CIRMP
What is CIRMP?
Critical Infrastructure Risk Management Program
The risk management program that responsible entities must establish and maintain under the SOCI Act. The CIRMP Rules 2023 set the baseline requirements. The Enhanced CIRMP Rules, which commenced in June 2026, raise those requirements substantially for a set of named asset classes, with staged compliance deadlines in June 2027 and June 2028. Cyber security framework compliance falls in the later of the two.
What the program has to do
It must identify each hazard where there is a material risk of a relevant impact on the asset, and establish a process to minimise or eliminate that risk so far as is reasonably practicable. It must also describe how the asset interacts with assets operated by other responsible entities.
The obligation is to run a process, not to hold a document. A program that was accurate when written and has not been reviewed since does not satisfy it.
All hazards, not just cyber
Five hazard vectors are in scope: cyber and information security, personnel, physical security, natural hazards, and supply chain. Programs scoped around cyber alone address roughly a fifth of the obligation, and that is the most common finding on review.
The Enhanced CIRMP Rules
The Enhanced CIRMP Rules commenced in June 2026 and create a two-tier structure: baseline requirements, and enhanced requirements that sit on top for nine named asset classes. Where the two conflict, the enhanced requirement prevails.
The enhanced tier raises the cyber maturity target a level, and adds phishing-resistant multi-factor authentication, logging, network segregation for critical systems, and explicit treatment of unsupported and legacy systems. Deadlines fall in June 2027 and June 2028, with cyber framework compliance in the later one.
Read more
- What Your TSRMP Needs to Contain for Telco Assets
Telecommunications assets have specific requirements under the SOCI Act TSRMP framework. What the risk management program needs to cover and where most entities leave gaps.
- The Essential Eight Is Being Retired: What It Means for Your CIRMP Nomination
ASD will retire the Essential Eight within about two years, replacing it with a domain-split Essentials series that includes an operational technology chapter. The Enhanced CIRMP Rules give you until June 2028 to comply with a nominated framework. Those two clocks overlap, and it changes what you should nominate.
See also
- SOCI Security of Critical Infrastructure Act 2018 Australian federal legislation, often searched for as the Security of Critical Infrastructure Act, that imposes positive security obligations on entities responsible for critical infrastructure assets across 11 sectors.
- E8 Essential Eight Eight mitigation strategies published by the Australian Signals Directorate: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups.
- AESCSF Australian Energy Sector Cyber Security Framework A cyber security framework maintained by AEMO for the Australian energy sector, adapted from the US DOE C2M2.
- TSRMP Telecommunications Security Risk Management Program A specialised risk management program required under the TSRMP Rules 2025 for responsible entities operating critical telecommunications assets.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.