Skip to main content

CIRMP

What is CIRMP?

Critical Infrastructure Risk Management Program

The risk management program that responsible entities must establish and maintain under the SOCI Act. The CIRMP Rules 2023 set the baseline requirements. The Enhanced CIRMP Rules, which commenced in June 2026, raise those requirements substantially for a set of named asset classes, with staged compliance deadlines in June 2027 and June 2028. Cyber security framework compliance falls in the later of the two.

What the program has to do

It must identify each hazard where there is a material risk of a relevant impact on the asset, and establish a process to minimise or eliminate that risk so far as is reasonably practicable. It must also describe how the asset interacts with assets operated by other responsible entities.

The obligation is to run a process, not to hold a document. A program that was accurate when written and has not been reviewed since does not satisfy it.

All hazards, not just cyber

Five hazard vectors are in scope: cyber and information security, personnel, physical security, natural hazards, and supply chain. Programs scoped around cyber alone address roughly a fifth of the obligation, and that is the most common finding on review.

The Enhanced CIRMP Rules

The Enhanced CIRMP Rules commenced in June 2026 and create a two-tier structure: baseline requirements, and enhanced requirements that sit on top for nine named asset classes. Where the two conflict, the enhanced requirement prevails.

The enhanced tier raises the cyber maturity target a level, and adds phishing-resistant multi-factor authentication, logging, network segregation for critical systems, and explicit treatment of unsupported and legacy systems. Deadlines fall in June 2027 and June 2028, with cyber framework compliance in the later one.

Read more

See also

Search all glossary terms

O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.