required to ‘establish and maintain a process or system’ that minimises or eliminates material risks as far as is reasonably practicable. This includes risks associated with Australia’s social and economic stability, national security or defence, foreign ownership, control or influence (FOCI), and offshore or remote access to critical components or business-critical data.

The enhanced CIRMP Rules have increased compliance requirements since the exposure draft, adding an obligation to establish new or reform current processes to minimise or eliminate an expanded list of material risks. These expanded risks include any impairment of the CI asset’s functions that could prejudice Australia’s social stability, economic stability, national security or defence, compromise or impairment of the functions of the CI asset as a result of, or in connection with, FOCI, and offshore or remote access to critical components or business critical data.

Related: De Brauw closes Shanghai office after 16 years

Entities must now establish and maintain a process or system in their CIRMP to, so far as is reasonably practicable, minimise or eliminate each of these specified material risks. This obligation must be met on or before 10 June 2027.

The enhanced CIRMP Rules now require that all ‘critical workers’ be assessed as suitable via either an AusCheck background check or by holding a relevant security clearance. This is defined as an active security clearance at Negative Vetting 1 level or higher, issued by an Australian Government entity.

Any critical worker unable to meet these requirements can still be granted access to the relevant critical asset, provided the entity’s CIRMP outlines the associated risks and relevant actions that have been taken, or will be taken as soon as is reasonably practicable, to minimise or eliminate the identified risks. The Explanatory Statement clarifies that ‘unable to meet the requirements’ refers to circumstances where an AusCheck background check or security clearance cannot be obtained (particularly, for offshore workers or due to processing delays) rather than where a worker has undergone and failed a check. The exception permits a risk-based approach in the interim, while awaiting finalisation of checks and clearances, suggesting that the provision operates as a transitional measure rather than a permanent bypass.

Related: AI and private capital spur boutique growth

Under section 8A(3), responsible entities must establish and maintain a process or system in their CIRMP that complies with one of the frameworks identified (AS ISO/IEC 27001, Essential Eight, NIST CSF 2.0, C2M2, AESCSF). However, equivalence can only be demonstrated against items 2, 4 or 5 of the framework table (Essential Eight, C2M2, AESCSF), excluding AS ISO/IEC27001 and NIST CSF 2.0 as equivalence benchmarks from the exposure draft.

The Australian Signals Directorate (ASD) has announced it intends to phase out the Essential Eight framework within the next two years, replacing it with the new ‘Essentials’ series, which will be adapted to modern technology environments. The ASD has indicated the Essential Eight will remain a live document during a transition period before being deprecated and ultimately retired. The remaining changes will need to be implemented within 24 months of commencement (that is, on or before 10 June 2028).

For entities that have elected to comply with a security framework that does not already mandate phishing-resistant MFA controls, the enhanced CIRMP Rules now require the establishment of a process or system in their CIRMP to outline where phishing-resistant MFA is required to authenticate access to internet connected computers and critical systems, privileged and unprivileged access to critical components, and remote access to computer applications, systems or services.

Leave a Comment

Your email address will not be published. Required fields are marked *